diff --git a/changelog b/changelog index de0f2f802115f5f2053358bfed2372cc344870c7..0251366cb66084cd5207baf148297447f689f4c5 100644 --- a/changelog +++ b/changelog @@ -36,3 +36,12 @@ added top-level services to responses 0.20: included both v4 & v6 addresses in peering info 0.21: added parsing of 'logical-systems' (DBOARD3-150) +0.22: return a skeleton response for unknown interfaces (DBOARD3-169) +0.23: use redis pipelines where possible +0.24: optimization, don't do aggressive pre-delete checking rebuilding +0.25: propagate errors when waiting for tasks to complete +0.26: NOT SUITABLE FOR PRODUCTION! filter qfx* routers until space is synced with opsdb +0.27: added some status flags to the latch structure +0.28: added latch to version response +0.29: DBOARD3-170 (don't return 404 for unrecognized peer addresses) + removed filter on qfx* routers \ No newline at end of file diff --git a/inventory_provider/juniper.py b/inventory_provider/juniper.py index 2925b7075cc6055e1c21b81e8429a2fa47030450..3e4405e4fc82f3df6d06e899bc6421e74a33c95d 100644 --- a/inventory_provider/juniper.py +++ b/inventory_provider/juniper.py @@ -3,6 +3,7 @@ import re import ipaddress from jnpr.junos import Device +from jnpr.junos import exception as EzErrors from lxml import etree import netifaces import requests @@ -55,6 +56,7 @@ CONFIG_SCHEMA = """<?xml version="1.1" encoding="UTF-8" ?> <xs:sequence> <xs:choice minOccurs="1" maxOccurs="unbounded"> <xs:element name="apply-groups" minOccurs="0" type="xs:string" /> + <xs:element name="interface-range" minOccurs="0" type="generic-sequence" /> <xs:element name="interface" minOccurs="1" maxOccurs="unbounded" type="juniper-interface" /> </xs:choice> </xs:sequence> @@ -69,6 +71,9 @@ CONFIG_SCHEMA = """<?xml version="1.1" encoding="UTF-8" ?> <xs:element name="firewall" minOccurs="0" type="generic-sequence" /> <xs:element name="routing-instances" minOccurs="0" type="generic-sequence" /> <xs:element name="bridge-domains" minOccurs="0" type="generic-sequence" /> + <xs:element name="virtual-chassis" minOccurs="0" type="generic-sequence" /> + <xs:element name="vlans" minOccurs="0" type="generic-sequence" /> + <xs:element name="comment" minOccurs="0" type="xs:string" /> </xs:choice> </xs:sequence> <xs:attribute name="changed-seconds" type="xs:string" /> @@ -156,7 +161,10 @@ def _rpc(hostname, ssh): host=hostname, user=ssh['username'], ssh_private_key_file=ssh['private-key']) - dev.open() + try: + dev.open() + except EzErrors.ConnectError as e: + raise ConnectionError(str(e)) return dev.rpc @@ -209,6 +217,8 @@ def list_interfaces(netconf_config): """ def _ifc_info(e): + # warning: this structure should match the default + # returned from routes.classifier.juniper_link_info name = e.find('name') assert name is not None, "expected interface 'name' child element" ifc = { diff --git a/inventory_provider/routes/classifier.py b/inventory_provider/routes/classifier.py index 2798b431a461d5ad55732a4a57bcca0955387f48..c62c50eea7313d7c21403948da53132e33d13591 100644 --- a/inventory_provider/routes/classifier.py +++ b/inventory_provider/routes/classifier.py @@ -107,6 +107,16 @@ def get_juniper_link_info(source_equipment, interface): 'netconf-interfaces:%s:%s' % (source_equipment, interface)) if ifc_info: result['interface'] = json.loads(ifc_info.decode('utf-8')) + else: + # warning: this should match the structure returned by + # juniper:list_interfaces:_ifc_info + result['interface'] = { + 'name': interface, + 'description': '', + 'bundle': [], + 'ipv4': [], + 'ipv6': [] + } def _related_services(): for related in related_interfaces(source_equipment, interface): @@ -123,12 +133,14 @@ def get_juniper_link_info(source_equipment, interface): related_services.extend(top_level_services) result['related-services'] = related_services - if not result: - return Response( - response="no available info for {} {}".format( - source_equipment, interface), - status=404, - mimetype="text/html") + # no longer possible, now that at least 'interface' is + # returned for unknown interfaces + # if not result: + # return Response( + # response="no available info for {} {}".format( + # source_equipment, interface), + # status=404, + # mimetype="text/html") result = json.dumps(result) # cache this data for the next call @@ -260,11 +272,11 @@ def peer_info(address): if interfaces: result['interfaces'] = interfaces - if not result: - return Response( - response='no peering info found for %s' % address, - status=404, - mimetype="text/html") + # if not result: + # return Response( + # response='no peering info found for %s' % address, + # status=404, + # mimetype="text/html") result = json.dumps(result) # cache this data for the next call diff --git a/inventory_provider/routes/default.py b/inventory_provider/routes/default.py index 5b4c6b92c4d1b6a87d97b175beb40cee4932612b..d7f1e897ed91f982a69b6a1d56f29f5fac471cad 100644 --- a/inventory_provider/routes/default.py +++ b/inventory_provider/routes/default.py @@ -1,7 +1,8 @@ import pkg_resources -from flask import Blueprint, jsonify +from flask import Blueprint, jsonify, current_app from inventory_provider.routes import common +from inventory_provider.tasks.common import get_current_redis, get_latch routes = Blueprint("inventory-data-default-routes", __name__) @@ -16,8 +17,13 @@ def after_request(resp): @routes.route("/version", methods=['GET', 'POST']) @common.require_accepts_json def version(): - return jsonify({ + config = current_app.config["INVENTORY_PROVIDER_CONFIG"] + version_params = { 'api': API_VERSION, 'module': pkg_resources.get_distribution('inventory_provider').version - }) + } + latch = get_latch(get_current_redis(config)) + if latch: + version_params['latch'] = latch + return jsonify(version_params) diff --git a/inventory_provider/tasks/common.py b/inventory_provider/tasks/common.py index 1ded6cfeecd82d7a37eeab4230320a4f2f6b0c8e..f4492f61d3be7dfbd6a4cede91017697b3efc4d0 100644 --- a/inventory_provider/tasks/common.py +++ b/inventory_provider/tasks/common.py @@ -13,7 +13,9 @@ DB_LATCH_SCHEMA = { "properties": { "current": {"type": "integer"}, "next": {"type": "integer"}, - "this": {"type": "integer"} + "this": {"type": "integer"}, + "pending": {"type": "boolean"}, + "failure": {"type": "boolean"} }, "required": ["current", "next", "this"], "additionalProperties": False @@ -35,6 +37,20 @@ def get_latch(r): return latch +def update_latch_status(config, pending=False, failure=False): + logger.debug('updating latch status: pending={}, failure={}'.format( + pending, failure)) + + for db in config['redis-databases']: + r = _get_redis(config, dbid=db) + latch = get_latch(r) + if not latch: + continue + latch['pending'] = pending + latch['failure'] = failure + r.set('db:latch', json.dumps(latch)) + + def set_latch(config, new_current, new_next): logger.debug('setting latch: new current={}, new next={}'.format( @@ -44,7 +60,9 @@ def set_latch(config, new_current, new_next): latch = { 'current': new_current, 'next': new_next, - 'this': db + 'this': db, + 'pending': False, + 'failure': False } r = _get_redis(config, dbid=db) diff --git a/inventory_provider/tasks/worker.py b/inventory_provider/tasks/worker.py index 3d56cba4e9e5a7f49d65f89a3b84bcb0b72ef0bc..33709d1f4d0ee3b219f32b99287b726f25ce8d37 100644 --- a/inventory_provider/tasks/worker.py +++ b/inventory_provider/tasks/worker.py @@ -13,7 +13,7 @@ import jsonschema from inventory_provider.tasks.app import app from inventory_provider.tasks.common \ - import get_next_redis, latch_db, get_latch, set_latch + import get_next_redis, latch_db, get_latch, set_latch, update_latch_status from inventory_provider import config from inventory_provider import environment from inventory_provider.db import db, opsdb @@ -27,6 +27,8 @@ FINALIZER_TIMEOUT_S = 300 environment.setup_logging() +logger = logging.getLogger(__name__) + class InventoryTaskError(Exception): pass @@ -54,16 +56,18 @@ class InventoryTask(Task): logging.debug("loaded config: %r" % InventoryTask.config) def update_state(self, **kwargs): - logger = logging.getLogger(__name__) logger.debug(json.dumps( - {'state': kwargs['state'], 'meta': kwargs['meta']} + {'state': kwargs['state'], 'meta': str(kwargs['meta'])} )) super().update_state(**kwargs) + def on_failure(self, exc, task_id, args, kwargs, einfo): + logger.exception(exc) + super().on_failure(exc, task_id, args, kwargs, einfo) + -@app.task -def snmp_refresh_interfaces(hostname, community): - logger = logging.getLogger(__name__) +@app.task(base=InventoryTask, bind=True) +def snmp_refresh_interfaces(self, hostname, community): logger.debug( '>>> snmp_refresh_interfaces(%r, %r)' % (hostname, community)) @@ -76,9 +80,8 @@ def snmp_refresh_interfaces(hostname, community): '<<< snmp_refresh_interfaces(%r, %r)' % (hostname, community)) -@app.task -def netconf_refresh_config(hostname): - logger = logging.getLogger(__name__) +@app.task(base=InventoryTask, bind=True) +def netconf_refresh_config(self, hostname): logger.debug('>>> netconf_refresh_config(%r)' % hostname) netconf_doc = juniper.load_config(hostname, InventoryTask.config["ssh"]) @@ -90,9 +93,8 @@ def netconf_refresh_config(hostname): logger.debug('<<< netconf_refresh_config(%r)' % hostname) -@app.task -def update_interfaces_to_services(): - logger = logging.getLogger(__name__) +@app.task(base=InventoryTask, bind=True) +def update_interfaces_to_services(self): logger.debug('>>> update_interfaces_to_services') interface_services = defaultdict(list) @@ -105,17 +107,18 @@ def update_interfaces_to_services(): r = get_next_redis(InventoryTask.config) for key in r.scan_iter('opsdb:interface_services:*'): r.delete(key) + rp = r.pipeline() for equipment_interface, services in interface_services.items(): - r.set( + rp.set( 'opsdb:interface_services:' + equipment_interface, json.dumps(services)) + rp.execute() logger.debug('<<< update_interfaces_to_services') -@app.task -def update_equipment_locations(): - logger = logging.getLogger(__name__) +@app.task(base=InventoryTask, bind=True) +def update_equipment_locations(self): logger.debug('>>> update_equipment_locations') r = get_next_redis(InventoryTask.config) @@ -132,9 +135,8 @@ def update_equipment_locations(): logger.debug('<<< update_equipment_locations') -@app.task -def update_circuit_hierarchy(): - logger = logging.getLogger(__name__) +@app.task(base=InventoryTask, bind=True) +def update_circuit_hierarchy(self): logger.debug('>>> update_circuit_hierarchy') # TODO: integers are not JSON keys @@ -150,36 +152,39 @@ def update_circuit_hierarchy(): r = get_next_redis(InventoryTask.config) for key in r.scan_iter('opsdb:services:parents:*'): r.delete(key) - for cid, parents in parent_to_children.items(): - r.set('opsdb:services:parents:%d' % cid, json.dumps(parents)) - for key in r.scan_iter('opsdb:services:children:*'): r.delete(key) + + rp = r.pipeline() + for cid, parents in parent_to_children.items(): + rp.set('opsdb:services:parents:%d' % cid, json.dumps(parents)) for cid, children in child_to_parents.items(): - r.set('opsdb:services:children:%d' % cid, json.dumps(children)) + rp.set('opsdb:services:children:%d' % cid, json.dumps(children)) + rp.execute() logger.debug('<<< update_circuit_hierarchy') -@app.task -def update_geant_lambdas(): - logger = logging.getLogger(__name__) +@app.task(base=InventoryTask, bind=True) +def update_geant_lambdas(self): logger.debug('>>> update_geant_lambdas') r = get_next_redis(InventoryTask.config) for key in r.scan_iter('opsdb:geant_lambdas:*'): r.delete(key) with db.connection(InventoryTask.config["ops-db"]) as cx: + rp = r.pipeline() for ld in opsdb.get_geant_lambdas(cx): - r.set('opsdb:geant_lambdas:%s' % ld['name'].lower(), - json.dumps(ld)) + rp.set( + 'opsdb:geant_lambdas:%s' % ld['name'].lower(), + json.dumps(ld)) + rp.execute() logger.debug('<<< geant_lambdas') @app.task(base=InventoryTask, bind=True) def update_junosspace_device_list(self): - logger = logging.getLogger(__name__) logger.debug('>>> update_junosspace_device_list') self.update_state( @@ -203,10 +208,12 @@ def update_junosspace_device_list(self): 'message': 'found %d routers, saving details' % len(routers) }) - for k in r.keys('junosspace:*'): + for k in r.scan_iter('junosspace:*'): r.delete(k) + rp = r.pipeline() for k, v in routers.items(): - r.set(k, v) + rp.set(k, v) + rp.execute() logger.debug('<<< update_junosspace_device_list') @@ -231,7 +238,6 @@ def load_netconf_data(hostname): def clear_cached_classifier_responses(hostname=None): - logger = logging.getLogger(__name__) if hostname: logger.debug( 'removing cached classifier responses for %r' % hostname) @@ -264,25 +270,29 @@ def clear_cached_classifier_responses(hostname=None): def _refresh_peers(hostname, key_base, peers): - logger = logging.getLogger(__name__) logger.debug( 'removing cached %s for %r' % (key_base, hostname)) r = get_next_redis(InventoryTask.config) - for k in r.keys(key_base + ':*'): - # potential race condition: another proc could have - # delete this element between the time we read the - # keys and the next statement ... check for None below - value = r.get(k.decode('utf-8')) - if value: - value = json.loads(value.decode('utf-8')) - if value['router'] == hostname: - r.delete(k) - + # WARNING (optimization): this is an expensive query if + # the redis connection is slow, and we currently only + # call this method during a full refresh + # for k in r.scan_iter(key_base + ':*'): + # # potential race condition: another proc could have + # # delete this element between the time we read the + # # keys and the next statement ... check for None below + # value = r.get(k.decode('utf-8')) + # if value: + # value = json.loads(value.decode('utf-8')) + # if value['router'] == hostname: + # r.delete(k) + + rp = r.pipeline() for peer in peers: peer['router'] = hostname - r.set( + rp.set( '%s:%s' % (key_base, peer['name']), json.dumps(peer)) + rp.execute() def refresh_ix_public_peers(hostname, netconf): @@ -307,36 +317,35 @@ def refresh_interface_address_lookups(hostname, netconf): def refresh_juniper_interface_list(hostname, netconf): - logger = logging.getLogger(__name__) logger.debug( 'removing cached netconf-interfaces for %r' % hostname) r = get_next_redis(InventoryTask.config) - for k in r.keys('netconf-interfaces:%s:*' % hostname): + for k in r.scan_iter('netconf-interfaces:%s:*' % hostname): r.delete(k) - for k in r.keys('netconf-interface-bundles:%s:*' % hostname): r.delete(k) all_bundles = defaultdict(list) + + rp = r.pipeline() for ifc in juniper.list_interfaces(netconf): bundles = ifc.get('bundle', None) for bundle in bundles: if bundle: all_bundles[bundle].append(ifc['name']) - - r.set( + rp.set( 'netconf-interfaces:%s:%s' % (hostname, ifc['name']), json.dumps(ifc)) for k, v in all_bundles.items(): - r.set( + rp.set( 'netconf-interface-bundles:%s:%s' % (hostname, k), json.dumps(v)) + rp.execute() @app.task(base=InventoryTask, bind=True) def reload_router_config(self, hostname): - logger = logging.getLogger(__name__) logger.debug('>>> reload_router_config') self.update_state( @@ -418,7 +427,6 @@ def reload_router_config(self, hostname): def _derive_router_hostnames(config): - logger = logging.getLogger(__name__) r = get_next_redis(config) junosspace_equipment = set() for k in r.keys('junosspace:*'): @@ -427,7 +435,7 @@ def _derive_router_hostnames(config): junosspace_equipment.add(m.group(1)) opsdb_equipment = set() - for k in r.keys('opsdb:interface_services:*'): + for k in r.scan_iter('opsdb:interface_services:*'): m = re.match( 'opsdb:interface_services:([^:]+):.*$', k.decode('utf-8')) @@ -463,10 +471,10 @@ def launch_refresh_cache_all(config): :param config: config structure as defined in config.py :return: """ - logger = logging.getLogger(__name__) - _erase_next_db(config) + update_latch_status(config, pending=True) + # first batch of subtasks: refresh cached opsdb data subtasks = [ update_junosspace_device_list.apply_async(), @@ -494,10 +502,21 @@ def launch_refresh_cache_all(config): def _wait_for_tasks(task_ids, update_callback=lambda s: None): + + all_successful = True + start_time = time.time() while task_ids and time.time() - start_time < FINALIZER_TIMEOUT_S: update_callback('waiting for tasks to complete: %r' % task_ids) time.sleep(FINALIZER_POLLING_FREQUENCY_S) + + def _is_error(id): + status = check_task_status(id) + return status['ready'] and not status['success'] + + if any([_is_error(id) for id in task_ids]): + all_successful = False + task_ids = [ id for id in task_ids if not check_task_status(id)['ready'] @@ -506,6 +525,9 @@ def _wait_for_tasks(task_ids, update_callback=lambda s: None): if task_ids: raise InventoryTaskError( 'timeout waiting for pending tasks to complete') + if not all_successful: + raise InventoryTaskError( + 'some tasks finished with an error') update_callback('pending taskscompleted in {} seconds'.format( time.time() - start_time)) @@ -513,7 +535,6 @@ def _wait_for_tasks(task_ids, update_callback=lambda s: None): @app.task(base=InventoryTask, bind=True) def refresh_finalizer(self, pending_task_ids_json): - logger = logging.getLogger(__name__) logger.debug('>>> refresh_finalizer') logger.debug('task_ids: %r' % pending_task_ids_json) @@ -532,14 +553,22 @@ def refresh_finalizer(self, pending_task_ids_json): 'message': s }) - task_ids = json.loads(pending_task_ids_json) - logger.debug('task_ids: %r' % task_ids) - jsonschema.validate(task_ids, input_schema) - _wait_for_tasks(task_ids, update_callback=_update) - _build_subnet_db(update_callback=_update) + try: + task_ids = json.loads(pending_task_ids_json) + logger.debug('task_ids: %r' % task_ids) + jsonschema.validate(task_ids, input_schema) + + _wait_for_tasks(task_ids, update_callback=_update) + _build_subnet_db(update_callback=_update) + + except (jsonschema.ValidationError, + json.JSONDecodeError, + InventoryTaskError) as e: + update_latch_status(InventoryTask.config, failure=True) + raise e - _update('latching current/next dbs') latch_db(InventoryTask.config) + _update('latched current/next dbs') logger.debug('<<< refresh_finalizer') @@ -558,8 +587,10 @@ def _build_subnet_db(update_callback=lambda s: None): update_callback('saving {} subnets'.format(len(subnets))) + rp = r.pipeline() for k, v in subnets.items(): - r.set('subnets:' + k, json.dumps(v)) + rp.set('subnets:' + k, json.dumps(v)) + rp.execute() def check_task_status(task_id): diff --git a/setup.py b/setup.py index 2ef16d74521bd373a69600c23a177cda06855b3e..ee7cc91c69fb3439fc4e02b17c82a778ed0169d5 100644 --- a/setup.py +++ b/setup.py @@ -2,7 +2,7 @@ from setuptools import setup, find_packages setup( name='inventory-provider', - version="0.22", + version="0.30", author='GEANT', author_email='swd@geant.org', description='Dashboard inventory provider', diff --git a/test/conftest.py b/test/conftest.py index 6009cc6a90f39ff520818e28846e953ce444dc30..392a01901fc4885ee9ff39597bc74fde652ab08b 100644 --- a/test/conftest.py +++ b/test/conftest.py @@ -79,7 +79,9 @@ class MockedRedis(object): MockedRedis.db['db:latch'] = json.dumps({ 'current': 0, 'next': 0, - 'this': 0 + 'this': 0, + 'pending': False, + 'failure': False }) def set(self, name, value): @@ -98,12 +100,12 @@ class MockedRedis(object): def scan_iter(self, glob=None): if not glob: - for k in MockedRedis.db.keys(): + for k in list(MockedRedis.db.keys()): yield k.encode('utf-8') m = re.match(r'^([^*]+)\*$', glob) assert m # all expected globs are like this - for k in MockedRedis.db.keys(): + for k in list(MockedRedis.db.keys()): if k.startswith(m.group(1)): yield k.encode('utf-8') @@ -114,6 +116,12 @@ class MockedRedis(object): # only called from testing routes (hopefully) pass + def execute(self): + pass + + def pipeline(self, *args, **kwargs): + return self + @pytest.fixture def cached_test_data(): diff --git a/test/data/mx1.buc.ro.geant.net-netconf.xml b/test/data/mx1.buc.ro.geant.net-netconf.xml new file mode 100644 index 0000000000000000000000000000000000000000..1dc540bc574980f28d2e1f79dfa2c03c1d40f0d5 --- /dev/null +++ b/test/data/mx1.buc.ro.geant.net-netconf.xml @@ -0,0 +1,17700 @@ +<configuration changed-seconds="1561995642" changed-localtime="2019-07-01 15:40:42 UTC"> + <version>17.4R2-S3.2</version> + <groups> + <name>re0</name> + <system> + <host-name>mx1.buc.ro.re0</host-name> + </system> + <interfaces> + <interface> + <name>fxp0</name> + <description>PHY INFRASTRUCTURE MANAGEMENT | re0</description> + <speed>100m</speed> + <link-mode>full-duplex</link-mode> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>172.16.37.3/24</name> + </address> + </inet> + </family> + </unit> + </interface> + </interfaces> + </groups> + <groups> + <name>re1</name> + <system> + <host-name>mx1.buc.ro.re1</host-name> + </system> + <interfaces> + <interface> + <name>fxp0</name> + <description>PHY INFRASTRUCTURE MANAGEMENT | re1</description> + <speed>100m</speed> + <link-mode>full-duplex</link-mode> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>172.16.37.4/24</name> + </address> + </inet> + </family> + </unit> + </interface> + </interfaces> + </groups> + <groups> + <name>urpf-template</name> + <firewall> + <family> + <inet> + <filter> + <name><*></name> + <interface-specific/> + <term> + <name>permit-multicast</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>urpf-multicast</count> + <accept/> + </then> + </term> + <term> + <name>discard-bogons</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>urpf-fail-bogons</count> + <discard> + </discard> + </then> + </term> + <term> + <name>discard</name> + <then> + <count>urpf-fail</count> + <discard> + </discard> + </then> + </term> + </filter> + </inet> + <inet6> + <filter> + <name><*></name> + <interface-specific/> + <term> + <name>permit-multicast</name> + <from> + <destination-address> + <name>ff00::/8</name> + </destination-address> + </from> + <then> + <count>urpfv6-multicast</count> + <accept/> + </then> + </term> + <term> + <name>discard-bogons</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>urpfv6-fail-bogons</count> + <discard/> + </then> + </term> + <term> + <name>discard</name> + <then> + <count>urpfv6-fail</count> + <discard/> + </then> + </term> + </filter> + </inet6> + </family> + </firewall> + </groups> + <groups> + <name>juniper-ais</name> + <system> + </system> + </groups> + <groups> + <name>load-balance-adaptive</name> + <interfaces> + <interface> + <name><ae*></name> + <aggregated-ether-options> + <load-balance> + <adaptive> + </adaptive> + </load-balance> + </aggregated-ether-options> + </interface> + </interfaces> + </groups> + <apply-groups>juniper-ais</apply-groups> + <system> + <apply-groups>re0</apply-groups> + <apply-groups>re1</apply-groups> + <domain-name>geant.net</domain-name> + <domain-search>geant2.net</domain-search> + <domain-search>geant.net</domain-search> + <backup-router> + <address>172.16.37.254</address> + <destination>172.16.5.252/30</destination> + </backup-router> + <time-zone>UTC</time-zone> + <undocumented><dump-on-panic> + </dump-on-panic></undocumented> + <authentication-order>radius</authentication-order> + <authentication-order>password</authentication-order> + <location> + <country-code>RO</country-code> + </location> + <root-authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </root-authentication> + <name-server> + <name>62.40.106.9</name> + </name-server> + <name-server> + <name>62.40.119.100</name> + </name-server> + <radius-server> + <name>62.40.120.136</name> + <timeout>2</timeout> + <source-address>62.40.96.19</source-address> + </radius-server> + <radius-server> + <name>62.40.121.121</name> + <timeout>2</timeout> + <source-address>62.40.96.19</source-address> + </radius-server> + <login> + <message>----------------------------------------------------------------\n\n This is mx1.buc.ro.geant2.net, a GEANT Router in Bucharest, Romania \n Warning: Unauthorized access to this equipment is strictly forbidden and will lead to prosecution \n\n-------------------------------------------------------------\n</message> + <class> + <name>DANTE-Class</name> + <idle-timeout>15</idle-timeout> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>NOC-Class</name> + <idle-timeout>60</idle-timeout> + <permissions>all</permissions> + </class> + <class> + <name>dante</name> + <idle-timeout>20</idle-timeout> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>geantnms</name> + <idle-timeout>15</idle-timeout> + <permissions>all</permissions> + </class> + <class> + <name>isisView</name> + <idle-timeout>5</idle-timeout> + <permissions>routing</permissions> + <allow-commands>(exit|show isis)</allow-commands> + <deny-commands>show route.*</deny-commands> + </class> + <class> + <name>level1</name> + <idle-timeout>5</idle-timeout> + <permissions>admin</permissions> + <permissions>clear</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>view</permissions> + </class> + <class> + <name>nrn</name> + <idle-timeout>5</idle-timeout> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>view</permissions> + <allow-commands>show .*</allow-commands> + <deny-commands>(ssh .*|telnet .*)</deny-commands> + </class> + <class> + <name>opennsa</name> + <idle-timeout>5</idle-timeout> + <permissions>configure</permissions> + <deny-commands>(file.*)|(load.*)|(op.*)|(request.*)|(save.*)|(start.*)|(test.*)|(set cli.*)|(set date.*)|(clear.*)|(help.*)|(telnet.*)|(ssh.*)|(traceroute.*)|(mtrace.*)|(monitor.*)|(ping.*)|(show.*)|(set.*)</deny-commands> + <allow-configuration-regexps>interfaces .*</allow-configuration-regexps> + <allow-configuration-regexps>protocols connections remote-interface-switch.*</allow-configuration-regexps> + <allow-configuration-regexps>protocols connections interface-switch.*</allow-configuration-regexps> + <allow-configuration-regexps>protocols mpls label-switched-path.*</allow-configuration-regexps> + <deny-configuration-regexps>vmhost .*</deny-configuration-regexps> + <deny-configuration-regexps>session-limit-group .*</deny-configuration-regexps> + <deny-configuration-regexps>multi-chassis .*</deny-configuration-regexps> + <deny-configuration-regexps>jsrc-partition .*</deny-configuration-regexps> + <deny-configuration-regexps>jsrc .*</deny-configuration-regexps> + <deny-configuration-regexps>groups .*</deny-configuration-regexps> + <deny-configuration-regexps>dynamic-profiles .*</deny-configuration-regexps> + <deny-configuration-regexps>diameter .*</deny-configuration-regexps> + <deny-configuration-regexps>apply-groups .*</deny-configuration-regexps> + <deny-configuration-regexps>access-profile .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces traceoptions .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces interface-set .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces interface-range .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces apply-groups .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces apply-groups-except .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces lt-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces ms-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces si-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces gr-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces lo.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces dsc.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces irb.*</deny-configuration-regexps> + </class> + <class> + <name>readonly-permissions</name> + <idle-timeout>15</idle-timeout> + <permissions>view</permissions> + <permissions>view-configuration</permissions> + <allow-commands>show .*|quit|ping .*|monitor .*|traceroute .*|file archive .*</allow-commands> + </class> + <class> + <name>restricted-mon</name> + <idle-timeout>5</idle-timeout> + <permissions>access</permissions> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>interface</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>view</permissions> + </class> + <user> + <name>DANTE</name> + <uid>2022</uid> + <class>DANTE-Class</class> + </user> + <user> + <name>Monit0r</name> + <full-name>Monitor</full-name> + <uid>2010</uid> + <class>dante</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>NOC</name> + <uid>2023</uid> + <class>NOC-Class</class> + </user> + <user> + <name>Prague</name> + <uid>2000</uid> + <class>dante</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>aconet</name> + <uid>2027</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>amres</name> + <uid>2028</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ansible</name> + <uid>2001</uid> + <class>NOC-Class</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>arnes</name> + <uid>2029</uid> + <class>nrn</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>basnet</name> + <uid>2030</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>belnet</name> + <uid>2031</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>bren</name> + <uid>2032</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>carnet</name> + <uid>2033</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ccssupport</name> + <uid>2016</uid> + <class>readonly-permissions</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>cnis</name> + <uid>2080</uid> + <class>isisView</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>cnis-dev</name> + <uid>2082</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>cnis-prod</name> + <uid>2081</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>dante</name> + <uid>2002</uid> + <class>dante</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>dfn</name> + <uid>2034</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>garr</name> + <uid>2035</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-cesnet</name> + <uid>2003</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-cynet</name> + <uid>2036</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-eenet</name> + <uid>2037</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-fccn</name> + <uid>2038</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-garr</name> + <uid>2039</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-hungar</name> + <uid>2041</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-malta</name> + <uid>2042</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-switch</name> + <uid>2043</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>grnet</name> + <uid>2044</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>heanet</name> + <uid>2045</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>hungarnet</name> + <uid>2046</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>iucc</name> + <uid>2047</uid> + <class>nrn</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>janet</name> + <uid>2048</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>lat</name> + <uid>2059</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>litnet</name> + <uid>2049</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>marnet</name> + <uid>2051</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>mren</name> + <uid>2052</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ncc</name> + <full-name>NOC Team Backup Account</full-name> + <uid>2024</uid> + <class>super-user</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>nordunet</name> + <uid>2053</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>opennsa</name> + <uid>2008</uid> + <class>opennsa</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>opnet</name> + <full-name>OPNET NEOP Planning system @ 62.40.105.114</full-name> + <uid>2026</uid> + <class>dante</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>opsdbv2</name> + <uid>2014</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>pionier</name> + <uid>2054</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>python</name> + <uid>2005</uid> + <class>NOC-Class</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>rediris</name> + <uid>2055</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>renater</name> + <uid>2056</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>reporting</name> + <uid>2007</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>restena</name> + <full-name>NREN RESTENA</full-name> + <uid>2057</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>restricted-mon</name> + <uid>2250</uid> + <class>restricted-mon</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>roedunet</name> + <uid>2004</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ruby</name> + <full-name>NOC Ruby script account</full-name> + <uid>2011</uid> + <class>level1</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>sa3-amps</name> + <uid>2240</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>sanet</name> + <uid>2058</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>space</name> + <full-name>NCC - Junos Space application login</full-name> + <uid>2019</uid> + <class>geantnms</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>space15.2R2.4-paris</name> + <uid>2013</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>space17.1R1.7-london</name> + <uid>2006</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>srv-space-ssh</name> + <uid>2009</uid> + <class>super-user</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>srv_packetdesign</name> + <full-name>Packet Design Test VM 62.40.99.51 LON2</full-name> + <uid>2015</uid> + <class>restricted-mon</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>surfnet</name> + <uid>2060</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ulakbim</name> + <uid>2061</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>uran</name> + <uid>2062</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>xantaro</name> + <uid>2012</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <password> + <minimum-length>10</minimum-length> + <minimum-numerics>1</minimum-numerics> + <minimum-upper-cases>1</minimum-upper-cases> + <minimum-lower-cases>1</minimum-lower-cases> + <minimum-punctuations>1</minimum-punctuations> + </password> + </login> + <static-host-mapping> + <name>lo0</name> + <inet>62.40.96.19</inet> + </static-host-mapping> + <services> + <ssh> + <root-login>deny</root-login> + <no-tcp-forwarding/> + <protocol-version>v2</protocol-version> + <max-sessions-per-connection>32</max-sessions-per-connection> + <ciphers>chacha20-poly1305@openssh.com</ciphers> + <ciphers>aes256-ctr</ciphers> + <ciphers>aes192-ctr</ciphers> + <ciphers>aes128-ctr</ciphers> + <ciphers>aes128-gcm@openssh.com</ciphers> + <ciphers>aes256-gcm@openssh.com</ciphers> + <ciphers>3des-cbc</ciphers> + <ciphers>blowfish-cbc</ciphers> + <key-exchange>curve25519-sha256</key-exchange> + <key-exchange>dh-group1-sha1</key-exchange> + <key-exchange>dh-group14-sha1</key-exchange> + <key-exchange>ecdh-sha2-nistp256</key-exchange> + <key-exchange>ecdh-sha2-nistp384</key-exchange> + <key-exchange>ecdh-sha2-nistp521</key-exchange> + <key-exchange>group-exchange-sha2</key-exchange> + <connection-limit>125</connection-limit> + <rate-limit>150</rate-limit> + </ssh> + <netconf> + <ssh> + </ssh> + </netconf> + </services> + <syslog> + <user> + <name>*</name> + <contents> + <name>any</name> + <emergency/> + </contents> + </user> + <host> + <name>62.40.119.31</name> + <contents> + <name>any</name> + <notice/> + </contents> + <contents> + <name>conflict-log</name> + <any/> + </contents> + <contents> + <name>change-log</name> + <any/> + </contents> + <facility-override>local0</facility-override> + </host> + <host> + <name>83.97.94.11</name> + <contents> + <name>any</name> + <any/> + </contents> + <match>!(kernel: rts_commi.*|RPD_MSDP_SRC_ACTIVE.*)</match> + <port>514</port> + </host> + <file> + <name>messages</name> + <contents> + <name>any</name> + <notice/> + </contents> + <contents> + <name>authorization</name> + <info/> + </contents> + <match>!(RPD_MSDP_SRC_ACTIVE.*)</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>interactive-commands</name> + <contents> + <name>interactive-commands</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>authorization</name> + <contents> + <name>authorization</name> + <any/> + </contents> + </file> + <file> + <name>firewall-log</name> + <contents> + <name>firewall</name> + <critical/> + </contents> + </file> + <file> + <name>daemon</name> + <contents> + <name>daemon</name> + <error/> + </contents> + </file> + <file> + <name>conf-history</name> + <contents> + <name>conflict-log</name> + <any/> + </contents> + <contents> + <name>change-log</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>net-alarms</name> + <contents> + <name>daemon</name> + <warning/> + </contents> + </file> + <file> + <name>low-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <notice/> + </contents> + <contents> + <name>kernel</name> + <notice/> + </contents> + <contents> + <name>user</name> + <notice/> + </contents> + <contents> + <name>pfe</name> + <notice/> + </contents> + </file> + <file> + <name>high-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <error/> + </contents> + <contents> + <name>kernel</name> + <error/> + </contents> + <contents> + <name>user</name> + <error/> + </contents> + <contents> + <name>pfe</name> + <error/> + </contents> + </file> + <file> + <name>commands-log</name> + <contents> + <name>interactive-commands</name> + <info/> + </contents> + </file> + <file> + <name>dnoc-events</name> + <contents> + <name>daemon</name> + <info/> + </contents> + <match>.*SNMP_TRAP_LINK_.*|.*RPD_BGP_NEIGHBOR_STATE_CHANGED.*|.*SNMPD_TRAP_COLD_START.*</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>default-log-messages</name> + <contents> + <name>any</name> + <info/> + </contents> + <match>(requested 'commit' operation)|(requested 'commit synchronize' operation)|(copying configuration to juniper.save)|(commit complete)|ifAdminStatus|(FRU power)|(FRU removal)|(FRU insertion)|(link UP)|transitioned|Transferred|transfer-file|(license add)|(license delete)|(package -X update)|(package -X delete)|(FRU Online)|(FRU Offline)|(plugged in)|(unplugged)|CFMD_CCM_DEFECT| LFMD_3AH | RPD_MPLS_PATH_BFD|(Master Unchanged, Members Changed)|(Master Changed, Members Changed)|(Master Detected, Members Changed)|(vc add)|(vc delete)|(Master detected)|(Master changed)|(Backup detected)|(Backup changed)|(interface vcp-)|(AIS_DATA_AVAILABLE)</match> + <structured-data> + </structured-data> + </file> + <file> + <name>pfed</name> + <contents> + <name>pfe</name> + <any/> + </contents> + <archive> + <size>20m</size> + <files>10</files> + </archive> + </file> + <file> + <name>kernel_jtac</name> + <contents> + <name>kernel</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <time-format> + <year/> + <millisecond/> + </time-format> + <source-address>62.40.96.19</source-address> + </syslog> + <commit> + <fast-synchronize/> + <synchronize/> + </commit> + <ntp> + <boot-server>193.62.22.66</boot-server> + <authentication-key> + <name>1</name> + <type>md5</type> + <value>/* SECRET-DATA */</value> + </authentication-key> + <server> + <name>62.40.97.11</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.97.12</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.97.14</name> + <key>/* SECRET-DATA */</key> + </server> + <trusted-key>1</trusted-key> + <source-address> + <name>62.40.96.19</name> + </source-address> + </ntp> + </system> + <chassis> + <undocumented><dump-on-panic/></undocumented> + <redundancy> + <routing-engine> + <name>0</name> + <master/> + </routing-engine> + <routing-engine> + <name>1</name> + <backup/> + </routing-engine> + <failover> + <on-loss-of-keepalives/> + <on-disk-failure/> + </failover> + <graceful-switchover> + </graceful-switchover> + </redundancy> + <aggregated-devices> + <ethernet> + <device-count>32</device-count> + </ethernet> + <sonet> + <device-count>8</device-count> + </sonet> + </aggregated-devices> + <fpc> + <name>0</name> + <pic> + <name>0</name> + <tunnel-services> + <bandwidth>10g</bandwidth> + </tunnel-services> + </pic> + <sampling-instance> + <name>ipfx</name> + </sampling-instance> + <inline-services> + <flow-table-size> + <ipv4-flow-table-size>5</ipv4-flow-table-size> + <ipv6-flow-table-size>5</ipv6-flow-table-size> + <mpls-flow-table-size>5</mpls-flow-table-size> + </flow-table-size> + </inline-services> + </fpc> + <fpc> + <name>1</name> + <pic> + <name>2</name> + <adaptive-services> + <service-package> + <extension-provider> + <syslog> + <name>daemon</name> + <critical/> + </syslog> + </extension-provider> + </service-package> + </adaptive-services> + </pic> + <sampling-instance> + <name>ipfx</name> + </sampling-instance> + <inline-services> + <flow-table-size> + <ipv4-flow-table-size>5</ipv4-flow-table-size> + <ipv6-flow-table-size>5</ipv6-flow-table-size> + <mpls-flow-table-size>5</mpls-flow-table-size> + </flow-table-size> + </inline-services> + </fpc> + </chassis> + <services> + <flow-monitoring> + <version-ipfix> + <template> + <name>ipv4</name> + <flow-active-timeout>60</flow-active-timeout> + <flow-inactive-timeout>60</flow-inactive-timeout> + <template-refresh-rate> + <seconds>300</seconds> + </template-refresh-rate> + <option-refresh-rate> + <seconds>300</seconds> + </option-refresh-rate> + <ipv4-template> + </ipv4-template> + </template> + <template> + <name>ipv6</name> + <flow-active-timeout>60</flow-active-timeout> + <flow-inactive-timeout>60</flow-inactive-timeout> + <template-refresh-rate> + <seconds>300</seconds> + </template-refresh-rate> + <option-refresh-rate> + <seconds>300</seconds> + </option-refresh-rate> + <ipv6-template> + </ipv6-template> + </template> + <template> + <name>mpls</name> + <flow-active-timeout>60</flow-active-timeout> + <flow-inactive-timeout>60</flow-inactive-timeout> + <template-refresh-rate> + <seconds>300</seconds> + </template-refresh-rate> + <option-refresh-rate> + <seconds>300</seconds> + </option-refresh-rate> + <mpls-ipv4-template> + <label-position>1</label-position> + <label-position>2</label-position> + <label-position>3</label-position> + </mpls-ipv4-template> + </template> + </version-ipfix> + </flow-monitoring> + <rpm> + <probe> + <name>iGEANT_mx1.tal.ee_62.40.96.1</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.1</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.tal.ee_62.40.96.2</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.2</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.dub.ie_62.40.96.3</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.3</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.rig.lv_62.40.96.4</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.4</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.kau.lt_62.40.96.5</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.5</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.kau.lt_62.40.96.6</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.6</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.zag.hr_62.40.96.8</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.8</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.lju.si_62.40.96.10</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.10</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.ath.gr_62.40.96.11</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.11</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.mar.fr_62.40.96.12</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.12</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.lon2.uk_62.40.96.15</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.15</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.lis.pt_62.40.96.16</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.16</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.lis.pt_62.40.96.17</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.17</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.bru.be_62.40.96.20</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.20</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.sof.bg_62.40.96.21</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.21</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.dub2.ie_62.40.96.25</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.25</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.ham.de_62.40.96.26</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.26</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.ath2.gr_62.40.96.39</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.39</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.bud.hu_62.40.97.1</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.1</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.pra.cz_62.40.97.2</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.2</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.bra.sk_62.40.97.4</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.4</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.lon.uk_62.40.97.5</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.5</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.vie.at_62.40.97.7</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.7</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.poz.pl_62.40.97.10</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.10</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.ams.nl_62.40.97.11</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.11</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.fra.de_62.40.97.12</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.12</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.par.fr_62.40.97.13</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.13</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.gen.ch_62.40.97.14</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.14</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.mil2.it_62.40.97.15</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.15</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.mad.es_62.40.97.16</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.16</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + </rpm> + </services> + <interfaces> + <apply-groups>re0</apply-groups> + <apply-groups>re1</apply-groups> + <apply-groups>load-balance-adaptive</apply-groups> + <interface> + <name>lt-0/0/0</name> + <description>TUN INFRASTRUCTURE ACCESS SRF0000001 </description> + <unit> + <name>16</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS IAS SRF0000001 | BGP Peering - RE_INTERCONNECT Side</description> + <encapsulation>ethernet</encapsulation> + <peer-unit>61</peer-unit> + <family> + <inet> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>83.97.89.18/31</name> + </address> + </inet> + <inet6> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::131/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>61</name> + <description>SRV_IAS INFRASTRUCTURE ACCESS GLOBAL SRF0000001 | BGP Peering - IAS Side</description> + <encapsulation>ethernet</encapsulation> + <peer-unit>16</peer-unit> + <family> + <inet> + <address> + <name>83.97.89.19/31</name> + </address> + </inet> + <inet6> + <address> + <name>2001:798:1::132/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>xe-0/0/0</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE8 SRF0000001 | sof-buc DANT0/10GbWL/227284</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-0/0/1</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE4 SRF0000001 | buc-bud L3 BCZG0606</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-0/1/0</name> + <description>PHY CUSTOMER ROEDUNET P_AE11 SRF9915022 | 1</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-0/1/1</name> + <description>PHY CUSTOMER ROEDUNET P_AE11 SRF9915022 | 2</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>ge-0/2/0</name> + <description>PHY INFRASTRUCTURE ACCESS LAN SRF0000001 | buc ro POP LAN</description> + <vlan-tagging/> + <unit> + <name>10</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | TEST</description> + <vlan-id>10</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>LAN-in</filter-name> + </input> + <output> + <filter-name>LAN-out</filter-name> + </output> + </filter> + <address> + <name>62.40.118.97/29</name> + </address> + <address> + <name>62.40.107.129/29</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <address> + <name>2001:798:2b:a::1/64</name> + </address> + <address> + <name>2001:798:fc01:1a::1/125</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>20</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | C1N1 iDRAC CONTACT: allen.kong@geant.org IMPLEMENTED: 20161027</description> + <vlan-id>20</vlan-id> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.118.6/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + </inet6> + </family> + </unit> + <unit> + <name>21</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | HADES DRAC</description> + <vlan-id>21</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>HADES-IN</filter-name> + </input> + <output> + <filter-name>HADES-OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.117.18/31</name> + </address> + </inet> + <iso> + </iso> + </family> + </unit> + <unit> + <name>30</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | Operations</description> + <vlan-id>30</vlan-id> + <family> + <inet> + <filter> + <input-list>C1N1-to-VCENTER</input-list> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>VCENTER-to-C1N1</output-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.108.37/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:2b:1e::1/64</name> + </address> + <address> + <name>2001:798:fc01:1a::9/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>60</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | KVMoIP - sw1 port 6</description> + <vlan-id>60</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>LAN-in</filter-name> + </input> + <output> + <filter-name>LAN-out</filter-name> + </output> + </filter> + <address> + <name>62.40.121.89/30</name> + </address> + </inet> + <iso> + </iso> + </family> + </unit> + <unit> + <name>124</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | Ps</description> + <vlan-id>124</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>VM-RANGE-VL124-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL124-OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.123.89/29</name> + </address> + </inet> + <inet6> + <filter> + <input> + <filter-name>VM-RANGE-VL124-V6-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL124-V6-OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:bb:1a::1/64</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>125</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | Nagiosxi VM</description> + <vlan-id>125</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>VM-RANGE-VL125-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL125-OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.123.177/29</name> + </address> + </inet> + <inet6> + <filter> + <input> + <filter-name>VM-RANGE-VL125-V6-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL125-V6-OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:bb:1b::1/64</name> + </address> + </inet6> + </family> + </unit> + <unit inactive="inactive"> + <name>171</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | TAAS Control (Nagios is .180)</description> + <vlan-id>171</vlan-id> + <family inactive="inactive"> + <inet> + <address> + <name>10.0.1.129/26</name> + </address> + </inet> + </family> + </unit> + <unit> + <name>190</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | OPS VM</description> + <vlan-id>190</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>VM-RANGE-VL190-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL190-OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.113.42/31</name> + </address> + </inet> + <inet6> + <address> + <name>2001:798:ffb4:1a::1/64</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>200</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | perfSONAR MADDASH service| CONTACT: IT IMPLEMENTED:20150901</description> + <vlan-id>200</vlan-id> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>VL200_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>VL200_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.122.89/29</name> + </address> + </inet> + <inet6> + <filter> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>VL200_V6_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>VL200_V6_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:bb:23::1/64</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/1</name> + <description>PHY INFRASTRUCTURE ACCESS PERFSONAR SRF9919033 | BWCTL CONTACT: ivan.garnizov@fau.de IMPLEMENTED: 20150811</description> + <mtu>9192</mtu> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS PERFSONAR SRF9919033 | BWCTL CONTACT: ivan.garnizov@fau.de IMPLEMENTED: 20150811</description> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>BWCTL_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>BWCTL_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.106.194/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>BWCTL_V6_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>BWCTL_V6_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:fc00:2b::5/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/2</name> + <description>PHY INFRASTRUCTURE ACCESS PERFSONAR SRF0000001 | OWAMP CONTACT: ivan.garnizov@fau.de IMPLEMENTED: 20150811</description> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS PERFSONAR SRF0000001 | OWAMP CONTACT: ivan.garnizov@fau.de IMPLEMENTED: 20150811</description> + <family> + <inet> + <filter inactive="inactive"> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>VL022_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>VL022_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.106.192/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter inactive="inactive"> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>VL022_V6_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>VL022_V6_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:fc00:2b::1/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/3</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/4</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/5</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/6</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/7</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/8</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/9</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/0</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/1</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/2</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/3</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/4</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/5</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/6</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/7</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/8</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/9</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>xe-1/0/0</name> + <description>PHY CUSTOMER RENAM P_AE12 SRF9942191 |</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-1/0/1</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE4 SRF0000001 | buc-bud L3 BCXJ2804</description> + <undocumented><enable/></undocumented> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-1/1/0</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE8 SRF0000001 | sof-buc DANT0/10GbWL/203952</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-1/1/1</name> + <description>PHY RESERVED | Roedu.net AP Upgrade 20-30Gb</description> + </interface> + <interface> + <name>ms-1/2/0</name> + <unit> + <name>0</name> + <family> + <inet> + </inet> + </family> + </unit> + <unit> + <name>1</name> + <family> + <inet6> + </inet6> + </family> + </unit> + <unit> + <name>2</name> + <family> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ge-2/1/1</name> + <unit> + <name>0</name> + <family> + <inet> + </inet> + <inet6> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>sp-2/2/0</name> + <unit> + <name>0</name> + <family> + <inet> + </inet> + </family> + </unit> + </interface> + <interface> + <name>ae4</name> + <description>LAG INFRASTRUCTURE BACKBONE BUD SRF0000001 | buc-bud</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>2</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE BUD SRF0000001 | buc-bud</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.166/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:1b01:2b01::2/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae8</name> + <description>LAG INFRASTRUCTURE BACKBONE SOF SRF0000001 | buc-sof</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE SOF SRF0000001 | buc-sof</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.52/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:1::35/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae11</name> + <description>LAG CUSTOMER ROEDUNET SRF998829 |</description> + <flexible-vlan-tagging/> + <native-vlan-id>100</native-vlan-id> + <mtu>9192</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>2</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL CUSTOMER ROEDUNET AP1 SRF998832 | ASN2614 |</description> + <vlan-id>100</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <filter> + <input> + <filter-name>ROEDU-in</filter-name> + </input> + <output> + <filter-name>ROEDU-out</filter-name> + </output> + </filter> + <address> + <name>62.40.125.137/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input> + <filter-name>ROEDU6-in</filter-name> + </input> + <output> + <filter-name>ROEDU6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:2b:10aa::1/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + <unit> + <name>111</name> + <description>SRV_L3VPN LHCONE CUSTOMER ROEDUNET AP1 SRF9915845 | ASN2614 |</description> + <vlan-id>111</vlan-id> + <family> + <inet> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>LHCONE-in</filter-name> + </input> + </filter> + <address> + <name>62.40.126.244/31</name> + </address> + </inet> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>LHCONE6-in</filter-name> + </input> + <output> + <filter-name>LHCONE6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:111:1::a5/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>333</name> + <description>SRV_IAS CUSTOMER ROEDUNET SRF9931719 | ASN2614 |</description> + <vlan-id>333</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_ROEDUNET_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_ROEDUNET_OUT</filter-name> + </output> + </filter> + <address> + <name>83.97.88.141/30</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_ROEDUNET_V6_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_ROEDUNET_V6_OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::a9/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae12</name> + <description>LAG CUSTOMER RENAM SRF18037 |</description> + <undocumented><enable/></undocumented> + <flexible-vlan-tagging/> + <mtu>9192</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + </aggregated-ether-options> + <unit> + <name>200</name> + <description>SRV_GLOBAL CUSTOMER RENAM AP1 SRF9942195 | ASN9199 |</description> + <vlan-id>200</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <filter> + <input> + <filter-name>nren_RENAM_IN</filter-name> + </input> + <output> + <filter-name>nren_RENAM_OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.125.197/30</name> + </address> + </inet> + <inet6> + <filter> + <input> + <filter-name>RENAM6-in</filter-name> + </input> + <output> + <filter-name>RENAM6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:99:1::a5/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>333</name> + <description>SRV_IAS CUSTOMER RENAM SRF9942405 | ASN9199 |</description> + <vlan-id>333</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_RENAM_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_RENAM_OUT</filter-name> + </output> + </filter> + <address> + <name>83.97.88.196/31</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_RENAM_V6_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_RENAM_V6_OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::1a1/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>dsc</name> + <unit> + <name>0</name> + <description>PHY INFRASTRUCTURE DISCARD | required for Multicast monitoring</description> + <family> + <inet> + <address> + <name>192.0.2.104/32</name> + </address> + </inet> + </family> + </unit> + </interface> + <interface> + <name>lo0</name> + <unit> + <name>0</name> + <family> + <inet> + <filter> + <input> + <filter-name>ROUTER_access</filter-name> + </input> + <output> + <filter-name>router-access-out</filter-name> + </output> + </filter> + <address> + <name>62.40.96.19/32</name> + <primary/> + <preferred/> + </address> + </inet> + <iso> + <address> + <name>49.51e5.0001.0620.4009.6019.00</name> + </address> + </iso> + <inet6> + <filter> + <input> + <filter-name>ROUTER_access_V6</filter-name> + </input> + </filter> + <address> + <name>2001:798:2b:10ff::3/128</name> + </address> + </inet6> + </family> + </unit> + </interface> + </interfaces> + <snmp> + <location>Bucharest, RO ##LOC 44 44 71 N 26 08 94 E 80m##</location> + <contact>GEANT OC, support@oc.geant.net, +44 (0) 1223 733033</contact> + <community> + <name>0pBiFbD</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.98.0/23</name> + </clients> + <clients> + <name>193.110.48.4/32</name> + </clients> + <clients> + <name>193.63.211.0/25</name> + </clients> + <clients> + <name>193.63.211.56/32</name> + </clients> + <clients> + <name>62.40.118.241/32</name> + </clients> + <clients> + <name>62.40.118.224/28</name> + </clients> + <clients> + <name>62.40.118.243/32</name> + </clients> + <clients> + <name>62.40.118.50/32</name> + </clients> + <clients> + <name>62.40.115.147/32</name> + </clients> + <clients> + <name>62.40.121.102/32</name> + </clients> + <clients> + <name>62.40.118.240/28</name> + </clients> + <clients> + <name>193.63.211.136/32</name> + </clients> + <clients> + <name>62.40.119.0/24</name> + </clients> + <clients> + <name>62.40.117.82/32</name> + </clients> + <clients> + <name>62.40.119.32/32</name> + </clients> + <clients> + <name>62.40.115.146/32</name> + </clients> + <clients> + <name>62.40.115.130/32</name> + </clients> + <clients> + <name>62.40.116.18/32</name> + </clients> + <clients> + <name>62.40.115.82/32</name> + </clients> + <clients> + <name>62.40.118.213/30</name> + </clients> + <clients> + <name>62.40.104.48/29</name> + </clients> + <clients> + <name>62.40.104.152/29</name> + </clients> + <clients> + <name>62.40.104.24/29</name> + </clients> + <clients> + <name>62.40.104.144/29</name> + </clients> + <clients> + <name>62.40.105.117/32</name> + </clients> + <clients> + <name>62.40.105.114/32</name> + </clients> + <clients> + <name>193.63.90.246/32</name> + </clients> + <clients> + <name>62.40.104.10/32</name> + </clients> + <clients> + <name>62.40.106.202/32</name> + </clients> + <clients> + <name>62.40.113.88/29</name> + </clients> + <clients> + <name>62.40.120.18/32</name> + </clients> + <clients> + <name>62.40.111.254/32</name> + </clients> + <clients> + <name>62.40.106.232/29</name> + </clients> + <clients> + <name>62.40.114.107/32</name> + </clients> + <clients> + <name>62.40.114.108/32</name> + </clients> + <clients> + <name>62.40.114.114/32</name> + </clients> + <clients> + <name>62.40.120.72/29</name> + </clients> + <clients> + <name>62.40.120.90/32</name> + </clients> + <clients> + <name>62.40.122.138/32</name> + </clients> + <clients> + <name>62.40.106.182/32</name> + </clients> + <clients> + <name>62.40.122.106/32</name> + </clients> + <clients> + <name>62.40.122.110/32</name> + </clients> + <clients> + <name>83.97.92.94/32</name> + </clients> + <clients> + <name>62.40.100.202/32</name> + </clients> + <clients> + <name>62.40.114.0/28</name> + </clients> + <clients> + <name>62.40.114.16/28</name> + </clients> + <clients> + <name>83.97.92.238/32</name> + </clients> + <clients> + <name>83.97.92.239/32</name> + </clients> + <clients> + <name>83.97.93.39/32</name> + </clients> + <clients> + <name>83.97.93.45/32</name> + </clients> + <clients> + <name>83.97.93.22/32</name> + </clients> + <clients> + <name>83.97.92.0/24</name> + </clients> + <clients> + <name>83.97.93.37/32</name> + </clients> + <clients> + <name>83.97.92.159/32</name> + </clients> + <clients> + <name>83.97.92.114/32</name> + </clients> + <clients> + <name>83.97.93.23/32</name> + </clients> + <clients> + <name>83.97.92.183/32</name> + </clients> + <clients> + <name>83.97.93.59/32</name> + </clients> + <clients> + <name>83.97.93.137/32</name> + </clients> + <clients> + <name>83.97.93.195/32</name> + </clients> + <clients> + <name>83.97.93.196/32</name> + </clients> + <clients> + <name>83.97.93.238/32</name> + </clients> + <clients> + <name>83.97.94.12/32</name> + </clients> + <clients> + <name>83.97.94.13/32</name> + </clients> + <clients> + <name>83.97.94.14/32</name> + </clients> + <clients> + <name>62.40.106.201/32</name> + </clients> + <clients> + <name>83.97.93.152/32</name> + </clients> + <clients> + <name>83.97.93.153/32</name> + </clients> + <clients> + <name>83.97.93.154/32</name> + </clients> + <clients> + <name>62.40.99.51/32</name> + </clients> + <clients> + <name>62.40.106.200/29</name> + </clients> + <clients> + <name>83.97.94.52/32</name> + </clients> + <clients> + <name>83.97.93.239/32</name> + </clients> + </community> + <community> + <name>As4n0gN!</name> + <authorization>read-only</authorization> + <clients> + <name>0.0.0.0/32</name> + </clients> + <clients> + <name>150.254.161.251/32</name> + </clients> + <clients> + <name>150.254.208.64/26</name> + </clients> + <clients> + <name>193.140.12.254/32</name> + </clients> + </community> + <community> + <name>c6N1rt5S</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.122.226/32</name> + </clients> + </community> + <community> + <name>c6N2rt5s</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.122.226/32</name> + </clients> + <clients> + <name>62.40.123.130/32</name> + </clients> + </community> + <community> + <name>MdM53r6Sk</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.123.162/32</name> + </clients> + <clients> + <name>62.40.123.162/31</name> + </clients> + </community> + <community> + <name>S3cur1tyS3rv1cE</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.123.172/32</name> + </clients> + <clients> + <name>62.40.106.106/32</name> + </clients> + </community> + <community> + <name>DeepF1eld</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.123.134/32</name> + </clients> + </community> + <community> + <name>k3nt1ktri@l2019</name> + <authorization>read-only</authorization> + <clients> + <name>193.177.128.0/22</name> + </clients> + </community> + <trap-options> + <source-address> + <address>62.40.96.19</address> + </source-address> + </trap-options> + <trap-group> + <name>space</name> + <version>v2</version> + <targets> + <name>62.40.99.3</name> + </targets> + <targets> + <name>62.40.113.91</name> + </targets> + <targets> + <name>62.40.120.19</name> + </targets> + <targets> + <name>62.40.113.93</name> + </targets> + <targets> + <name>83.97.93.151</name> + </targets> + <targets> + <name>83.97.94.51</name> + </targets> + </trap-group> + <trap-group> + <name>geantnms</name> + <version>v2</version> + <categories> + <link/> + <routing/> + </categories> + <targets> + <name>62.40.104.51</name> + </targets> + <targets> + <name>62.40.104.155</name> + </targets> + <targets> + <name>62.40.104.50</name> + </targets> + <targets> + <name>62.40.104.53</name> + </targets> + <targets> + <name>62.40.114.3</name> + </targets> + <targets> + <name>62.40.114.2</name> + </targets> + <targets> + <name>62.40.114.18</name> + </targets> + <targets> + <name>62.40.114.19</name> + </targets> + <targets> + <name>83.97.92.238</name> + </targets> + <targets> + <name>83.97.92.239</name> + </targets> + <targets> + <name>83.97.92.228</name> + </targets> + <targets> + <name>83.97.93.53</name> + </targets> + <targets> + <name>83.97.93.151</name> + </targets> + <targets> + <name>83.97.94.51</name> + </targets> + </trap-group> + </snmp> + <forwarding-options> + <sampling> + <instance> + <name>ipfx</name> + <input> + <rate>300</rate> + </input> + <family> + <inet> + <output> + <flow-server> + <name>62.40.100.166</name> + <port>7711</port> + <version-ipfix> + <template> + <template-name>ipv4</template-name> + </template> + </version-ipfix> + </flow-server> + <flow-server> + <name>62.40.106.182</name> + <port>7712</port> + <version-ipfix> + <template> + <template-name>ipv4</template-name> + </template> + </version-ipfix> + </flow-server> + <inline-jflow> + <source-address>62.40.96.19</source-address> + <flow-export-rate>30</flow-export-rate> + </inline-jflow> + </output> + </inet> + <inet6> + <output> + <flow-server> + <name>62.40.100.166</name> + <port>7711</port> + <version-ipfix> + <template> + <template-name>ipv6</template-name> + </template> + </version-ipfix> + </flow-server> + <flow-server> + <name>62.40.106.182</name> + <port>7712</port> + <version-ipfix> + <template> + <template-name>ipv6</template-name> + </template> + </version-ipfix> + </flow-server> + <inline-jflow> + <source-address>62.40.96.19</source-address> + <flow-export-rate>30</flow-export-rate> + </inline-jflow> + </output> + </inet6> + <mpls> + <output> + <flow-server> + <name>62.40.100.166</name> + <port>7711</port> + <version-ipfix> + <template> + <template-name>mpls</template-name> + </template> + </version-ipfix> + </flow-server> + <flow-server> + <name>62.40.106.182</name> + <port>7712</port> + <version-ipfix> + <template> + <template-name>mpls</template-name> + </template> + </version-ipfix> + </flow-server> + <inline-jflow> + <source-address>62.40.96.19</source-address> + <flow-export-rate>30</flow-export-rate> + </inline-jflow> + </output> + </mpls> + </family> + </instance> + </sampling> + </forwarding-options> + <routing-options> + <nonstop-routing/> + <interface-routes> + <rib-group> + <inet>unicast-multicast</inet> + <inet6>unicast-multicastv6</inet6> + </rib-group> + </interface-routes> + <rib> + <name>inet.2</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>inet6.0</name> + <static> + <route> + <name>0100::/64</name> + <discard/> + <no-readvertise/> + </route> + <route> + <name>2001:798::/32</name> + <discard/> + <community>20965:155</community> + <community>20965:65532</community> + <community>20965:65533</community> + <community>64700:65532</community> + <community>64700:65533</community> + <community>64700:65534</community> + </route> + <route> + <name>::/0</name> + <next-hop>2001:798:1::132</next-hop> + </route> + </static> + </rib> + <rib> + <name>inet6.2</name> + <static> + <route> + <name>2001:798::/32</name> + <reject/> + </route> + </static> + </rib> + <rib> + <name>inet.1</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>inet.3</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>inet.4</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>inetflow.0</name> + <maximum-prefixes> + <limit>100</limit> + <threshold>90</threshold> + </maximum-prefixes> + </rib> + <static> + <route> + <name>172.16.5.252/30</name> + <next-hop>172.16.37.254</next-hop> + <retain/> + <no-readvertise/> + </route> + <route> + <name>0.0.0.0/0</name> + <next-hop>83.97.89.19</next-hop> + </route> + <route> + <name>192.0.2.101/32</name> + <discard/> + <no-readvertise/> + </route> + <route> + <name>62.40.96.0/19</name> + <discard/> + <community>20965:155</community> + <community>20965:65532</community> + <community>20965:65533</community> + <community>64700:65532</community> + <community>64700:65533</community> + <community>64700:65534</community> + </route> + </static> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + <rib-groups> + <name>multicast</name> + <export-rib>inet.2</export-rib> + <import-rib>inet.2</import-rib> + </rib-groups> + <rib-groups> + <name>unicast-multicast</name> + <export-rib>inet.0</export-rib> + <import-rib>inet.0</import-rib> + <import-rib>inet.2</import-rib> + </rib-groups> + <rib-groups> + <name>multicastv6</name> + <import-rib>inet6.2</import-rib> + </rib-groups> + <rib-groups> + <name>unicast-multicastv6</name> + <export-rib>inet6.0</export-rib> + <import-rib>inet6.0</import-rib> + <import-rib>inet6.2</import-rib> + </rib-groups> + <rib-groups> + <name>ias-to-geant-cls-rtbh</name> + <import-rib>IAS.inet.0</import-rib> + <import-rib>CLS.inet.0</import-rib> + <import-rib>inet.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>ias-to-geant-cls-rtbh6</name> + <import-rib>IAS.inet6.0</import-rib> + <import-rib>CLS.inet6.0</import-rib> + <import-rib>inet6.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>geant-to-ias-cls-rtbh</name> + <import-rib>inet.0</import-rib> + <import-rib>IAS.inet.0</import-rib> + <import-rib>CLS.inet.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>geant-to-ias-cls-rtbh6</name> + <import-rib>inet6.0</import-rib> + <import-rib>IAS.inet6.0</import-rib> + <import-rib>CLS.inet6.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>cls-to-geant-geant-rtbh</name> + <import-rib>CLS.inet.0</import-rib> + <import-rib>inet.0</import-rib> + <import-rib>IAS.inet.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>cls-to-geant-geant-rtbh6</name> + <import-rib>CLS.inet6.0</import-rib> + <import-rib>inet6.0</import-rib> + <import-rib>IAS.inet6.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <router-id>62.40.96.19</router-id> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + <forwarding-table> + <export>dest-class-usage</export> + <export>source-class-usage</export> + <export>load-balancing-policy</export> + </forwarding-table> + <multicast> + <forwarding-cache> + <threshold> + <suppress>20000</suppress> + <reuse>18000</reuse> + </threshold> + </forwarding-cache> + </multicast> + </routing-options> + <protocols> + <igmp> + <interface> + <name>ge-0/2/0.10</name> + <version>3</version> + </interface> + <interface> + <name>ge-0/2/0.20</name> + <version>3</version> + </interface> + <interface> + <name>ge-0/2/0.30</name> + <version>3</version> + </interface> + <interface> + <name>all</name> + <disable/> + </interface> + <interface> + <name>dsc.0</name> + <version>3</version> + <static> + <group> + <name>232.223.222.1</name> + <source> + <name>212.201.139.66</name> + </source> + <source> + <name>193.17.9.3</name> + </source> + </group> + </static> + </interface> + </igmp> + <mld> + <interface> + <name>ge-0/2/0.30</name> + </interface> + <interface> + <name>ge-0/2/0.20</name> + </interface> + <interface> + <name>all</name> + <disable/> + </interface> + </mld> + <rsvp> + <interface> + <name>all</name> + </interface> + </rsvp> + <mpls> + <statistics> + <file> + <filename>mpls-stat</filename> + <size>5m</size> + <files>10</files> + <undocumented><no-stamp/></undocumented> + </file> + <interval>60</interval> + <auto-bandwidth/> + </statistics> + <explicit-null/> + <ipv6-tunneling/> + <icmp-tunneling/> + <interface> + <name>all</name> + </interface> + </mpls> + <bgp> + <precision-timers/> + <path-selection> + <external-router-id/> + </path-selection> + <log-updown/> + <undocumented><drop-path-attributes>128</drop-path-attributes></undocumented> + <group> + <name>iGEANT</name> + <type>internal</type> + <local-address>62.40.96.19</local-address> + <import>rtbh-ibgp</import> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh</ribgroup-name> + </rib-group> + </unicast> + <flow> + <no-validate>accept-all-flowspec</no-validate> + </flow> + <any> + </any> + </inet> + <inet-vpn> + <unicast> + </unicast> + <flow> + </flow> + </inet-vpn> + <inet6-vpn> + <unicast> + </unicast> + </inet6-vpn> + <l2vpn> + <signaling> + </signaling> + </l2vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <neighbor> + <name>62.40.96.1</name> + <description>mx1.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.2</name> + <description>mx2.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.3</name> + <description>mx1.dub.ie.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.4</name> + <description>mx2.rig.lv.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.5</name> + <description>mx2.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.6</name> + <description>mx1.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.8</name> + <description>mx2.zag.hr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.10</name> + <description>mx2.lju.si.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.11</name> + <description>mx2.ath.gr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.12</name> + <description>mx1.mar.fr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.15</name> + <description>mx1.lon2.uk.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.16</name> + <description>mx1.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.17</name> + <description>mx2.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.20</name> + <description>mx2.bru.be.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.21</name> + <description>mx1.sof.bg.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.25</name> + <description>mx1.dub2.ie.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.26</name> + <description>mx1.ham.de.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.39</name> + <description>mx1.ath2.gr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.1</name> + <description>mx1.bud.hu.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.2</name> + <description>mx1.pra.cz.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.4</name> + <description>mx2.bra.sk.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.5</name> + <description>mx1.lon.uk.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.7</name> + <description>mx1.vie.at.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.10</name> + <description>mx1.poz.pl.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.11</name> + <description>mx1.ams.nl.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.12</name> + <description>mx1.fra.de.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.13</name> + <description>mx1.par.fr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.14</name> + <description>mx1.gen.ch.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.15</name> + <description>mx1.mil2.it.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.16</name> + <description>mx1.mad.es.geant.net</description> + </neighbor> + </group> + <group> + <name>eGEANT</name> + <type>external</type> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh</ribgroup-name> + </rib-group> + </unicast> + <multicast> + </multicast> + <any> + </any> + </inet> + </family> + <neighbor> + <name>62.40.125.138</name> + <description>-- Peering with RoEduNet --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-RoEduNet-nren</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-to-RoEduNet-nren</export> + <peer-as>2614</peer-as> + </neighbor> + <neighbor> + <name>62.40.125.198</name> + <description>--- Peering with RENAM EAP ---</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-RENAM-nren</import> + <export>ps-BOGONS</export> + <export>ps-to-RENAM-nren</export> + <peer-as>9199</peer-as> + </neighbor> + </group> + <group> + <name>eGEANT6</name> + <type>external</type> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh6</ribgroup-name> + </rib-group> + </unicast> + <multicast> + </multicast> + <any> + </any> + </inet6> + </family> + <neighbor> + <name>2001:798:2b:10aa::2</name> + <description>-- IPv6 Peering with RoEduNet --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS-V6</import> + <import>ps-from-RoEduNet-V6-nren</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-to-RoEduNet-V6-nren</export> + <peer-as>2614</peer-as> + </neighbor> + <neighbor> + <name>2001:798:99:1::a6</name> + <description>-- IPv6 Peering with RENAM AP --</description> + <out-delay>10</out-delay> + <import>ps-BOGONS-V6</import> + <import>ps-from-RENAM-V6-nren</import> + <export>ps-BOGONS-V6</export> + <export>ps-to-RENAM-V6-nren</export> + <peer-as>9199</peer-as> + </neighbor> + </group> + <group> + <name>iGEANT6</name> + <type>internal</type> + <local-address>2001:798:2b:10ff::3</local-address> + <import>rtbh-ibgp</import> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh6</ribgroup-name> + </rib-group> + </unicast> + <any> + </any> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <neighbor> + <name>2001:798:19:20ff::1</name> + <description>mx2.ath.gr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:16:20ff::3</name> + <description>mx1.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:16:20ff::4</name> + <description>mx2.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:21:20ff::4</name> + <description>mx2.rig.lv.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:1f:20ff::3</name> + <description>mx2.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:1f:20ff::4</name> + <description>mx1.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2d:20ff::2</name> + <description>mx2.zag.hr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:32:20ff::2</name> + <description>mx2.lju.si.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2f:20ff::1</name> + <description>mx1.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2f:20ff::2</name> + <description>mx2.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2b:20ff::2</name> + <description>mx2.bru.be.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:10:20ff::1</name> + <description>mx1.vie.at.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:14:20ff::1</name> + <description>mx1.fra.de.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:12:20ff::1</name> + <description>mx1.gen.ch.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:17:20ff::1</name> + <description>mx1.mad.es.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:23:20ff::1</name> + <description>mx1.poz.pl.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:13:20ff::1</name> + <description>mx1.pra.cz.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:1b:20ff::1</name> + <description>mx1.bud.hu.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:18:20ff::3</name> + <description>mx1.par.fr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:22:20ff::3</name> + <description>mx1.ams.nl.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:33:20ff::2</name> + <description>mx2.bra.sk.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:1e:20ff::3</name> + <description>mx1.mil2.it.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:28:20ff::1</name> + <description>mx1.lon.uk.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2c:10ff::2</name> + <description>mx1.sof.bg.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::3</name> + <description>mx1.ham.de.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::4</name> + <description>mx1.mar.fr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::5</name> + <description>mx1.lon2.uk.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::1</name> + <description>mx1.dub.ie.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::2</name> + <description>mx1.dub2.ie.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::a</name> + <description>mx1.ath2.gr.geant.net</description> + </neighbor> + </group> + <group> + <name>TOOLS</name> + <type>internal</type> + <description>PEERING WITH TOOLS</description> + <local-address>62.40.96.19</local-address> + <neighbor> + <name>62.40.123.134</name> + <description>DEEPFIELD SERVER</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>PS_TO_DEEPFIELD</export> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>83.97.93.247</name> + <description>EARL Netflow/ISIS/BGP feed VM</description> + <hold-time>180</hold-time> + <passive/> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + <multicast> + </multicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>62.40.99.51</name> + <description>Packet Design Route Recorder VM LON2</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>193.177.129.61</name> + <description>Kentik EU</description> + <hold-time>720</hold-time> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + </group> + <group> + <name>DUMMY_EBGP</name> + <type>external</type> + <description>Dummy group for stability; see XTAC TT#2016122634000229</description> + <local-address>62.40.96.19</local-address> + <family> + <inet> + <any> + </any> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + <inet6> + <any> + </any> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <cluster>62.40.96.19</cluster> + <peer-as>56902</peer-as> + <local-as> + <as-number>20965</as-number> + </local-as> + <neighbor> + <name>192.168.254.254</name> + <passive/> + <import>ps-deny-all</import> + <export>nhs-ibgp</export> + </neighbor> + </group> + <group> + <name>DUMMY_EBGP6</name> + <type>external</type> + <description>Dummy group for stability; see XTAC TT#2016122634000229</description> + <local-address>2001:798:2b:10ff::3</local-address> + <family> + <inet6> + <any> + </any> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <cluster>62.40.96.19</cluster> + <peer-as>56902</peer-as> + <local-as> + <as-number>20965</as-number> + </local-as> + <neighbor> + <name>100::1</name> + <passive/> + <import>ps-deny-all</import> + <export>nhs-ibgp</export> + </neighbor> + </group> + <group> + <name>TOOLSv6</name> + <type>internal</type> + <description>PEERING WITH TOOLS</description> + <local-address>2001:798:2b:10ff::3</local-address> + <neighbor> + <name>2001:798:bb:2::2</name> + <description>DEEPFIELD SERVER</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet6> + <unicast> + </unicast> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>PS_TO_DEEPFIELD</export> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>2001:798:3::1de</name> + <description>EARL Netflow/ISIS/BGP feed VM</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet6> + <unicast> + </unicast> + <multicast> + </multicast> + </inet6> + </family> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>2a0c:dec0:f100:1::179</name> + <description>Kentik EU</description> + <hold-time>720</hold-time> + <import>ps-deny-all</import> + <family> + <inet6> + <unicast> + </unicast> + <multicast> + </multicast> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + </group> + </bgp> + <isis> + <traceoptions> + <file> + <filename>ISIS_trace</filename> + <size>10m</size> + <files>10</files> + </file> + <flag> + <name>state</name> + </flag> + </traceoptions> + <export>ps-static-mx-to-igp</export> + <rib-group> + <inet>unicast-multicast</inet> + <inet6>unicast-multicastv6</inet6> + </rib-group> + <source-packet-routing> + <node-segment> + <ipv4-index>4619</ipv4-index> + <ipv6-index>6619</ipv6-index> + <index-range>8192</index-range> + </node-segment> + </source-packet-routing> + <level> + <name>1</name> + <disable/> + </level> + <level> + <name>2</name> + <wide-metrics-only/> + </level> + <interface> + <name>ae4.0</name> + <point-to-point/> + <undocumented><bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection></undocumented> + <level> + <name>2</name> + <metric>500</metric> + </level> + </interface> + <interface> + <name>ae8.0</name> + <point-to-point/> + <undocumented><bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection></undocumented> + <level> + <name>2</name> + <metric>70</metric> + </level> + </interface> + <interface> + <name>all</name> + <passive> + </passive> + </interface> + <interface> + <name>fxp0.0</name> + <disable/> + </interface> + </isis> + <msdp> + <rib-group> + <undocumented><inet/></undocumented> + <ribgroup-name>multicast</ribgroup-name> + </rib-group> + <active-source-limit> + <maximum>20000</maximum> + <threshold>20000</threshold> + <log-interval>32700</log-interval> + </active-source-limit> + <local-address>62.40.96.19</local-address> + <traceoptions inactive="inactive"> + <file> + <filename>msdp-trace2</filename> + <size>50m</size> + </file> + <flag> + <name>all</name> + </flag> + </traceoptions> + <source> + <name>0.0.0.0/0</name> + <active-source-limit> + <maximum>1000</maximum> + <threshold>900</threshold> + <log-interval>32700</log-interval> + </active-source-limit> + </source> + <group> + <name>external_msdp</name> + <export>Bogon-Sources</export> + <export>ASM-Allow</export> + <import>Bogon-Sources</import> + <import>ASM-Allow</import> + <peer> + <name>62.40.125.138</name> + <local-address>62.40.125.137</local-address> + </peer> + </group> + <group> + <name>internal_msdp</name> + <mode>mesh-group</mode> + <peer> + <name>62.40.96.1</name> + </peer> + <peer> + <name>62.40.96.2</name> + </peer> + <peer> + <name>62.40.96.4</name> + </peer> + <peer> + <name>62.40.96.5</name> + </peer> + <peer> + <name>62.40.96.6</name> + </peer> + <peer> + <name>62.40.96.8</name> + </peer> + <peer> + <name>62.40.96.10</name> + </peer> + <peer> + <name>62.40.96.16</name> + </peer> + <peer> + <name>62.40.96.17</name> + </peer> + <peer> + <name>62.40.96.20</name> + </peer> + <peer> + <name>62.40.97.1</name> + </peer> + <peer> + <name>62.40.97.2</name> + </peer> + <peer> + <name>62.40.97.4</name> + </peer> + <peer> + <name>62.40.97.5</name> + </peer> + <peer> + <name>62.40.97.7</name> + </peer> + <peer> + <name>62.40.97.10</name> + </peer> + <peer> + <name>62.40.97.11</name> + </peer> + <peer> + <name>62.40.97.12</name> + </peer> + <peer> + <name>62.40.97.13</name> + </peer> + <peer> + <name>62.40.97.14</name> + </peer> + <peer> + <name>62.40.97.16</name> + </peer> + <peer> + <name>62.40.97.15</name> + </peer> + <peer> + <name>62.40.96.11</name> + </peer> + <peer> + <name>62.40.96.21</name> + </peer> + <peer> + <name>62.40.96.26</name> + </peer> + <peer> + <name>62.40.96.25</name> + </peer> + <peer> + <name>62.40.96.3</name> + </peer> + <peer> + <name>62.40.96.12</name> + </peer> + <peer> + <name>62.40.96.15</name> + </peer> + <peer> + <name>62.40.96.39</name> + </peer> + </group> + </msdp> + <ldp> + <track-igp-metric/> + <deaggregate/> + <interface> + <name>ae4.0</name> + </interface> + <interface> + <name>ae8.0</name> + </interface> + <interface> + <name>lo0.0</name> + </interface> + <neighbor> + <name>62.40.99.50</name> + </neighbor> + </ldp> + <pim> + <rib-group> + <inet>multicast</inet> + <inet6>multicastv6</inet6> + </rib-group> + <rp> + <bootstrap> + <family> + <inet6> + <priority>1</priority> + <import>pim-import</import> + <export>pim-export</export> + </inet6> + </family> + </bootstrap> + <embedded-rp> + <group-ranges> + <name>ff7e::/16</name> + </group-ranges> + </embedded-rp> + <static> + <address> + <name>10.10.10.10</name> + </address> + <address> + <name>2001:660:3007:300:1::</name> + <group-ranges> + <name>ff0e::/16</name> + </group-ranges> + <group-ranges> + <name>ff1e::/16</name> + </group-ranges> + <group-ranges> + <name>ff3e::/16</name> + </group-ranges> + </address> + <address> + <name>2001:798:2016:10ff::3</name> + <group-ranges> + <name>ff08::1/128</name> + </group-ranges> + </address> + </static> + </rp> + <interface> + <name>all</name> + <mode>sparse</mode> + <undocumented><version>2</version></undocumented> + </interface> + <interface> + <name>fxp0.0</name> + <disable/> + </interface> + </pim> + <l2circuit> + <traceoptions> + <file> + <filename>l2circuits</filename> + <size>2m</size> + <files>10</files> + <world-readable/> + </file> + <flag> + <name>connections</name> + </flag> + <flag> + <name>error</name> + </flag> + </traceoptions> + </l2circuit> + <neighbor-discovery> + <onlink-subnet-only/> + </neighbor-discovery> + <oam> + <ethernet> + <link-fault-management> + <traceoptions> + <file> + <filename>lfmd_traceopts</filename> + <size>4000000</size> + <files>10</files> + </file> + <flag> + <name>all</name> + </flag> + </traceoptions> + <action-profile> + <name>log-event-frame-error</name> + <event> + <link-event-rate> + <frame-error>1</frame-error> + </link-event-rate> + </event> + <action> + <syslog/> + </action> + </action-profile> + <action-profile> + <name>log-event-frame-period</name> + <event> + <link-event-rate> + <frame-period>1</frame-period> + </link-event-rate> + </event> + <action> + <syslog/> + </action> + </action-profile> + <action-profile> + <name>log-event-symbol-period</name> + <event> + <link-event-rate> + <symbol-period>1</symbol-period> + </link-event-rate> + </event> + <action> + <syslog/> + </action> + </action-profile> + <interface> + <name>xe-0/0/0</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-1/0/1</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-1/1/0</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-0/0/1</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + </link-fault-management> + <connectivity-fault-management> + <performance-monitoring> + <hardware-assisted-timestamping/> + <delegate-server-processing/> + <hardware-assisted-keepalives>enable</hardware-assisted-keepalives> + </performance-monitoring> + <maintenance-domain> + <name>GEANT</name> + <level>0</level> + <maintenance-association> + <name>GEANT-BB-mx1.buc.ro-to-mx1.bud.hu</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8003</name> + <interface> + <interface-name>ae4.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8004</name> + </remote-mep> + </mep> + </maintenance-association> + <maintenance-association> + <name>GEANT-BB-mx1.buc.ro-to-mx1.sof.bg</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8003</name> + <interface> + <interface-name>ae8.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8020</name> + </remote-mep> + </mep> + </maintenance-association> + </maintenance-domain> + </connectivity-fault-management> + </ethernet> + </oam> + <lldp> + <interface> + <name>all</name> + <disable/> + </interface> + <interface> + <name>xe-0/0/1</name> + </interface> + <interface> + <name>xe-1/0/1</name> + </interface> + <interface> + <name>xe-0/0/0</name> + </interface> + <interface> + <name>xe-1/1/0</name> + </interface> + <interface> + <name>ge-0/2/0</name> + </interface> + </lldp> + </protocols> + <policy-options> + <prefix-list> + <name>geant-address-space</name> + <prefix-list-item> + <name>62.40.96.0/19</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-address-space-short</name> + <prefix-list-item> + <name>62.40.96.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.98.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.102.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.40/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.120/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.16/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.27/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.109.16/29</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.112.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.116.0/23</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-address-space-V6</name> + <prefix-list-item> + <name>2001:798::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-RoEduNet</name> + <prefix-list-item> + <name>31.14.19.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.120.248.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>37.128.224.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>46.243.112.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>62.192.70.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>77.81.184.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.11.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.21.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.107.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.120.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.170.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.191.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.222.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.223.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.96.227.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.16.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.64.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.84.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.86.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.88.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.108.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.208.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.250.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.252.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.181.70.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.181.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.181.156.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.181.247.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.247.22.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.46.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.47.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.49.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.54.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.77.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.87.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.92.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.139.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.140.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.177.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.182.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.202.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.203.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.204.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.208.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.236.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.240.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.120.252.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.20.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.21.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.22.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.32.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.33.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.59.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.64.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.128.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.141.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.152.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.166.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.176.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.121.251.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.122.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>89.34.160.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>89.38.156.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>89.38.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>89.40.218.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.212.254.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.113.252.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>94.176.135.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>94.177.29.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>141.85.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>176.126.208.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>178.23.64.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>185.118.200.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>188.209.215.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>188.240.81.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>188.247.234.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.129.3.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.129.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.162.16.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.0.225.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.138.98.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.27.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.34.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.37.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.38.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.40.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.48.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.56.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.62.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.65.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.90.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.93.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.230.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>193.230.188.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.230.232.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.230.235.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.230.238.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.3.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.5.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.32.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.44.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.129.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.254.230.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.32.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.40.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.42.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.44.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.45.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.57.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.58.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.61.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.62.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.65.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.69.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.70.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.73.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.114.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.120.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.148.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.156.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.174.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.180.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.197.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.102.240.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.105.6.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.105.9.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.105.10.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.105.16.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.116.136.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.169.191.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.176.164.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.14.13.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.95.166.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.110.4.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.110.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.110.5.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.189.145.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.35.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>217.73.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>217.156.11.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.156.104.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project-interfaces</name> + <prefix-list-item> + <name>62.40.100.160/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.162/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.169/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.209/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.20/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.224/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.60/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.62/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.113/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.121/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.174/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.178/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.213/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.5/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.89/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.56/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.102/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.177/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.185/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.209/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.225/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.233/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.241/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.5/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.13/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.37/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.53/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.69/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.77/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.105/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.241/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.89/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.105/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.113/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.121/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.145/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.153/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.169/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.185/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.148/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.150/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.209/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.217/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.225/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.233/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.241/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.249/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.9/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-ROEDUNET-v6</name> + <prefix-list-item> + <name>2001:b30::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:5e80::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project-interfaces6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::b9/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::bd/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::c1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::cd/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:5::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:d::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:33::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:35::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:36::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:37::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:38::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:39::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:3a::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:41::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:42::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:49::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:3::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:7::1/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project6</name> + <prefix-list-item> + <name>2001:798:1:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:1:2::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2:1::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:0002:284d::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2:284d::/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2:284d::60/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::103/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::104/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::10a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::10b/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::147/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::151/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:2::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:3::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:3::d/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:5::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:11::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:96::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:aa::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:aa::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:14:c8::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:18:96::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:18:99::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:22:16::0/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:50::11/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::7/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:99::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::16/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::1a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::1b/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::1c/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::22/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::26/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::2a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::2e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::32/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::33/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::36/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::38/126</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::3a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::3e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::42/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::46/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::4a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::4e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::52/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::56/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::5a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::5e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::62/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::66/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::6a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::6e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::72/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::76/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::7a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::7e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::82/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::86/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::8a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::8e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::92/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::96/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::9a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::9e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::a2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::a6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::aa/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::ae/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::b2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::ba/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::be/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::c2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::ce/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:5::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:c::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:c::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:d::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1a::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1b::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1e::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1e::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1e::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:23::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:25::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:25::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2a::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2a::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2b::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2b::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2e::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2e::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:33::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:34::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:34::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:34::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:35::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:36::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:37::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:38::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:39::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:3a::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:41::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:42::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:43::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:49::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:4d::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:3::0/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:7::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:10::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::52/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::56/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::5a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::5e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::62/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::66/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::6a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::6e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::72/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::76/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2001::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2002::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2012:47::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:28::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:2d::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f99a:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f9a1:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f9a2:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f9a3:28::0/125</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:28::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:2d01::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:2d02::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:28::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:2d01::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:2d02::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:10::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:10::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:12::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:12::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:13::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:13::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:14::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:14::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:16::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:16::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:17::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:17::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:18::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:18::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:19::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:19::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1b::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1b::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1e::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1e::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1f::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:21::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:21::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:22::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:22::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:23::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:23::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:28::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:28::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2b::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2b::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2c::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2c::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff10:a5::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:ff10:00a5::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:11::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff23:28::2/128</name> + </prefix-list-item> + <comment>/* TT#2016083134000549 pS LS testing instance access on port 8090 */</comment> + <prefix-list-item> + <name>2001:798:ff32:2e::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff98:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9b:18::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9b:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9d:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9e:10::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9e:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9e:28::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ffa4:14::0/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:1::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b30:1000:19::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2620:0:6b0::26e5:4207/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geantnoc-address-space6</name> + </prefix-list> + <prefix-list> + <name>bogons-list6</name> + <prefix-list-item> + <name>::/8</name> + </prefix-list-item> + <prefix-list-item> + <name>100::/8</name> + </prefix-list-item> + <prefix-list-item> + <name>200::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>400::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>600::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>800::/5</name> + </prefix-list-item> + <prefix-list-item> + <name>1000::/4</name> + </prefix-list-item> + <prefix-list-item> + <name>2000::/16</name> + </prefix-list-item> + <prefix-list-item> + <name>3fff::/16</name> + </prefix-list-item> + <prefix-list-item> + <name>4000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>6000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>8000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>a000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>c000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>e000::/4</name> + </prefix-list-item> + <prefix-list-item> + <name>f000::/5</name> + </prefix-list-item> + <prefix-list-item> + <name>f800::/6</name> + </prefix-list-item> + <prefix-list-item> + <name>fc00::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>fe00::/9</name> + </prefix-list-item> + <prefix-list-item> + <name>fec0::/10</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>pref-list-router-access</name> + <prefix-list-item> + <name>62.40.106.232/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.72/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.102/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.197.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.227.249/32</name> + </prefix-list-item> + <prefix-list-item> + <name>130.104.230.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>139.165.223.48/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.7.100/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project</name> + <prefix-list-item> + <name>38.229.66.20/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.8/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.42/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.51/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.106/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.136/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.192/26</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.215/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.161/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.168/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.208/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.8/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.32/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.72/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.76/30</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.80/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.88/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.98/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.104/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.112/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.132/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.134/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.136/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.168/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.176/30</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.180/30</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.184/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.192/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.197/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.199/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.202/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.205/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.207/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.212/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.224/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.225/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.227/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.105.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.3/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.32/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.34/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.35/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.42/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.63/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.67/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.68/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.80/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.83/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.90/32</name> + </prefix-list-item> + <comment>/* Netflow Auditor */</comment> + <prefix-list-item> + <name>62.40.106.104/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.112/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.120/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.131/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.133/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.135/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.137/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.145/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.147/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.149/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.151/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.153/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.155/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.157/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.159/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.161/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.165/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.167/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.169/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.171/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.173/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.175/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.177/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.181/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.183/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.185/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.189/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.191/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.195/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.197/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.199/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.201/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.240/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.251/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.255/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.198/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.206/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.214/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.222/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.230/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.246/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.248/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.50/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.58/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.98/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.140/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.192/26</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.0/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.32/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.64/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.96/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.128/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.112.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.58/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.59/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.60/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.88/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.104/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.115/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.157/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.166/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.167/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.168/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.3/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.19/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.35/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.37/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.39/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.43/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.47/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.51/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.53/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.55/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.59/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.63/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.67/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.69/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.71/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.75/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.77/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.79/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.83/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.85/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.87/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.99/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.103/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.107/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.108/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.130/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.138/32</name> + </prefix-list-item> + <comment>/* requested Massimiliano Adamo */</comment> + <prefix-list-item> + <name>62.40.114.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.162/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.164/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.170/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.176/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.184/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.192/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.208/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.224/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.232/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.240/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.46/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.107/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.111/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.156/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.74/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.82/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.126/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.153/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.48/29</name> + </prefix-list-item> + <comment>/* TT#2016083134000549 pS LS testing instance access on port 8090 */</comment> + <prefix-list-item> + <name>62.40.120.50/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.66/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.67/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.240/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.92/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.110/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.201/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.92/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.134/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.142/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.149/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.151/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.218/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.234/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.235/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.242/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.125.254/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.155/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.171/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.187/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.189/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.191/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.195/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.197/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.127.32/31</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.88.190/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.89.64/26</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.89.128/26</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.239/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.245/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.246/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.51/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.140.82/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>bogons-list</name> + <prefix-list-item> + <name>0.0.0.0/8</name> + </prefix-list-item> + <prefix-list-item> + <name>10.0.0.0/8</name> + </prefix-list-item> + <prefix-list-item> + <name>100.64.0.0/10</name> + </prefix-list-item> + <prefix-list-item> + <name>127.0.0.0/8</name> + </prefix-list-item> + <prefix-list-item> + <name>169.254.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>172.16.0.0/12</name> + </prefix-list-item> + <prefix-list-item> + <name>192.0.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.0.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.168.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>198.18.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>198.51.100.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>203.0.113.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>224.0.0.0/3</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>cnis-server</name> + <prefix-list-item> + <name>62.40.122.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.130/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>ncc-oob-address-space</name> + <prefix-list-item> + <name>172.16.5.252/30</name> + </prefix-list-item> + <prefix-list-item> + <name>172.16.14.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-</name> + </prefix-list> + <prefix-list> + <name>INTERNAL-address-space</name> + <prefix-list-item> + <name>62.40.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>EXTERNAL-address-space</name> + <prefix-list-item> + <name>62.40.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-routers</name> + <prefix-list-item> + <name>62.40.96.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geantncc-address-space</name> + <comment>/* NCC DR VPN */</comment> + <prefix-list-item> + <name>62.40.108.192/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.125.250/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DNS</name> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.100/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.146/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>nren-access</name> + <prefix-list-item> + <name>62.40.96.11/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.124.22/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.124.89/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.124.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.160.0/26</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.250.128/26</name> + </prefix-list-item> + <prefix-list-item> + <name>82.116.200.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.212.9.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>85.254.248.3/32</name> + </prefix-list-item> + <prefix-list-item> + <name>85.254.248.15/32</name> + </prefix-list-item> + <prefix-list-item> + <name>109.105.113.42/32</name> + </prefix-list-item> + <prefix-list-item> + <name>109.105.113.85/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.197.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.202.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.229.249/32</name> + </prefix-list-item> + <prefix-list-item> + <name>130.59.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>130.59.211.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>130.206.6.0/27</name> + </prefix-list-item> + <prefix-list-item> + <name>141.85.128.0/26</name> + </prefix-list-item> + <prefix-list-item> + <name>158.64.1.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>158.64.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.65.185.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.192.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.219.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.228.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.231.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.247.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.248.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.249.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.250.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.2.18.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.7.96/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.44.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.46.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.174.247.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.188.32.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.206.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.140.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>194.42.9.200/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.42.9.252/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.141.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.141.251.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.160.23.0/27</name> + </prefix-list-item> + <prefix-list-item> + <name>194.177.210.213/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.177.211.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.177.211.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.98.238.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.113.228.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.64.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>195.251.27.7/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:660:3001:4019::194/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:18::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:1c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:f0:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:400::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:19:10aa::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:19:20ff::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:1e:10aa::5/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:948:4:2::42/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:948:4:3::85/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b30:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b30:1:140::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>fe80::21d:b500:64d6:127a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>fe80::21d:b5ff:fe69:893d/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>restena-access-v6</name> + <prefix-list-item> + <name>2001:a18:1:4::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a18:1:8::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a18:1:40::/60</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a18:1:1000::/52</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:4::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:8::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:40::/60</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:1000::/52</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>restena-access</name> + <prefix-list-item> + <name>158.64.1.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>158.64.15.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>nmteam-dev-servers</name> + <prefix-list-item> + <name>62.40.106.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.254/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DC</name> + <prefix-list-item> + <name>62.40.106.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.10/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.134/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.136/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.121/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.15/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.20/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.87/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.100/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.103/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.66/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Infrastructure</name> + <prefix-list-item> + <name>62.40.97.11/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.12/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.14/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.15/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.178/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.134/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.212/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.228/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.35/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.166/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.186/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.198/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.218/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.242/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.10/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.14/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.22/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.34/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.38/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.46/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.58/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.77/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.128/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.130/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.131/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.132/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.133/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.134/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.135/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.136/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.137/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.140/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.142/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.143/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.144/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.145/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.147/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.53/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.130/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.50/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.76/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.222/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.100/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.32/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.40/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.150/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.154/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.155/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.156/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.157/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.158/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.165/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.181/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.184/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.195/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.227/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.147/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.186/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.23/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.103/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.150/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.180/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.63/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.87/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.85/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.90.187/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.5/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.16/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.68/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.80/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.104/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.107/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.119/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.16/30</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.20/31</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.66/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::145/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-f</name> + </prefix-list> + <prefix-list> + <name>r</name> + </prefix-list> + <prefix-list> + <name>vuln-scanner</name> + <prefix-list-item> + <name>83.97.93.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::145/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>renater-access</name> + <prefix-list-item> + <name>195.98.238.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:660:3001:4019::194/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-anycast</name> + <prefix-list-item> + <name>192.33.14.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.58.128.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.2.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-anycast-v6</name> + <prefix-list-item> + <name>2001:678:4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:5::/48</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination-count</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination-count6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source-count</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source-count6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DC-v6</name> + <prefix-list-item> + <name>2001:610:9d8:5::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280::1100/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280:0:44ce:41ac:526a:df53/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280:0:88bc:3d46:679b:41c6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280:0:b052:e71f:8254:470b/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::123/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:10:99::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:52::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:52::8/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>INTERNAL-address-spaceV6</name> + <prefix-list-item> + <name>2001:798:ee::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f000::/39</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Infrastructure-v6</name> + <prefix-list-item> + <name>2001:630:280::1005/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::11f/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::182/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:10:97::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:12:20ff::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:a0::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:a0::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:20ff::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:15:a0::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:22:20ff::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:58::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::5/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::7/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:33::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:50::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:50::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:50::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:b4::e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9e:10::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:1::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2002:3e28:69d2::3e28:69d2/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>EXTERNAL-address-spaceV6</name> + <prefix-list-item> + <name>2001:798:dd::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f200::/39</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f400::/38</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f800::/40</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geantnoc-address-space-v6</name> + </prefix-list> + <prefix-list> + <name>GEANT-DNS-V6</name> + <prefix-list-item> + <name>2001:798:2:284d::30/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:4d::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:10::2/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-JUNOSSPACE</name> + <prefix-list-item> + <name>62.40.113.90/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.18/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-ias-address-space</name> + <prefix-list-item> + <name>83.97.88.0/21</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-ias-address-space-V6</name> + <prefix-list-item> + <name>2001:798:1::/48</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_NTP</name> + <prefix-list-item> + <name>62.40.97.11/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.12/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.14/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.23/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.103/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>RE_BGP_inet</name> + <apply-path>protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>RE_BGP_inet6</name> + <apply-path>protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_BGP_inet</name> + <apply-path>routing-instances IAS protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_BGP_inet6</name> + <apply-path>routing-instances IAS protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>CLS_BGP_inet</name> + <apply-path>routing-instances CLS protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>CLS_BGP_inet6</name> + <apply-path>routing-instances CLS protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_DUMMY_BGP_inet</name> + <apply-path>routing-instances IAS_DUMMY protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_DUMMY_BGP_inet6</name> + <apply-path>routing-instances IAS_DUMMY protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>lhcone-l3vpn_BGP_inet</name> + <apply-path>routing-instances lhcone-l3vpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>lhcone-l3vpn_BGP_inet6</name> + <apply-path>routing-instances lhcone-l3vpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>taas-control_BGP_inet</name> + <apply-path>routing-instances taas-control protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>taas-control_BGP_inet6</name> + <apply-path>routing-instances taas-control protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>mgmt-l3vpn_BGP_inet</name> + <apply-path>routing-instances mgmt-l3vpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>mgmt-l3vpn_BGP_inet6</name> + <apply-path>routing-instances mgmt-l3vpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn_BGP_inet</name> + <apply-path>routing-instances mdvpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn_BGP_inet6</name> + <apply-path>routing-instances mdvpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>GWS_GRNET_BGP_inet</name> + <apply-path>routing-instances GWS_GRNET protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>GWS_GRNET_BGP_inet6</name> + <apply-path>routing-instances GWS_GRNET protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn-nren-gn_BGP_inet</name> + <apply-path>routing-instances mdvpn-nren-gn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn-nren-gn_BGP_inet6</name> + <apply-path>routing-instances mdvpn-nren-gn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>confine-l3vpn_BGP_inet</name> + <apply-path>routing-instances confine-l3vpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>confine-l3vpn_BGP_inet6</name> + <apply-path>routing-instances confine-l3vpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_BGP_inet</name> + <apply-path>logical-systems VPN-PROXY protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_BGP_inet6</name> + <apply-path>logical-systems VPN-PROXY protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>VRR_BGP_inet</name> + <apply-path>logical-systems VRR protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>VRR_BGP_inet6</name> + <apply-path>logical-systems VRR protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>geant-cameras</name> + <prefix-list-item> + <name>62.40.115.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.64/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.128/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.144/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.160/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.168/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.32/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.16/28</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_RI_BGP_inet</name> + <apply-path>logical-systems VPN-PROXY routing-instances <*> protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_RI_BGP_inet6</name> + <apply-path>logical-systems VPN-PROXY routing-instances <*> protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>space-local</name> + <prefix-list-item> + <name>127.0.0.1/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>xantaro-address-space</name> + <prefix-list-item> + <name>213.86.104.34/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DNS-EXT</name> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.100/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-MSDP</name> + <apply-path>protocols msdp group <*> peer <*></apply-path> + </prefix-list> + <prefix-list> + <name>GEANT-SNMP</name> + <apply-path>snmp community <*> clients <*></apply-path> + </prefix-list> + <prefix-list> + <name>GEANT-LDP</name> + <apply-path>protocols l2circuit neighbor <*></apply-path> + </prefix-list> + <prefix-list> + <name>geant-nagiosmonitoring-space</name> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.100/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.108/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.122/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-nagiosmonitoring-spacev6</name> + <prefix-list-item> + <name>2001:798:ee:f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:10::2/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>ddos-scrubbing</name> + <prefix-list-item> + <name>62.40.100.178/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.41/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-lg</name> + <prefix-list-item> + <name>83.97.92.82/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.39/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.62/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.63/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dashboard-servers</name> + <prefix-list-item> + <name>62.40.104.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.239/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dashboard-servers-v6</name> + <prefix-list-item> + <name>2001:798:f99c:18::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f99c:22::/64</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-renam</name> + <prefix-list-item> + <name>81.180.64.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.84.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.57.44.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.226.65.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-renam-v6</name> + <prefix-list-item> + <name>2a04:7580::/29</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dashboard-vm</name> + <prefix-list-item> + <name>62.40.114.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.239/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>imerja-external</name> + <prefix-list-item> + <name>94.199.232.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.234.36/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.236.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.239.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.239.66/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Superpop-v4</name> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Superpop-v6</name> + <prefix-list-item> + <name>2001:798:3::/64</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-address-space-v6</name> + <prefix-list-item> + <name>2001:798::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>opennsa-servers</name> + <prefix-list-item> + <name>83.97.93.92/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>opennsa-servers-v6</name> + <prefix-list-item> + <name>2001:798:3::15f/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-rancid</name> + <comment>/* TEST */</comment> + <prefix-list-item> + <name>83.97.92.115/32</name> + </prefix-list-item> + <comment>/* UAT */</comment> + <prefix-list-item> + <name>83.97.92.142/32</name> + </prefix-list-item> + <comment>/* PROD */</comment> + <prefix-list-item> + <name>83.97.92.246/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>corporate-address-space6</name> + <prefix-list-item> + <name>2001:610:9d8::/62</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:610:9d8:4::/62</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:2::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:3::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:64::/56</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2::/56</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:100::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:101::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:102::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:103::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:104::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:108::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:110::/64</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>corporate-address-space</name> + <prefix-list-item> + <name>62.40.99.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.201/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.112.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.248/29</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.0/24</name> + </prefix-list-item> + </prefix-list> + <policy-statement> + <name>ASM-Allow</name> + <term> + <name>Bogon-Groups</name> + <from> + <route-filter> + <address>224.0.1.2/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.1/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.3/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.8/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.22/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.24/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.25/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.35/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.39/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.40/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.60/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.76/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.2.1/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.2.2/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.1.0.1/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.1.0.38/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.77.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>224.128.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>232.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>233.0.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>233.128.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>239.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>224.0.0.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <trace/> + <reject/> + </then> + </term> + <term> + <name>ASM-Whitelist</name> + <from> + <route-filter> + <address>224.0.0.0/4</address> + <orlonger/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Deny-Everything-Else</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>Bogon-Sources</name> + <term> + <name>RFC-1918-Addresses</name> + <from> + <source-address-filter> + <address>10.0.0.0/8</address> + <orlonger/> + </source-address-filter> + <source-address-filter> + <address>127.0.0.0/8</address> + <orlonger/> + </source-address-filter> + <source-address-filter> + <address>172.16.0.0/12</address> + <orlonger/> + </source-address-filter> + <source-address-filter> + <address>192.168.0.0/16</address> + <orlonger/> + </source-address-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>accept-everything-else</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>PS_TO_DEEPFIELD</name> + <term> + <name>BOGONS_REJECT</name> + <from> + <prefix-list> + <name>bogons-list</name> + </prefix-list> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>REDISTRIBUTE_CONNECTED</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <community> + <add/> + <community-name>IGP_ROUTES_DEEPFIELD</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>BGP_ACCEPT</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DEFAULT</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>accept-all-flowspec</name> + <then> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>dest-class-usage</name> + <term> + <name>DWS</name> + <from> + <community>geant-dws</community> + </from> + <then> + <destination-class>dws-in</destination-class> + </then> + </term> + <term> + <name>google-in</name> + <from> + <community>geant-google</community> + </from> + <then> + <destination-class>google-in</destination-class> + </then> + </term> + <term> + <name>ixpeers-in</name> + <from> + <community>geant-ixpeers</community> + </from> + <then> + <destination-class>ixpeers-in</destination-class> + </then> + </term> + </policy-statement> + <policy-statement> + <name>load-balancing-policy</name> + <then> + <load-balance> + <per-packet/> + </load-balance> + </then> + </policy-statement> + <policy-statement> + <name>nhs-ibgp</name> + <term> + <name>next-hop-self</name> + <then> + <next-hop> + <self/> + </next-hop> + </then> + </term> + </policy-statement> + <policy-statement> + <name>no-bsr</name> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>pim-export</name> + <from> + <interface>xe-1/1/0.0</interface> + <interface>ae11.0</interface> + </from> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>pim-import</name> + <from> + <interface>xe-1/1/0.0</interface> + <interface>ae11.0</interface> + </from> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>ps-AS-SELF-REJECT</name> + <term> + <name>1</name> + <from> + <as-path>AS-SELF</as-path> + </from> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-BOGONS</name> + <term> + <name>bogons</name> + <from> + <route-filter> + <address>0.0.0.0/0</address> + <exact/> + </route-filter> + <route-filter> + <address>0.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>169.254.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>172.16.0.0/12</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.0.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.0.2.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.168.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>198.18.0.0/15</address> + <orlonger/> + </route-filter> + <route-filter> + <address>198.51.100.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>203.0.113.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>224.0.0.0/3</address> + <orlonger/> + </route-filter> + <route-filter> + <address>10.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>127.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>100.64.0.0/10</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>as-path-length-limit</name> + <from> + <protocol>bgp</protocol> + <as-path>MAX-AS_PATH</as-path> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>community-limit</name> + <from> + <protocol>bgp</protocol> + <community-count> + <name>50</name> + <orhigher/> + </community-count> + <community-count> + <name>100</name> + <orhigher/> + </community-count> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>REJECT_IX_PREFIXES</name> + <from> + <route-filter> + <address>80.249.208.0/21</address> + <orlonger/> + </route-filter> + <route-filter> + <address>193.203.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>195.66.224.0/22</address> + <orlonger/> + </route-filter> + <route-filter> + <address>217.29.66.0/23</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.65.185.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>91.210.16.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>185.1.47.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>80.81.192.0/21</address> + <orlonger/> + </route-filter> + <route-filter> + <address>185.1.68.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>193.188.137.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-BOGONS-V6</name> + <term> + <name>martians</name> + <from> + <family>inet6</family> + <route-filter> + <address>::/0</address> + <exact/> + </route-filter> + <route-filter> + <address>::/96</address> + <exact/> + </route-filter> + <route-filter> + <address>::1/128</address> + <exact/> + </route-filter> + <route-filter> + <address>fec0::/10</address> + <orlonger/> + </route-filter> + <route-filter> + <address>fe80::/10</address> + <orlonger/> + </route-filter> + <route-filter> + <address>ff00::/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>3ffe::/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:0db8::/32</address> + <orlonger/> + </route-filter> + <route-filter> + <address>fc00::/7</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>as-path-length-limit</name> + <from> + <family>inet6</family> + <protocol>bgp</protocol> + <as-path>MAX-AS_PATH</as-path> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>community-limit</name> + <from> + <family>inet6</family> + <protocol>bgp</protocol> + <community-count> + <name>50</name> + <orhigher/> + </community-count> + <community-count> + <name>100</name> + <orhigher/> + </community-count> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>REJECT_IX_PREFIXES</name> + <from> + <route-filter> + <address>2001:7f8:30::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:1::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:4::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:b:100::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:1c:24a::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:14::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:36::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:a0::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:35::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-RENAM-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-renam-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RENAM-V6-nren</name> + <from> + <prefix-list> + <name>route-from-renam-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>geant-renam</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RENAM-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-RENAM-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-renam</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RENAM-nren</name> + <from> + <prefix-list> + <name>route-from-renam</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>geant-renam</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RENAM-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-RoEduNet-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-ROEDUNET-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-V6-nren</name> + <from> + <prefix-list> + <name>route-from-ROEDUNET-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-RoEduNet-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-RoEduNet</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-nren</name> + <from> + <prefix-list> + <name>route-from-RoEduNet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-RENAM-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-renam-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-RENAM-V6-nren-general</name> + <from> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>INFO_PUBLIC_PEER</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-RENAM-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-RENAM-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-renam-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-RENAM-nren-general</name> + <from> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-helix</community> + <community>INFO_PUBLIC_PEER</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-RENAM-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-RoEduNet-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-roedunet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-RoEduNet-V6-nren-general</name> + <from> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>INFO_PUBLIC_PEER</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-RoEduNet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-RoEduNet-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-roedunet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-RoEduNet-nren-general</name> + <from> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-helix</community> + <community>INFO_PUBLIC_PEER</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-RoEduNet-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-PRIVATE-AS-BLOCK</name> + <from> + <as-path>AS-PRIVATE</as-path> + </from> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>ps-deny-all</name> + <term> + <name>deny-all</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-direct-route-label</name> + <term> + <name>1</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <label-allocation>per-table</label-allocation> + <accept/> + </then> + </term> + <term> + <name>2</name> + <then> + <label-allocation>per-nexthop</label-allocation> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-V6-static</name> + <from> + <prefix-list> + <name>geant-address-space-V6</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-V6-static-MED20</name> + <from> + <prefix-list> + <name>geant-address-space-V6</name> + </prefix-list> + </from> + <then> + <metric> + <metric>20</metric> + </metric> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-static</name> + <term> + <name>static</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-static-MED20</name> + <term> + <name>static</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + <then> + <metric> + <metric>20</metric> + </metric> + </then> + </policy-statement> + <policy-statement> + <name>ps-from-CLS-vrf</name> + <term> + <name>CLS-routes</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <community> + <add/> + <community-name>CLS-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>CLS-interface-routes</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <community> + <add/> + <community-name>CLS-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-RENAM-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-renam-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-renam</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>INFO_EAP_NREN</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-renam-V6-nren</name> + <from> + <prefix-list> + <name>route-from-renam-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-renam</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>INFO_EAP_NREN</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-renam-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-RENAM-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-renam</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-renam</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>INFO_EAP_NREN</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RENAM-nren</name> + <from> + <prefix-list> + <name>route-from-renam</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-renam</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-buc</community-name> + </community> + <community> + <add/> + <community-name>INFO_EAP_NREN</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RENAM-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-RoEduNet-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-ROEDUNET-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-V6-nren</name> + <from> + <prefix-list> + <name>route-from-ROEDUNET-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-RoEduNet-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-RoEduNet</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-nren</name> + <from> + <prefix-list> + <name>route-from-RoEduNet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-RoEduNet-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-coriant-vrf</name> + <term> + <name>mgmt-routes</name> + <from> + <protocol>direct</protocol> + <protocol>static</protocol> + </from> + <then> + <community> + <add/> + <community-name>coriant-mgmt</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-ias-vrf</name> + <term> + <name>ias-routes</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <community> + <add/> + <community-name>ias-routes</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>ias-interface-routes</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <community> + <add/> + <community-name>ias-routes</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-lhcone-nren</name> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-from-lhcone-peer</name> + <then> + <community> + <add/> + <community-name>geant-peer-RE</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-from-lhcone-vrf</name> + <term> + <name>lhcone-routes</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <community> + <add/> + <community-name>lhcone-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>lhcone-geant-ptp</name> + <from> + <route-filter> + <address>62.40.126.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <community> + <add/> + <community-name>lhcone-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>lhcone-geant-ptp6</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <community> + <add/> + <community-name>lhcone-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-into-CLS-vrf</name> + <term> + <name>CLS-routes</name> + <from> + <protocol>bgp</protocol> + <community>CLS-vpn</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-into-ias-vrf</name> + <term> + <name>ias-routes</name> + <from> + <protocol>bgp</protocol> + <community>ias-routes</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-into-lhcone-vrf</name> + <term> + <name>lhcone-routes</name> + <from> + <protocol>bgp</protocol> + <community>lhcone-vpn</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-static-mx-to-igp</name> + <term> + <name>mx-loopbacks</name> + <from> + <protocol>static</protocol> + <route-filter> + <address>62.40.97.0/24</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-RENAM-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-renam-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-renam-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-anycast</community> + <community>geant-peer-RE</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>to-renam-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-RENAM-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-renam-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-renam-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-anycast</community> + <community>geant-peer-RE</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>to-renam-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-ROEDUNET-LHCONE-TE</name> + <term> + <name>BLOCK</name> + <from> + <community>LHCONE-BLOCK-ROEDUNET-2614</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>PREPEND_x1</name> + <from> + <community>LHCONE-PREPEND-ROEDUNET-2614-x1</community> + </from> + <then> + <as-path-prepend>20965</as-path-prepend> + </then> + </term> + <term> + <name>PREPEND_x2</name> + <from> + <community>LHCONE-PREPEND-ROEDUNET-2614-x2</community> + </from> + <then> + <as-path-prepend>20965 20965</as-path-prepend> + </then> + </term> + <term> + <name>PREPEND_x3</name> + <from> + <community>LHCONE-PREPEND-ROEDUNET-2614-x3</community> + </from> + <then> + <as-path-prepend>20965 20965 20965</as-path-prepend> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-RoEduNet-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-roedunet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-RoEduNet-V6-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-aarnet</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-RoEduNet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-RoEduNet-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-roedunet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-RoEduNet-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-aarnet</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + <community>geant-helix</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-RoEduNet-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-coriant-vrf</name> + <term> + <name>mgmt-routes</name> + <from> + <protocol>bgp</protocol> + <community>coriant-mgmt</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-nren</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>62.40.126.0/24</address> + <exact/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>62.40.103.0/25</address> + <orlonger/> + </route-filter> + <route-filter> + <address>62.40.126.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <then> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-nren-v6</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <exact/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <then> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-peer</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>62.40.126.0/24</address> + <exact/> + </route-filter> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>62.40.103.0/25</address> + <orlonger/> + </route-filter> + <route-filter> + <address>62.40.126.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>allow-nren-routes</name> + <from> + <community>geant-nrn</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <then> + <default-action>reject</default-action> + </then> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-peer-v6</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <exact/> + </route-filter> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>allow-nren-routes</name> + <from> + <community>geant-nrn</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <then> + <default-action>reject</default-action> + </then> + </policy-statement> + <policy-statement> + <name>rtbh-ibgp</name> + <term> + <name>1</name> + <from> + <protocol>bgp</protocol> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + </from> + <then> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>2</name> + <from> + <protocol>bgp</protocol> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + </from> + <then> + <next-hop> + <address>0100::</address> + </next-hop> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>rtbh-policy</name> + <term> + <name>11</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>22</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>source-class-usage</name> + <term> + <name>DWS</name> + <from> + <community>geant-dws</community> + </from> + <then> + <source-class>dws-out</source-class> + </then> + </term> + <term> + <name>google-out</name> + <from> + <community>geant-google</community> + </from> + <then> + <source-class>google-out</source-class> + </then> + </term> + <term> + <name>ixpeers-out</name> + <from> + <community>geant-ixpeers</community> + </from> + <then> + <source-class>ixpeers-out</source-class> + </then> + </term> + </policy-statement> + <community> + <name>CLS-vpn</name> + <members>target:20965:667</members> + </community> + <community> + <name>CLS_AGGREGATE_ROUTES</name> + <members>20965:64912</members> + </community> + <community> + <name>IAS_AGGREGATE_ROUTES</name> + <members>21320:64912</members> + </community> + <community> + <name>IGP_ROUTES_DEEPFIELD</name> + <members>20965:65002</members> + </community> + <community> + <name>INFO_EAP_NREN</name> + <members>20965:65103</members> + </community> + <community> + <name>INFO_PUBLIC_PEER</name> + <members>21320:646..</members> + </community> + <community> + <name>LHCONE-BLOCK-ROEDUNET-2614</name> + <members>65010:2614</members> + </community> + <community> + <name>LHCONE-PREPEND-ROEDUNET-2614-x1</name> + <members>65001:2614</members> + </community> + <community> + <name>LHCONE-PREPEND-ROEDUNET-2614-x2</name> + <members>65002:2614</members> + </community> + <community> + <name>LHCONE-PREPEND-ROEDUNET-2614-x3</name> + <members>65003:2614</members> + </community> + <community> + <name>TE_ANNOUNCE_ALL_PUBLIC_PEERS_2</name> + <members>64712:65532</members> + </community> + <community> + <name>TE_ANNOUNCE_ALL_PUBLIC_PEERS_3</name> + <members>20965:65532</members> + </community> + <community> + <name>TE_BLOCK_ALL_PUBLIC_PEERS</name> + <members>64512:65532</members> + </community> + <community> + <name>TE_BLOCK_PEERS_2</name> + <members>64512:65533</members> + </community> + <community> + <name>TE_PRIVATE_COMMUNITIES</name> + <members>^(6451[2-9]|645[2-9][0-9]|64[6-9][0-9][0-9]|65[0-4][0-9][0-9]|655[0-2][0-9]|6553[0-5]).*$</members> + </community> + <community> + <name>coriant-mgmt</name> + <members>target:20965:991</members> + </community> + <community> + <name>geant-IAS-dws-block</name> + <members>64512:65534</members> + </community> + <community> + <name>geant-IAS-dws-nren</name> + <members>64700:65534</members> + </community> + <community> + <name>geant-RTBH</name> + <members>20965:0008</members> + </community> + <community> + <name>geant-aarnet</name> + <members>20965:7575</members> + </community> + <community> + <name>geant-adv2-private-peer</name> + <members>20965:65533</members> + </community> + <community> + <name>geant-adv2-public-peer</name> + <members>20965:65532</members> + </community> + <community> + <name>geant-anycast</name> + <members>20965:0002</members> + </community> + <community> + <name>geant-dummy</name> + <members>20965:65000</members> + </community> + <community> + <name>geant-dws</name> + <members>20965:7777</members> + </community> + <community> + <name>geant-dws-nren</name> + <members>20965:65534</members> + </community> + <community> + <name>geant-google</name> + <members>20965:15169</members> + </community> + <community> + <name>geant-helix</name> + <members>20965:65293</members> + </community> + <community> + <name>geant-ixpeers</name> + <members>20965:0003</members> + </community> + <community> + <name>geant-nren-buc</name> + <members>21320:64917</members> + </community> + <community> + <name>geant-nrn</name> + <members>20965:0155</members> + </community> + <community> + <name>geant-peer-RE</name> + <members>20965:65530</members> + </community> + <community> + <name>geant-peers</name> + <members>20965:0004</members> + </community> + <community> + <name>geant-renam</name> + <members>20965:9199</members> + </community> + <community> + <name>geant-renam-block</name> + <members>20965:64950</members> + </community> + <community> + <name>geant-roedunet-block</name> + <members>64512:2614</members> + </community> + <community> + <name>ias-routes</name> + <members>target:20965:333</members> + </community> + <community> + <name>lhcone-vpn</name> + <members>target:20965:111</members> + </community> + <community> + <name>no-export</name> + <members>no-export</members> + </community> + <as-path> + <name>AS-PRIVATE</name> + <path>.* (0|64512-65535|4200000000-4294967295) .*</path> + </as-path> + <as-path> + <name>MAX-AS_PATH</name> + <path>.{41,}</path> + </as-path> + <as-path> + <name>AS-SELF</name> + <path>.*(20965|21320).*</path> + </as-path> + </policy-options> + <class-of-service protect="protect"> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + <import>default</import> + <forwarding-class> + <name>best-effort</name> + <loss-priority> + <name>low</name> + <code-points>af11</code-points> + <code-points>af12</code-points> + <code-points>af13</code-points> + </loss-priority> + </forwarding-class> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + <import>default</import> + <forwarding-class> + <name>best-effort</name> + <loss-priority> + <name>low</name> + <code-points>af11</code-points> + <code-points>af12</code-points> + <code-points>af13</code-points> + </loss-priority> + </forwarding-class> + </dscp-ipv6> + <exp> + <name>GEANT-BASIC</name> + <import>default</import> + <forwarding-class> + <name>best-effort</name> + <loss-priority> + <name>low</name> + <code-points>100</code-points> + <code-points>101</code-points> + </loss-priority> + </forwarding-class> + </exp> + </classifiers> + <drop-profiles> + <name>BEST-EFFORT</name> + <interpolate> + <fill-level>75</fill-level> + <fill-level>80</fill-level> + <fill-level>85</fill-level> + <fill-level>90</fill-level> + <fill-level>95</fill-level> + <fill-level>100</fill-level> + <drop-probability>0</drop-probability> + <drop-probability>25</drop-probability> + <drop-probability>75</drop-probability> + <drop-probability>90</drop-probability> + <drop-probability>95</drop-probability> + <drop-probability>100</drop-probability> + </interpolate> + </drop-profiles> + <interfaces> + <interface> + <name>et-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>ge-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>so-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>xe-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>ae*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + </interfaces> + <scheduler-maps> + <name>GEANT-BASIC</name> + <forwarding-class> + <name>expedited-forwarding</name> + <scheduler>EXPEDITED-FORWARDING</scheduler> + </forwarding-class> + <forwarding-class> + <name>network-control</name> + <scheduler>NETWORK-CONTROL</scheduler> + </forwarding-class> + <forwarding-class> + <name>best-effort</name> + <scheduler>BEST-EFFORT</scheduler> + </forwarding-class> + </scheduler-maps> + <schedulers> + <name>EXPEDITED-FORWARDING</name> + <transmit-rate> + <percent>15</percent> + <rate-limit/> + </transmit-rate> + <buffer-size> + <temporal>15k</temporal> + </buffer-size> + <priority>strict-high</priority> + </schedulers> + <schedulers> + <name>BEST-EFFORT</name> + <transmit-rate> + <remainder> + </remainder> + </transmit-rate> + <buffer-size> + <remainder> + </remainder> + </buffer-size> + <priority>low</priority> + <drop-profile-map> + <loss-priority>any</loss-priority> + <protocol>any</protocol> + <drop-profile>BEST-EFFORT</drop-profile> + </drop-profile-map> + </schedulers> + <schedulers> + <name>NETWORK-CONTROL</name> + <transmit-rate> + <percent>5</percent> + </transmit-rate> + <buffer-size> + <percent>5</percent> + </buffer-size> + <priority>high</priority> + </schedulers> + </class-of-service> + <firewall> + <family> + <inet> + <filter> + <name>LAN-in</name> + <term> + <name>LAN-DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <policer>pol-DWS-in</policer> + <count>dws-in</count> + <loss-priority>high</loss-priority> + <forwarding-class>best-effort</forwarding-class> + <accept/> + </then> + </term> + <term> + <name>LAN-LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>block-snmp</name> + <from> + <address> + <name>62.40.109.199/32</name> + </address> + <port>snmp</port> + <port>snmptrap</port> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LAN-out</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>router-access-out</name> + <term> + <name>geant-network-control-traffic</name> + <from> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <accept/> + </then> + </term> + <term> + <name>accept</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-RoEduNet</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>ROEDU-out</name> + <interface-specific/> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <policer>pol-RoEdu-DWS-out</policer> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>LBE-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ROEDU-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>62.40.125.138/32</name> + </source-address> + <source-address> + <name>193.231.140.82/32</name> + </source-address> + <destination-address> + <name>62.40.125.137/32</name> + </destination-address> + <destination-address> + <name>62.40.97.11/32</name> + </destination-address> + <destination-address> + <name>62.40.97.12/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>62.40.125.138/32</name> + </source-address> + <destination-address> + <name>62.40.125.137/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <source-address> + <name>62.40.125.138/32</name> + </source-address> + <destination-address> + <name>62.40.125.137/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-allow</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External-Equipment</name> + <from> + <destination-address> + <name>62.40.126.0/24</name> + </destination-address> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <accept/> + </then> + </term> + <term> + <name>LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>mcast-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-ulakbim</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>NEW-ULAKBIM-MGEN-in</name> + <term> + <name>new_ulakbim_mgen_in</name> + <from> + <source-address> + <name>62.40.118.66/32</name> + </source-address> + <destination-address> + <name>192.168.8.1/32</name> + </destination-address> + <protocol>udp</protocol> + <protocol>icmp</protocol> + <source-port>5001</source-port> + </from> + <then> + <count>new_ulakbim_mgen_in</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>NEW-ULAKBIM-MGEN-out</name> + <term> + <name>new_ulakbim_mgen_out</name> + <from> + <source-address> + <name>62.40.118.66/32</name> + </source-address> + <destination-address> + <name>192.168.8.1/32</name> + </destination-address> + <protocol>udp</protocol> + <protocol>icmp</protocol> + <source-port>5001</source-port> + </from> + <then> + <count>new_ulakbim_mgen_out</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LHCONE-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>HADES-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <protocol>tcp</protocol> + <port>22</port> + <port>861</port> + <port>4823</port> + <port>8090</port> + <port>5000-5099</port> + <port>32768-61000</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <port>123</port> + <port>5000-5099</port> + <port>32768-61000</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP_from_MPs</name> + <from> + <address> + <name>62.40.106.128/25</name> + </address> + <protocol>udp</protocol> + <port>65000-65060</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SSH_Access</name> + <from> + <source-address> + <name>131.188.81.0/24</name> + </source-address> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>HADES-IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>861</port> + <port>1024-65535</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL190-IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>53</port> + <port>43</port> + <port>80</port> + <port>4321</port> + <port>4823</port> + <port>5000-6200</port> + <port>861</port> + <port>8760-8960</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL190-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>80</port> + <port>4321</port> + <port>4823</port> + <port>5000-6200</port> + <port>861</port> + <port>8760-8960</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>man-c1n1-buc-IN</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <destination-prefix-list> + <name>EXTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>man-c1n1-buc-OUT</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access-out</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>lm-c1n1-buc-IN</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <destination-prefix-list> + <name>EXTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>lm-c1n1-buc-OUT</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access-out</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>RTBH-count</name> + <term> + <name>count</name> + <then> + <count>RTBH-count</count> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL124-IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>22</port> + <port>80</port> + <port>443</port> + <port>8140</port> + <port>10514</port> + <port>8090</port> + <port>33434-33524</port> + <port>53</port> + <port>88</port> + <port>123</port> + <port>137</port> + <port>139</port> + <port>389</port> + <port>469</port> + <port>8096</port> + <port>445</port> + <port>464</port> + <port>3268</port> + <port>5222</port> + <port>44325</port> + <port>61614</port> + <port>8</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL124-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>22</port> + <port>80</port> + <port>443</port> + <port>8140</port> + <port>10514</port> + <port>33434-33524</port> + <port>5222</port> + <port>5693</port> + <port>8</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <comment>/* This is a test */</comment> + <filter> + <name>VM-RANGE-VL125-IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>22</port> + <port>43</port> + <port>80</port> + <port>443</port> + <port>8140</port> + <port>10514</port> + <port>12489</port> + <port>5666</port> + <port>8090</port> + <port>3306</port> + <port>161</port> + <port>8080</port> + <port>8888</port> + <port>5693</port> + <port>8000</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>NAGIOS-monitoring_Allow</name> + <from> + <destination-prefix-list> + <name>geant-nagiosmonitoring-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>161</port> + <port>53</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL125-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>22</port> + <port>80</port> + <port>443</port> + <port>8140</port> + <port>10514</port> + <port>5666</port> + <port>5693</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>NAGIOS-monitoring_Allow</name> + <from> + <source-prefix-list> + <name>geant-nagiosmonitoring-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <protocol>udp</protocol> + <port>53</port> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>BWCTL_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>22</destination-port> + <destination-port>25</destination-port> + <destination-port>53</destination-port> + <destination-port>80</destination-port> + <destination-port>88</destination-port> + <destination-port>139</destination-port> + <destination-port>389</destination-port> + <destination-port>443</destination-port> + <destination-port>445</destination-port> + <destination-port>464</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>4505-4506</destination-port> + <destination-port>8140</destination-port> + <destination-port>10051</destination-port> + <destination-port>5222</destination-port> + <destination-port>5269</destination-port> + <destination-port>5693</destination-port> + <destination-port>69</destination-port> + <destination-port>161</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <port>53</port> + <port>88</port> + <port>123</port> + <port>139</port> + <port>137</port> + <port>3000-65535</port> + <port>389</port> + <port>464</port> + <port>10051</port> + <port>69</port> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BWCTL_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>22</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>4823</destination-port> + <destination-port>8090</destination-port> + <destination-port>5000-5900</destination-port> + <destination-port>6001-6200</destination-port> + <destination-port>53</destination-port> + <destination-port>10050</destination-port> + <destination-port>5222</destination-port> + <destination-port>5347</destination-port> + <destination-port>5693</destination-port> + <destination-port>5666</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <port>5000-5900</port> + <port>6001-6200</port> + <port>33434-33634</port> + <port>53</port> + <port>10050</port> + <port>161</port> + <port>162</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP_ALLOW</name> + <from> + <source-prefix-list> + <name>GEANT_NTP</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL022_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>861</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL022_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>861</destination-port> + <destination-port>8090</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <destination-port>8760-9960</destination-port> + <destination-port>33434-33634</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL200_MIDDLE_IN</name> + <term> + <name>VLAN_Access_Allow</name> + <from> + <port>80</port> + <port>443</port> + <port>22</port> + <port>8140</port> + <port>5693</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL200_MIDDLE_OUT</name> + <term> + <name>VLAN_Access_Allow</name> + <from> + <port>22</port> + <port>443</port> + <port>80</port> + <port>8140</port> + <port>8090</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ROEDUNET_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>ROEDUNET_blocking_service</name> + <from> + <destination-prefix-list> + <name>ROEDUNET-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>ROEDUNET-blocking-service</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>83.97.88.142/32</name> + </source-address> + <destination-address> + <name>83.97.88.141/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>83.97.88.142/32</name> + </source-address> + <destination-address> + <name>83.97.88.141/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>83.97.88.142/32</name> + </source-address> + <destination-address> + <name>83.97.88.141/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>83.97.88.142/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ROEDUNET_OUT</name> + <interface-specific/> + <term> + <name>DWS_out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS_same_out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ROUTER_access</name> + <term> + <name>TCP_established_accept</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SSH_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space-short</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>pref-list-router-access</name> + </source-prefix-list> + <source-prefix-list> + <name>cnis-server</name> + </source-prefix-list> + <source-prefix-list> + <name>ncc-oob-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>space-local</name> + </source-prefix-list> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <source-prefix-list> + <name>restena-access</name> + </source-prefix-list> + <source-prefix-list> + <name>nmteam-dev-servers</name> + </source-prefix-list> + <source-prefix-list> + <name>vuln-scanner</name> + </source-prefix-list> + <source-prefix-list> + <name>renater-access</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-JUNOSSPACE</name> + </source-prefix-list> + <source-prefix-list> + <name>xantaro-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-lg</name> + </source-prefix-list> + <source-prefix-list> + <name>dashboard-servers</name> + </source-prefix-list> + <source-prefix-list> + <name>opennsa-servers</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-rancid</name> + </source-prefix-list> + <protocol>tcp</protocol> + <destination-port>ssh</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_accept</name> + <from> + <source-prefix-list> + <name>RE_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_DUMMY_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>CLS_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>lhcone-l3vpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>taas-control_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>mgmt-l3vpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>GWS_GRNET_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn-nren-gn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>confine-l3vpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>VPN-PROXY_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>VRR_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>VPN-PROXY_RI_BGP_inet</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>FTP_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space-short</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>ncc-oob-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>xantaro-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RADIUS_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>1812</port> + <port>1813</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP_accept</name> + <from> + <source-prefix-list> + <name>geant-routers</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-cameras</name> + </source-prefix-list> + <source-prefix-list> + <name>ddos-scrubbing</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>ntp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Netconf_accept</name> + <from> + <source-prefix-list> + <name>GEANT-JUNOSSPACE</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Superpop-v4</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>830</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP_accept</name> + <from> + <source-prefix-list> + <name>GEANT-SNMP</name> + </source-prefix-list> + <destination-port>161</destination-port> + </from> + <then> + <policer>lo0-flood</policer> + <accept/> + </then> + </term> + <term> + <name>DNS_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DNS</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-DNS-EXT</name> + </source-prefix-list> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>LDP_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-LDP</name> + </source-prefix-list> + <destination-port>646</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MPLS_LSP_echo_accept</name> + <from> + <source-prefix-list> + <name>geant-routers</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>3503</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_access</name> + <from> + <protocol>pim</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BFD_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <port>3784</port> + <port>4784</port> + <port>3785</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>IGMP_accept</name> + <from> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_accept</name> + <from> + <source-prefix-list> + <name>GEANT-MSDP</name> + </source-prefix-list> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TRACEROUTE_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33534</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + <icmp-type>echo-reply</icmp-type> + <icmp-type>echo-request</icmp-type> + <icmp-type>unreachable</icmp-type> + <icmp-type>time-exceeded</icmp-type> + <icmp-type>timestamp</icmp-type> + <icmp-type>timestamp-reply</icmp-type> + </from> + <then> + <policer>lo0-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_HEAD_IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <next>term</next> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GOC_accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_HEAD_OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <next>term</next> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GOC_GEANT_accept</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>83.97.92.0/22</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_TAIL_OUT</name> + <term> + <name>GEANT_SSH_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_TAIL_IN</name> + <term> + <name>GEANT_SSH_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_HEAD_OUT</name> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>83.97.92.0/22</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>C1N1-to-VCENTER</name> + <term> + <name>default</name> + <from> + <destination-address> + <name>62.40.108.134/32</name> + </destination-address> + <destination-address> + <name>62.40.108.128/27</name> + </destination-address> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VCENTER-to-C1N1</name> + <term> + <name>default</name> + <from> + <source-address> + <name>62.40.108.134/32</name> + </source-address> + <source-address> + <name>62.40.108.128/27</name> + </source-address> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_RENAM_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>KEEPALIVES_IN</name> + <from> + <source-address> + <name>62.40.125.198/32</name> + </source-address> + <destination-address> + <name>255.255.255.255/32</name> + </destination-address> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>GRE_ALLOW</name> + <from> + <protocol>gre</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>62.40.125.198/32</name> + </source-address> + <destination-address> + <name>62.40.125.197/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>62.40.125.198/32</name> + </source-address> + <destination-address> + <name>62.40.125.197/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>62.40.125.198/32</name> + </source-address> + <destination-address> + <name>62.40.125.197/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>62.40.125.198/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_RENAM_OUT</name> + <interface-specific/> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_RENAM_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>83.97.88.197/32</name> + </source-address> + <destination-address> + <name>83.97.88.196/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>83.97.88.197/32</name> + </source-address> + <destination-address> + <name>83.97.88.196/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>83.97.88.197/32</name> + </source-address> + <destination-address> + <name>83.97.88.196/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>83.97.88.197/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_RENAM_OUT</name> + <interface-specific/> + <term> + <name>DWS_out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS_same_out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>bone-out</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>bone-in</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + </inet> + <inet6> + <filter> + <name>ROEDU6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:2b:10aa::2/126</name> + </source-address> + <source-address> + <name>2001:b30:1000:19::2/128</name> + </source-address> + <destination-address> + <name>2001:798:2b:10aa::1/126</name> + </destination-address> + <destination-address> + <name>2001:798:14:20ff::1/128</name> + </destination-address> + <destination-address> + <name>2001:798:22:20ff::3/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects-interfaces6</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <count>extv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ROEDU6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>router-access-ipv6</name> + <term> + <name>nren-access-ssh</name> + <from> + <source-prefix-list> + <name>restena-access-v6</name> + </source-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>allow-ssh-ftp</name> + <from> + <source-address> + <name>2001:798:f99b:14::/64</name> + </source-address> + <source-address> + <name>2001:798:ff9a:28::/64</name> + </source-address> + <source-address> + <name>2001:798:22:96::/64</name> + </source-address> + <source-address> + <name>2001:798:5e00::/48</name> + </source-address> + <source-address> + <name>2001:798:2::/35</name> + </source-address> + <source-address> + <name>2001:630:280::/48</name> + </source-address> + <source-address> + <name>2001:799:3::/64</name> + </source-address> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + <destination-port>ssh</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>discard</name> + <from> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + <destination-port>ssh</destination-port> + <destination-port>telnet</destination-port> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>ubfd-block</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>6784</destination-port> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpfv6-filter-RoEduNet</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>urpfv6-filter-ulakbim</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>bone6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LHCONE6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <next>term</next> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL150-V6-OUT</name> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantnoc-address-space-v6</name> + </source-prefix-list> + </from> + </term> + </filter> + <filter> + <name>VM-RANGE-VL124-V6-IN</name> + <term> + <name>PROTECTED</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-spaceV6</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>80</port> + <port>443</port> + <port>22</port> + <port>8140</port> + <port>10514</port> + </from> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard/> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL124-V6-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantnoc-address-space-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>80</port> + <port>443</port> + <port>22</port> + <port>8140</port> + <port>10514</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard/> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL125-V6-IN</name> + <term> + <name>PROTECTED</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-spaceV6</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>22</port> + <port>43</port> + <port>80</port> + <port>443</port> + <port>5693</port> + <port>8140</port> + <port>10514</port> + </from> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>infoblox-monitoring-accept</name> + <from> + <destination-prefix-list> + <name>geant-nagiosmonitoring-spacev6</name> + </destination-prefix-list> + <next-header>tcp</next-header> + <next-header>udp</next-header> + <port>53</port> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard/> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL125-V6-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantnoc-address-space-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>80</port> + <port>443</port> + <port>22</port> + <port>8140</port> + <port>10514</port> + <port>5693</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>infoblox-monitoring-accept</name> + <from> + <source-prefix-list> + <name>geant-nagiosmonitoring-spacev6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <next-header>udp</next-header> + <port>53</port> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard/> + </then> + </term> + </filter> + <filter> + <name>BWCTL_V6_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>22</destination-port> + <destination-port>25</destination-port> + <destination-port>53</destination-port> + <destination-port>80</destination-port> + <destination-port>88</destination-port> + <destination-port>139</destination-port> + <destination-port>389</destination-port> + <destination-port>443</destination-port> + <destination-port>445</destination-port> + <destination-port>464</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>4505-4506</destination-port> + <destination-port>8140</destination-port> + <destination-port>10051</destination-port> + <destination-port>5222</destination-port> + <destination-port>5269</destination-port> + <destination-port>5693</destination-port> + <destination-port>69</destination-port> + <destination-port>161</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <port>53</port> + <port>88</port> + <port>123</port> + <port>139</port> + <port>137</port> + <port>389</port> + <port>464</port> + <port>3000-65535</port> + <port>10051</port> + <port>69</port> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BWCTL_V6_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>22</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>4823</destination-port> + <destination-port>5000-5900</destination-port> + <destination-port>6001-6200</destination-port> + <destination-port>8090</destination-port> + <destination-port>53</destination-port> + <destination-port>10050</destination-port> + <destination-port>5222</destination-port> + <destination-port>5347</destination-port> + <destination-port>5693</destination-port> + <destination-port>5666</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <port>5000-5900</port> + <port>6001-6200</port> + <port>33434-33634</port> + <port>53</port> + <port>10050</port> + <port>161</port> + <port>162</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL022_V6_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>861</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL022_V6_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>861</destination-port> + <destination-port>8090</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>8760-9960</destination-port> + <destination-port>33434-33634</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL200_V6_MIDDLE_IN</name> + <term> + <name>VLAN_Access_Allow</name> + <from> + <payload-protocol>tcp</payload-protocol> + <port>80</port> + <port>443</port> + <port>22</port> + <port>8140</port> + <port>5693</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL200_V6_MIDDLE_OUT</name> + <term> + <name>VLAN_Access_Allow</name> + <from> + <payload-protocol>tcp</payload-protocol> + <port>80</port> + <port>443</port> + <port>22</port> + <port>8140</port> + <port>8090</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>bone6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ROEDUNET_V6_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>ROEDUNET_blocking_service</name> + <from> + <destination-prefix-list> + <name>ROEDUNET6-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>ROEDUNET-blocking-service6</count> + <discard/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-src</count> + <discard/> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-dst</count> + <discard/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>2001:798:1::aa/128</name> + </source-address> + <destination-address> + <name>2001:798:1::a9/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>2001:798:1::aa/128</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External_Projects_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ROEDUNET_V6_OUT</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ROUTER_access_V6</name> + <term> + <name>SSH_accept</name> + <from> + <source-address> + <name>2001:798:f99b:14::/64</name> + </source-address> + <source-address> + <name>2001:798:ff9a:28::/64</name> + </source-address> + <source-address> + <name>2001:798:22:96::/64</name> + </source-address> + <source-address> + <name>2001:798:5e00::/48</name> + </source-address> + <source-address> + <name>2001:798:2::/35</name> + </source-address> + <source-address> + <name>2001:630:280::/48</name> + </source-address> + <source-address> + <name>2001:799:3::/64</name> + </source-address> + <source-address> + <name>2001:799:7::fe/128</name> + </source-address> + <source-address> + <name>2001:798:ffb4:6f::/64</name> + </source-address> + <source-address> + <name>2001:798:15:a2::/64</name> + </source-address> + <source-address> + <name>2001:610:9d8:7:8000::/112</name> + </source-address> + <source-address> + <name>2001:610:9d8:1::4/128</name> + </source-address> + <source-address> + <name>2001:798:64::/64</name> + </source-address> + <source-address> + <name>2001:799:64::/64</name> + </source-address> + <source-prefix-list> + <name>restena-access-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>dashboard-servers-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>opennsa-servers-v6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Netconf_accept</name> + <from> + <source-prefix-list> + <name>GEANT-Superpop-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-v6</name> + </source-prefix-list> + <payload-protocol>tcp</payload-protocol> + <destination-port>830</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SSH_discard</name> + <from> + <port>22</port> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>FTP_accept</name> + <from> + <source-address> + <name>2001:798:f99b:14::/64</name> + </source-address> + <source-address> + <name>2001:798:ff9a:28::/64</name> + </source-address> + <source-address> + <name>2001:798:22:96::/64</name> + </source-address> + <source-address> + <name>2001:798:5e00::/48</name> + </source-address> + <source-address> + <name>2001:798:2::/35</name> + </source-address> + <source-address> + <name>2001:630:280::/48</name> + </source-address> + <source-address> + <name>2001:799:3::/64</name> + </source-address> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_accept</name> + <from> + <source-prefix-list> + <name>RE_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_DUMMY_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>CLS_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>lhcone-l3vpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>taas-control_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>mgmt-l3vpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>GWS_GRNET_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn-nren-gn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>confine-l3vpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>VPN-PROXY_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>VRR_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>VPN-PROXY_RI_BGP_inet6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DENY</name> + <from> + <next-header>tcp</next-header> + <next-header>udp</next-header> + <port>bgp</port> + <port>ftp</port> + <port>ftp-data</port> + <port>ssh</port> + <port>telnet</port> + <port>6784</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_HEAD_IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-spaceV6</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_TAIL_IN</name> + <term> + <name>GEANT_SSH_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_HEAD_OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GOC_GEANT_accept</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>2001:798:3::0/64</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_TAIL_OUT</name> + <term> + <name>GEANT_SRV_SSH_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + </filter> + <filter> + <name>router-access-out_V6</name> + <term> + <name>geant-network-control-traffic</name> + <from> + <traffic-class>48</traffic-class> + <traffic-class>56</traffic-class> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <accept/> + </then> + </term> + <term> + <name>accept</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_V6_HEAD_OUT</name> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>2001:798:3::0/64</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>RENAM6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:99:1::a6/126</name> + </source-address> + <destination-address> + <name>2001:798:99:1::a5/126</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>workstations-SSHv6-accept</name> + <from> + <source-address> + <name>2001:0798:5e00::/48</name> + </source-address> + <source-address> + <name>2001:0798:5e01::/48</name> + </source-address> + <destination-address> + <name>2001:798:2028:006e::10/64</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:0047::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects-interfaces6</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <count>extv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>RENAM6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_RENAM_V6_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-src</count> + <discard/> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-dst</count> + <discard/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>2001:798:1::1a2/128</name> + </source-address> + <destination-address> + <name>2001:798:1::1a1/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>2001:798:1::1a2/128</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External_Projects_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_RENAM_V6_OUT</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LHCONE6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + </inet6> + </family> + <policer> + <name>pol-DWS-in</name> + <if-exceeding> + <bandwidth-limit>5m</bandwidth-limit> + <burst-size-limit>625k</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>ICMP-flood</name> + <if-exceeding> + <bandwidth-limit>10m</bandwidth-limit> + <burst-size-limit>1m</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>ICMPv6-flood</name> + <if-exceeding> + <bandwidth-limit>10m</bandwidth-limit> + <burst-size-limit>1m</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-ULAKBIM-DWS-out</name> + <if-exceeding> + <bandwidth-limit>4g</bandwidth-limit> + <burst-size-limit>2500000</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-RoEdu-DWS-out</name> + <if-exceeding> + <bandwidth-limit>1030000000</bandwidth-limit> + <burst-size-limit>6250000</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-rate-limiting</name> + <if-exceeding> + <bandwidth-limit>10m</bandwidth-limit> + <burst-size-limit>125k</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>lo0-flood</name> + <if-exceeding> + <bandwidth-limit>12m</bandwidth-limit> + <burst-size-limit>900k</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + </firewall> + <routing-instances> + <instance inactive="inactive"> + <name>CLEAN_IAS</name> + <description>Clean IAS VRF traffic returned from scrubber</description> + <instance-type>vrf</instance-type> + <route-distinguisher> + <rd-type>20965:334</rd-type> + </route-distinguisher> + <vrf-import>ps-into-clean-ias-vrf</vrf-import> + <vrf-export>ps-from-clean-ias-vrf</vrf-export> + <vrf-target> + <community>target:20965:334</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <rib> + <name>CLEAN_IAS.inet6.0</name> + <static> + <route> + <name>2001:7f8:3c::/48</name> + <discard/> + </route> + </static> + </rib> + <static> + <route> + <name>83.97.88.0/23</name> + <discard/> + </route> + </static> + </routing-options> + </instance> + <instance> + <name>CLS</name> + <description>L3 BGP/MPLS VPN for Cloud Services (CLS)</description> + <instance-type>vrf</instance-type> + <route-distinguisher> + <rd-type>62.40.96.19:667</rd-type> + </route-distinguisher> + <vrf-import>ps-into-CLS-vrf</vrf-import> + <vrf-export>ps-from-CLS-vrf</vrf-export> + <vrf-target> + <community>target:20965:667</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <rib> + <name>CLS.inet.0</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>CLS.inet6.0</name> + <static> + <route> + <name>::/0</name> + <discard/> + </route> + <route> + <name>0100::/64</name> + <discard/> + <no-readvertise/> + </route> + </static> + <aggregate> + <route> + <name>2001:798::/64</name> + <community>20965:64912</community> + </route> + </aggregate> + </rib> + <static> + <route> + <name>0.0.0.0/0</name> + <discard/> + </route> + <route> + <name>192.0.2.101/32</name> + <discard/> + <no-readvertise/> + </route> + </static> + <aggregate> + <route> + <name>62.40.100.0/24</name> + <community>20965:64912</community> + </route> + </aggregate> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + <protocols> + <bgp> + <log-updown/> + <group> + <name>CLS-NRENS-ipv6</name> + <description>NRENS</description> + </group> + <group> + <name>CLS-NRENS</name> + <description>NRENS</description> + </group> + <group> + <name>CLS-PROVIDERS</name> + <description>PROVIDERS</description> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>cls-to-geant-geant-rtbh</ribgroup-name> + </rib-group> + </unicast> + </inet> + </family> + </group> + <group> + <name>CLS-PROVIDERS-ipv6</name> + <description>PROVIDERS</description> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>cls-to-geant-geant-rtbh6</ribgroup-name> + </rib-group> + </unicast> + </inet6> + </family> + </group> + </bgp> + </protocols> + </instance> + <instance> + <name>IAS</name> + <description>GEANT IAS Internet VRF</description> + <instance-type>vrf</instance-type> + <interface> + <name>lt-0/0/0.61</name> + </interface> + <interface> + <name>ae11.333</name> + </interface> + <interface> + <name>ae12.333</name> + </interface> + <route-distinguisher> + <rd-type>20965:333</rd-type> + </route-distinguisher> + <vrf-import>ps-into-ias-vrf</vrf-import> + <vrf-export>ps-from-ias-vrf</vrf-export> + <vrf-target> + <community>target:20965:333</community> + </vrf-target> + <vrf-table-label> + <source-class-usage/> + </vrf-table-label> + <routing-options> + <rib> + <name>IAS.inet6.0</name> + <static> + <route> + <name>0100::/64</name> + <discard/> + <no-readvertise/> + </route> + <route> + <name>2001:798:1::/48</name> + <discard/> + <community>21320:64912</community> + </route> + </static> + </rib> + <static> + <route> + <name>83.97.88.0/21</name> + <discard/> + <community>21320:64912</community> + <community>64700:65532</community> + <community>64700:65533</community> + <community>64700:65534</community> + </route> + <route> + <name>192.0.2.101/32</name> + <discard/> + <no-readvertise/> + </route> + </static> + <label> + <allocation>ps-direct-route-label</allocation> + </label> + </routing-options> + <protocols> + <bgp> + <log-updown/> + <group> + <name>IAS-NRENS</name> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>ias-to-geant-cls-rtbh</ribgroup-name> + </rib-group> + </unicast> + </inet> + </family> + <neighbor> + <name>83.97.88.142</name> + <description>-- Peering with ROEDUNET --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-IAS-from-RoEduNet-nren</import> + <family> + <inet> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-IAS-to-RoEduNet-nren</export> + <peer-as>2614</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>83.97.88.197</name> + <description>-- Peering with RENAM --| under testing</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-IAS-from-RENAM-nren</import> + <family> + <inet> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-IAS-to-RENAM-nren</export> + <peer-as>9199</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>IAS-NRENS-ipv6</name> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>ias-to-geant-cls-rtbh6</ribgroup-name> + </rib-group> + </unicast> + </inet6> + </family> + <neighbor> + <name>2001:798:1::aa</name> + <description>-- IPv6 Peering with ROEDUNET --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-IAS-from-RoEduNet-V6-nren</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-IAS-to-RoEduNet-V6-nren</export> + <peer-as>2614</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:798:1::1a2</name> + <description>-- IPv6 Peering with RENAM --|under testing</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-IAS-from-RENAM-V6-nren</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-IAS-to-RENAM-V6-nren</export> + <peer-as>9199</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + </bgp> + </protocols> + </instance> + <instance> + <name>coriant-mgmt</name> + <description>L3VPN for Coriant Groove Management</description> + <instance-type>vrf</instance-type> + <route-distinguisher> + <rd-type>20965:991</rd-type> + </route-distinguisher> + <vrf-import>ps-to-coriant-vrf</vrf-import> + <vrf-export>ps-from-coriant-vrf</vrf-export> + <vrf-target> + <community>target:20965:991</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + </instance> + <instance> + <name>lhcone-l3vpn</name> + <description>L3 BGP/MPLS VPN for LHCONE</description> + <instance-type>vrf</instance-type> + <interface> + <name>ae11.111</name> + </interface> + <route-distinguisher> + <rd-type>62.40.96.19:111</rd-type> + </route-distinguisher> + <vrf-import>ps-into-lhcone-vrf</vrf-import> + <vrf-export>ps-from-lhcone-vrf</vrf-export> + <vrf-target> + <community>target:20965:111</community> + </vrf-target> + <vrf-table-label inactive="inactive"> + </vrf-table-label> + <routing-options> + <rib> + <name>lhcone-l3vpn.inet.0</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>lhcone-l3vpn.inet6.0</name> + <aggregate> + <route> + <name>2001:798:111:1::/64</name> + <community>20965:0155</community> + </route> + </aggregate> + </rib> + <static> + <route> + <name>62.40.126.0/24</name> + <discard/> + <community>20965:0155</community> + </route> + </static> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + <protocols> + <bgp> + <log-updown/> + <group> + <name>lhcone-nrens</name> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-nren</import> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-lhcone-nren</export> + <neighbor> + <name>62.40.126.245</name> + <description>RoEduNet LHCONE IP VPN</description> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-nren</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>100</maximum> + <teardown> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-ROEDUNET-LHCONE-TE</export> + <export>ps-to-lhcone-nren</export> + <peer-as>2614</peer-as> + </neighbor> + </group> + <group> + <name>lhcone-peers</name> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-peer</import> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-lhcone-peer</export> + </group> + <group> + <name>lhcone6-nrens</name> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-nren</import> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-lhcone-nren-v6</export> + <neighbor> + <name>2001:798:111:1::a6</name> + <description>ROEDUNET LHCONE IPv6 VPN</description> + <out-delay>10</out-delay> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-nren</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>100</maximum> + <teardown> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-ROEDUNET-LHCONE-TE</export> + <export>ps-to-lhcone-nren-v6</export> + <peer-as>2614</peer-as> + </neighbor> + </group> + </bgp> + </protocols> + </instance> + <instance> + <name>taas-control</name> + <description>Control network for TaaS</description> + <instance-type>vrf</instance-type> + <interface> + <name>ge-0/2/0.171</name> + </interface> + <route-distinguisher> + <rd-type>62.40.96.19:888</rd-type> + </route-distinguisher> + <vrf-target> + <community>target:20965:888</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <rib> + <name>taas-control.inet.0</name> + <martians> + <address>10.0.0.0/8</address> + <orlonger/> + <allow/> + </martians> + </rib> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + </instance> + </routing-instances> +</configuration> diff --git a/test/data/mx1.bud.hu.geant.net-netconf.xml b/test/data/mx1.bud.hu.geant.net-netconf.xml new file mode 100644 index 0000000000000000000000000000000000000000..a2eac8404aff531b1c6ae87741006b4f94e8f628 --- /dev/null +++ b/test/data/mx1.bud.hu.geant.net-netconf.xml @@ -0,0 +1,39758 @@ +<configuration changed-seconds="1561995643" changed-localtime="2019-07-01 15:40:43 UTC"> + <version>15.1F6-S10.9</version> + <groups> + <name>re0</name> + <system> + <host-name>mx1.bud.hu.re0</host-name> + </system> + <interfaces> + <interface> + <name>fxp0</name> + <description>PHY INFRASTRUCTURE MANAGEMENT | re0</description> + <speed>100m</speed> + <link-mode>full-duplex</link-mode> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>172.16.18.100/24</name> + </address> + </inet> + </family> + </unit> + </interface> + </interfaces> + </groups> + <groups> + <name>re1</name> + <system> + <host-name>mx1.bud.hu.re1</host-name> + </system> + <interfaces> + <interface> + <name>fxp0</name> + <description>PHY INFRASTRUCTURE MANAGEMENT | re1</description> + <speed>100m</speed> + <link-mode>full-duplex</link-mode> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>172.16.18.101/24</name> + </address> + </inet> + </family> + </unit> + </interface> + </interfaces> + </groups> + <groups> + <name>urpf-template</name> + <firewall> + <family> + <inet> + <filter> + <name><*></name> + <interface-specific/> + <term> + <name>permit-multicast</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>urpf-multicast</count> + <accept/> + </then> + </term> + <term> + <name>discard-bogons</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>urpf-fail-bogons</count> + <discard> + </discard> + </then> + </term> + <term> + <name>discard</name> + <then> + <count>urpf-fail</count> + <discard> + </discard> + </then> + </term> + </filter> + </inet> + <inet6> + <filter> + <name><*></name> + <interface-specific/> + <term> + <name>permit-multicast</name> + <from> + <destination-address> + <name>ff00::/8</name> + </destination-address> + </from> + <then> + <count>urpfv6-multicast</count> + <accept/> + </then> + </term> + <term> + <name>discard-bogons</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>urpfv6-fail-bogons</count> + <discard/> + </then> + </term> + <term> + <name>discard</name> + <then> + <count>urpfv6-fail</count> + <discard/> + </then> + </term> + </filter> + </inet6> + </family> + </firewall> + </groups> + <groups> + <name>juniper-ais</name> + <system> + </system> + </groups> + <groups> + <name>load-balance-adaptive</name> + <interfaces> + <interface> + <name><ae*></name> + <aggregated-ether-options> + <load-balance> + <adaptive> + </adaptive> + </load-balance> + </aggregated-ether-options> + </interface> + </interfaces> + </groups> + <apply-groups>juniper-ais</apply-groups> + <system> + <apply-groups>re0</apply-groups> + <apply-groups>re1</apply-groups> + <domain-name>geant.net</domain-name> + <domain-search>geant2.net</domain-search> + <domain-search>geant.net</domain-search> + <backup-router> + <address>172.16.18.254</address> + <destination>172.16.5.252/30</destination> + </backup-router> + <time-zone>UTC</time-zone> + <authentication-order>radius</authentication-order> + <authentication-order>password</authentication-order> + <location> + <country-code>hu</country-code> + </location> + <root-authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </root-authentication> + <name-server> + <name>62.40.106.9</name> + </name-server> + <name-server> + <name>62.40.119.100</name> + </name-server> + <radius-server> + <name>62.40.120.136</name> + <timeout>2</timeout> + <source-address>62.40.97.1</source-address> + </radius-server> + <radius-server> + <name>62.40.121.121</name> + <timeout>2</timeout> + <source-address>62.40.97.1</source-address> + </radius-server> + <login> + <announcement>IMPORTANT NOTE: as part of the maintenance #2016051034001021 the MS-MIC has been moved to FPC4 a MPC3E slot, there is a note on using other cards in the ther MIC slot together with an MS-MIC on MPC3E - On MPC3E, the installation of the Multiservices MIC (MS-MIC-16G) with MIC3-3D-2X40GE-QSFPP, MIC3-3D-10XGE-SFPP, or MIC3-3D-1X100GE-CFP does not meet the NEBS criteria.\n\n\n</announcement> + <message>----------------------------------------------------------------\n\n This is mx1.bud.hu.geant.net, a GEANT Router in Budapest, Hungary \n Warning: Unauthorized access to this equipment is strictly forbidden and will lead to prosecution \n\n-------------------------------------------------------------\n</message> + <class> + <name>DANTE-Class</name> + <idle-timeout>15</idle-timeout> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>NOC-Class</name> + <idle-timeout>60</idle-timeout> + <permissions>all</permissions> + </class> + <class> + <name>dante</name> + <idle-timeout>20</idle-timeout> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>geantnms</name> + <idle-timeout>15</idle-timeout> + <permissions>all</permissions> + </class> + <class> + <name>isisView</name> + <idle-timeout>5</idle-timeout> + <permissions>routing</permissions> + <allow-commands>(exit|show isis)</allow-commands> + <deny-commands>show route.*</deny-commands> + </class> + <class> + <name>level1</name> + <idle-timeout>5</idle-timeout> + <permissions>admin</permissions> + <permissions>clear</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>nrn</name> + <idle-timeout>5</idle-timeout> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>view</permissions> + <allow-commands>show .*</allow-commands> + <deny-commands>(ssh .*|telnet .*)</deny-commands> + </class> + <class> + <name>opennsa</name> + <idle-timeout>5</idle-timeout> + <permissions>configure</permissions> + <deny-commands>(file.*)|(load.*)|(op.*)|(request.*)|(save.*)|(start.*)|(test.*)|(set cli.*)|(set date.*)|(clear.*)|(help.*)|(telnet.*)|(ssh.*)|(traceroute.*)|(mtrace.*)|(monitor.*)|(ping.*)|(show.*)|(set.*)</deny-commands> + <allow-configuration-regexps>interfaces .*</allow-configuration-regexps> + <allow-configuration-regexps>protocols connections remote-interface-switch.*</allow-configuration-regexps> + <allow-configuration-regexps>protocols connections interface-switch.*</allow-configuration-regexps> + <allow-configuration-regexps>protocols mpls label-switched-path.*</allow-configuration-regexps> + <deny-configuration-regexps>vmhost .*</deny-configuration-regexps> + <deny-configuration-regexps>session-limit-group .*</deny-configuration-regexps> + <deny-configuration-regexps>multi-chassis .*</deny-configuration-regexps> + <deny-configuration-regexps>jsrc-partition .*</deny-configuration-regexps> + <deny-configuration-regexps>jsrc .*</deny-configuration-regexps> + <deny-configuration-regexps>groups .*</deny-configuration-regexps> + <deny-configuration-regexps>dynamic-profiles .*</deny-configuration-regexps> + <deny-configuration-regexps>diameter .*</deny-configuration-regexps> + <deny-configuration-regexps>apply-groups .*</deny-configuration-regexps> + <deny-configuration-regexps>access-profile .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces traceoptions .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces interface-set .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces interface-range .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces apply-groups .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces apply-groups-except .*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces lt-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces ms-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces si-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces gr-.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces lo.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces dsc.*</deny-configuration-regexps> + <deny-configuration-regexps>interfaces irb.*</deny-configuration-regexps> + </class> + <class> + <name>readonly-permissions</name> + <idle-timeout>15</idle-timeout> + <permissions>view</permissions> + <permissions>view-configuration</permissions> + <allow-commands>show .*|quit|ping .*|monitor .*|traceroute .*|file archive .*</allow-commands> + </class> + <class> + <name>restricted-mon</name> + <idle-timeout>5</idle-timeout> + <permissions>access</permissions> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>interface</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>view</permissions> + </class> + <user> + <name>DANTE</name> + <uid>2021</uid> + <class>DANTE-Class</class> + </user> + <user> + <name>Monit0r</name> + <full-name>Monitor</full-name> + <uid>2001</uid> + <class>dante</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>NOC</name> + <uid>2022</uid> + <class>NOC-Class</class> + </user> + <user> + <name>aconet</name> + <uid>2014</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>amresnoc</name> + <uid>2053</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ansible</name> + <uid>2000</uid> + <class>NOC-Class</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>arnes</name> + <uid>2016</uid> + <class>nrn</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>basnet</name> + <uid>2017</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>belnet</name> + <uid>2018</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>bren</name> + <uid>2019</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>carnet</name> + <uid>2020</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ccssupport</name> + <uid>2015</uid> + <class>readonly-permissions</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>cnis</name> + <uid>2002</uid> + <comment>/* For cNIS NDM - TR Feb 07 */</comment> + <class>isisView</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>cnis-dev</name> + <uid>2003</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>cnis-prod</name> + <uid>2004</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>dfn</name> + <uid>2023</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>garr</name> + <uid>2024</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-cesnet</name> + <uid>2025</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-cynet</name> + <uid>2026</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-eenet</name> + <uid>2027</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-fccn</name> + <uid>2028</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-garr</name> + <uid>2029</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-hungar</name> + <uid>2030</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-malta</name> + <uid>2031</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>geant-switch</name> + <uid>2032</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>grnet</name> + <uid>2033</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>heanet</name> + <uid>2034</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>hungarnet</name> + <uid>2035</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>iucc</name> + <uid>2036</uid> + <class>nrn</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>janet</name> + <uid>2037</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>lat</name> + <uid>2048</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>litnet</name> + <uid>2038</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>marnet</name> + <uid>2039</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>mian</name> + <uid>2010</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>mren</name> + <uid>2040</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ncc</name> + <full-name>NOC Team Backup Account</full-name> + <uid>2005</uid> + <class>super-user</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>nordunet</name> + <uid>2041</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>opennsa</name> + <uid>2011</uid> + <class>opennsa</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>opnet</name> + <full-name>OPNET NEOP Planning system @ 62.40.105.114</full-name> + <uid>2013</uid> + <class>dante</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>opsdbv2</name> + <uid>2060</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>pionier</name> + <uid>2042</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>python</name> + <uid>2052</uid> + <class>NOC-Class</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>rediris</name> + <uid>2043</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>renater</name> + <uid>2044</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>reporting</name> + <uid>2055</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>restena</name> + <full-name>NREN RESTENA</full-name> + <uid>2045</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>restricted-mon</name> + <uid>2006</uid> + <class>restricted-mon</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>roedunet</name> + <uid>2046</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ruby</name> + <full-name>NOC Ruby script account</full-name> + <uid>2007</uid> + <class>level1</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>sanet</name> + <uid>2047</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>space</name> + <full-name>NCC - Junos Space application login</full-name> + <uid>2008</uid> + <class>geantnms</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>space15.2R2.4-paris</name> + <uid>2059</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>space17.1R1.7-london</name> + <uid>2009</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>srv-space-ssh</name> + <uid>2057</uid> + <class>super-user</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>srv_packetdesign</name> + <full-name>Packet Design Test VM 62.40.99.51 LON2</full-name> + <uid>2012</uid> + <class>restricted-mon</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>surfnet</name> + <uid>2049</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>ulakbim</name> + <uid>2050</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>uran</name> + <uid>2051</uid> + <class>nrn</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>xantaro</name> + <uid>2058</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <password> + <minimum-length>10</minimum-length> + <minimum-numerics>1</minimum-numerics> + <minimum-upper-cases>1</minimum-upper-cases> + <minimum-lower-cases>1</minimum-lower-cases> + <minimum-punctuations>1</minimum-punctuations> + </password> + </login> + <static-host-mapping> + <name>ts1.bud.hu</name> + <inet>172.16.18.254</inet> + </static-host-mapping> + <static-host-mapping> + <name>lo0</name> + <inet>62.40.97.1</inet> + </static-host-mapping> + <services> + <ssh> + <root-login>deny</root-login> + <no-tcp-forwarding/> + <protocol-version>v2</protocol-version> + <max-sessions-per-connection>32</max-sessions-per-connection> + <connection-limit>125</connection-limit> + <rate-limit>150</rate-limit> + </ssh> + <netconf> + <ssh> + </ssh> + </netconf> + </services> + <syslog> + <user> + <name>*</name> + <contents> + <name>any</name> + <emergency/> + </contents> + </user> + <host> + <name>62.40.119.31</name> + <contents> + <name>any</name> + <notice/> + </contents> + <contents> + <name>conflict-log</name> + <any/> + </contents> + <contents> + <name>change-log</name> + <any/> + </contents> + <facility-override>local0</facility-override> + </host> + <host> + <name>83.97.94.11</name> + <contents> + <name>any</name> + <any/> + </contents> + <match>!(kernel: rts_commi.*|RPD_MSDP_SRC_ACTIVE.*)</match> + <port>514</port> + </host> + <file> + <name>messages</name> + <contents> + <name>any</name> + <notice/> + </contents> + <contents> + <name>authorization</name> + <info/> + </contents> + <match>!(RPD_MSDP_SRC_ACTIVE.*)</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>interactive-commands</name> + <contents> + <name>interactive-commands</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>authorization</name> + <contents> + <name>authorization</name> + <any/> + </contents> + </file> + <file> + <name>firewall-log</name> + <contents> + <name>firewall</name> + <critical/> + </contents> + </file> + <file> + <name>daemon</name> + <contents> + <name>daemon</name> + <error/> + </contents> + </file> + <file> + <name>conf-history</name> + <contents> + <name>conflict-log</name> + <any/> + </contents> + <contents> + <name>change-log</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>net-alarms</name> + <contents> + <name>daemon</name> + <warning/> + </contents> + </file> + <file> + <name>low-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <notice/> + </contents> + <contents> + <name>kernel</name> + <notice/> + </contents> + <contents> + <name>user</name> + <notice/> + </contents> + <contents> + <name>pfe</name> + <notice/> + </contents> + </file> + <file> + <name>high-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <error/> + </contents> + <contents> + <name>kernel</name> + <error/> + </contents> + <contents> + <name>user</name> + <error/> + </contents> + <contents> + <name>pfe</name> + <error/> + </contents> + </file> + <file> + <name>commands-log</name> + <contents> + <name>interactive-commands</name> + <info/> + </contents> + </file> + <file> + <name>dnoc-events</name> + <contents> + <name>daemon</name> + <info/> + </contents> + <match>.*SNMP_TRAP_LINK_.*|.*RPD_BGP_NEIGHBOR_STATE_CHANGED.*|.*SNMPD_TRAP_COLD_START.*</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>default-log-messages</name> + <contents> + <name>any</name> + <info/> + </contents> + <match>(requested 'commit' operation)|(requested 'commit synchronize' operation)|(copying configuration to juniper.save)|(commit complete)|ifAdminStatus|(FRU power)|(FRU removal)|(FRU insertion)|(link UP)|transitioned|Transferred|transfer-file|(license add)|(license delete)|(package -X update)|(package -X delete)|(FRU Online)|(FRU Offline)|(plugged in)|(unplugged)|CFMD_CCM_DEFECT| LFMD_3AH | RPD_MPLS_PATH_BFD|(Master Unchanged, Members Changed)|(Master Changed, Members Changed)|(Master Detected, Members Changed)|(vc add)|(vc delete)|(Master detected)|(Master changed)|(Backup detected)|(Backup changed)|(interface vcp-)|(AIS_DATA_AVAILABLE)</match> + <structured-data> + </structured-data> + </file> + <file> + <name>pfed</name> + <contents> + <name>pfe</name> + <any/> + </contents> + <archive> + <size>20m</size> + <files>10</files> + </archive> + </file> + <time-format> + <year/> + <millisecond/> + </time-format> + <source-address>62.40.97.1</source-address> + </syslog> + <commit> + <fast-synchronize/> + <synchronize/> + </commit> + <ntp> + <boot-server>193.62.22.66</boot-server> + <authentication-key> + <name>1</name> + <type>md5</type> + <value>/* SECRET-DATA */</value> + </authentication-key> + <server> + <name>62.40.97.11</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.97.12</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.97.14</name> + <key>/* SECRET-DATA */</key> + </server> + <trusted-key>1</trusted-key> + <source-address> + <name>62.40.97.1</name> + </source-address> + </ntp> + </system> + <chassis> + <undocumented><dump-on-panic/></undocumented> + <redundancy> + <routing-engine> + <name>0</name> + <master/> + </routing-engine> + <routing-engine> + <name>1</name> + <backup/> + </routing-engine> + <failover> + <on-loss-of-keepalives/> + <on-disk-failure/> + </failover> + <graceful-switchover> + </graceful-switchover> + </redundancy> + <aggregated-devices> + <ethernet> + <device-count>32</device-count> + </ethernet> + </aggregated-devices> + <fpc> + <name>0</name> + <pic> + <name>0</name> + <tunnel-services> + <bandwidth>10g</bandwidth> + </tunnel-services> + </pic> + </fpc> + <fpc> + <name>4</name> + <pic> + <name>0</name> + <adaptive-services> + <service-package> + <extension-provider> + <syslog> + <name>daemon</name> + <critical/> + </syslog> + </extension-provider> + </service-package> + </adaptive-services> + </pic> + </fpc> + </chassis> + <services> + <flow-monitoring> + <version9> + <template> + <name>ipv4</name> + <flow-active-timeout>60</flow-active-timeout> + <flow-inactive-timeout>60</flow-inactive-timeout> + <template-refresh-rate> + <seconds>300</seconds> + </template-refresh-rate> + <option-refresh-rate> + <seconds>300</seconds> + </option-refresh-rate> + <ipv4-template> + </ipv4-template> + </template> + <template> + <name>ipv6</name> + <flow-active-timeout>60</flow-active-timeout> + <flow-inactive-timeout>60</flow-inactive-timeout> + <template-refresh-rate> + <seconds>300</seconds> + </template-refresh-rate> + <option-refresh-rate> + <seconds>300</seconds> + </option-refresh-rate> + <ipv6-template> + </ipv6-template> + </template> + <template> + <name>mpls</name> + <flow-active-timeout>60</flow-active-timeout> + <flow-inactive-timeout>60</flow-inactive-timeout> + <template-refresh-rate> + <seconds>300</seconds> + </template-refresh-rate> + <option-refresh-rate> + <seconds>300</seconds> + </option-refresh-rate> + <mpls-ipv4-template> + <label-position>1</label-position> + <label-position>2</label-position> + <label-position>3</label-position> + </mpls-ipv4-template> + </template> + </version9> + </flow-monitoring> + <rpm> + <probe> + <name>iGEANT_mx1.pra.cz_62.40.97.2</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.2</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.bra.sk_62.40.97.4</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.4</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.lon.uk_62.40.97.5</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.5</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.vie.at_62.40.97.7</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.7</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.poz.pl_62.40.97.10</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.10</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.ams.nl_62.40.97.11</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.11</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.fra.de_62.40.97.12</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.12</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.par.fr_62.40.97.13</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.13</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.gen.ch_62.40.97.14</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.14</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.mil2.it_62.40.97.15</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.15</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.mad.es_62.40.97.16</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.97.16</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.tal.ee_62.40.96.1</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.1</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.tal.ee_62.40.96.2</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.2</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.rig.lv_62.40.96.4</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.4</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.kau.lt_62.40.96.5</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.5</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.kau.lt_62.40.96.6</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.6</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.zag.hr_62.40.96.8</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.8</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.lju.si_62.40.96.10</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.10</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.lis.pt_62.40.96.16</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.16</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.lis.pt_62.40.96.17</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.17</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.bru.be_62.40.96.20</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.20</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx2.ath.gr_62.40.96.11</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.11</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.buc.ro_62.40.96.19</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.19</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.sof.bg_62.40.96.21</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.21</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.ham.de_62.40.96.26</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.26</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.mar.fr_62.40.96.12</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.12</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.lon2.uk_62.40.96.15</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.15</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.dub.ie_62.40.96.3</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.3</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.dub2.ie_62.40.96.25</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.25</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + <probe> + <name>iGEANT_mx1.ath2.gr_62.40.96.39</name> + <test> + <name>icmp-test</name> + <probe-type>icmp-ping-timestamp</probe-type> + <target> + <address>62.40.96.39</address> + </target> + <probe-count>10</probe-count> + <probe-interval>6</probe-interval> + <test-interval>3600</test-interval> + <history-size>512</history-size> + <hardware-timestamp/> + </test> + </probe> + </rpm> + <service-set> + <name>NETFLOW_EXPORT</name> + <jflow-rules> + <sampling> + </sampling> + </jflow-rules> + <sampling-service> + <service-interface>ms-4/0/0.0</service-interface> + </sampling-service> + </service-set> + <service-set> + <name>NETFLOW_EXPORT-v6</name> + <jflow-rules> + <sampling> + </sampling> + </jflow-rules> + <sampling-service> + <service-interface>ms-4/0/0.1</service-interface> + </sampling-service> + </service-set> + <service-set> + <name>NETFLOW_MPLS_EXPORT</name> + <jflow-rules> + <sampling> + </sampling> + </jflow-rules> + <sampling-service> + <service-interface>ms-4/0/0.2</service-interface> + </sampling-service> + </service-set> + </services> + <interfaces> + <apply-groups>re0</apply-groups> + <apply-groups>re1</apply-groups> + <apply-groups>load-balance-adaptive</apply-groups> + <interface> + <name>lt-0/0/0</name> + <description>TUN INFRASTRUCTURE ACCESS SRF0000001 </description> + <unit> + <name>16</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS IAS SRF0000001 | BGP Peering - RE_INTERCONNECT Side</description> + <encapsulation>ethernet</encapsulation> + <peer-unit>61</peer-unit> + <family> + <inet> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>83.97.88.224/31</name> + </address> + </inet> + <inet6> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::fd/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>61</name> + <description>SRV_IAS INFRASTRUCTURE ACCESS GLOBAL SRF0000001 | BGP Peering - IAS Side</description> + <encapsulation>ethernet</encapsulation> + <peer-unit>16</peer-unit> + <family> + <inet> + <address> + <name>83.97.88.225/31</name> + </address> + </inet> + <inet6> + <address> + <name>2001:798:1::fe/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>xe-0/0/0</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE7 SRF0000001 |</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-0/0/1</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE7 SRF0000001 |</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-0/1/0</name> + <description>PHY CUSTOMER CESNET P_AE13 SRF9919647|</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-0/1/1</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE1 SRF0000001 |</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>ge-0/2/0</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/1</name> + <description>PHY INFRASTRUCTURE ACCESS INFINERA SRF9915905 | BUD01-DTNX10-1 XCM 1</description> + <unit> + <name>0</name> + <family> + <bridge> + <interface-mode>access</interface-mode> + <vlan-id>999</vlan-id> + </bridge> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/2</name> + <description>PHY INFRASTRUCTURE ACCESS INFINERA SRF0000001 | BUD01_CX_01 DCN</description> + <unit> + <name>0</name> + <family> + <bridge> + <interface-mode>access</interface-mode> + <vlan-id>999</vlan-id> + </bridge> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/3</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/4</name> + <description>PHY UPSTREAM LEVEL3 SRF0000001 |EAP GRENA GWS</description> + <mtu>9192</mtu> + <encapsulation>ethernet-ccc</encapsulation> + <unit> + <name>0</name> + <description>SRV_L2CIRCUIT UPSTREAM LEVEL3 SRF0000001 | bud-bud_EAP_GRENA-Level3_9933983</description> + <input-vlan-map> + <push/> + <vlan-id>210</vlan-id> + </input-vlan-map> + <output-vlan-map> + <pop/> + </output-vlan-map> + <family> + <ccc> + </ccc> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/5</name> + <description>PHY UPSTREAM LEVEL3 SRF0000001 | EAP AzScienceNet GWS-Service ID-BDBG6203 </description> + <mtu>9192</mtu> + <encapsulation>ethernet-ccc</encapsulation> + <unit> + <name>0</name> + <description>SRV_L2CIRCUIT UPSTREAM LEVEL3 SRF9934181 | bud-fra_EAP_AzScienceNet-Level3_SRF9934181</description> + <input-vlan-map> + <push/> + <vlan-id>220</vlan-id> + </input-vlan-map> + <output-vlan-map> + <pop/> + </output-vlan-map> + <family> + <ccc> + </ccc> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/6</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/2/7</name> + <description>PHY CUSTOMER MREN P_AE15 SRF9934755 |</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae15</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>ge-0/2/8</name> + <description>PHY INFRASTRUCTURE ACCESS PERFSONAR SRF0000001 | PSMP OWAMP</description> + <undocumented><enable/></undocumented> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS PERFSONAR SRF0000001 | OWAMP CONTACT: ivan.garnizov@fau.de IMPLEMENTED: 20160607</description> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>OWAMP_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>OWAMP_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.114.44/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>OWAMP_V6_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>OWAMP_V6_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:bb:2::4d/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ge-0/2/9</name> + <description>PHY CUSTOMER GRENA P_AE12 SRF9917825 | TURK TELEKOM ID: IIE0004UW</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>ge-0/3/0</name> + <description>PHY INFRASTRUCTURE ACCESS INFINERA SRF9915907 | BUD01-DTNX10-1 XCM 2</description> + <unit> + <name>0</name> + <family> + <bridge> + <interface-mode>access</interface-mode> + <vlan-id>999</vlan-id> + </bridge> + </family> + </unit> + </interface> + <interface> + <name>ge-0/3/1</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/2</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/3</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/4</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/5</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/6</name> + <description>PHY INFRASTRUCTURE ACCESS LAN | bud hu POP LAN</description> + <vlan-tagging/> + <unit> + <name>7</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | NTP4.GEANT.NET</description> + <vlan-id>7</vlan-id> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>VL07_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>VL07_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.123.20/31</name> + </address> + </inet> + </family> + </unit> + <unit> + <name>10</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | TEST - C3524 g0/2</description> + <vlan-id>10</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>LAN-in</filter-name> + </input> + <output> + <filter-name>LAN-out</filter-name> + </output> + </filter> + <address> + <name>62.40.107.81/29</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <address> + <name>2001:798:fc01:1b::1/125</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>20</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | C1N1 iDRAC CONTACT: allen.kong@geant.net IMPLEMENTED: 20161027</description> + <vlan-id>20</vlan-id> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.118.120/31</name> + </address> + </inet> + <iso> + </iso> + </family> + </unit> + <unit> + <name>23</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | perfSONAR iDRAC</description> + <vlan-id>23</vlan-id> + <family> + <inet> + <filter> + <input-list>INTERNAL_HEAD_IN</input-list> + <input-list>VL023_MIDDLE_IN</input-list> + <input-list>INTERNAL_TAIL_IN</input-list> + <output-list>INTERNAL_HEAD_OUT</output-list> + <output-list>VL023_MIDDLE_OUT</output-list> + <output-list>INTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.118.72/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input-list>INTERNAL_V6_HEAD_IN</input-list> + <input-list>VL023_V6_MIDDLE_IN</input-list> + <input-list>INTERNAL_V6_TAIL_IN</input-list> + <output-list>INTERNAL_V6_HEAD_OUT</output-list> + <output-list>VL023_V6_MIDDLE_OUT</output-list> + <output-list>INTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:ee:b::1d/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>24</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | perfSONAR MGMT</description> + <vlan-id>24</vlan-id> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>PSMGMT_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>PSMGMT_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.114.42/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>PSMGMT_V6_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>PSMGMT_V6_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:bb:2::49/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>30</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | OPERATIONS - C3524 g0/2</description> + <vlan-id>30</vlan-id> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.107.241/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:2018:1e::1/64</name> + </address> + <address> + <name>2001:798:fc01:1b::9/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>60</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | KVMoIP</description> + <vlan-id>60</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>LAN-in</filter-name> + </input> + <output> + <filter-name>LAN-out</filter-name> + </output> + </filter> + <address> + <name>62.40.121.33/30</name> + </address> + </inet> + <iso> + </iso> + </family> + </unit> + <unit> + <name>93</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | GIDP</description> + <vlan-id>93</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>gidp-in</filter-name> + </input> + <output> + <filter-name>gidp-out</filter-name> + </output> + </filter> + <address> + <name>62.40.121.113/30</name> + </address> + </inet> + <iso> + </iso> + </family> + </unit> + <unit> + <name>170</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | IP cameras</description> + <vlan-id>170</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>VM-RANGE-VL170-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL170-OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.116.169/29</name> + </address> + </inet> + <iso> + </iso> + <inet6 inactive="inactive"> + <address> + <name>2001:798:ee:6::1/64</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>190</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | OPS VM</description> + <vlan-id>190</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>VM-RANGE-VL190-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL190-OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.113.30/31</name> + </address> + </inet> + <inet6> + <address> + <name>2001:798:ffb4:1b::1/64</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>200</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS SRF0000001 | INFOBLOX DNS APPLIANCES</description> + <vlan-id>200</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>VM-RANGE-VL200-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL200-OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.116.105/29</name> + </address> + </inet> + <inet6> + <filter> + <input> + <filter-name>VM-RANGE-VL200-V6-IN</filter-name> + </input> + <output> + <filter-name>VM-RANGE-VL200-V6-OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:ee:e::1/64</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ge-0/3/7</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/8</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ge-0/3/9</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>ms-4/0/0</name> + <unit> + <name>0</name> + <family> + <inet> + </inet> + </family> + </unit> + <unit> + <name>1</name> + <family> + <inet6> + </inet6> + </family> + </unit> + <unit> + <name>2</name> + <family> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>xe-4/2/0</name> + <description>PHY UPSTREAM TELIA SRF9944007 | Telia ID: IC-338564</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae17</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/1</name> + <description>PHY UPSTREAM COGENT SRF0000001 | Cogent ID: 1-300280816</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae19</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/2</name> + <description>PHY SPARE NON-OPERATIONAL</description> + <disable/> + </interface> + <interface> + <name>xe-4/2/3</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE2 SRF0000001 | bud-lju</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/4</name> + <description>PHY CUSTOMER HUNGARNET P_AE10 SRF9937897 |</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/5</name> + <description>PHY CUSTOMER ULAKBIM P_AE11 SRF9934761 | ID: WL050804</description> + <hold-time> + <up>100</up> + <down>3000</down> + </hold-time> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/6</name> + <description>PHY PRIVATE FACEBOOK P_AE14 SRF9938053 | To FB Cisco 3132 port 3</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/7</name> + <description>PHY PRIVATE FACEBOOK P_AE14 SRF9938055 | To FB Cisco 3132 port 4</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/8</name> + <description>PHY UPSTREAM TELIA SRF9940473 | Telia ID: IC-326863</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae17</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-4/2/9</name> + <description>PHY CUSTOMER CESNET P_AE13 SRF9939551|</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/0/0</name> + <description>PHY CUSTOMER AMRES SRF9935923 |Telekom Serbia ID: Beograd/RCUB-AMRES-Budapest/ICL/NIIF/GEANT 10G02</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae16</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/0/1</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE1 SRF0000001 |</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/0/2</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE2 SRF0000001 | bud-lju</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/0/3</name> + <description>PHY SPARE NON-OPERATIONAL</description> + <disable/> + </interface> + <interface> + <name>xe-5/0/4</name> + <description>PHY CUSTOMER ULAKBIM P_AE11 SRF9923121 | ID: PI0005N6</description> + <hold-time> + <up>100</up> + <down>3000</down> + </hold-time> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/0/5</name> + <description>PHY CUSTOMER ULAKBIM P_AE11 SRF9923123 | ID: PI0005N5</description> + <hold-time> + <up>100</up> + <down>3000</down> + </hold-time> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/0/6</name> + <description>PHY SPARE</description> + <disable/> + </interface> + <interface> + <name>xe-5/0/7</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE2 | bud-lju</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/1/0</name> + <description>PHY PUBLIC BIX P_AE18 SRF9946211 | GEANT 10G #1 - VH-NX7710-1 Eth2/14</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae18</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/1/1</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE0 SRF0000001 |</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/1/2</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE0 SRF0000001 |</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/1/3</name> + <description>PHY SPARE NON-OPERATIONAL | Connected to 1-B-2-1-3</description> + <disable/> + <framing> + <lan-phy/> + </framing> + </interface> + <interface> + <name>xe-5/1/4</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE7 SRF0000001 |</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/1/5</name> + <description>PHY CUSTOMER HUNGARNET P_AE10 SRF9923325 |</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/1/6</name> + <description>PHY UPSTREAM COGENT SRF0000001 | Cogent ID: 1-300280814</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae19</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/1/7</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE7 SRF0000001 |</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/2/0</name> + <description>PHY CUSTOMER HUNGARNET P_AE10 SRF9922913 |</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/2/1</name> + <description>PHY SPARE NON-OPERATIONAL | Connected to 1-A-2-3-2</description> + <disable/> + <framing> + <lan-phy/> + </framing> + </interface> + <interface> + <name>xe-5/2/2</name> + <description>PHY INFRASTRUCTURE ACCESS PERFSONAR SRF0000001 | PSMP BWCTL</description> + <mtu>9192</mtu> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS PERFSONAR SRF0000001 | BWCTL CONTACT: ivan.garnizov@fau.de IMPLEMENTED: 20160607</description> + <family> + <inet> + <filter> + <input-list>PROTECTED_EXTERNAL_HEAD_IN</input-list> + <input-list>BWCTL_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_HEAD_OUT</output-list> + <output-list>BWCTL_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_TAIL_OUT</output-list> + </filter> + <address> + <name>62.40.114.46/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input-list>PROTECTED_EXTERNAL_V6_HEAD_IN</input-list> + <input-list>BWCTL_V6_MIDDLE_IN</input-list> + <input-list>PROTECTED_EXTERNAL_V6_TAIL_IN</input-list> + <output-list>PROTECTED_EXTERNAL_V6_HEAD_OUT</output-list> + <output-list>BWCTL_V6_MIDDLE_OUT</output-list> + <output-list>PROTECTED_EXTERNAL_V6_TAIL_OUT</output-list> + </filter> + <address> + <name>2001:798:bb:2::51/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>xe-5/2/3</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE4 SRF0000001 | buc-bud L3 BCXJ2804</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/2/4</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE2 SRF0000001 | bud-lju</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/2/5</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE4 SRF0000001 | buc-bud L3 BCZG0606</description> + <undocumented><enable/></undocumented> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/2/6</name> + <description>PHY PRIVATE FACEBOOK P_AE14 SRF9936767 | To FB Cisco 3132 port 1</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/2/7</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE2 SRF0000001 | bud-lju</description> + <undocumented><enable/></undocumented> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/3/0</name> + <description>PHY SPARE NON OPERATIONAL</description> + <disable/> + </interface> + <interface> + <name>xe-5/3/1</name> + <description>PHY CUSTOMER HUNGARNET P_AE10 SRF9916010 |</description> + <undocumented><enable/></undocumented> + <gigether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/3/2</name> + <description>PHY CUSTOMER AMRES SRF9934757 |Telekom Serbia ID: Beograd/RCUB-AMRES-Budapest/ICL/NIIF/GEANT 10G01</description> + <framing> + <wan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae16</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/3/3</name> + <description>PHY PRIVATE FACEBOOK P_AE14 SRF9936769 | To FB Cisco 3132 port 2</description> + <framing> + <lan-phy/> + </framing> + <gigether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>xe-5/3/4</name> + <description>PHY SPARE NON-OPERATIONAL</description> + <disable/> + </interface> + <interface> + <name>xe-5/3/5</name> + <description>PHY SPARE NON-OPERATIONAL</description> + <disable/> + </interface> + <interface> + <name>xe-5/3/6</name> + <description>PHY SPARE NON-OPERATIONAL</description> + <disable/> + </interface> + <interface> + <name>xe-5/3/7</name> + <description>PHY SPARE NON-OPERATIONAL</description> + <disable/> + </interface> + <interface> + <name>et-10/0/0</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE6 SRF??? |</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae6</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>et-11/0/0</name> + <description>PHY INFRASTRUCTURE BACKBONE P_AE3 SRF??? |</description> + <gigether-options> + <ieee-802.3ad> + <bundle>ae3</bundle> + </ieee-802.3ad> + </gigether-options> + </interface> + <interface> + <name>ae0</name> + <description>LAG INFRASTRUCTURE BACKBONE BRA SRF0000001 | bra-bud</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>2</minimum-links> + <link-speed>10g</link-speed> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE BRA SRF0000001 | bra-bud</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.110/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:3301:1b01::6/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae1</name> + <description>LAG INFRASTRUCTURE BACKBONE ZAG SRF0000001 | bud-zag</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE ZAG SRF0000001 | bud-zag</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.15/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:2d01:1b01::6/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae2</name> + <description>LAG INFRASTRUCTURE BACKBONE LJU SRF0000001 | bud-lju</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>4</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE LJU SRF0000001 | bud-lju</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.32/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:3201:1001::5/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae3</name> + <description>LAG INFRASTRUCTURE BACKBONE VIE SRF0000001 | bud-vie</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE VIE SRF0000001 | bud-vie</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.44/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:1::d/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae4</name> + <description>LAG INFRASTRUCTURE BACKBONE BUC SRF0000001 | buc-bud</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>2</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE BUC SRF0000001 | buc-bud</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.167/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:1b01:2b01::1/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae6</name> + <description>LAG INFRASTRUCTURE BACKBONE FRA SRF0000001 | bud-fra</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE FRA SRF0000001 | bud-fra</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.46/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:1::11/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae7</name> + <description>LAG INFRASTRUCTURE BACKBONE PRA SRF0000001 | bud-pra</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <minimum-links>3</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_GLOBAL INFRASTRUCTURE BACKBONE PRA SRF0000001 | bud-pra</description> + <family> + <inet> + <accounting> + <source-class-usage> + <input/> + </source-class-usage> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone-in</filter-name> + </input> + <output> + <filter-name>bone-out</filter-name> + </output> + </filter> + <address> + <name>62.40.98.50/31</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>bone6-in</filter-name> + </input> + <output> + <filter-name>bone6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:cc:1::19/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae10</name> + <description>LAG CUSTOMER HUNGARNET SRF9923213 |</description> + <vlan-tagging/> + <mtu>9192</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>3</minimum-links> + <link-speed>10g</link-speed> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>100</name> + <description>SRV_GLOBAL CUSTOMER HUNGARNET AP1 SRF9923329 | ASN1955 |</description> + <vlan-id>100</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>HUNGA-in</filter-name> + </input> + <output> + <filter-name>HUNGA-out</filter-name> + </output> + </filter> + <address> + <name>62.40.124.101/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>HUNGA6-in</filter-name> + </input> + <output> + <filter-name>HUNGA6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:1b:10aa::5/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + <unit> + <name>333</name> + <description>SRV_IAS CUSTOMER HUNGARNET SRF9931685 | ASN1955 |</description> + <vlan-id>333</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_HUNGARNET_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_HUNGARNET_OUT</filter-name> + </output> + </filter> + <address> + <name>83.97.88.81/30</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_HUNGARNET_V6_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_HUNGARNET_V6_OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::65/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>909</name> + <description>SRV_L2CIRCUIT CUSTOMER HUNGARNET SRF9912012 | bud-gen_WIGNER_CERN-NIIF_12012</description> + <encapsulation>vlan-ccc</encapsulation> + <vlan-id>909</vlan-id> + </unit> + <unit> + <name>911</name> + <description>SRV_MDVPN CUSTOMER HUNGARNET SRF9927673 |</description> + <vlan-id>911</vlan-id> + <family> + <inet> + <mtu>9000</mtu> + <address> + <name>62.40.102.26/31</name> + </address> + </inet> + <mpls> + <filter> + <input>NREN-MDVPN-MPLS-in</input> + </filter> + </mpls> + </family> + </unit> + </interface> + <interface> + <name>ae11</name> + <description>LAG CUSTOMER ULAKBIM SRF9926155 |</description> + <vlan-tagging/> + <mtu>9192</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>2</minimum-links> + <link-speed>oc192</link-speed> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>100</name> + <description>SRV_GLOBAL CUSTOMER ULAKBIM AP1 SRF9911377 | ASN8517 |</description> + <vlan-id>100</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <filter> + <input> + <filter-name>ULAKB-in</filter-name> + </input> + <output> + <filter-name>ULAKB-out</filter-name> + </output> + </filter> + <address> + <name>62.40.125.129/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input> + <filter-name>ULAKB6-in</filter-name> + </input> + <output> + <filter-name>ULAKB6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:2c:10aa::5/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + <unit> + <name>333</name> + <description>SRV_IAS CUSTOMER ULAKBIM SRF9931735 | ASN8517 |</description> + <vlan-id>333</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_ULAKBIM_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_ULAKBIM_OUT</filter-name> + </output> + </filter> + <address> + <name>83.97.88.161/30</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_ULAKBIM_V6_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_ULAKBIM_V6_OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::c5/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae12</name> + <description>LAG CUSTOMER GRENA SRF0000001 |</description> + <vlan-tagging/> + <mtu>9192</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + </aggregated-ether-options> + <unit> + <name>200</name> + <description>SRV_GLOBAL CUSTOMER GRENA AP1 SRF0000001 | ASN20545 |</description> + <vlan-id>200</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <filter> + <input> + <filter-name>nren_GRENA_IN</filter-name> + </input> + <output> + <filter-name>nren_GRENA_OUT</filter-name> + </output> + </filter> + <address> + <name>62.40.125.33/30</name> + </address> + </inet> + </family> + </unit> + <unit> + <name>210</name> + <description>SRV_L2CIRCUIT CUSTOMER GRENA SRF0000001 | fra-fra_EAP_GRENA-Level3_99XXXXX</description> + <encapsulation>vlan-ccc</encapsulation> + <vlan-id>210</vlan-id> + </unit> + </interface> + <interface> + <name>ae13</name> + <description>LAG CUSTOMER CESNET SRF9927751 |</description> + <flexible-vlan-tagging/> + <mtu>9100</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>2</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>333</name> + <description>SRV_IAS CUSTOMER CESNET SRF9931659 | ASN2852 |</description> + <vlan-id>333</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_CESNET_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_CESNET_OUT</filter-name> + </output> + </filter> + <address> + <name>83.97.88.37/30</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_CESNET_V6_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_CESNET_V6_OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::29/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>600</name> + <description>SRV_GLOBAL CUSTOMER CESNET AP2 SRF9922181 | ASN2852 |</description> + <vlan-id>600</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <filter> + <input> + <filter-name>CESNET-in</filter-name> + </input> + <output> + <filter-name>CESNET-out</filter-name> + </output> + </filter> + <address> + <name>62.40.124.13/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <filter> + <input> + <filter-name>CESNET6-in</filter-name> + </input> + <output> + <filter-name>CESNET6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:1b:10aa::19/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae14</name> + <description>LAG PRIVATE FACEBOOK SRF9935147</description> + <mtu>1514</mtu> + <aggregated-ether-options> + <lacp> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_IAS PRIVATE FACEBOOK SRF9935149 | ASN63293 | FB ID: FBUD2-1 CONTACT: fna-ops@fb.com</description> + <family> + <inet> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>FACEBOOK-in</filter-name> + </input> + <output> + <filter-name>FACEBOOK-out</filter-name> + </output> + </filter> + <address> + <name>83.97.89.6/31</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>FACEBOOKV6-in</filter-name> + </input> + <output> + <filter-name>FACEBOOKV6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::/127</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae15</name> + <description>LAG CUSTOMER MREN SRF9937799 | Telecom Serbia ID: Budapest/NIIF/GEANT-Podgorica/MTELCG/CIS-AMUCG 1000M01</description> + <flexible-vlan-tagging/> + <mtu>9192</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + </aggregated-ether-options> + <unit> + <name>100</name> + <description>SRV_GLOBAL CUSTOMER MREN AP1 SRF9924425 | ASN40981 |</description> + <vlan-id>100</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>MREN-in</filter-name> + </input> + <output> + <filter-name>MREN-out</filter-name> + </output> + </filter> + <address> + <name>62.40.125.209/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>MREN6-in</filter-name> + </input> + <output> + <filter-name>MREN6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:1b:10aa::9/126</name> + </address> + </inet6> + </family> + </unit> + <unit> + <name>333</name> + <description>SRV_IAS CUSTOMER MREN SRF9931701 | ASN40981 |</description> + <vlan-id>333</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_MREN_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_MREN_OUT</filter-name> + </output> + </filter> + <address> + <name>83.97.88.109/30</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_MREN_V6_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_MREN_V6_OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::85/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae16</name> + <description>LAG CUSTOMER AMRES SRF9938887 |</description> + <flexible-vlan-tagging/> + <mtu>9192</mtu> + <encapsulation>flexible-ethernet-services</encapsulation> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>oc192</link-speed> + <lacp> + <active/> + </lacp> + </aggregated-ether-options> + <unit> + <name>1</name> + <description>SRV_GLOBAL CUSTOMER AMRES AP1 SRF9921979 | ASN13092 |</description> + <vlan-id>1</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>AMRES-in</filter-name> + </input> + <output> + <filter-name>AMRES-out</filter-name> + </output> + </filter> + <address> + <name>62.40.125.177/30</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>9000</mtu> + <filter> + <input> + <filter-name>AMRES6-in</filter-name> + </input> + <output> + <filter-name>AMRES6-out</filter-name> + </output> + </filter> + <address> + <name>2001:798:1b:10aa::1/126</name> + </address> + </inet6> + <mpls> + </mpls> + </family> + </unit> + <unit> + <name>10</name> + <description>SRV_MDVPN CUSTOMER AMRES SRF9927501 |</description> + <vlan-id>10</vlan-id> + <family> + <inet> + <address> + <name>62.40.102.6/31</name> + </address> + </inet> + <mpls> + <filter> + <input>NREN-MDVPN-MPLS-in</input> + </filter> + </mpls> + </family> + </unit> + <unit> + <name>333</name> + <description>SRV_IAS CUSTOMER AMRES SRF9931637 | ASN13092 |</description> + <vlan-id>333</vlan-id> + <family> + <inet> + <accounting> + <source-class-usage> + <output/> + </source-class-usage> + <destination-class-usage/> + </accounting> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_AMRES_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_AMRES_OUT</filter-name> + </output> + </filter> + <address> + <name>83.97.88.5/30</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>nren_IAS_AMRES_V6_IN</filter-name> + </input> + <output> + <filter-name>nren_IAS_AMRES_V6_OUT</filter-name> + </output> + </filter> + <address> + <name>2001:798:1::9/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae17</name> + <description>LAG UPSTREAM TELIA SRF9940473</description> + <mtu>1514</mtu> + <aggregated-ether-options> + <minimum-links>2</minimum-links> + <link-speed>10g</link-speed> + <lacp> + <active/> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_IAS UPSTREAM TELIA SRF9940473 | ASN1299</description> + <family> + <inet> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>Telia-in</filter-name> + </input> + <output> + <filter-name>Telia-out</filter-name> + </output> + </filter> + <address> + <name>80.239.135.139/31</name> + </address> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>Telia6-in</filter-name> + </input> + <output> + <filter-name>Telia6-out</filter-name> + </output> + </filter> + <address> + <name>2001:2000:3080:14f2::2/126</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae18</name> + <description>LAG PUBLIC BIX SRF9946209</description> + <vlan-tagging/> + <mtu>1518</mtu> + <mac>a8:d0:e5:f7:23:62</mac> + <no-gratuitous-arp-reply/> + <no-gratuitous-arp-request/> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + </aggregated-ether-options> + <unit> + <name>10</name> + <vlan-id>10</vlan-id> + <family> + <inet> + <filter> + <input> + <filter-name>BIX.HU-in</filter-name> + </input> + <output> + <filter-name>BIX.HU-out</filter-name> + </output> + </filter> + <address> + <name>193.188.137.37/24</name> + </address> + </inet> + </family> + </unit> + <unit> + <name>11</name> + <vlan-id>11</vlan-id> + <family> + <inet> + <mtu>1500</mtu> + </inet> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>BIX.HU-V6-in</filter-name> + </input> + <output> + <filter-name>BIX.HU-V6-out</filter-name> + </output> + </filter> + <address> + <name>2001:7f8:35::2:1320:1/64</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>ae19</name> + <description>LAG UPSTREAM COGENT SRF9946737 | Cogent ID: 1-300280816</description> + <mtu>1514</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <description>SRV_IAS UPSTREAM COGENT SRF9943647 | ASN174 |</description> + <family> + <inet> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>Cogent-in</filter-name> + </input> + <output> + <filter-name>Cogent-out</filter-name> + </output> + </filter> + <address> + <name>149.6.182.114/29</name> + </address> + </inet> + <iso> + </iso> + <inet6> + <mtu>1500</mtu> + <filter> + <input> + <filter-name>Cogent6-in</filter-name> + </input> + <output> + <filter-name>Cogent6-out</filter-name> + </output> + </filter> + <address> + <name>2001:978:2:26::2/112</name> + </address> + </inet6> + </family> + </unit> + </interface> + <interface> + <name>dsc</name> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>192.0.2.131/32</name> + </address> + </inet> + </family> + </unit> + </interface> + <interface> + <name>irb</name> + <unit> + <name>999</name> + <description>SRV_GLOBAL INFRASTRUCTURE ACCESS INFINERA SRF0000001 |</description> + <family> + <inet> + <address> + <name>10.0.4.100/24</name> + </address> + </inet> + </family> + </unit> + </interface> + <interface> + <name>lo0</name> + <unit> + <name>0</name> + <family> + <inet> + <filter> + <input> + <filter-name>ROUTER_access</filter-name> + </input> + <output> + <filter-name>router-access-out</filter-name> + </output> + </filter> + <address> + <name>62.40.97.1/32</name> + </address> + </inet> + <iso> + <address> + <name>49.51e5.0001.0620.4009.7001.00</name> + </address> + </iso> + <inet6> + <filter> + <input> + <filter-name>ROUTER_access_V6</filter-name> + </input> + </filter> + <address> + <name>2001:798:1b:20ff::1/128</name> + </address> + </inet6> + </family> + </unit> + </interface> + </interfaces> + <snmp> + <location>bud, hu ##LOC 47 31 4.45 N 19 3 19.57 E ##</location> + <contact>GEANT OC, support@oc.geant.net, +44 (0) 1223 733033</contact> + <view> + <name>nasra-view</name> + <oid> + <name>.1.3.6.1.2.1.2.2</name> + </oid> + <oid> + <name>.1.3.6.1.2.1.31.1.1.1</name> + </oid> + </view> + <community> + <name>0pBiFbD</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.98.0/23</name> + </clients> + <clients> + <name>193.110.48.4/32</name> + </clients> + <clients> + <name>193.63.211.0/25</name> + </clients> + <clients> + <name>193.63.211.56/32</name> + </clients> + <clients> + <name>62.40.118.241/32</name> + </clients> + <clients> + <name>62.40.118.224/28</name> + </clients> + <clients> + <name>62.40.118.243/32</name> + </clients> + <clients> + <name>62.40.118.50/32</name> + </clients> + <clients> + <name>62.40.115.147/32</name> + </clients> + <clients> + <name>62.40.121.102/32</name> + </clients> + <clients> + <name>83.97.91.0/24</name> + </clients> + <clients> + <name>83.97.92.0/24</name> + </clients> + <clients> + <name>62.40.118.240/28</name> + </clients> + <clients> + <name>193.63.211.136/32</name> + </clients> + <clients> + <name>62.40.119.0/24</name> + </clients> + <clients> + <name>62.40.117.82/32</name> + </clients> + <clients> + <name>62.40.119.32/32</name> + </clients> + <clients> + <name>62.40.115.146/32</name> + </clients> + <clients> + <name>62.40.115.130/32</name> + </clients> + <clients> + <name>62.40.116.18/32</name> + </clients> + <clients> + <name>62.40.115.82/32</name> + </clients> + <clients> + <name>62.40.118.213/30</name> + </clients> + <clients> + <name>62.40.99.0/29</name> + </clients> + <clients> + <name>62.40.104.48/29</name> + </clients> + <clients> + <name>62.40.104.152/29</name> + </clients> + <comment>/* OPNET NEOPS Server - Feb 2013 */</comment> + <clients> + <name>62.40.105.117/32</name> + </clients> + <comment>/* OPNET V2000/ARX Flow Collector - For helping with output format of reports - Feb 2013 */</comment> + <clients> + <name>62.40.105.114/32</name> + </clients> + <clients> + <name>62.40.104.24/29</name> + </clients> + <clients> + <name>62.40.104.144/29</name> + </clients> + <clients> + <name>193.63.90.246/32</name> + </clients> + <clients> + <name>62.40.104.10/32</name> + </clients> + <clients> + <name>62.40.106.202/32</name> + </clients> + <clients> + <name>62.40.113.88/29</name> + </clients> + <clients> + <name>62.40.120.18/32</name> + </clients> + <clients> + <name>62.40.111.254/32</name> + </clients> + <clients> + <name>62.40.106.232/29</name> + </clients> + <clients> + <name>62.40.114.107/32</name> + </clients> + <clients> + <name>62.40.114.108/32</name> + </clients> + <clients> + <name>62.40.114.114/32</name> + </clients> + <clients> + <name>62.40.120.72/29</name> + </clients> + <clients> + <name>62.40.120.90/32</name> + </clients> + <clients> + <name>62.40.122.138/32</name> + </clients> + <clients> + <name>62.40.106.182/32</name> + </clients> + <clients> + <name>62.40.122.106/32</name> + </clients> + <clients> + <name>62.40.122.110/32</name> + </clients> + <clients> + <name>83.97.92.94/32</name> + </clients> + <clients> + <name>62.40.100.202/32</name> + </clients> + <clients> + <name>62.40.114.0/28</name> + </clients> + <clients> + <name>62.40.114.16/28</name> + </clients> + <clients> + <name>83.97.92.238/32</name> + </clients> + <clients> + <name>83.97.92.239/32</name> + </clients> + <clients> + <name>83.97.93.39/32</name> + </clients> + <clients> + <name>83.97.93.45/32</name> + </clients> + <clients> + <name>83.97.93.22/32</name> + </clients> + <clients> + <name>83.97.93.37/32</name> + </clients> + <clients> + <name>83.97.92.159/32</name> + </clients> + <clients> + <name>83.97.92.114/32</name> + </clients> + <clients> + <name>83.97.93.23/32</name> + </clients> + <clients> + <name>83.97.92.183/32</name> + </clients> + <clients> + <name>83.97.93.59/32</name> + </clients> + <clients> + <name>83.97.93.137/32</name> + </clients> + <clients> + <name>83.97.93.195/32</name> + </clients> + <clients> + <name>83.97.93.196/32</name> + </clients> + <clients> + <name>83.97.93.238/32</name> + </clients> + <clients> + <name>83.97.94.12/32</name> + </clients> + <clients> + <name>83.97.94.13/32</name> + </clients> + <clients> + <name>83.97.94.14/32</name> + </clients> + <clients> + <name>62.40.106.201/32</name> + </clients> + <clients> + <name>83.97.93.152/32</name> + </clients> + <clients> + <name>83.97.93.153/32</name> + </clients> + <clients> + <name>83.97.93.154/32</name> + </clients> + <clients> + <name>62.40.99.51/32</name> + </clients> + <clients> + <name>62.40.106.200/29</name> + </clients> + <clients> + <name>83.97.94.52/32</name> + </clients> + <clients> + <name>83.97.93.239/32</name> + </clients> + </community> + <community> + <name>As4n0gN!</name> + <authorization>read-only</authorization> + <clients> + <name>212.51.192.2/32</name> + </clients> + <clients> + <name>212.51.192.18/32</name> + </clients> + <clients> + <name>212.51.192.185/32</name> + </clients> + <comment>/* JANET monitoring tool */</comment> + <clients> + <name>128.86.32.16/29</name> + </clients> + </community> + <community> + <name>c6N1rt5S</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.122.226/32</name> + </clients> + </community> + <community> + <name>c6N2rt5s</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.122.0/24</name> + </clients> + <clients> + <name>62.40.123.130/32</name> + </clients> + </community> + <community> + <name>MdM53r6Sk</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.123.162/32</name> + </clients> + <clients> + <name>62.40.123.162/31</name> + </clients> + </community> + <community> + <name>S3cur1tyS3rv1cE</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.123.172/32</name> + </clients> + <clients> + <name>62.40.106.106/32</name> + </clients> + </community> + <community> + <name>1430-lknQWEmq</name> + <authorization>read-only</authorization> + <clients> + <name>93.187.162.62/32</name> + </clients> + <clients> + <name>62.40.119.32/32</name> + </clients> + <clients> + <name>37.26.173.2/32</name> + </clients> + </community> + <community> + <name>DeepF1eld</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.123.134/32</name> + </clients> + </community> + <community> + <name>k3nt1ktri@l2019</name> + <authorization>read-only</authorization> + <clients> + <name>193.177.128.0/22</name> + </clients> + </community> + <trap-options> + <source-address> + <address>62.40.97.1</address> + </source-address> + </trap-options> + <trap-group> + <name>space</name> + <targets> + <name>62.40.99.3</name> + </targets> + <targets> + <name>62.40.113.91</name> + </targets> + <targets> + <name>62.40.120.19</name> + </targets> + <targets> + <name>62.40.113.93</name> + </targets> + <targets> + <name>83.97.93.151</name> + </targets> + <targets> + <name>83.97.94.51</name> + </targets> + </trap-group> + <trap-group> + <name>geantnms</name> + <version>v2</version> + <categories> + <link/> + <routing/> + </categories> + <comment>/* test-dboard01.geant.net */</comment> + <targets> + <name>62.40.104.50</name> + </targets> + <comment>/* uat-dboard01.geant.net */</comment> + <targets> + <name>62.40.104.51</name> + </targets> + <comment>/* uat-dboard02.geant.net */</comment> + <targets> + <name>62.40.104.155</name> + </targets> + <comment>/* Trupti Dashboard Test VM */</comment> + <targets> + <name>62.40.104.53</name> + </targets> + <targets> + <name>62.40.114.3</name> + </targets> + <targets> + <name>62.40.114.2</name> + </targets> + <targets> + <name>62.40.114.18</name> + </targets> + <targets> + <name>62.40.114.19</name> + </targets> + <targets> + <name>83.97.92.238</name> + </targets> + <targets> + <name>83.97.92.239</name> + </targets> + <targets> + <name>83.97.92.228</name> + </targets> + <targets> + <name>83.97.93.53</name> + </targets> + <targets> + <name>83.97.93.151</name> + </targets> + <targets> + <name>83.97.94.51</name> + </targets> + </trap-group> + </snmp> + <forwarding-options> + <sampling> + <input> + <rate>300</rate> + </input> + <family> + <inet> + <output> + <flow-server> + <name>62.40.100.166</name> + <port>7710</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv4</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.100.194</name> + <port>7712</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv4</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.100.202</name> + <port>7712</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv4</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.106.182</name> + <port>7711</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv4</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.111.254</name> + <port>9000</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv4</template-name> + </template> + </version9> + </flow-server> + <interface> + <name>ms-4/0/0.0</name> + <source-address>62.40.97.1</source-address> + </interface> + </output> + </inet> + <inet6> + <output> + <flow-server> + <name>62.40.100.166</name> + <port>7710</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv6</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.100.194</name> + <port>7712</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv6</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.100.202</name> + <port>7712</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv6</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.106.182</name> + <port>7711</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv6</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.111.254</name> + <port>9000</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv6</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.120.91</name> + <port>7710</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>ipv6</template-name> + </template> + </version9> + </flow-server> + <interface> + <name>ms-4/0/0.1</name> + <source-address>62.40.97.1</source-address> + </interface> + </output> + </inet6> + <mpls> + <output> + <flow-server> + <name>62.40.100.166</name> + <port>7710</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>mpls</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.100.194</name> + <port>7712</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>mpls</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.100.202</name> + <port>7712</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>mpls</template-name> + </template> + </version9> + </flow-server> + <flow-server> + <name>62.40.106.182</name> + <port>7711</port> + <autonomous-system-type>peer</autonomous-system-type> + <no-local-dump/> + <source-address>62.40.97.1</source-address> + <version9> + <template> + <template-name>mpls</template-name> + </template> + </version9> + </flow-server> + <interface> + <name>ms-4/0/0.2</name> + <source-address>62.40.97.1</source-address> + </interface> + </output> + </mpls> + </family> + </sampling> + </forwarding-options> + <routing-options> + <nonstop-routing/> + <interface-routes> + <rib-group> + <inet>unicast-multicast</inet> + <inet6>unicast-multicastv6</inet6> + </rib-group> + </interface-routes> + <rib> + <name>inet6.0</name> + <static> + <route> + <name>2a02:4280:0:0f01:0:0:0:0071/128</name> + <next-hop>2001:798:1b:10aa::a</next-hop> + </route> + <route> + <name>0100::/64</name> + <discard/> + <no-readvertise/> + </route> + <route> + <name>::/0</name> + <next-hop>2001:798:1::fe</next-hop> + </route> + <route> + <name>2001:798::/32</name> + <discard/> + <community>20965:155</community> + <community>20965:65532</community> + <community>20965:65533</community> + <community>64700:65532</community> + <community>64700:65533</community> + <community>64700:65534</community> + </route> + </static> + </rib> + <rib> + <name>inetflow.0</name> + <maximum-prefixes> + <limit>100</limit> + <threshold>90</threshold> + </maximum-prefixes> + </rib> + <rib> + <name>inet6.2</name> + <static> + <route> + <name>2001:798::/32</name> + <reject/> + </route> + </static> + </rib> + <static> + <route> + <name>172.16.5.252/30</name> + <next-hop>172.16.18.254</next-hop> + <retain/> + <no-readvertise/> + </route> + <route> + <name>89.188.32.126/32</name> + <next-hop>62.40.125.210</next-hop> + </route> + <route> + <name>0.0.0.0/0</name> + <next-hop>83.97.88.225</next-hop> + </route> + <route> + <name>192.0.2.101/32</name> + <discard/> + <no-readvertise/> + </route> + <route> + <name>62.40.96.0/19</name> + <discard/> + <community>20965:155</community> + <community>20965:65532</community> + <community>20965:65533</community> + <community>64700:65532</community> + <community>64700:65533</community> + <community>64700:65534</community> + </route> + </static> + <rib-groups> + <name>unicast-multicast</name> + <export-rib>inet.0</export-rib> + <import-rib>inet.0</import-rib> + <import-rib>inet.2</import-rib> + </rib-groups> + <rib-groups> + <name>unicast-multicastv6</name> + <export-rib>inet6.0</export-rib> + <import-rib>inet6.0</import-rib> + <import-rib>inet6.2</import-rib> + </rib-groups> + <rib-groups> + <name>multicast</name> + <export-rib>inet.2</export-rib> + <import-rib>inet.2</import-rib> + </rib-groups> + <rib-groups> + <name>multicastv6</name> + <import-rib>inet6.2</import-rib> + </rib-groups> + <rib-groups> + <name>ias-to-geant-cls-rtbh</name> + <import-rib>IAS.inet.0</import-rib> + <import-rib>CLS.inet.0</import-rib> + <import-rib>inet.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>ias-to-geant-cls-rtbh6</name> + <import-rib>IAS.inet6.0</import-rib> + <import-rib>CLS.inet6.0</import-rib> + <import-rib>inet6.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>geant-to-ias-cls-rtbh</name> + <import-rib>inet.0</import-rib> + <import-rib>IAS.inet.0</import-rib> + <import-rib>CLS.inet.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>geant-to-ias-cls-rtbh6</name> + <import-rib>inet6.0</import-rib> + <import-rib>IAS.inet6.0</import-rib> + <import-rib>CLS.inet6.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>cls-to-geant-geant-rtbh</name> + <import-rib>CLS.inet.0</import-rib> + <import-rib>inet.0</import-rib> + <import-rib>IAS.inet.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <rib-groups> + <name>cls-to-geant-geant-rtbh6</name> + <import-rib>CLS.inet6.0</import-rib> + <import-rib>inet6.0</import-rib> + <import-rib>IAS.inet6.0</import-rib> + <import-policy>rtbh-policy</import-policy> + </rib-groups> + <router-id>62.40.97.1</router-id> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + <forwarding-table> + <export>dest-class-usage</export> + <export>source-class-usage</export> + </forwarding-table> + </routing-options> + <protocols> + <igmp> + <interface> + <name>all</name> + <disable/> + </interface> + <interface> + <name>dsc.0</name> + <version>3</version> + <static> + <group> + <name>232.223.222.1</name> + <source> + <name>193.17.9.3</name> + </source> + </group> + </static> + </interface> + </igmp> + <mld> + <interface> + <name>all</name> + <disable/> + </interface> + </mld> + <rsvp> + <interface> + <name>all</name> + </interface> + </rsvp> + <mpls> + <explicit-null/> + <ipv6-tunneling/> + <icmp-tunneling/> + <interface> + <name>all</name> + </interface> + </mpls> + <bgp> + <precision-timers/> + <path-selection> + <external-router-id/> + </path-selection> + <log-updown/> + <undocumented><drop-path-attributes>128</drop-path-attributes></undocumented> + <group> + <name>iGEANT</name> + <type>internal</type> + <local-address>62.40.97.1</local-address> + <import>rtbh-ibgp</import> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh</ribgroup-name> + </rib-group> + </unicast> + <flow> + <no-validate>accept-all-flowspec</no-validate> + </flow> + <any> + </any> + </inet> + <inet-vpn> + <unicast> + </unicast> + <flow> + </flow> + </inet-vpn> + <inet6-vpn> + <unicast> + </unicast> + </inet6-vpn> + <l2vpn> + <signaling> + </signaling> + </l2vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-to-iGEANT</export> + <neighbor> + <name>62.40.97.2</name> + <description>mx1.pra.cz.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.4</name> + <description>mx2.bra.sk.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.5</name> + <description>mx1.lon.uk.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.7</name> + <description>mx1.vie.at.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.10</name> + <description>mx1.poz.pl.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.11</name> + <description>mx1.ams.nl.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.12</name> + <description>mx1.fra.de.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.13</name> + <description>mx1.par.fr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.14</name> + <description>mx1.gen.ch.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.15</name> + <description>mx1.mil2.it.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.97.16</name> + <description>mx1.mad.es.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.1</name> + <description>mx1.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.2</name> + <description>mx2.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.4</name> + <description>mx2.rig.lv.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.5</name> + <description>mx2.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.6</name> + <description>mx1.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.8</name> + <description>mx2.zag.hr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.10</name> + <description>mx2.lju.si.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.16</name> + <description>mx1.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.17</name> + <description>mx2.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.20</name> + <description>mx2.bru.be.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.11</name> + <description>mx2.ath.gr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.19</name> + <description>mx1.buc.ro.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.21</name> + <description>mx1.sof.bg.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.26</name> + <description>mx1.ham.de.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.12</name> + <description>mx1.mar.fr.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.15</name> + <description>mx1.lon2.uk.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.3</name> + <description>mx1.dub.ie.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.25</name> + <description>mx1.dub2.ie.geant.net</description> + </neighbor> + <neighbor> + <name>62.40.96.39</name> + <description>mx1.ath2.gr.geant.net</description> + </neighbor> + </group> + <group> + <name>iGEANT6</name> + <type>internal</type> + <local-address>2001:798:1b:20ff::1</local-address> + <import>rtbh-ibgp</import> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh6</ribgroup-name> + </rib-group> + </unicast> + <any> + </any> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-to-iGEANT6</export> + <neighbor> + <name>2001:798:10:20ff::1</name> + <description>mx1.vie.at.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:14:20ff::1</name> + <description>mx1.fra.de.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:12:20ff::1</name> + <description>mx1.gen.ch.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:17:20ff::1</name> + <description>mx1.mad.es.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:23:20ff::1</name> + <description>mx1.poz.pl.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:13:20ff::1</name> + <description>mx1.pra.cz.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:18:20ff::3</name> + <description>mx1.par.fr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:22:20ff::3</name> + <description>mx1.ams.nl.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:33:20ff::2</name> + <description>mx2.bra.sk.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:19:20ff::1</name> + <description>mx2.ath.gr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:21:20ff::4</name> + <description>mx2.rig.lv.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:16:20ff::3</name> + <description>mx1.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:16:20ff::4</name> + <description>mx2.tal.ee.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:1f:20ff::3</name> + <description>mx2.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:1f:20ff::4</name> + <description>mx1.kau.lt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2d:20ff::2</name> + <description>mx2.zag.hr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2f:20ff::1</name> + <description>mx1.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2f:20ff::2</name> + <description>mx2.lis.pt.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2b:20ff::2</name> + <description>mx2.bru.be.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:32:20ff::2</name> + <description>mx2.lju.si.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:1e:20ff::3</name> + <description>mx1.mil2.it.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:28:20ff::1</name> + <description>mx1.lon.uk.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2b:10ff::3</name> + <description>mx1.buc.ro.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:2c:10ff::2</name> + <description>mx1.sof.bg.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::3</name> + <description>mx1.ham.de.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::4</name> + <description>mx1.mar.fr.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::5</name> + <description>mx1.lon2.uk.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::1</name> + <description>mx1.dub.ie.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::2</name> + <description>mx1.dub2.ie.geant.net</description> + </neighbor> + <neighbor> + <name>2001:798:aa:1::a</name> + <description>mx1.ath2.gr.geant.net</description> + </neighbor> + </group> + <group> + <name>eGEANT</name> + <type>external</type> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh</ribgroup-name> + </rib-group> + </unicast> + <multicast> + </multicast> + <any> + </any> + </inet> + </family> + <neighbor> + <name>62.40.125.178</name> + <description>-- Peering with AMRES --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-AMRES-nren</import> + <export>ps-BOGONS</export> + <export>ps-to-AMRES-nren</export> + <peer-as>13092</peer-as> + </neighbor> + <neighbor> + <name>62.40.124.14</name> + <description>-- Peering with CESNet Backup --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-CESNET-backup-nren</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-to-CESNET-backup-nren</export> + <peer-as>2852</peer-as> + </neighbor> + <neighbor> + <name>62.40.124.102</name> + <description>-- Peering with Hungarnet --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-HUNGARnet1-nren</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-to-HUNGARnet1-nren</export> + <remove-private> + </remove-private> + <peer-as>1955</peer-as> + </neighbor> + <neighbor> + <name>62.40.125.210</name> + <description>--Peering with MREN--</description> + <accept-remote-nexthop/> + <hold-time>180</hold-time> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-MREN-nren</import> + <export>ps-BOGONS</export> + <export>ps-to-MREN</export> + <peer-as>40981</peer-as> + </neighbor> + <neighbor> + <name>62.40.125.130</name> + <description>-- Peering with ULAKBIM AP --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-ULAKBIM-nren</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-to-ULAKBIM-nren</export> + <peer-as>8517</peer-as> + </neighbor> + <comment>/* See ticket 2016062734001014 for custom routes distribution */</comment> + <neighbor> + <name>62.40.125.34</name> + <description>--- Peering with GRENA EAP ---</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-GRENA-nren</import> + <export>ps-BOGONS</export> + <export>ps-to-GRENA-nren</export> + <peer-as>20545</peer-as> + </neighbor> + </group> + <group> + <name>eGEANT6</name> + <type>external</type> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>geant-to-ias-cls-rtbh6</ribgroup-name> + </rib-group> + </unicast> + <multicast> + </multicast> + <any> + </any> + </inet6> + </family> + <neighbor> + <name>2001:798:1b:10aa::2</name> + <description>-- IPv6 Peering with AMRES --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS</import> + <import>ps-from-AMRES-V6-nren</import> + <export>ps-BOGONS-V6</export> + <export>ps-to-AMRES-V6-nren</export> + <peer-as>13092</peer-as> + </neighbor> + <neighbor> + <name>2001:798:1b:10aa::1a</name> + <description>-- IPv6 Peering with CESnet Backup --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS-V6</import> + <import>ps-from-CESNET-V6-backup-nren</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-to-CESNET-V6-backup-nren</export> + <peer-as>2852</peer-as> + </neighbor> + <neighbor> + <name>2001:798:1b:10aa::6</name> + <description>-- IPv6 Peering with Hungarnet Primary --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS-V6</import> + <import>ps-from-HUNGARnet-V6-nren</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-to-HUNGARnet-V6-nren</export> + <peer-as>1955</peer-as> + </neighbor> + <neighbor> + <name>2001:798:1b:10aa::a</name> + <description> -- Peering with MREN --</description> + <accept-remote-nexthop/> + <hold-time>180</hold-time> + <out-delay>10</out-delay> + <import>ps-BOGONS-V6</import> + <import>ps-from-MREN-V6-nren</import> + <export>ps-BOGONS-V6</export> + <export>ps-to-MREN-V6-nren</export> + <peer-as>40981</peer-as> + <comment>/* To Stop continuous fluctuations on BGPv6 */</comment> + <tcp-mss>4096</tcp-mss> + </neighbor> + <neighbor> + <name>2001:798:2c:10aa::6</name> + <description>-- IPv6 Peering with ULAKBIM AP --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-BOGONS-V6</import> + <import>ps-from-ULAKBIM-V6-nren</import> + <authentication-key inactive="inactive">/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-to-ULAKBIM-V6-nren</export> + <peer-as>8517</peer-as> + </neighbor> + </group> + <group> + <name>TOOLS</name> + <type>internal</type> + <description>PEERING WITH TOOLS</description> + <local-address>62.40.97.1</local-address> + <neighbor> + <name>62.40.123.134</name> + <description>DEEPFIELD SERVER</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>PS_TO_DEEPFIELD</export> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>83.97.93.247</name> + <description>EARL Netflow/ISIS/BGP feed VM</description> + <hold-time>180</hold-time> + <passive/> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + <multicast> + </multicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>62.40.99.51</name> + <description>Packet Design Route Recorder VM LON2</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>193.177.129.61</name> + <description>Kentik EU</description> + <hold-time>720</hold-time> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + </unicast> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + </group> + <group> + <name>DUMMY_EBGP</name> + <type>external</type> + <description>Dummy group for stability; see XTAC TT#2016122634000229</description> + <local-address>62.40.97.1</local-address> + <family> + <inet> + <any> + </any> + </inet> + <inet-vpn> + <unicast> + </unicast> + </inet-vpn> + <inet6> + <any> + </any> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <cluster>62.40.97.1</cluster> + <peer-as>56902</peer-as> + <local-as> + <as-number>20965</as-number> + </local-as> + <neighbor> + <name>192.168.254.254</name> + <passive/> + <import>ps-deny-all</import> + <export>nhs-ibgp</export> + </neighbor> + </group> + <group> + <name>DUMMY_EBGP6</name> + <type>external</type> + <description>Dummy group for stability; see XTAC TT#2016122634000229</description> + <local-address>2001:798:1b:20ff::1</local-address> + <family> + <inet6> + <any> + </any> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <cluster>62.40.97.1</cluster> + <peer-as>56902</peer-as> + <local-as> + <as-number>20965</as-number> + </local-as> + <neighbor> + <name>100::1</name> + <passive/> + <import>ps-deny-all</import> + <export>nhs-ibgp</export> + </neighbor> + </group> + <group> + <name>20965-to-21320-v4</name> + <type>internal</type> + <description>20965-to-21320 BGP Peering IPv4</description> + <local-address>83.97.88.224</local-address> + <import>ps-deny-all</import> + <export>ps-20965-v4</export> + <neighbor> + <name>83.97.88.225</name> + <peer-as>20965</peer-as> + </neighbor> + </group> + <group> + <name>20965-to-21320-v6</name> + <type>internal</type> + <description>20965-to-21320 BGP Peering IPv6</description> + <local-address>2001:798:1::fd</local-address> + <import>ps-deny-all</import> + <export>ps-20965-v6</export> + <neighbor> + <name>2001:798:1::fe</name> + <peer-as>20965</peer-as> + </neighbor> + </group> + <group> + <name>TOOLSv6</name> + <type>internal</type> + <description>PEERING WITH TOOLS</description> + <local-address>2001:798:1b:20ff::1</local-address> + <neighbor> + <name>2001:798:bb:2::2</name> + <description>DEEPFIELD SERVER</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet6> + <unicast> + </unicast> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>PS_TO_DEEPFIELD</export> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>2001:798:3::1de</name> + <description>EARL Netflow/ISIS/BGP feed VM</description> + <hold-time>180</hold-time> + <import>ps-deny-all</import> + <family> + <inet6> + <unicast> + </unicast> + <multicast> + </multicast> + </inet6> + </family> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + <neighbor> + <name>2a0c:dec0:f100:1::179</name> + <description>Kentik EU</description> + <hold-time>720</hold-time> + <import>ps-deny-all</import> + <family> + <inet6> + <unicast> + </unicast> + <multicast> + </multicast> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <local-as> + <as-number>20965</as-number> + </local-as> + </neighbor> + </group> + <group> + <name>RTBH</name> + <type>external</type> + <family> + <inet> + <unicast> + </unicast> + </inet> + </family> + <neighbor> + <name>195.111.97.179</name> + <description>HUNGARNET_RTBH</description> + <multihop> + </multihop> + <local-address>62.40.124.101</local-address> + <out-delay>10</out-delay> + <import>PS_HUNGARNET_RTBH_IMPORT</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-deny-all</export> + <peer-as>1955</peer-as> + </neighbor> + </group> + <group> + <name>RTBH_V6</name> + <type>external</type> + <family> + <inet6> + <unicast> + </unicast> + </inet6> + </family> + <neighbor> + <name>2001:738::179:1</name> + <description>HUNGARNET_RTBH</description> + <multihop> + </multihop> + <local-address>2001:798:1b:10aa::5</local-address> + <out-delay>10</out-delay> + <import>PS_HUNGARNET_RTBH_V6_IMPORT</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-deny-all</export> + <peer-as>1955</peer-as> + </neighbor> + </group> + </bgp> + <isis> + <rib-group> + <inet>unicast-multicast</inet> + <inet6>unicast-multicastv6</inet6> + </rib-group> + <source-packet-routing> + <node-segment> + <ipv4-index>4701</ipv4-index> + <ipv6-index>6701</ipv6-index> + <index-range>8192</index-range> + </node-segment> + </source-packet-routing> + <level> + <name>1</name> + <disable/> + </level> + <level> + <name>2</name> + <wide-metrics-only/> + </level> + <interface> + <name>xe-5/3/1.0</name> + <disable/> + </interface> + <interface> + <name>ae0.0</name> + <point-to-point/> + <bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection> + <level> + <name>2</name> + <metric>500</metric> + </level> + </interface> + <interface> + <name>ae1.0</name> + <point-to-point/> + <bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection> + <level> + <name>2</name> + <metric>100</metric> + </level> + </interface> + <interface> + <name>ae2.0</name> + <point-to-point/> + <bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection> + <level> + <name>2</name> + <metric>500</metric> + </level> + </interface> + <interface> + <name>ae3.0</name> + <point-to-point/> + <bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection> + <level> + <name>2</name> + <metric>75</metric> + </level> + </interface> + <interface> + <name>ae4.0</name> + <point-to-point/> + <bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection> + <level> + <name>2</name> + <metric>500</metric> + </level> + </interface> + <interface> + <name>ae6.0</name> + <point-to-point/> + <bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection> + <level> + <name>2</name> + <metric>100</metric> + </level> + </interface> + <interface> + <name>ae7.0</name> + <point-to-point/> + <bfd-liveness-detection> + <minimum-interval>100</minimum-interval> + </bfd-liveness-detection> + <level> + <name>2</name> + <metric>100</metric> + </level> + </interface> + <interface> + <name>all</name> + <passive> + </passive> + </interface> + <interface> + <name>fxp0.0</name> + <disable/> + </interface> + </isis> + <msdp> + <rib-group> + <ribgroup-name>multicast</ribgroup-name> + </rib-group> + <active-source-limit> + <maximum>20000</maximum> + <threshold>20000</threshold> + <log-interval>32700</log-interval> + </active-source-limit> + <local-address>62.40.97.1</local-address> + <source> + <name>0.0.0.0/0</name> + <active-source-limit> + <maximum>1000</maximum> + <threshold>900</threshold> + <log-interval>32700</log-interval> + </active-source-limit> + </source> + <group> + <name>internal_msdp</name> + <mode>mesh-group</mode> + <peer> + <name>62.40.96.1</name> + </peer> + <peer> + <name>62.40.96.2</name> + </peer> + <peer> + <name>62.40.96.4</name> + </peer> + <peer> + <name>62.40.96.5</name> + </peer> + <peer> + <name>62.40.96.6</name> + </peer> + <peer> + <name>62.40.96.8</name> + </peer> + <peer> + <name>62.40.96.10</name> + </peer> + <peer> + <name>62.40.96.16</name> + </peer> + <peer> + <name>62.40.96.17</name> + </peer> + <peer> + <name>62.40.96.20</name> + </peer> + <peer> + <name>62.40.97.2</name> + </peer> + <peer> + <name>62.40.97.4</name> + </peer> + <peer> + <name>62.40.97.5</name> + </peer> + <peer> + <name>62.40.97.7</name> + </peer> + <peer> + <name>62.40.97.10</name> + </peer> + <peer> + <name>62.40.97.11</name> + </peer> + <peer> + <name>62.40.97.12</name> + </peer> + <peer> + <name>62.40.97.13</name> + </peer> + <peer> + <name>62.40.97.14</name> + </peer> + <peer> + <name>62.40.97.16</name> + </peer> + <peer> + <name>62.40.97.15</name> + </peer> + <peer> + <name>62.40.96.11</name> + </peer> + <peer> + <name>62.40.96.19</name> + </peer> + <peer> + <name>62.40.96.21</name> + </peer> + <peer> + <name>62.40.96.26</name> + </peer> + <peer> + <name>62.40.96.25</name> + </peer> + <peer> + <name>62.40.96.3</name> + </peer> + <peer> + <name>62.40.96.12</name> + </peer> + <peer> + <name>62.40.96.15</name> + </peer> + <peer> + <name>62.40.96.39</name> + </peer> + </group> + <group> + <name>external_msdp</name> + <export>Bogon-Sources</export> + <export>ASM-Allow</export> + <import>Bogon-Sources</import> + <import>ASM-Allow</import> + <comment>/* Peering with AMRES */</comment> + <peer> + <name>147.91.0.129</name> + <local-address>62.40.125.177</local-address> + </peer> + <peer> + <name>62.40.124.102</name> + <local-address>62.40.124.101</local-address> + </peer> + <peer> + <name>62.40.125.130</name> + <local-address>62.40.125.129</local-address> + </peer> + <comment>/* MSDP Peering with LEvel3 */</comment> + <peer> + <name>212.113.0.9</name> + <local-address>62.40.97.1</local-address> + </peer> + <comment>/* MSDP Peering with LEvel3 */</comment> + <peer> + <name>212.113.0.10</name> + <local-address>62.40.97.1</local-address> + </peer> + <peer> + <name>62.40.125.34</name> + <local-address>62.40.125.33</local-address> + </peer> + </group> + </msdp> + <ldp> + <track-igp-metric/> + <deaggregate/> + <interface> + <name>ae0.0</name> + </interface> + <interface> + <name>ae1.0</name> + </interface> + <interface> + <name>ae2.0</name> + </interface> + <interface> + <name>ae3.0</name> + </interface> + <interface> + <name>ae4.0</name> + </interface> + <interface> + <name>ae6.0</name> + </interface> + <interface> + <name>ae7.0</name> + </interface> + <interface> + <name>lo0.0</name> + </interface> + <neighbor> + <name>62.40.99.50</name> + </neighbor> + </ldp> + <pim> + <rib-group> + <inet>multicast</inet> + <inet6>multicastv6</inet6> + </rib-group> + <rp> + <bootstrap> + <family> + <inet6> + <priority>1</priority> + <import>pim-import</import> + <export>pim-export</export> + </inet6> + </family> + </bootstrap> + <embedded-rp> + <group-ranges> + <name>ff7e::/16</name> + </group-ranges> + </embedded-rp> + <static> + <address> + <name>10.10.10.10</name> + </address> + <address> + <name>2001:660:3007:300:1::</name> + <group-ranges> + <name>ff0e::/16</name> + </group-ranges> + <group-ranges> + <name>ff1e::/16</name> + </group-ranges> + <group-ranges> + <name>ff3e::/16</name> + </group-ranges> + </address> + <address> + <name>2001:798:2016:10ff::3</name> + <group-ranges> + <name>ff08::1/128</name> + </group-ranges> + </address> + </static> + </rp> + <interface> + <name>all</name> + <mode>sparse</mode> + <version>2</version> + </interface> + <interface> + <name>fxp0.0</name> + <disable/> + </interface> + </pim> + <l2circuit> + <traceoptions> + <file> + <filename>l2circuits</filename> + <size>2m</size> + <files>10</files> + <world-readable/> + </file> + <flag> + <name>connections</name> + </flag> + <flag> + <name>error</name> + </flag> + </traceoptions> + <neighbor> + <name>62.40.97.7</name> + <interface> + <name>xe-5/2/0.600</name> + <virtual-circuit-id>2</virtual-circuit-id> + <no-control-word/> + <mtu>9100</mtu> + </interface> + </neighbor> + <neighbor inactive="inactive"> + <name>62.40.97.2</name> + <interface> + <name>ae13.600</name> + <virtual-circuit-id>3</virtual-circuit-id> + <no-control-word/> + <mtu>9100</mtu> + </interface> + </neighbor> + <neighbor> + <name>62.40.97.3</name> + </neighbor> + <neighbor> + <name>62.40.97.5</name> + </neighbor> + <neighbor> + <name>62.40.97.11</name> + </neighbor> + <neighbor> + <name>62.40.97.14</name> + <interface> + <name>ae10.909</name> + <virtual-circuit-id>12012</virtual-circuit-id> + <mtu>9100</mtu> + </interface> + </neighbor> + <neighbor> + <name>62.40.97.12</name> + <interface> + <name>ge-0/2/5.0</name> + <virtual-circuit-id>34181</virtual-circuit-id> + <mtu>9100</mtu> + </interface> + </neighbor> + <neighbor> + <name>62.40.97.9</name> + </neighbor> + <neighbor> + <name>62.40.97.10</name> + </neighbor> + <neighbor> + <name>62.40.97.13</name> + </neighbor> + <local-switching> + <interface> + <name>ge-0/2/4.0</name> + <end-interface> + <interface>ae12.210</interface> + </end-interface> + <ignore-mtu-mismatch/> + </interface> + </local-switching> + </l2circuit> + <neighbor-discovery> + <onlink-subnet-only/> + </neighbor-discovery> + <oam> + <ethernet> + <link-fault-management> + <traceoptions> + <file> + <filename>lfmd_traceopts</filename> + <size>4000000</size> + <files>10</files> + </file> + <flag> + <name>all</name> + </flag> + </traceoptions> + <action-profile> + <name>log-event-frame-error</name> + <event> + <link-event-rate> + <frame-error>1</frame-error> + </link-event-rate> + </event> + <action> + <syslog/> + </action> + </action-profile> + <action-profile> + <name>log-event-frame-period</name> + <event> + <link-event-rate> + <frame-period>1</frame-period> + </link-event-rate> + </event> + <action> + <syslog/> + </action> + </action-profile> + <action-profile> + <name>log-event-symbol-period</name> + <event> + <link-event-rate> + <symbol-period>1</symbol-period> + </link-event-rate> + </event> + <action> + <syslog/> + </action> + </action-profile> + <interface> + <name>et-10/0/0</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>et-11/0/0</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-0/0/0</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-0/0/1</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-0/1/1</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/0/1</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/0/2</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/1/1</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/1/2</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/1/4</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/1/7</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/2/3</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/2/4</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/2/5</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + <interface> + <name>xe-5/2/7</name> + <apply-action-profile>log-event-frame-error</apply-action-profile> + <apply-action-profile>log-event-frame-period</apply-action-profile> + <apply-action-profile>log-event-symbol-period</apply-action-profile> + <pdu-interval>1000</pdu-interval> + <link-discovery>active</link-discovery> + <pdu-threshold>3</pdu-threshold> + <negotiation-options> + <allow-remote-loopback/> + </negotiation-options> + <event-thresholds> + <symbol-period>1</symbol-period> + <frame-error>1</frame-error> + <frame-period>1</frame-period> + </event-thresholds> + </interface> + </link-fault-management> + <connectivity-fault-management> + <performance-monitoring> + <hardware-assisted-timestamping/> + <delegate-server-processing/> + <hardware-assisted-keepalives>enable</hardware-assisted-keepalives> + </performance-monitoring> + <maintenance-domain> + <name>GEANT</name> + <level>0</level> + <maintenance-association> + <name>GEANT-BB-mx1.bud.hu-to-mx2.bra.sk</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8004</name> + <interface> + <interface-name>ae0.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8024</name> + </remote-mep> + </mep> + </maintenance-association> + <maintenance-association> + <name>GEANT-BB-mx1.bud.hu-to-mx2.zag.hr</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8004</name> + <interface> + <interface-name>ae1.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8031</name> + </remote-mep> + </mep> + </maintenance-association> + <maintenance-association> + <name>GEANT-BB-mx1.bud.hu-to-mx2.lju.si</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8004</name> + <interface> + <interface-name>ae2.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8028</name> + </remote-mep> + </mep> + </maintenance-association> + <maintenance-association> + <name>GEANT-BB-mx1.bud.hu-to-mx1.vie.at</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8004</name> + <interface> + <interface-name>ae3.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8022</name> + </remote-mep> + </mep> + </maintenance-association> + <maintenance-association> + <name>GEANT-BB-mx1.buc.ro-to-mx1.bud.hu</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8004</name> + <interface> + <interface-name>ae4.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8003</name> + </remote-mep> + </mep> + </maintenance-association> + <maintenance-association> + <name>GEANT-BB-mx1.bud.hu-to-mx1.fra.de</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8004</name> + <interface> + <interface-name>ae6.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8007</name> + </remote-mep> + </mep> + </maintenance-association> + <maintenance-association> + <name>GEANT-BB-mx1.bud.hu-to-mx1.pra.cz</name> + <continuity-check> + <interval>1s</interval> + </continuity-check> + <mep> + <name>8004</name> + <interface> + <interface-name>ae7.0</interface-name> + </interface> + <direction>down</direction> + <auto-discovery/> + <remote-mep> + <name>8019</name> + </remote-mep> + </mep> + </maintenance-association> + </maintenance-domain> + </connectivity-fault-management> + </ethernet> + <gre-tunnel> + </gre-tunnel> + </oam> + <lldp> + <interface> + <name>all</name> + <disable/> + </interface> + <interface> + <name>xe-5/1/2</name> + </interface> + <interface> + <name>xe-5/1/1</name> + </interface> + <interface> + <name>xe-0/1/1</name> + </interface> + <interface> + <name>xe-5/0/1</name> + </interface> + <interface> + <name>xe-4/2/3</name> + </interface> + <interface> + <name>xe-5/0/2</name> + </interface> + <interface> + <name>xe-5/0/7</name> + </interface> + <interface> + <name>xe-5/2/4</name> + </interface> + <interface> + <name>xe-5/2/7</name> + </interface> + <interface> + <name>et-11/0/0</name> + </interface> + <interface> + <name>xe-5/2/3</name> + </interface> + <interface> + <name>xe-5/2/5</name> + </interface> + <interface> + <name>et-10/0/0</name> + </interface> + <interface> + <name>xe-0/0/0</name> + </interface> + <interface> + <name>xe-0/0/1</name> + </interface> + <interface> + <name>xe-5/1/4</name> + </interface> + <interface> + <name>xe-5/1/7</name> + </interface> + <interface> + <name>ge-0/3/6</name> + </interface> + </lldp> + </protocols> + <policy-options> + <prefix-list> + <name>geant-address-space</name> + <prefix-list-item> + <name>62.40.96.0/19</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-address-space-short</name> + <prefix-list-item> + <name>62.40.96.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.98.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.102.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.40/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.120/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.16/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.27/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.109.16/29</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.112.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.116.0/23</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-routers</name> + <prefix-list-item> + <name>62.40.96.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geantncc-address-space</name> + <comment>/* NCC DR VPN */</comment> + <prefix-list-item> + <name>62.40.108.192/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.125.250/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>pref-list-router-access</name> + <prefix-list-item> + <name>62.40.106.232/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.72/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.102/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.197.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.227.249/32</name> + </prefix-list-item> + <prefix-list-item> + <name>130.104.230.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>139.165.223.48/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.7.100/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>ncc-oob-address-space</name> + <prefix-list-item> + <name>172.16.5.252/30</name> + </prefix-list-item> + <prefix-list-item> + <name>172.16.14.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>space-local</name> + <prefix-list-item> + <name>127.0.0.1/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>cnis-server</name> + <prefix-list-item> + <name>62.40.122.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.130/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project6</name> + <prefix-list-item> + <name>2001:798:1:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2:1::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:0002:284d::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2:284d::/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2:284d::60/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::103/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::104/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::10a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::10b/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::147/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::151/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:2::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:3::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:3::d/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:4:5::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:11::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:96::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:aa::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:aa::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:14:c8::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:18:96::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:18:99::/64</name> + </prefix-list-item> + <comment>/* HADES */</comment> + <prefix-list-item> + <name>2001:798:22:16::0/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:50::11/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::7/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:99::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::16/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::1a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::1b/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::1c/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::22/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::26/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::2a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::2e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::32/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::33/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::36/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::38/126</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::3a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::3e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::42/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::46/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::4a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::4e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::52/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::56/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::5a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::5e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::62/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::66/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::6a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::6e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::72/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::76/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::7a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::7e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::82/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::86/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::8a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::8e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::92/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::96/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::9a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::9e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::a2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::a6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::aa/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::ae/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::b2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::ba/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::be/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::c2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::ce/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:5::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:c::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:c::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:d::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1a::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1b::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1e::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1e::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1e::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:23::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:25::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:25::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2a::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2a::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2b::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2b::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2e::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2e::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:33::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:34::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:34::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:34::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:35::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:36::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:37::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:38::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:39::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:3a::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:41::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:42::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:43::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:49::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:4d::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:3::0/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:7::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:10::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::52/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::56/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::5a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::5e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::62/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::66/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::6a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::6e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::72/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:111:1::76/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2001::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2002::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:2012:47::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:28::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f27a:2d::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f99a:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f9a1:10::/64</name> + </prefix-list-item> + <comment>/* LHCONE */</comment> + <prefix-list-item> + <name>2001:798:f9a2:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f9a3:28::0/125</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:28::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:2d01::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa78:2d02::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:28::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:2d01::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fa79:2d02::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:10::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:10::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:12::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:12::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:13::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:13::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:14::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:14::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:16::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:16::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:17::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:17::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:18::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:18::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:19::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:19::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1b::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1b::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1e::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1e::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:1f::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:21::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:21::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:22::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:22::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:23::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:23::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:28::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:28::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2b::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2b::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2c::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:fc00:2c::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff10:a5::/64</name> + </prefix-list-item> + <comment>/* SHAREPOINT */</comment> + <prefix-list-item> + <name>2001:0798:ff10:00a5::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:11::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff23:28::2/128</name> + </prefix-list-item> + <comment>/* TT#2016083134000549 pS LS testing instance access on port 8090 */</comment> + <prefix-list-item> + <name>2001:798:ff32:2e::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff98:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9b:18::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9b:22::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9d:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9e:10::2/128</name> + </prefix-list-item> + <comment>/* Site Archives */</comment> + <prefix-list-item> + <name>2001:798:ff9e:14::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9e:28::/64</name> + </prefix-list-item> + <comment>/* HADES */</comment> + <prefix-list-item> + <name>2001:798:ffa4:14::0/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:1::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:7::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b30:1000:19::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2620:0:6b0::26e5:4207/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project</name> + <prefix-list-item> + <name>38.229.66.20/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.8/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.42/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.51/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.106/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.136/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.192/26</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.215/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.161/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.168/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.208/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.0/29</name> + </prefix-list-item> + <comment>/* GÉANT Intermapper Server */</comment> + <prefix-list-item> + <name>62.40.104.8/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.21/32</name> + </prefix-list-item> + <comment>/* tools.geant.net */</comment> + <prefix-list-item> + <name>62.40.104.32/29</name> + </prefix-list-item> + <comment>/* Primary Dashboard */</comment> + <prefix-list-item> + <name>62.40.104.51/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.72/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.76/30</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.80/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.88/29</name> + </prefix-list-item> + <comment>/* OC Server */</comment> + <prefix-list-item> + <name>62.40.104.98/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.104/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.112/29</name> + </prefix-list-item> + <comment>/* cbt.geant.net */</comment> + <prefix-list-item> + <name>62.40.104.132/31</name> + </prefix-list-item> + <comment>/* mail.geant.net */</comment> + <prefix-list-item> + <name>62.40.104.134/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.136/29</name> + </prefix-list-item> + <comment>/* Backup Dashboard */</comment> + <prefix-list-item> + <name>62.40.104.155/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.168/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.176/30</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.180/30</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.184/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.192/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.197/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.199/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.202/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.205/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.207/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.212/32</name> + </prefix-list-item> + <comment>/* LHCONE */</comment> + <prefix-list-item> + <name>62.40.104.224/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.225/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.227/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.105.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.3/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.32/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.34/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.35/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.42/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.63/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.67/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.68/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.80/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.83/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.90/32</name> + </prefix-list-item> + <comment>/* Netflow Auditor */</comment> + <prefix-list-item> + <name>62.40.106.104/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.112/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.120/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.131/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.133/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.135/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.137/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.145/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.147/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.149/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.151/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.153/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.155/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.157/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.159/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.161/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.165/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.167/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.169/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.171/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.173/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.175/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.177/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.181/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.183/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.185/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.189/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.191/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.195/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.197/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.199/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.201/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.240/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.251/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.255/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.198/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.206/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.214/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.222/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.230/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.246/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.248/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.50/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.58/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.98/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.140/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.192/26</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.0/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.32/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.64/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.96/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.128/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.112.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.58/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.59/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.60/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.88/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.104/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.115/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.157/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.166/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.167/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.168/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.3/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.19/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.35/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.37/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.39/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.43/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.47/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.51/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.53/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.55/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.59/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.63/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.67/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.69/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.71/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.75/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.77/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.79/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.83/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.85/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.87/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.99/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.103/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.107/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.108/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.130/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.138/32</name> + </prefix-list-item> + <comment>/* requested Massimiliano Adamo */</comment> + <prefix-list-item> + <name>62.40.114.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.162/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.164/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.170/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.176/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.184/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.192/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.208/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.224/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.232/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.240/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.46/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.107/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.111/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.156/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.74/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.82/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.126/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.153/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.48/29</name> + </prefix-list-item> + <comment>/* TT#2016083134000549 pS LS testing instance access on port 8090 */</comment> + <prefix-list-item> + <name>62.40.120.50/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.66/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.67/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.240/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.92/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.110/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.201/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.92/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.134/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.142/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.149/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.151/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.218/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.234/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.235/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.242/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.125.254/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.155/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.171/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.187/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.189/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.191/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.195/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.197/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.127.32/31</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.88.190/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.89.64/26</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.89.128/26</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.239/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.245/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.246/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.51/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.140.82/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-address-space-V6</name> + <prefix-list-item> + <name>2001:798::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project-interfaces</name> + <prefix-list-item> + <name>62.40.100.160/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.162/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.169/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.209/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.20/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.224/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.60/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.62/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.113/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.121/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.174/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.178/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.213/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.5/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.89/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.56/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.102/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.177/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.185/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.209/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.225/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.233/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.241/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.5/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.13/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.37/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.53/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.61/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.69/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.77/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.105/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.241/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.73/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.81/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.89/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.97/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.105/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.113/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.121/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.145/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.153/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.169/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.185/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.193/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.148/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.150/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.209/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.217/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.225/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.233/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.241/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.249/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.9/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>external-project-interfaces6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::b9/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::bd/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::c1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:2::cd/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:5::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:d::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:33::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:35::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:36::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:37::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:38::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:39::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:3a::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:41::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:42::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:49::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:3::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:dd:7::1/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geantnoc-address-space6</name> + </prefix-list> + <prefix-list> + <name>bogons-list6</name> + <prefix-list-item> + <name>::/8</name> + </prefix-list-item> + <prefix-list-item> + <name>100::/8</name> + </prefix-list-item> + <prefix-list-item> + <name>200::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>400::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>600::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>800::/5</name> + </prefix-list-item> + <prefix-list-item> + <name>1000::/4</name> + </prefix-list-item> + <prefix-list-item> + <name>2000::/16</name> + </prefix-list-item> + <prefix-list-item> + <name>3fff::/16</name> + </prefix-list-item> + <prefix-list-item> + <name>4000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>6000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>8000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>a000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>c000::/3</name> + </prefix-list-item> + <prefix-list-item> + <name>e000::/4</name> + </prefix-list-item> + <prefix-list-item> + <name>f000::/5</name> + </prefix-list-item> + <prefix-list-item> + <name>f800::/6</name> + </prefix-list-item> + <prefix-list-item> + <name>fc00::/7</name> + </prefix-list-item> + <prefix-list-item> + <name>fe00::/9</name> + </prefix-list-item> + <prefix-list-item> + <name>fec0::/10</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>bogons-list</name> + <prefix-list-item> + <name>0.0.0.0/8</name> + </prefix-list-item> + <prefix-list-item> + <name>10.0.0.0/8</name> + </prefix-list-item> + <prefix-list-item> + <name>100.64.0.0/10</name> + </prefix-list-item> + <prefix-list-item> + <name>127.0.0.0/8</name> + </prefix-list-item> + <prefix-list-item> + <name>169.254.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>172.16.0.0/12</name> + </prefix-list-item> + <prefix-list-item> + <name>192.0.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.0.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.168.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>198.18.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>198.51.100.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>203.0.113.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>224.0.0.0/3</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>INTERNAL-address-space</name> + <prefix-list-item> + <name>62.40.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>EXTERNAL-address-space</name> + <prefix-list-item> + <name>62.40.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.126.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>Infinera-address-space</name> + <prefix-list-item> + <name>61.12.38.243/32</name> + </prefix-list-item> + <comment>/* laptop.rt1.ams.nl.geant.net */</comment> + <prefix-list-item> + <name>62.40.123.2/32</name> + </prefix-list-item> + <comment>/* esa1.infinera.iphmx.com */</comment> + <prefix-list-item> + <name>68.232.131.211/32</name> + </prefix-list-item> + <comment>/* esa2.infinera.iphmx.com */</comment> + <prefix-list-item> + <name>68.232.137.62/32</name> + </prefix-list-item> + <prefix-list-item> + <name>79.36.208.252/32</name> + </prefix-list-item> + <prefix-list-item> + <name>79.43.236.65/32</name> + </prefix-list-item> + <prefix-list-item> + <name>80.181.224.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>82.30.3.171/32</name> + </prefix-list-item> + <prefix-list-item> + <name>82.53.162.144/32</name> + </prefix-list-item> + <prefix-list-item> + <name>82.57.172.98/32</name> + </prefix-list-item> + <prefix-list-item> + <name>86.5.158.53/32</name> + </prefix-list-item> + <comment>/* cpc13-swin15-2-0-cust158.3-1.cable.virginm.net */</comment> + <prefix-list-item> + <name>86.26.204.159/32</name> + </prefix-list-item> + <comment>/* cpc5-rdng20-2-0-cust488.15-3.cable.virginm.net */</comment> + <prefix-list-item> + <name>86.28.111.233/32</name> + </prefix-list-item> + <prefix-list-item> + <name>86.142.182.121/32</name> + </prefix-list-item> + <prefix-list-item> + <name>87.6.225.113/32</name> + </prefix-list-item> + <comment>/* host90-152-38-170.ipv4.regusnet.com */</comment> + <prefix-list-item> + <name>90.152.38.170/32</name> + </prefix-list-item> + <prefix-list-item> + <name>95.144.147.56/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.178.153.169/32</name> + </prefix-list-item> + <comment>/* Infinera's London Office */</comment> + <prefix-list-item> + <name>195.110.76.131/32</name> + </prefix-list-item> + <prefix-list-item> + <name>206.205.90.140/32</name> + </prefix-list-item> + <prefix-list-item> + <name>217.33.229.50/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>Infinera-DNA-servers</name> + <comment>/* Frankfurt DNA Server */</comment> + <prefix-list-item> + <name>62.40.99.106/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.110/32</name> + </prefix-list-item> + <comment>/* London DNA Server */</comment> + <prefix-list-item> + <name>62.40.99.114/32</name> + </prefix-list-item> + <comment>/* OTSv VM in LAB - Guy Roberts */</comment> + <prefix-list-item> + <name>62.40.113.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.2/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>NASA-prefixes</name> + <prefix-list-item> + <name>128.102.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>128.154.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>128.156.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>128.157.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>128.158.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>128.159.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>128.183.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>128.217.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>129.99.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>129.164.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>129.165.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>130.134.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>130.135.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>130.167.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>131.110.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>131.182.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>134.12.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>138.115.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>139.88.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>139.169.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>140.169.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>143.232.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>146.58.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>146.154.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>148.114.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>150.144.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>156.68.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>157.132.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>158.154.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>161.40.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>163.205.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>163.206.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>169.154.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>192.5.41.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.5.63.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.31.241.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.42.70.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.52.83.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.52.85.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.52.86.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.52.88.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.52.90.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.55.90.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>192.58.19.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.58.21.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.67.83.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.67.107.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.67.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.67.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.67.113.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.67.118.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.68.52.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.68.162.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.70.125.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.70.244.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.70.249.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.27.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.30.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.31.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.32.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.33.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.36.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.39.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.40.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.41.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.42.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.43.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.44.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.45.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.77.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.77.80.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>192.83.252.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.84.8.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.92.90.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.92.168.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.94.65.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.100.9.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.100.12.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.100.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.101.148.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.102.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.102.219.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.190.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.191.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.192.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.193.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.196.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.3.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.6.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.10.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.12.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.22.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.223.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.238.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.112.239.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.119.135.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.124.20.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.138.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.138.172.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.104.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.107.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.130.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.131.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.135.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.138.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.140.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.141.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.142.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.146.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.150.27.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.150.28.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.150.29.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.150.32.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>192.150.224.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.159.138.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.160.74.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.160.78.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.188.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.203.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.225.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>192.243.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>192.243.16.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.23.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.48.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.56.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.57.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.9.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>198.10.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>198.17.71.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.17.72.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.17.73.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.27.38.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.27.48.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.27.54.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.116.0.0/14</name> + </prefix-list-item> + <prefix-list-item> + <name>198.120.0.0/14</name> + </prefix-list-item> + <prefix-list-item> + <name>198.182.16.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.182.24.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.182.25.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.182.26.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.182.28.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>198.182.30.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>199.4.250.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>199.191.37.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>204.89.132.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>204.145.215.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>204.152.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>204.152.109.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-IM-backup</name> + <prefix-list-item> + <name>62.40.115.82/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.82/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.50/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.195/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-AMRES</name> + <prefix-list-item> + <name>78.28.128.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>91.187.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>91.187.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>91.187.144.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.0.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.8.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.176.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>160.99.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>160.99.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>160.99.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>185.181.68.0/22</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-AMRES-v6</name> + <prefix-list-item> + <name>2001:67c:3ac::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4170::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-CESnet</name> + <prefix-list-item> + <name>5.172.184.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>5.172.190.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>5.201.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>5.201.0.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>23.128.24.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>23.128.25.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>23.128.25.240/28</name> + </prefix-list-item> + <prefix-list-item> + <name>27.0.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>27.50.0.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>31.25.248.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>31.131.48.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>31.133.80.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>31.193.96.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>37.128.152.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>39.0.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>46.30.88.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>46.30.88.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>46.30.92.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>46.227.172.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>46.239.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>62.3.160.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>62.93.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>62.108.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>62.108.176.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.128.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.129.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.130.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.131.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.132.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.133.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.135.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.136.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.137.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.138.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.139.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.140.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.141.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.142.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.143.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.144.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.145.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.146.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.147.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.148.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.149.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.150.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.151.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.152.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.153.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.154.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.155.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.156.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.157.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.159.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.160.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.160.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.161.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.162.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.163.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.164.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.165.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.166.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.167.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.168.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.169.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.170.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.171.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.172.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.173.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.174.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.175.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.176.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.177.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.178.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.179.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.180.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.181.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.182.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.183.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.184.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.185.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.186.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.187.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.188.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.189.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.190.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.191.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.192.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.193.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.194.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.195.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.196.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.197.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.198.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.200.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.201.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.202.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.203.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.204.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.205.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.206.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.207.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.208.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.209.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.210.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.211.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.212.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.213.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.214.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.215.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.216.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.217.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.218.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.219.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.220.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.221.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.222.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.223.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.224.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.225.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.226.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.227.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.228.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.229.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.231.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.232.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.233.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.234.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.235.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.236.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.237.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.238.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.239.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.240.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.241.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.242.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.243.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.244.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.245.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.246.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.247.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.248.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.249.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.250.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.251.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.252.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.253.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.254.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.47.255.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.80.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>78.41.144.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>78.41.144.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.41.145.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.41.148.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.41.149.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.41.150.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.104.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>78.104.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>78.104.68.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>78.104.72.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.104.145.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.104.175.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>78.128.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.104.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.104.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.105.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.106.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.107.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.108.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.170.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.160.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.160.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.161.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.162.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.163.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.164.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.165.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.166.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.167.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.168.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.168.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.169.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.170.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.170.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.171.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.172.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.173.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.174.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.175.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.6.176.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>81.6.184.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>81.6.187.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.6.188.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>81.26.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>81.26.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>81.91.164.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.161.112.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>82.139.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>82.139.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>82.139.144.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>82.139.152.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>82.139.168.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>82.139.176.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>82.145.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>82.146.224.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.32.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.32.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.33.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.34.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.36.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.37.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.38.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.136.39.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.230.64.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>83.230.94.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.230.96.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>83.230.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>83.230.118.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>83.230.123.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.65.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.66.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.67.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.68.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.69.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.70.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.71.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.72.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.73.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.74.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.75.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.76.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.77.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.78.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.79.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.80.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.81.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.82.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.83.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.84.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.85.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.86.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.87.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.88.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.89.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.90.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.91.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.92.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.93.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.94.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>84.205.95.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.31.243.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.158.224.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>86.49.91.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>87.246.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>87.246.240.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>89.106.208.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>89.188.196.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>89.188.200.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>89.188.204.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>89.188.208.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>89.188.221.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>89.191.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>91.199.203.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.202.128.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>91.208.94.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.208.95.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.208.138.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.209.20.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.209.141.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.210.48.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.210.49.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.210.50.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.210.51.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.213.170.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.216.239.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.217.142.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.218.164.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>91.220.17.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.220.103.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.220.201.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.221.46.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>91.221.46.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.221.47.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.223.241.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.228.113.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.228.204.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.229.57.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.230.222.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>91.230.222.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.230.223.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.233.191.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.234.40.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>91.235.216.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>91.237.67.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.125.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.125.120.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.144.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.146.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.147.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.148.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.149.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.150.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.151.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>94.113.244.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.80.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.80.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.81.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.82.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.83.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.84.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.85.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.86.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.130.87.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.131.192.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>95.131.196.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>95.131.198.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>95.131.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>103.0.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>103.1.0.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>103.1.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>106.0.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>109.69.88.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>128.130.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>129.27.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>130.180.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>131.130.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>137.208.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>137.208.250.10/32</name> + </prefix-list-item> + <prefix-list-item> + <name>138.22.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>138.232.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>140.78.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>141.201.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>141.203.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>141.244.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>143.50.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>143.130.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>143.205.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>143.224.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>144.65.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>145.244.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>146.102.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.32.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>147.125.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.175.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.213.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.228.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.128.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.224.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.240.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.240.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>147.229.242.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>147.230.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>147.232.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.251.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.11.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.116.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.246.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>148.81.248.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>149.148.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>149.156.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>150.254.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>150.254.236.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>153.19.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>155.158.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>156.17.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>157.158.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>157.177.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>158.75.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>158.193.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>158.194.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>158.195.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>158.196.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>158.197.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>160.216.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>161.110.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>171.25.192.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>176.97.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>176.103.224.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>176.111.168.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>178.172.212.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>178.212.104.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>185.8.160.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.12.8.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.21.196.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.21.198.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.32.156.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.48.20.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.48.20.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.48.22.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.61.6.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.61.7.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.62.108.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.68.28.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.80.188.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.80.188.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.80.189.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.80.190.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.80.191.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.83.44.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.85.28.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.85.28.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.88.12.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.89.116.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.92.48.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.102.12.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.102.13.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.102.14.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.102.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.117.40.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.125.7.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.126.188.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.130.108.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.130.252.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.140.236.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.143.56.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.149.204.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.149.204.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.149.205.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.150.124.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.151.141.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.151.142.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.151.143.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.153.192.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.153.192.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.153.194.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.154.40.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.167.176.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.178.156.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.187.140.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.189.204.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.197.44.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.205.152.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.223.20.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.240.220.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>192.5.162.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.26.237.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.26.238.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.35.240.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>192.35.244.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.76.243.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.76.244.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.82.157.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.82.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.86.14.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.88.23.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.88.24.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.92.125.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.102.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.124.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.232.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.107.233.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.108.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>192.108.130.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.108.131.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.108.132.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>192.108.138.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.108.149.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.108.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>192.111.104.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.149.232.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.150.203.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.152.54.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.173.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.174.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.175.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.176.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.177.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.178.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.180.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.182.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.164.176.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>192.164.192.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>192.174.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.174.65.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.174.66.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.174.67.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.174.68.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.188.121.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.188.234.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.189.51.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.195.72.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.245.169.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.0.24.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.0.64.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>193.0.106.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.24.14.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.28.200.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.29.206.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.33.150.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.41.88.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.104.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.104.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.105.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.106.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.107.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.112.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.112.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.113.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.114.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.115.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.116.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.118.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.119.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.120.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.121.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.122.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.123.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.124.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.125.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.126.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.128.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.128.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.129.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.130.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.131.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.132.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.133.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.135.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.46.188.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.80.132.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.80.136.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.80.144.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.80.160.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.81.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.32.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.53.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.55.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.56.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.80.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.116.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.124.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.124.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.125.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.126.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.192.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.84.208.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.128.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.129.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.130.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.131.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.132.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.133.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.87.135.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.104.244.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.105.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.105.164.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.107.32.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.107.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.110.137.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.111.144.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.150.69.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.151.68.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.1.128/28</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.1.144/28</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.32.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.50.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.52.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.54.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.55.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.56.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.57.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.58.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.59.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.60.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.72.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.72.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.76.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.78.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.79.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.80.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.84.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.86.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.87.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.88.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.93.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.94.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.96.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.100.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.102.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.104.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.115.32/28</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.117.0/26</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.120.40/29</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.120.96/28</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.124.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.128.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.132.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.137.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.138.192/28</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.150.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.151.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.184.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.185.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.186.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.187.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.190.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.192.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.213.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.214.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.218.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.219.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.220.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.170.238.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.3.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.4.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.8.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.32.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.52.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.61.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.74.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.80.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.88.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.90.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.108.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.112.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.113.128/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.115.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.122.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.157.224/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.159.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.176.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.184.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.190.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.192.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.194.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.196.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.200.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.255.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.255.8/29</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.255.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.255.32/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.255.64/26</name> + </prefix-list-item> + <prefix-list-item> + <name>193.171.255.64/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.178.34.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.88.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.96.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.176.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.188.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.190.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.191.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.186.214.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.187.2.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.187.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.187.3.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.193.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>193.193.64.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.201.164.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.203.0.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.219.28.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.228.100.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.239.180.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.239.180.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.239.181.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.10.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.11.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.12.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.13.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.14.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.24.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.24.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.25.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.26.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.1.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>194.8.45.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.8.46.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.8.51.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.8.61.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.29.99.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.29.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>194.29.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.29.176.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.37.4.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.37.8.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.37.72.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.41.12.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.41.13.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.41.14.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.41.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.44.28.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.44.217.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.48.4.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.48.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>194.48.64.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.48.236.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.50.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.107.60.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.107.64.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.107.68.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.145.96.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.153.217.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.158.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>194.158.133.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.160.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>194.165.48.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.21.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.48.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.55.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.79.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.95.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.116.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.232.133.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.246.96.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.22.112.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.22.132.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.42.152.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.0.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.3.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.16.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.17.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.18.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.19.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.20.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.21.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.22.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.23.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.24.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.25.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.26.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.27.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.28.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.29.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.30.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.50.31.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.68.210.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.68.211.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.85.252.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.93.216.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.113.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>195.150.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>195.150.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>195.150.9.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.150.128.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>195.150.224.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.160.178.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.177.250.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.128.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.136.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.144.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.154.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.155.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.182.63.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.187.64.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>195.191.38.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.191.38.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.191.39.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.200.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.234.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.245.225.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.254.190.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>198.32.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>199.253.250.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>200.128.0.0/9</name> + </prefix-list-item> + <prefix-list-item> + <name>200.219.158.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>200.219.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>200.219.159.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.14.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.14.32.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.14.48.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.33.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.51.192.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>212.51.204.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.51.207.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.51.208.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.51.224.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.87.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.87.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.87.224.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>212.87.232.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>212.87.234.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>212.87.236.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>212.87.238.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>212.106.176.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.106.183.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.106.184.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>212.109.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.192.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.192.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.193.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.195.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.196.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.197.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.198.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.201.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.203.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.204.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.205.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.206.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.208.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.209.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.111.213.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.122.192.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.122.208.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>212.182.0.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>212.182.64.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.126.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.224.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.225.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.226.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.227.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.229.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.239.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.240.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.241.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.191.244.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>213.73.0.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>213.73.20.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>213.73.24.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>213.73.28.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>213.73.30.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.32.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.40.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.43.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.44.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.48.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.50.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.52.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.56.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.56.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>213.135.63.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>213.155.160.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>213.184.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>213.184.16.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>213.184.24.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>213.184.228.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>213.227.80.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>213.227.96.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>217.21.40.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.21.41.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.21.42.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.21.43.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.21.57.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.21.62.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.113.156.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>217.116.64.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>217.149.224.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>217.173.192.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>217.173.200.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>217.173.206.0/23</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-CE</name> + </prefix-list> + <prefix-list> + <name>route-f</name> + </prefix-list> + <prefix-list> + <name>route-from-CESNET-v6</name> + <prefix-list-item> + <name>2001:628::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:404::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:404:250::10/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:453::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2000::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2003::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2020::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2090::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:20d0::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2100::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2120::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2130::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:628:2280::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:629::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:62a::/31</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:2::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:4::/47</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:5::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:d::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:e::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:f::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:11::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:1c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:20::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:24::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:1c0::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:4b4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:5c4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:618::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:8d4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:64::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:148::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1bc::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:210::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:27c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:468::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:10b8::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:10e0::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1220::/46</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1280::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1324::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:133c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:13b8::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:13f8::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1518::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1864::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1b70::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:1b90::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:23c0::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:23f4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:24cc::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:256c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:25ac::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:6a0::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:6a0::/34</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:6a0:4000::/34</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:6d8::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:6d8::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:6df::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:718::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7f8:30::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7f9:c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fd02::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fd03::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe00::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe01::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe02::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe03::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe04::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe05::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe06::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe07::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe0a::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe0b::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe0c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe0d::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe0e::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe0f::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe10::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe12::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe13::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe14::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe15::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe16::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:fe17::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff00::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff01::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff02::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff03::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff04::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff05::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff06::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff07::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff0a::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff0b::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff0c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff0d::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff0e::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff0f::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff10::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff12::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff13::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff14::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff15::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff16::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:7fb:ff17::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:808::/35</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:908::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b10::/35</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b10:bff0::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b10:c000::/35</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:12f8:c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:12f8:d::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:1a68:a::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4070::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4070::/33</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:40f8::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4118::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4c58::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4c5c::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4c70::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2604:3500::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2620:10a:80ba::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:1488::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:1610::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:1ba0:2::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:4400::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:6c40::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:cd80::/33</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:fc00:e009::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:190:15ed::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:1d8::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:1dc::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:1dd::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:1de::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:468::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:698::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:5c40::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:5c40:3::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:6e40::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:95a0::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:95a0::/33</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:95a0:8000::/33</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:3e0::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:568:fe00::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:568:fe01::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:568:fe02::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:850::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:850::/44</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:850:ffff::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:db0::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:db0::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:db0:8000::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:1770::/33</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:c280::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:2e0::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:2e4::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:1380::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:2320::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:5dc0:6::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:8320::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:f080::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:f080:1000::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:f080:1800::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a04:440::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2a04:440::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a04:4740::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a04:4740:6293::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a04:9440::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2a05:37c0::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a05:7f00::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a05:7f00:188::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a05:7f00:189::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a05:7f00:190::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a05:7f00:191::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:6bc0::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d80::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d80::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d81::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d82::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d83::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d84::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d85::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d86::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:8d87::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a07:dd40::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a09:c400::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2a09:c404::/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2a0a:8bc0::/29</name> + </prefix-list-item> + <prefix-list-item> + <name>2a0a:f500::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a0b:2e80::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a0b:6700::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a0b:8e00::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a0b:8e00:1::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a0c:8080::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-RUNNET</name> + <prefix-list-item> + <name>31.133.104.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>62.61.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.6.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.8.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.32.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.36.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.76.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.92.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.116.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.151.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.193.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.202.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.207.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.246.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.248.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.76.250.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>77.234.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>77.241.144.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>80.78.192.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>80.250.174.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.250.186.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>80.250.189.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>81.5.64.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>81.89.176.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>82.137.176.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>82.179.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>82.179.32.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>82.179.90.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>82.179.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>82.179.144.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>82.179.176.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>83.149.192.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.32.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.65.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.68.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.116.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.148.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.151.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.154.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.156.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.142.160.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.20.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.28.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.88.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.104.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.104.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.106.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.122.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>85.143.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>86.110.96.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>87.236.16.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>88.204.72.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>89.249.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>91.151.176.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>91.212.61.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.222.128.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>91.225.112.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>91.238.188.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>92.42.24.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>92.255.9.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>92.255.51.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>93.175.16.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>93.180.0.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>94.140.204.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>94.232.136.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>147.45.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>158.250.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>159.93.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>164.138.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>164.138.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>178.74.145.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>188.44.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>188.93.104.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>188.93.106.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>188.93.108.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>192.102.229.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.148.166.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.160.233.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.188.189.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.203.80.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.228.84.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.19.126.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.41.86.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.41.140.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.104.197.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.124.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.124.85.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.124.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.124.224.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.125.142.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.227.232.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.66.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.68.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.84.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.85.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.93.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.128.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.131.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.137.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.139.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.172.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.175.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.231.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.233.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>193.233.48.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.233.64.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.233.192.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.233.208.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.54.64.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.67.64.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.4.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.8.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.11.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.14.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.21.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.26.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.64.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.80.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.96.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.104.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.105.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.106.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.118.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.119.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.120.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.183.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.185.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.186.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.208.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.224.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.85.252.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.125.236.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.149.64.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.44.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.132.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.132.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.136.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.138.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.141.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.142.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.145.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.148.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.155.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.156.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.160.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.168.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.190.244.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.16.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.17.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.18.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.20.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.24.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.25.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.28.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.29.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.30.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.31.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.64.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.67.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.69.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.73.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.75.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.226.224.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>194.242.4.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.2.210.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.160.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.168.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.176.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.184.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.200.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.19.224.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.66.71.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.69.204.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.70.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.208.22.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.208.22.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.208.96.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.208.96.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.208.192.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.208.240.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>195.209.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.209.7.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.209.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.209.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.209.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>195.209.244.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>212.192.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.192.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.192.112.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.192.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.32.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.48.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.56.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.96.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.106.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.107.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.112.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.162.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.193.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>213.131.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>213.159.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>217.9.84.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>217.9.86.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>217.9.88.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>217.9.88.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>217.9.90.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.9.92.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>217.71.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>217.74.112.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>217.74.113.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.74.116.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.74.117.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.197.0.0/20</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-RUNNET6</name> + <prefix-list-item> + <name>2001:640::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:640:8000::/33</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b08:2::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b08:4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b08:9::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b08:a::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b08:b::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b08:13::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b08:15::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:f480::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:210::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:9d8::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a02:7bc0::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-Hungarnet</name> + <prefix-list-item> + <name>5.28.0.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>78.28.128.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>81.160.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>84.206.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>91.120.248.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>91.187.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>91.187.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>91.187.144.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>91.208.95.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>146.110.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.0.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.8.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.176.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>148.6.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>152.66.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>152.66.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>157.181.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>160.99.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>160.99.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>160.99.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>160.114.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>171.19.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>185.181.68.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>192.146.134.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>192.153.18.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.160.172.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.188.242.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.188.243.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.188.244.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>192.190.173.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.16.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.23.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.26.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.96.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.102.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.104.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.112.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.120.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.124.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.200.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.202.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.208.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.6.238.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.0.0/15</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.28.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.48.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.60.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.79.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.82.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.166.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.185.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.190.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.224.208.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.6.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.8.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.81.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.82.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.86.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.104.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.118.16/30</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.152.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.161.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.173.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.202.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.225.213.32/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.239.148.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.239.149.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.2.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.111.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>195.111.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.111.2.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.111.4.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.111.8.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.111.12.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>195.199.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>198.32.64.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-HUNGARNET-v6</name> + <prefix-list-item> + <name>2001:678:4::/47</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:5::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:67c:3ac::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:738::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:738:4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:4170::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:e6a0::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:e6a0:3::/48</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-MREN-v6</name> + <prefix-list-item> + <name>2a02:4280::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-mren</name> + <prefix-list-item> + <name>89.188.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>89.188.48.0/20</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DNS</name> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.100/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.146/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-ULAKBIM</name> + <prefix-list-item> + <name>5.23.120.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>46.182.64.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.164.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.176.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.176.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.178.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.179.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.180.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.181.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.182.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.183.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.216.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.218.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>79.123.224.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>80.251.32.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>91.240.37.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>92.61.0.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>95.183.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.0.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.32.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.96.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.128.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.160.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.192.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>139.179.224.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.95.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.104.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.112.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.144.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.198.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>144.122.199.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>155.223.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>159.20.64.0/19</name> + </prefix-list-item> + <prefix-list-item> + <name>160.75.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>160.75.0.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>160.75.64.0/18</name> + </prefix-list-item> + <prefix-list-item> + <name>160.75.120.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>160.75.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>161.9.0.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>161.9.128.0/17</name> + </prefix-list-item> + <prefix-list-item> + <name>161.9.152.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>161.9.180.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>176.117.96.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>185.7.0.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.22.248.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.67.32.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.67.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.83.244.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.2.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.4.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.24.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.39.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.40.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.41.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.71.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.72.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.83.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.88.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.95.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.100.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.109.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.110.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.127.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.140.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.143.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.148.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.152.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.176.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.178.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.181.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.183.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.192.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.192.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.193.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.194.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.195.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.196.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.196.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.200.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.204.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.208.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.216.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.224.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.232.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.244.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.248.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.140.252.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.2.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.4.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.8.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.16.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.24.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.28.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.30.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.31.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.32.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.36.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.38.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.46.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.48.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.50.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.52.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.58.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.64.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.68.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.69.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.74.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.76.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.82.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.83.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.84.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.92.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.97.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.98.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.100.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.102.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.106.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.108.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.112.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.120.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.134.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.134.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.135.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.137.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.140.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.145.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.146.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.151.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.152.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.156.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.160.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.176.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.178.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.184.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.188.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.215.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.221.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.222.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.224.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.232.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.236.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.240.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.243.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.244.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.248.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.255.252.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.5.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.24.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.28.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.30.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.31.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.32.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.33.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.38.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.43.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.45.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.47.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.48.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.50.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.52.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.56.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.64.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.68.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.71.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.72.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.73.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.76.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.80.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.92.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.96.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.100.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.102.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.104.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.112.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.123.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.128.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.144.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.149.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.150.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.151.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.152.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.156.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.160.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.168.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.176.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.192.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.227.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.228.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.232.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.236.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.238.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>194.27.240.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>195.49.216.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>195.49.216.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.49.220.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>208.218.35.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>208.218.36.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>208.218.37.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>208.218.43.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>208.218.46.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>208.225.48.0/20</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-ULAKBIM-v6</name> + <prefix-list-item> + <name>2001:67c:2988::/47</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a98::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a98:30::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a98:50::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a98:100::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a98:8000::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a00:1880::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:188::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:718::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a01:720::/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2a03:23e0:1::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2a05:9ec0::/31</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>nren-access</name> + <prefix-list-item> + <name>62.40.96.11/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.110.2/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.124.22/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.124.89/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.124.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.160.0/26</name> + </prefix-list-item> + <prefix-list-item> + <name>81.180.250.128/26</name> + </prefix-list-item> + <prefix-list-item> + <name>82.116.200.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.212.9.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>85.254.248.3/32</name> + </prefix-list-item> + <prefix-list-item> + <name>85.254.248.15/32</name> + </prefix-list-item> + <prefix-list-item> + <name>109.105.113.42/32</name> + </prefix-list-item> + <prefix-list-item> + <name>109.105.113.85/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.197.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.202.17/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.229.249/32</name> + </prefix-list-item> + <prefix-list-item> + <name>130.59.0.0/16</name> + </prefix-list-item> + <prefix-list-item> + <name>130.59.211.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>130.206.6.0/27</name> + </prefix-list-item> + <prefix-list-item> + <name>141.85.128.0/26</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.255.0/27</name> + </prefix-list-item> + <prefix-list-item> + <name>158.64.1.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>158.64.15.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.65.185.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.192.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.219.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.228.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.231.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.247.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.248.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.249.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.250.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.2.18.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.7.96/27</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.44.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.46.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.174.247.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.188.32.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.206.158.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.231.140.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>194.42.9.200/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.42.9.252/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.141.0.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.141.251.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.160.23.0/27</name> + </prefix-list-item> + <prefix-list-item> + <name>194.177.210.213/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.177.211.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>194.177.211.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.98.238.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.113.228.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.64.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>195.251.27.7/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:660:3001:4019::194/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:18::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:1c::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:f0:10::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:770:400::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:19:10aa::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:19:20ff::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:1e:10aa::5/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:948:4:2::42/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:948:4:3::85/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b30:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:b30:1:140::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>fe80::21d:b500:64d6:127a/128</name> + </prefix-list-item> + <prefix-list-item> + <name>fe80::21d:b5ff:fe69:893d/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>restena-access-v6</name> + <prefix-list-item> + <name>2001:a18:1:4::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a18:1:8::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a18:1:40::/60</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:a18:1:1000::/52</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:4::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:8::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:40::/60</name> + </prefix-list-item> + <prefix-list-item> + <name>2004:a18:1:1000::/52</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>restena-access</name> + <prefix-list-item> + <name>158.64.1.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>158.64.15.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>deepfield-support</name> + <prefix-list-item> + <name>107.21.96.169/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>deepfield-servers</name> + <prefix-list-item> + <name>62.40.123.134/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-AMTLD</name> + <prefix-list-item> + <name>185.77.192.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>195.43.74.0/23</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dashboard-vm</name> + <prefix-list-item> + <name>62.40.104.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.239/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>nmteam-dev-servers</name> + <prefix-list-item> + <name>62.40.106.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.254/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Infrastructure-v6</name> + <prefix-list-item> + <name>2001:630:280::1005/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::11f/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::182/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:10:97::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:12:20ff::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:a0::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:a0::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:14:20ff::1/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:15:a0::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:22:20ff::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:58::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::5/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:59::7/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:1b::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:33::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:50::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:50::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:50::4/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff17:b4::e/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ff9e:10::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:1::3/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2002:3e28:69d2::3e28:69d2/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DC-v6</name> + <prefix-list-item> + <name>2001:610:9d8:5::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280::1100/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280:0:44ce:41ac:526a:df53/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280:0:88bc:3d46:679b:41c6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:630:280:0:b052:e71f:8254:470b/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::123/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:10:99::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:52::6/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:28:52::8/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DC</name> + <prefix-list-item> + <name>62.40.106.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.10/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.134/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.136/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.121/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.15/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.20/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.33/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.87/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.100/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.103/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.66/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Infrastructure</name> + <prefix-list-item> + <name>62.40.97.11/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.12/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.14/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.15/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.178/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.134/31</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.9/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.212/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.228/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.106.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.35/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.166/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.186/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.198/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.210/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.218/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.226/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.107.242/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.10/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.14/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.22/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.34/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.38/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.46/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.58/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.77/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.128/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.130/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.131/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.132/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.133/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.134/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.135/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.136/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.137/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.139/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.140/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.142/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.143/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.144/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.145/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.147/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.29/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.53/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.130/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.50/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.76/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.222/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.100/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.32/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.40/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.150/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.154/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.155/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.156/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.157/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.158/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.163/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.165/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.179/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.181/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.184/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.195/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.211/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.227/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.147/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.186/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.23/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.103/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.146/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.150/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.180/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.63/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.87/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.85/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.138/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.90.187/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.5/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.16/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.25/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.68/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.80/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.101/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.104/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.107/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.119/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.16/30</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.20/31</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.66/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::145/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>EXTERNAL-address-spaceV6</name> + <prefix-list-item> + <name>2001:798:dd::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f200::/39</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f400::/38</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f800::/40</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>imerja-external</name> + <prefix-list-item> + <name>94.199.232.57/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.234.36/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.236.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.239.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>94.199.239.66/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>infinera-dna-servers</name> + <prefix-list-item> + <name>62.40.99.106/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.114/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>Iron-Mountain</name> + <prefix-list-item> + <name>188.95.84.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>188.95.86.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.30.234.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.239.113.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>208.66.136.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>208.66.142.0/23</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-</name> + </prefix-list> + <prefix-list> + <name>r</name> + </prefix-list> + <prefix-list> + <name>vuln-scanner</name> + <prefix-list-item> + <name>62.40.122.56/29</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:3::145/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>renater-access</name> + <prefix-list-item> + <name>195.98.238.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:660:3001:4019::194/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-anycast</name> + <prefix-list-item> + <name>192.33.14.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>192.58.128.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.1.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.0.2.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-anycast-v6</name> + <prefix-list-item> + <name>2001:678:4::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:678:5::/48</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>infinera-atc</name> + <prefix-list-item> + <name>62.40.106.86/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.75/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>camera-server</name> + <prefix-list-item> + <name>62.40.115.226/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination-count</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-destination-count6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source-count</name> + <prefix-list-item> + <name>0.0.0.0/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dos-attack-source-count6</name> + <prefix-list-item> + <name>::/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DNS-V6</name> + <prefix-list-item> + <name>2001:798:2:284d::30/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:bb:4d::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:f::2/128</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:ee:10::2/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_TS</name> + <prefix-list-item> + <name>37.60.197.172/32</name> + </prefix-list-item> + <prefix-list-item> + <name>37.99.193.133/32</name> + </prefix-list-item> + <prefix-list-item> + <name>37.110.198.18/32</name> + </prefix-list-item> + <prefix-list-item> + <name>37.128.230.54/32</name> + </prefix-list-item> + <prefix-list-item> + <name>77.67.62.162/32</name> + </prefix-list-item> + <prefix-list-item> + <name>80.53.141.6/32</name> + </prefix-list-item> + <prefix-list-item> + <name>80.66.38.102/32</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.48.178/32</name> + </prefix-list-item> + <prefix-list-item> + <name>80.233.128.123/32</name> + </prefix-list-item> + <prefix-list-item> + <name>81.90.60.129/32</name> + </prefix-list-item> + <prefix-list-item> + <name>81.92.227.208/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.212.7.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>84.207.244.154/32</name> + </prefix-list-item> + <prefix-list-item> + <name>88.205.100.10/32</name> + </prefix-list-item> + <prefix-list-item> + <name>93.117.248.110/32</name> + </prefix-list-item> + <prefix-list-item> + <name>148.6.201.1/32</name> + </prefix-list-item> + <prefix-list-item> + <name>178.250.208.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>185.19.234.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>188.129.6.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.200.34/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.1.200.38/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.2.41.166/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.40.132.26/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.219.152.6/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.111.111.46/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.178.64.230/32</name> + </prefix-list-item> + <prefix-list-item> + <name>212.3.238.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>213.191.204.166/32</name> + </prefix-list-item> + <prefix-list-item> + <name>217.15.33.76/32</name> + </prefix-list-item> + <prefix-list-item> + <name>217.20.33.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>217.20.45.74/32</name> + </prefix-list-item> + <prefix-list-item> + <name>217.29.76.21/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>static-route</name> + <prefix-list-item> + <name>0.0.0.0/0</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>IPv6-static-route</name> + <prefix-list-item> + <name>::/0</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geantnoc-address-space-v6</name> + </prefix-list> + <prefix-list> + <name>INTERNAL-address-spaceV6</name> + <prefix-list-item> + <name>2001:798:ee::/48</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>DWS-allocated-prefixes</name> + <prefix-list-item> + <name>149.6.42.72/30</name> + </prefix-list-item> + <prefix-list-item> + <name>149.6.174.32/30</name> + </prefix-list-item> + <prefix-list-item> + <name>149.6.182.113/32</name> + </prefix-list-item> + <prefix-list-item> + <name>149.11.10.4/30</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:978:2::3:0/112</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:978:2:7::5:0/126</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:978:2:27::6:0/112</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-JUNOSSPACE</name> + <prefix-list-item> + <name>62.40.113.90/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.18/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-ias-address-space</name> + <prefix-list-item> + <name>83.97.88.0/21</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-ias-address-space-V6</name> + <prefix-list-item> + <name>2001:798:1::/48</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_NTP</name> + <prefix-list-item> + <name>62.40.97.11/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.12/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.14/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.23/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.103/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>route-from-GRENA</name> + <prefix-list-item> + <name>37.26.168.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.168.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.168.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.169.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.170.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.170.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.171.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.172.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.172.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.173.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.174.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.174.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>37.26.175.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.170.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>80.94.171.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>87.252.232.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.160.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.160.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.160.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.161.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.162.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.163.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.164.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.165.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.166.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>93.187.167.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.40.0/21</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.40.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.40.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.41.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.44.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.44.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.45.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>109.205.46.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.127.64.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>185.127.64.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>185.127.64.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.127.65.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.127.66.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>185.212.252.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.228.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.232.229.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>194.158.195.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.224.0/20</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.224.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.225.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.226.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.227.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.228.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.229.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.230.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.230.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.231.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.232.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.232.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.233.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.234.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.235.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.236.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.237.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.238.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>217.147.239.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_NTP_APPLIANCES</name> + <prefix-list-item> + <name>62.40.123.21/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.23/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.123.103/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_NTP_APPLIANCES_USERS</name> + <prefix-list-item> + <name>150.100.209.162/32</name> + </prefix-list-item> + <prefix-list-item> + <name>150.100.209.163/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>RE_BGP_inet</name> + <apply-path>protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>RE_BGP_inet6</name> + <apply-path>protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_BGP_inet</name> + <apply-path>routing-instances IAS protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_BGP_inet6</name> + <apply-path>routing-instances IAS protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>CLS_BGP_inet</name> + <apply-path>routing-instances CLS protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>CLS_BGP_inet6</name> + <apply-path>routing-instances CLS protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_DUMMY_BGP_inet</name> + <apply-path>routing-instances IAS_DUMMY protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>IAS_DUMMY_BGP_inet6</name> + <apply-path>routing-instances IAS_DUMMY protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>lhcone-l3vpn_BGP_inet</name> + <apply-path>routing-instances lhcone-l3vpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>lhcone-l3vpn_BGP_inet6</name> + <apply-path>routing-instances lhcone-l3vpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>taas-control_BGP_inet</name> + <apply-path>routing-instances taas-control protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>taas-control_BGP_inet6</name> + <apply-path>routing-instances taas-control protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>mgmt-l3vpn_BGP_inet</name> + <apply-path>routing-instances mgmt-l3vpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>mgmt-l3vpn_BGP_inet6</name> + <apply-path>routing-instances mgmt-l3vpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn_BGP_inet</name> + <apply-path>routing-instances mdvpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn_BGP_inet6</name> + <apply-path>routing-instances mdvpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>GWS_GRNET_BGP_inet</name> + <apply-path>routing-instances GWS_GRNET protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>GWS_GRNET_BGP_inet6</name> + <apply-path>routing-instances GWS_GRNET protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn-nren-gn_BGP_inet</name> + <apply-path>routing-instances mdvpn-nren-gn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>mdvpn-nren-gn_BGP_inet6</name> + <apply-path>routing-instances mdvpn-nren-gn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>confine-l3vpn_BGP_inet</name> + <apply-path>routing-instances confine-l3vpn protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>confine-l3vpn_BGP_inet6</name> + <apply-path>routing-instances confine-l3vpn protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_BGP_inet</name> + <apply-path>logical-systems VPN-PROXY protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_BGP_inet6</name> + <apply-path>logical-systems VPN-PROXY protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>VRR_BGP_inet</name> + <apply-path>logical-systems VRR protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>VRR_BGP_inet6</name> + <apply-path>logical-systems VRR protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>geant-cameras</name> + <prefix-list-item> + <name>62.40.115.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.64/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.128/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.144/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.160/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.168/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.32/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.16/28</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_RI_BGP_inet</name> + <apply-path>logical-systems VPN-PROXY routing-instances <*> protocols bgp group <*> neighbor <*.*></apply-path> + </prefix-list> + <prefix-list> + <name>VPN-PROXY_RI_BGP_inet6</name> + <apply-path>logical-systems VPN-PROXY routing-instances <*> protocols bgp group <*> neighbor <*:*></apply-path> + </prefix-list> + <prefix-list> + <name>dante-address-space6</name> + <prefix-list-item> + <name>2001:630:280::/48</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:0798:5e00::/48</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>DANTE-address-space</name> + <prefix-list-item> + <name>62.40.104.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.90.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.90.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.136/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>xantaro-address-space</name> + <prefix-list-item> + <name>213.86.104.34/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>router-loopbacks</name> + <prefix-list-item> + <name>62.40.96.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.97.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_RADIUS</name> + <prefix-list-item> + <name>62.40.120.136/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.121/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>qfx-vme-interfaces</name> + <prefix-list-item> + <name>62.40.117.162/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.170/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_SUPERPOP_DRAC</name> + <prefix-list-item> + <name>62.40.117.208/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.117.224/28</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT_SUPERPOP_ESXI</name> + <prefix-list-item> + <name>62.40.108.64/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.108.128/27</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-DNS-EXT</name> + <prefix-list-item> + <name>62.40.104.250/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.122/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.100/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>JRA2_MICHAL_ACCESS_DSTIPS</name> + <prefix-list-item> + <name>62.40.96.35/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.36/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.42/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.43/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.44/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.46/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.47/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.48/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.96.49/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.114/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.254/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.91/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.113.182/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.105/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.107/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.109/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.115.111/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.41/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.43/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.47/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.19/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>JRA2_MICHAL_ACCESS_SRCIPS</name> + <prefix-list-item> + <name>78.128.217.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>147.91.255.0/26</name> + </prefix-list-item> + <prefix-list-item> + <name>195.113.142.32/27</name> + </prefix-list-item> + <prefix-list-item> + <name>195.113.161.160/28</name> + </prefix-list-item> + <prefix-list-item> + <name>195.113.222.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>212.79.96.72/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-MSDP</name> + <apply-path>protocols msdp group <*> peer <*></apply-path> + </prefix-list> + <prefix-list> + <name>GEANT-SNMP</name> + <apply-path>snmp community <*> clients <*></apply-path> + </prefix-list> + <prefix-list> + <name>GEANT-LDP</name> + <apply-path>protocols l2circuit neighbor <*></apply-path> + </prefix-list> + <prefix-list> + <name>default-route-v6</name> + <prefix-list-item> + <name>::/0</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>default-route-v4</name> + <prefix-list-item> + <name>0.0.0.0/0</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>ddos-scrubbing</name> + <prefix-list-item> + <name>62.40.100.178/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.41/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>superpop-address-space</name> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-lg</name> + <prefix-list-item> + <name>83.97.92.82/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.39/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.62/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.63/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dashboard-servers</name> + <prefix-list-item> + <name>62.40.104.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.239/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dashboard-servers-v6</name> + <prefix-list-item> + <name>2001:798:f99c:18::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:798:f99c:22::/64</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>temp-hungarnet-hijack-test</name> + </prefix-list> + <prefix-list> + <name>GEANT-Superpop-v4</name> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Superpop-v6</name> + <prefix-list-item> + <name>2001:798:3::/64</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geant-address-space-v6</name> + <prefix-list-item> + <name>2001:798::/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>opennsa-servers</name> + <prefix-list-item> + <name>83.97.93.92/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>opennsa-servers-v6</name> + <prefix-list-item> + <name>2001:798:3::15f/128</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-rancid</name> + <comment>/* TEST */</comment> + <prefix-list-item> + <name>83.97.92.115/32</name> + </prefix-list-item> + <comment>/* UAT */</comment> + <prefix-list-item> + <name>83.97.92.142/32</name> + </prefix-list-item> + <comment>/* PROD */</comment> + <prefix-list-item> + <name>83.97.92.246/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>corporate-address-space6</name> + <prefix-list-item> + <name>2001:610:9d8::/62</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:610:9d8:4::/62</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:1::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:2::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:3::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:64::/56</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2::/56</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:100::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:101::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:102::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:103::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:104::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:108::/64</name> + </prefix-list-item> + <prefix-list-item> + <name>2001:799:cb2:110::/64</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>corporate-address-space</name> + <prefix-list-item> + <name>62.40.99.160/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.201/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.112.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.122.248/29</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.0/24</name> + </prefix-list-item> + </prefix-list> + <policy-statement> + <name>ASM-Allow</name> + <term> + <name>Bogon-Groups</name> + <from> + <route-filter> + <address>224.0.1.2/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.1/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.3/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.8/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.22/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.24/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.25/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.35/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.39/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.40/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.60/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.1.76/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.2.1/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.0.2.2/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.1.0.1/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.1.0.38/32</address> + <exact/> + </route-filter> + <route-filter> + <address>224.77.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>224.128.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>232.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>233.0.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>233.128.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>239.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>224.0.0.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <trace/> + <reject/> + </then> + </term> + <term> + <name>ASM-Whitelist</name> + <from> + <route-filter> + <address>224.0.0.0/4</address> + <orlonger/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Deny-Everything-Else</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>Bogon-Sources</name> + <term> + <name>RFC-1918-Addresses</name> + <from> + <source-address-filter> + <address>10.0.0.0/8</address> + <orlonger/> + </source-address-filter> + <source-address-filter> + <address>127.0.0.0/8</address> + <orlonger/> + </source-address-filter> + <source-address-filter> + <address>172.16.0.0/12</address> + <orlonger/> + </source-address-filter> + <source-address-filter> + <address>192.168.0.0/16</address> + <orlonger/> + </source-address-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>accept-everything-else</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</name> + <term> + <name>BLEACH_PRIVATE_COMMUNITIES</name> + <then> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + </then> + </term> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</name> + <term> + <name>GENERAL_ACCEPT</name> + <then> + <local-preference> + <local-preference>90</local-preference> + </local-preference> + <community> + <add/> + <community-name>INFO_PUBLIC_PEER_BIX.HU</community-name> + </community> + <community> + <add/> + <community-name>INFO_PUBLIC_PEER_BUD</community-name> + </community> + <community> + <add/> + <community-name>geant-peers</community-name> + </community> + <community> + <add/> + <community-name>geant-ixpeers</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-FROM-PUBLIC-PEER_AS13335_Cloudflare</name> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-FROM-PUBLIC-PEER_AS5400_BT</name> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-FROM-PUBLIC-PEER_AS6939_Hurricane_Electric</name> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-FROM-PUBLIC-PEER_AS8075_Microsoft_Corporation</name> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</name> + <term> + <name>BLOCK_ALL_PUBLIC_PEERS</name> + <from> + <community>TE_BLOCK_ALL_PUBLIC_PEERS</community> + <community>TE_BLOCK_ALL_PUBLIC_PEERS_2</community> + <community>TE_BLOCK_ALL_PUBLIC_PEERS_3</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>BLOCK_THIS_IX</name> + <from> + <community>TE_BLOCK_BIX.HU</community> + <community>TE_BLOCK_LOCAL_IXES</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>PREPEND_ALL_PUBLIC_PEERSx1</name> + <from> + <community>TE_PREPEND_ALL_PUBLIC_PEERS_x1_PREPEND</community> + </from> + <then> + <as-path-expand> + <aspath>21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_ALL_PUBLIC_PEERSx2</name> + <from> + <community>TE_PREPEND_ALL_PUBLIC_PEERS_x2_PREPEND</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_ALL_PUBLIC_PEERSx3</name> + <from> + <community>TE_PREPEND_ALL_PUBLIC_PEERS_x3_PREPEND</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_ALL_PUBLIC_PEERSx6</name> + <from> + <community>TE_PREPEND_ALL_PUBLIC_PEERS_x6_PREPEND</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320 21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</name> + <term> + <name>DEFAULT_REJECT</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-TO-PUBLIC-PEER_AS13335_Cloudflare</name> + <term> + <name>BLOCK_THIS_PEER</name> + <from> + <community>TE_BLOCK_AS13335</community> + <community>TE_BLOCK_AS13335_2</community> + <community>TE_BLOCK_AS13335_BIX.HU</community> + <community>TE_BLOCK_AS13335_BIX.HU_2</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x1</name> + <from> + <community>TE_PREPEND_AS13335_x1_4byte</community> + <community>TE_PREPEND_AS13335_x1_2byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x1_4byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x1_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x2</name> + <from> + <community>TE_PREPEND_AS13335_x2_4byte</community> + <community>TE_PREPEND_AS13335_x2_2byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x2_4byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x2_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x3</name> + <from> + <community>TE_PREPEND_AS13335_x3_4byte</community> + <community>TE_PREPEND_AS13335_x3_2byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x3_4byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x3_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x6</name> + <from> + <community>TE_PREPEND_AS13335_x6_4byte</community> + <community>TE_PREPEND_AS13335_x6_2byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x6_4byte</community> + <community>TE_PREPEND_AS13335_BIX.HU_x6_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320 21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>ANNOUNCE</name> + <from> + <community>TE_ANNOUNCE_AS13335</community> + <community>TE_ANNOUNCE_AS13335_2</community> + <community>TE_ANNOUNCE_AS13335_3</community> + <community>TE_ANNOUNCE_AS13335_4</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_2</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_3</community> + <community>TE_ANNOUNCE_AS13335_BIX.HU</community> + <community>TE_ANNOUNCE_AS13335_BIX.HU_2</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-TO-PUBLIC-PEER_AS5400_BT</name> + <term> + <name>BLOCK_THIS_PEER</name> + <from> + <community>TE_BLOCK_AS5400</community> + <community>TE_BLOCK_AS5400_2</community> + <community>TE_BLOCK_AS5400_BIX.HU</community> + <community>TE_BLOCK_AS5400_BIX.HU_2</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x1</name> + <from> + <community>TE_PREPEND_AS5400_x1_4byte</community> + <community>TE_PREPEND_AS5400_x1_2byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x1_4byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x1_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x2</name> + <from> + <community>TE_PREPEND_AS5400_x2_4byte</community> + <community>TE_PREPEND_AS5400_x2_2byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x2_4byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x2_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x3</name> + <from> + <community>TE_PREPEND_AS5400_x3_4byte</community> + <community>TE_PREPEND_AS5400_x3_2byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x3_4byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x3_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x6</name> + <from> + <community>TE_PREPEND_AS5400_x6_4byte</community> + <community>TE_PREPEND_AS5400_x6_2byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x6_4byte</community> + <community>TE_PREPEND_AS5400_BIX.HU_x6_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320 21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>ANNOUNCE</name> + <from> + <community>TE_ANNOUNCE_AS5400</community> + <community>TE_ANNOUNCE_AS5400_2</community> + <community>TE_ANNOUNCE_AS5400_3</community> + <community>TE_ANNOUNCE_AS5400_4</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_2</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_3</community> + <community>TE_ANNOUNCE_AS5400_BIX.HU</community> + <community>TE_ANNOUNCE_AS5400_BIX.HU_2</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-TO-PUBLIC-PEER_AS6939_Hurricane_Electric</name> + <term> + <name>BLOCK_THIS_PEER</name> + <from> + <community>TE_BLOCK_AS6939</community> + <community>TE_BLOCK_AS6939_2</community> + <community>TE_BLOCK_AS6939_BIX.HU</community> + <community>TE_BLOCK_AS6939_BIX.HU_2</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x1</name> + <from> + <community>TE_PREPEND_AS6939_x1_4byte</community> + <community>TE_PREPEND_AS6939_x1_2byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x1_4byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x1_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x2</name> + <from> + <community>TE_PREPEND_AS6939_x2_4byte</community> + <community>TE_PREPEND_AS6939_x2_2byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x2_4byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x2_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x3</name> + <from> + <community>TE_PREPEND_AS6939_x3_4byte</community> + <community>TE_PREPEND_AS6939_x3_2byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x3_4byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x3_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x6</name> + <from> + <community>TE_PREPEND_AS6939_x6_4byte</community> + <community>TE_PREPEND_AS6939_x6_2byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x6_4byte</community> + <community>TE_PREPEND_AS6939_BIX.HU_x6_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320 21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>ANNOUNCE</name> + <from> + <community>TE_ANNOUNCE_AS6939</community> + <community>TE_ANNOUNCE_AS6939_2</community> + <community>TE_ANNOUNCE_AS6939_3</community> + <community>TE_ANNOUNCE_AS6939_4</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_2</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_3</community> + <community>TE_ANNOUNCE_AS6939_BIX.HU</community> + <community>TE_ANNOUNCE_AS6939_BIX.HU_2</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>IAS_PS-TO-PUBLIC-PEER_AS8075_Microsoft_Corporation</name> + <term> + <name>BLOCK_THIS_PEER</name> + <from> + <community>TE_BLOCK_AS8075</community> + <community>TE_BLOCK_AS8075_2</community> + <community>TE_BLOCK_AS8075_BIX.HU</community> + <community>TE_BLOCK_AS8075_BIX.HU_2</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x1</name> + <from> + <community>TE_PREPEND_AS8075_x1_4byte</community> + <community>TE_PREPEND_AS8075_x1_2byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x1_4byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x1_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x2</name> + <from> + <community>TE_PREPEND_AS8075_x2_4byte</community> + <community>TE_PREPEND_AS8075_x2_2byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x2_4byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x2_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x3</name> + <from> + <community>TE_PREPEND_AS8075_x3_4byte</community> + <community>TE_PREPEND_AS8075_x3_2byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x3_4byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x3_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>PREPEND_THIS_PEER_x6</name> + <from> + <community>TE_PREPEND_AS8075_x6_4byte</community> + <community>TE_PREPEND_AS8075_x6_2byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x6_4byte</community> + <community>TE_PREPEND_AS8075_BIX.HU_x6_2byte</community> + </from> + <then> + <as-path-expand> + <aspath>21320 21320 21320 21320 21320 21320</aspath> + </as-path-expand> + </then> + </term> + <term> + <name>ANNOUNCE</name> + <from> + <community>TE_ANNOUNCE_AS8075</community> + <community>TE_ANNOUNCE_AS8075_2</community> + <community>TE_ANNOUNCE_AS8075_3</community> + <community>TE_ANNOUNCE_AS8075_4</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_2</community> + <community>TE_ANNOUNCE_ALL_PUBLIC_PEERS_3</community> + <community>TE_ANNOUNCE_AS8075_BIX.HU</community> + <community>TE_ANNOUNCE_AS8075_BIX.HU_2</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>NEXT_POLICY</name> + <then> + <next>policy</next> + </then> + </term> + </policy-statement> + <policy-statement> + <name>PS_HUNGARNET_RTBH_IMPORT</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-Hungarnet</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>DEFAULT</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>PS_HUNGARNET_RTBH_V6_IMPORT</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-HUNGARNET-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>DEFAULT</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>PS_TO_DEEPFIELD</name> + <term> + <name>BOGONS_REJECT</name> + <from> + <prefix-list> + <name>bogons-list</name> + </prefix-list> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>REDISTRIBUTE_CONNECTED</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <community> + <add/> + <community-name>IGP_ROUTES_DEEPFIELD</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>BGP_ACCEPT</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DEFAULT</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>accept-all-flowspec</name> + <then> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>dest-class-usage</name> + <term> + <name>DWS</name> + <from> + <community>geant-dws</community> + </from> + <then> + <destination-class>dws-in</destination-class> + </then> + </term> + <term> + <name>google-in</name> + <from> + <community>geant-google</community> + </from> + <then> + <destination-class>google-in</destination-class> + </then> + </term> + <term> + <name>ixpeers-in</name> + <from> + <community>geant-ixpeers</community> + </from> + <then> + <destination-class>ixpeers-in</destination-class> + </then> + </term> + </policy-statement> + <policy-statement> + <name>mdvpn-export</name> + <term> + <name>1</name> + <from> + <protocol>bgp</protocol> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + </from> + <then> + <community> + <add/> + <community-name>mdvpn-comm</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>2</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>mdvpn-import</name> + <term> + <name>1</name> + <from> + <protocol>bgp</protocol> + <community>mdvpn-comm</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>2</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>nhs-ibgp</name> + <term> + <name>next-hop-self</name> + <then> + <next-hop> + <self/> + </next-hop> + </then> + </term> + </policy-statement> + <policy-statement> + <name>no-bsr</name> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>pim-export</name> + <from> + <interface>ae13.600</interface> + <interface>ae10.100</interface> + <interface>ae11.0</interface> + <interface>ae12.200</interface> + <interface>ae15.100</interface> + <interface>ae16.1</interface> + </from> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>pim-import</name> + <from> + <interface>ae13.600</interface> + <interface>ae10.100</interface> + <interface>ae11.0</interface> + <interface>ae12.200</interface> + <interface>ae15.100</interface> + <interface>ae16.1</interface> + </from> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>ps-20965-v4</name> + <term> + <name>geant-prefix</name> + <from> + <route-filter> + <address>62.40.96.0/19</address> + <exact/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>datacenter-prefix</name> + <from> + <route-filter> + <address>83.97.92.0/22</address> + <exact/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-20965-v6</name> + <term> + <name>geant-prefix</name> + <from> + <route-filter> + <address>2001:798::/32</address> + <exact/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-AS-SELF-REJECT</name> + <term> + <name>1</name> + <from> + <as-path>AS-SELF</as-path> + </from> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-BOGONS</name> + <term> + <name>bogons</name> + <from> + <route-filter> + <address>0.0.0.0/0</address> + <exact/> + </route-filter> + <route-filter> + <address>0.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>10.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>127.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>169.254.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>172.16.0.0/12</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.0.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.0.2.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.168.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>198.18.0.0/15</address> + <orlonger/> + </route-filter> + <route-filter> + <address>198.51.100.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>203.0.113.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>224.0.0.0/3</address> + <orlonger/> + </route-filter> + <route-filter> + <address>100.64.0.0/10</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>as-path-length-limit</name> + <from> + <protocol>bgp</protocol> + <as-path>MAX-AS_PATH</as-path> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>community-limit</name> + <from> + <protocol>bgp</protocol> + <community-count> + <name>50</name> + <orhigher/> + </community-count> + <community-count> + <name>100</name> + <orhigher/> + </community-count> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>REJECT_IX_PREFIXES</name> + <from> + <route-filter> + <address>80.249.208.0/21</address> + <orlonger/> + </route-filter> + <route-filter> + <address>193.203.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>195.66.224.0/22</address> + <orlonger/> + </route-filter> + <route-filter> + <address>217.29.66.0/23</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.65.185.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>91.210.16.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>185.1.47.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>80.81.192.0/21</address> + <orlonger/> + </route-filter> + <route-filter> + <address>185.1.68.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>193.188.137.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-BOGONS-V6</name> + <term> + <name>martians</name> + <from> + <family>inet6</family> + <route-filter> + <address>::/0</address> + <exact/> + </route-filter> + <route-filter> + <address>::/96</address> + <exact/> + </route-filter> + <route-filter> + <address>::1/128</address> + <exact/> + </route-filter> + <route-filter> + <address>fec0::/10</address> + <orlonger/> + </route-filter> + <route-filter> + <address>fe80::/10</address> + <orlonger/> + </route-filter> + <route-filter> + <address>ff00::/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>3ffe::/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:0db8::/32</address> + <orlonger/> + </route-filter> + <route-filter> + <address>fc00::/7</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>as-path-length-limit</name> + <from> + <family>inet6</family> + <protocol>bgp</protocol> + <as-path>MAX-AS_PATH</as-path> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>community-limit</name> + <from> + <family>inet6</family> + <protocol>bgp</protocol> + <community-count> + <name>50</name> + <orhigher/> + </community-count> + <community-count> + <name>100</name> + <orhigher/> + </community-count> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>REJECT_IX_PREFIXES</name> + <from> + <route-filter> + <address>2001:7f8:30::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:1::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:4::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:b:100::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:1c:24a::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:14::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:36::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:a0::/64</address> + <orlonger/> + </route-filter> + <route-filter> + <address>2001:7f8:35::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-BOGONS-def-route</name> + <term> + <name>bogons</name> + <from> + <route-filter> + <address>0.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>10.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>127.0.0.0/8</address> + <orlonger/> + </route-filter> + <route-filter> + <address>169.254.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>172.16.0.0/12</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.0.0.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.0.2.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>192.168.0.0/16</address> + <orlonger/> + </route-filter> + <route-filter> + <address>198.18.0.0/15</address> + <orlonger/> + </route-filter> + <route-filter> + <address>198.51.100.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>203.0.113.0/24</address> + <orlonger/> + </route-filter> + <route-filter> + <address>224.0.0.0/3</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>as-path-length-limit</name> + <from> + <protocol>bgp</protocol> + <as-path>MAX-AS_PATH</as-path> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>community-limit</name> + <from> + <protocol>bgp</protocol> + <community-count> + <name>50</name> + <orhigher/> + </community-count> + </from> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-AMRES-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-AMRES-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-V6-nren-general</name> + <from> + <prefix-list> + <name>route-from-AMRES-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-v6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-AMRES-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-AMRES</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-nren</name> + <from> + <prefix-list> + <name>route-from-AMRES</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-CESNET-V6-backup-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-CESNET-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-CESnet-V6-nren</name> + <from> + <prefix-list> + <name>route-from-CESNET-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>125</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-CESnet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-CESNET-backup-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-CESnet</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>ULTIMUM-IO</name> + <from> + <as-path>ULTIMUM-IO</as-path> + <community>CLS_PROVIDER_ROUTES</community> + <prefix-list> + <name>route-from-CESnet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>125</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-CESNET-nren</name> + <from> + <prefix-list> + <name>route-from-CESnet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>125</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-CESNET-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-DWS-Cogent</name> + <term> + <name>antispoofing</name> + <from> + <community>geant-nrn</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>remove-RTBH</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <community> + <delete/> + <community-name>geant-RTBH</community-name> + </community> + </then> + </term> + <term> + <name>BLEACH_PRIVATE_COMMUNITIES</name> + <then> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + </then> + </term> + <term> + <name>from-DWS-Cogent</name> + <then> + <metric> + <metric>0</metric> + </metric> + <local-preference> + <local-preference>80</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-cogent</community-name> + </community> + <community> + <add/> + <community-name>geant-dws</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-budapest</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-DWS-Cogent-v6</name> + <term> + <name>antispoofing</name> + <from> + <family>inet6</family> + <community>geant-nrn</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>remove-RTBH</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <community> + <delete/> + <community-name>geant-RTBH</community-name> + </community> + </then> + </term> + <term> + <name>BLEACH_PRIVATE_COMMUNITIES</name> + <then> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + </then> + </term> + <term> + <name>from-DWS-Cogent</name> + <then> + <metric> + <metric>0</metric> + </metric> + <local-preference> + <local-preference>80</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-cogent</community-name> + </community> + <community> + <add/> + <community-name>geant-dws</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-budapest</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-DWS-Telia</name> + <term> + <name>antispoofing</name> + <from> + <community>geant-nrn</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>remove-RTBH</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <community> + <delete/> + <community-name>geant-RTBH</community-name> + </community> + </then> + </term> + <term> + <name>BLEACH_PRIVATE_COMMUNITIES</name> + <then> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + </then> + </term> + <term> + <name>from-DWS-telia</name> + <then> + <metric> + <metric>0</metric> + </metric> + <local-preference> + <local-preference>80</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-telia</community-name> + </community> + <community> + <add/> + <community-name>geant-dws</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-budapest</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-DWS-Telia-v6</name> + <term> + <name>antispoofing</name> + <from> + <family>inet6</family> + <community>geant-nrn</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>remove-RTBH</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <community> + <delete/> + <community-name>geant-RTBH</community-name> + </community> + </then> + </term> + <term> + <name>BLEACH_PRIVATE_COMMUNITIES</name> + <then> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + </then> + </term> + <term> + <name>from-DWS-telia</name> + <then> + <metric> + <metric>0</metric> + </metric> + <local-preference> + <local-preference>80</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-telia</community-name> + </community> + <community> + <add/> + <community-name>geant-dws</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-budapest</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-FACEBOOK</name> + <term> + <name>remove-RTBH</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <community> + <delete/> + <community-name>geant-RTBH</community-name> + </community> + </then> + </term> + <term> + <name>BLEACH_PRIVATE_COMMUNITIES</name> + <then> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + </then> + </term> + <term> + <name>from-FACEBOOK</name> + <then> + <local-preference> + <local-preference>95</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-peers</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-private-peer-BUD</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-HUNGARnet-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-HUNGARNET-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet-V6-nren-general</name> + <from> + <prefix-list> + <name>route-from-HUNGARNET-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-HUNGARnet1-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-Hungarnet</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet1-nren</name> + <from> + <prefix-list> + <name>route-from-Hungarnet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet1-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-MREN-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-MREN-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren</name> + <from> + <prefix-list> + <name>route-from-MREN-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-MREN-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-mren</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren</name> + <from> + <prefix-list> + <name>route-from-mren</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-ULAKBIM-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-ULAKBIM-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKBIM-V6-nren</name> + <from> + <prefix-list> + <name>route-from-ULAKBIM-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKBIM-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-from-ULAKBIM-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-ULAKBIM</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKMBIM-nren</name> + <from> + <prefix-list> + <name>route-from-ULAKBIM</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKMBIM-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-AMRES-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-amres-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-AMRES-V6-nren-general</name> + <from> + <family>inet6</family> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-AMRES-V6-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-AMRES-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-amres-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-AMRES-nren-general</name> + <from> + <community>geant-google</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-dws</community> + <community>geant-helix</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>to-AMRES-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-CESNET-V6-backup-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-cesnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-CESNET-nren-general</name> + <from> + <community>geant-ixpeers</community> + <community>geant-peers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>20</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-CESNET-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-CESNET-backup-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-cesnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-CESNET-nren-general</name> + <from> + <community>geant-ixpeers</community> + <community>geant-peers</community> + <community>geant-google</community> + <community>geant-helix</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>20</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-CESNET-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-DWS-Cogent</name> + <term> + <name>to-DWS-block</name> + <from> + <community>geant-dws-block</community> + <community>geant-IAS-dws-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-Cogent-block</name> + <from> + <community>geant-dws-cogent-block</community> + <community>geant-dws-cogent-block2</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>DWS</name> + <from> + <community>geant-dws</community> + <community>geant-cogent</community> + </from> + <then> + <destination-class>dws-in</destination-class> + </then> + </term> + <term> + <name>to-DWS-prepend1</name> + <from> + <community>geant-dws-prepend1</community> + <community>geant-IAS-dws-prepend1</community> + </from> + <then> + <as-path-prepend>21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend2</name> + <from> + <community>geant-dws-prepend2</community> + <community>geant-IAS-dws-prepend2</community> + </from> + <then> + <as-path-prepend>21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend3</name> + <from> + <community>geant-dws-prepend3</community> + <community>geant-IAS-dws-prepend3</community> + </from> + <then> + <as-path-prepend>21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend6</name> + <from> + <community>geant-dws-prepend6</community> + <community>geant-IAS-dws-prepend6</community> + </from> + <then> + <as-path-prepend>21320 21320 21320 21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-IGP-MED</name> + <from> + <community>geant-dws-nren</community> + <community>geant-IAS-dws-nren</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>to-DWS-geant-address</name> + <from> + <route-filter> + <address>62.40.96.0/19</address> + <exact/> + </route-filter> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <term> + <name>drop-others</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-DWS-Cogent-v6</name> + <term> + <name>to-DWS-block</name> + <from> + <family>inet6</family> + <community>geant-dws-block</community> + <community>geant-IAS-dws-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-Cogent-block</name> + <from> + <family>inet6</family> + <community>geant-dws-cogent-block</community> + <community>geant-dws-cogent-block2</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-DWS-prepend1</name> + <from> + <community>geant-dws-prepend1</community> + <community>geant-IAS-dws-prepend1</community> + </from> + <then> + <as-path-prepend>21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend2</name> + <from> + <community>geant-dws-prepend2</community> + <community>geant-IAS-dws-prepend2</community> + </from> + <then> + <as-path-prepend>21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend3</name> + <from> + <community>geant-dws-prepend3</community> + <community>geant-IAS-dws-prepend3</community> + </from> + <then> + <as-path-prepend>21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend6</name> + <from> + <community>geant-dws-prepend6</community> + <community>geant-IAS-dws-prepend6</community> + </from> + <then> + <as-path-prepend>21320 21320 21320 21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-IGP-MED</name> + <from> + <community>geant-dws-nren</community> + <community>geant-IAS-dws-nren</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-DWS-Telia</name> + <term> + <name>to-DWS-block</name> + <from> + <community>geant-dws-block</community> + <community>geant-IAS-dws-block</community> + <community>geant-dws-telia-block</community> + <community>geant-dws-telia-block2</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>DWS</name> + <from> + <community>geant-telia</community> + <community>geant-dws</community> + </from> + <then> + <destination-class>dws-in</destination-class> + </then> + </term> + <term> + <name>to-DWS-prepend1</name> + <from> + <community>geant-dws-prepend1</community> + <community>geant-IAS-dws-prepend1</community> + </from> + <then> + <as-path-prepend>21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend2</name> + <from> + <community>geant-dws-prepend2</community> + <community>geant-IAS-dws-prepend2</community> + </from> + <then> + <as-path-prepend>21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend3</name> + <from> + <community>geant-dws-prepend3</community> + <community>geant-IAS-dws-prepend3</community> + </from> + <then> + <as-path-prepend>21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend6</name> + <from> + <community>geant-dws-prepend6</community> + <community>geant-IAS-dws-prepend6</community> + </from> + <then> + <as-path-prepend>21320 21320 21320 21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-IGP-MED</name> + <from> + <community>geant-dws-nren</community> + <community>geant-IAS-dws-nren</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>to-DWS-geant-address</name> + <from> + <route-filter> + <address>62.40.96.0/19</address> + <exact/> + </route-filter> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <term> + <name>drop-others</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-DWS-Telia-v6</name> + <term> + <name>to-DWS-block</name> + <from> + <family>inet6</family> + <community>geant-dws-block</community> + <community>geant-dws-telia-block</community> + <community>geant-dws-telia-block2</community> + <community>geant-IAS-dws-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-DWS-NRN-block</name> + <from> + <family>inet6</family> + <as-path>RENATER</as-path> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-DWS-prepend1</name> + <from> + <community>geant-dws-prepend1</community> + <community>geant-IAS-dws-prepend1</community> + </from> + <then> + <as-path-prepend>21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend2</name> + <from> + <community>geant-dws-prepend2</community> + <community>geant-IAS-dws-prepend2</community> + </from> + <then> + <as-path-prepend>21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend3</name> + <from> + <community>geant-dws-prepend3</community> + <community>geant-IAS-dws-prepend3</community> + </from> + <then> + <as-path-prepend>21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-prepend6</name> + <from> + <community>geant-dws-prepend6</community> + <community>geant-IAS-dws-prepend6</community> + </from> + <then> + <as-path-prepend>21320 21320 21320 21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-DWS-IGP-MED</name> + <from> + <community>geant-dws-nren</community> + <community>geant-IAS-dws-nren</community> + </from> + <then> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-FACEBOOK</name> + <term> + <name>to-private-peers-block</name> + <from> + <community>TE_BLOCK_PEERS</community> + <community>TE_BLOCK_PEERS_2</community> + <community>TE_BLOCK_PEERS_3</community> + <community>TE_BLOCK_AS63293</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-private-peers-prepend-1</name> + <from> + <community>geant-private-peers-prepend-1</community> + <community>TE_PREPEND_AS63293_x1_2byte_BUD</community> + <community>TE_PREPEND_AS63293_x1_4byte_BUD</community> + </from> + <then> + <as-path-prepend>21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-private-peers-prepend-3</name> + <from> + <community>geant-private-peers-prepend</community> + <community>peers-prepend-3</community> + <community>TE_PREPEND_AS63293_x3_2byte_BUD</community> + <community>TE_PREPEND_AS63293_x3_4byte_BUD</community> + </from> + <then> + <as-path-prepend>21320 21320 21320</as-path-prepend> + <next>term</next> + </then> + </term> + <term> + <name>to-private-peers-prepend-6</name> + <from> + <community>TE_PREPEND_AS63293_x6_2byte_BUD</community> + <community>TE_PREPEND_AS63293_x6_4byte_BUD</community> + </from> + <then> + <next>term</next> + </then> + </term> + <term> + <name>to-FACEBOOK</name> + <from> + <community>TE_ANNOUNCE_ALL_PRIVATE_PEERS</community> + <community>TE_ANNOUNCE_ALL_PRIVATE_PEERS_2</community> + <community>TE_ANNOUNCE_AS63293</community> + <community>TE_ANNOUNCE_AS63293_2</community> + <community>TE_ANNOUNCE_AS63293_3</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <community> + <delete/> + <community-name>TE_PRIVATE_COMMUNITIES</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default-reject</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-HUNGARnet-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-hungarnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-HUNGARnet-V6-nren-general</name> + <from> + <family>inet6</family> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-HUNGARnet-V6-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-HUNGARnet1-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-hungarnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-HUNGARnet1-nren-general</name> + <from> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-helix</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-nren-temp-hijack-test</name> + <from> + <prefix-list> + <name>temp-hungarnet-hijack-test</name> + </prefix-list> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-HUNGARnet1-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-MREN</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-mren-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-MREN-general</name> + <from> + <community>geant-google</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-dws</community> + <community>geant-helix</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-MREN-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-MREN-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-mren-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-MREN-V6-nren-general</name> + <from> + <family>inet6</family> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-MREN-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-ULAKBIM-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-ulakbim-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-ULAKBIM-V6-nren</name> + <from> + <family>inet6</family> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-ULAKBIM-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-IAS-to-ULAKBIM-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-ulakbim-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-ULAKBIM-nren</name> + <from> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-helix</community> + <community>IAS_AGGREGATE_ROUTES</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-ULAKBIM-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-PRIVATE-AS-BLOCK</name> + <from> + <as-path>AS-PRIVATE</as-path> + </from> + <then> + <reject/> + </then> + </policy-statement> + <policy-statement> + <name>ps-advertise-default</name> + <term> + <name>static</name> + <from> + <prefix-list> + <name>static-route</name> + </prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-advertise-default-v6</name> + <term> + <name>static6</name> + <from> + <protocol>static</protocol> + <protocol>bgp</protocol> + <prefix-list> + <name>IPv6-static-route</name> + </prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-deny-all</name> + <term> + <name>deny-all</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-direct-route-label</name> + <term> + <name>1</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <label-allocation>per-table</label-allocation> + <accept/> + </then> + </term> + <term> + <name>2</name> + <then> + <label-allocation>per-nexthop</label-allocation> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-V6-static</name> + <from> + <prefix-list> + <name>geant-address-space-V6</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-V6-static-MED20</name> + <from> + <prefix-list> + <name>geant-address-space-V6</name> + </prefix-list> + </from> + <then> + <metric> + <metric>20</metric> + </metric> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-static</name> + <term> + <name>static</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-eGEANT-static-MED20</name> + <term> + <name>static</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + </from> + <then> + <metric> + <metric>20</metric> + </metric> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-AMRES-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-AMRES-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-V6-nren-general</name> + <from> + <prefix-list> + <name>route-from-AMRES-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-v6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-AMRES-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-AMRES</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-nren</name> + <from> + <prefix-list> + <name>route-from-AMRES</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMRES-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-AMTLD</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-AMTLD</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMTLD-nren</name> + <from> + <prefix-list> + <name>route-from-AMTLD</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-nasra</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-AMTLD-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-CESNET-V6-backup-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-CESNET-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-CESnet-V6-nren</name> + <from> + <prefix-list> + <name>route-from-CESNET-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>125</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-CESnet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-CESNET-backup-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-CESnet</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>ULTIMUM-IO</name> + <from> + <as-path>ULTIMUM-IO</as-path> + <community>CLS_PROVIDER_ROUTES</community> + <prefix-list> + <name>route-from-CESnet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>125</local-preference> + </local-preference> + <accept/> + </then> + </term> + <term> + <name>from-CESNET-nren</name> + <from> + <prefix-list> + <name>route-from-CESnet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>125</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-CESNET-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-CLS-vrf</name> + <term> + <name>CLS-routes</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <community> + <add/> + <community-name>CLS-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>CLS-interface-routes</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <community> + <add/> + <community-name>CLS-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-DWS-Cogent</name> + <term> + <name>antispoofing</name> + <from> + <community>geant-nrn</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>remove-RTBH</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <community> + <delete/> + <community-name>geant-RTBH</community-name> + </community> + </then> + </term> + <term> + <name>from-DWS-Cogent</name> + <then> + <metric> + <metric>0</metric> + </metric> + <local-preference> + <local-preference>80</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-cogent</community-name> + </community> + <community> + <add/> + <community-name>geant-dws</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-DWS-Cogent-v6</name> + <term> + <name>antispoofing</name> + <from> + <family>inet6</family> + <community>geant-nrn</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>remove-RTBH</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <community> + <delete/> + <community-name>geant-RTBH</community-name> + </community> + </then> + </term> + <term> + <name>from-DWS-Cogent</name> + <then> + <metric> + <metric>0</metric> + </metric> + <local-preference> + <local-preference>80</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-cogent</community-name> + </community> + <community> + <add/> + <community-name>geant-dws</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-GRENA-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-GRENA</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-grena</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>INFO_EAP_NREN</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-GRENA-nren</name> + <from> + <prefix-list> + <name>route-from-GRENA</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-grena</community-name> + </community> + <community> + <add/> + <community-name>geant-nren-bud</community-name> + </community> + <community> + <add/> + <community-name>INFO_EAP_NREN</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-GRENA-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-HUNGARnet-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-HUNGARNET-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet-V6-nren-general</name> + <from> + <prefix-list> + <name>route-from-HUNGARNET-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-HUNGARnet1-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-Hungarnet</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet1-nren</name> + <from> + <prefix-list> + <name>route-from-Hungarnet</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-HUNGARnet1-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-MREN-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-MREN-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren</name> + <from> + <prefix-list> + <name>route-from-MREN-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-MREN-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-mren</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren</name> + <from> + <prefix-list> + <name>route-from-mren</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-MREN-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-ULAKBIM-V6-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-ULAKBIM-v6</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>100::</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKBIM-V6-nren</name> + <from> + <prefix-list> + <name>route-from-ULAKBIM-v6</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKBIM-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-ULAKBIM-nren</name> + <term> + <name>RTBH</name> + <from> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + <prefix-list-filter> + <list_name>route-from-ULAKBIM</list_name> + <orlonger/> + </prefix-list-filter> + </from> + <then> + <local-preference> + <local-preference>200</local-preference> + </local-preference> + <community> + <add/> + <community-name>TE_BLOCK_ALL_PUBLIC_PEERS</community-name> + </community> + <community> + <add/> + <community-name>TE_BLOCK_PEERS_2</community-name> + </community> + <community> + <add/> + <community-name>geant-IAS-dws-block</community-name> + </community> + <community> + <add/> + <community-name>geant-dummy</community-name> + </community> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>anycast-prefixes</name> + <from> + <community>geant-anycast</community> + <prefix-list> + <name>geant-anycast</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-dws-nren</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKMBIM-nren</name> + <from> + <prefix-list> + <name>route-from-ULAKBIM</name> + </prefix-list> + </from> + <then> + <local-preference> + <local-preference>150</local-preference> + </local-preference> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-public-peer</community-name> + </community> + <community> + <add/> + <community-name>geant-adv2-private-peer</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>from-ULAKMBIM-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-coriant-vrf</name> + <term> + <name>mgmt-routes</name> + <from> + <protocol>direct</protocol> + <protocol>static</protocol> + </from> + <then> + <community> + <add/> + <community-name>coriant-mgmt</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-ias-vrf</name> + <term> + <name>ias-routes</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <community> + <add/> + <community-name>ias-routes</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>ias-interface-routes</name> + <from> + <protocol>direct</protocol> + </from> + <then> + <community> + <add/> + <community-name>ias-routes</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>ias-facebook-static-routes</name> + <from> + <protocol>static</protocol> + </from> + <then> + <community> + <add/> + <community-name>ias-routes</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-lhcone-nren</name> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-from-lhcone-peer</name> + <then> + <community> + <add/> + <community-name>geant-peer-RE</community-name> + </community> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-from-lhcone-vrf</name> + <term> + <name>lhcone-routes</name> + <from> + <protocol>bgp</protocol> + </from> + <then> + <community> + <add/> + <community-name>lhcone-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>lhcone-geant-ptp</name> + <from> + <route-filter> + <address>62.40.126.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <community> + <add/> + <community-name>lhcone-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>lhcone-geant-ptp6</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <community> + <add/> + <community-name>lhcone-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-from-mgmt-vrf</name> + <term> + <name>mgmt-routes</name> + <from> + <protocol>direct</protocol> + <protocol>static</protocol> + </from> + <then> + <community> + <add/> + <community-name>mgmt-vpn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-into-CLS-vrf</name> + <term> + <name>CLS-routes</name> + <from> + <protocol>bgp</protocol> + <community>CLS-vpn</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-into-ias-vrf</name> + <term> + <name>ias-routes</name> + <from> + <protocol>bgp</protocol> + <community>ias-routes</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-into-lhcone-vrf</name> + <term> + <name>lhcone-routes</name> + <from> + <protocol>bgp</protocol> + <community>lhcone-vpn</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-into-mgmt-vrf</name> + <term> + <name>mgmt-routes</name> + <from> + <protocol>bgp</protocol> + <community>mgmt-vpn</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-AMRES-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-amres-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-AMRES-V6-nren-general</name> + <from> + <family>inet6</family> + <community>geant-nrn</community> + <community>geant-m6bone</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-AMRES-V6-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-AMRES-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-amres-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-AMRES-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-google</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + <community>geant-helix</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>to-AMRES-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-AMTLD</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-AMTLD-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-anycast</community> + <community>geant-peer-RE</community> + <community>geant-dws</community> + <community>geant-peers</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>to-AMTLD-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-CESNET-V6-backup-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-cesnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-CESNET-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-ixpeers</community> + <community>geant-peers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + </from> + <then> + <metric> + <metric>20</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-CESNET-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-CESNET-backup-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-cesnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-CESNET-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-ixpeers</community> + <community>geant-peers</community> + <community>geant-google</community> + <community>geant-peer-RE</community> + <community>geant-helix</community> + </from> + <then> + <metric> + <metric>20</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-CESNET-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-GRENA-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-GRENA-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-anycast</community> + <community>geant-peer-RE</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>to-GRENA-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-HUNGARnet-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-hungarnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-HUNGARnet-V6-nren-general</name> + <from> + <family>inet6</family> + <community>geant-nrn</community> + <community>geant-m6bone</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-HUNGARnet-V6-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-HUNGARnet1-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-hungarnet-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-HUNGARnet1-nren-general</name> + <from> + <community>geant-nrn</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + <community>geant-helix</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-HUNGARnet1-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-MREN</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-mren-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-MREN-general</name> + <from> + <community>geant-nrn</community> + <community>geant-google</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-peer-RE</community> + <community>geant-dws</community> + <community>geant-helix</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-MREN-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-MREN-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-mren-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-MREN-V6-nren-general</name> + <from> + <family>inet6</family> + <community>geant-nrn</community> + <community>geant-m6bone</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-MREN-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-ULAKBIM-V6-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-ulakbim-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-ULAKBIM-V6-nren</name> + <from> + <family>inet6</family> + <community>geant-nrn</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-dws</community> + <community>geant-peer-RE</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-ULAKBIM-V6-nren-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-ULAKBIM-nren</name> + <term> + <name>exception-block</name> + <from> + <community>geant-dummy</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-nren-block</name> + <from> + <community>geant-ulakbim-block</community> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>to-ULAKBIM-nren</name> + <from> + <community>geant-nrn</community> + <community>geant-peers</community> + <community>geant-ixpeers</community> + <community>geant-google</community> + <community>geant-peer-RE</community> + <community>geant-helix</community> + </from> + <then> + <metric> + <metric>0</metric> + </metric> + <accept/> + </then> + </term> + <term> + <name>to-ULAKBIM-drop</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-coriant-vrf</name> + <term> + <name>mgmt-routes</name> + <from> + <protocol>bgp</protocol> + <community>coriant-mgmt</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-iGEANT</name> + <term> + <name>to-iGEANT</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>to-iGEANT-default</name> + <from> + <prefix-list> + <name>default-route-v4</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>no-export</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-iGEANT6</name> + <term> + <name>to-iGEANT-v6</name> + <from> + <prefix-list> + <name>geant-address-space-V6</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>geant-nrn</community-name> + </community> + <accept/> + </then> + </term> + <term> + <name>to-iGEANT-v6-default</name> + <from> + <prefix-list> + <name>default-route-v6</name> + </prefix-list> + </from> + <then> + <community> + <add/> + <community-name>no-export</community-name> + </community> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-nren</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>62.40.126.0/24</address> + <exact/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>62.40.103.0/25</address> + <orlonger/> + </route-filter> + <route-filter> + <address>62.40.126.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <then> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-nren-v6</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <exact/> + </route-filter> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <then> + <accept/> + </then> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-peer</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>62.40.126.0/24</address> + <exact/> + </route-filter> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>62.40.103.0/25</address> + <orlonger/> + </route-filter> + <route-filter> + <address>62.40.126.0/24</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>allow-nren-routes</name> + <from> + <community>geant-nrn</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <then> + <default-action>reject</default-action> + </then> + </policy-statement> + <policy-statement> + <name>ps-to-lhcone-peer-v6</name> + <term> + <name>ptp-routes</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <exact/> + </route-filter> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <term> + <name>ptp-routes-specific-deny</name> + <from> + <route-filter> + <address>2001:798:111:1::/64</address> + <orlonger/> + </route-filter> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>allow-nren-routes</name> + <from> + <community>geant-nrn</community> + </from> + <then> + <metric> + <igp> + </igp> + </metric> + <accept/> + </then> + </term> + <then> + <default-action>reject</default-action> + </then> + </policy-statement> + <policy-statement> + <name>reject-bsr-inet-only</name> + <term> + <name>reject-BSR-inet</name> + <from> + <family>inet</family> + </from> + <then> + <reject/> + </then> + </term> + <term> + <name>accept-BSR-inet6</name> + <from> + <family>inet6</family> + </from> + <then> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>rtbh-ibgp</name> + <term> + <name>1</name> + <from> + <protocol>bgp</protocol> + <community>geant-RTBH</community> + <route-filter> + <address>0.0.0.0/0</address> + <prefix-length-range>/32-/32</prefix-length-range> + </route-filter> + </from> + <then> + <next-hop> + <address>192.0.2.101</address> + </next-hop> + <accept/> + </then> + </term> + <term> + <name>2</name> + <from> + <protocol>bgp</protocol> + <community>geant-RTBH</community> + <route-filter> + <address>::/0</address> + <prefix-length-range>/128-/128</prefix-length-range> + </route-filter> + </from> + <then> + <next-hop> + <address>0100::</address> + </next-hop> + <accept/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>rtbh-policy</name> + <term> + <name>11</name> + <from> + <community>geant-RTBH</community> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>22</name> + <then> + <reject/> + </then> + </term> + </policy-statement> + <policy-statement> + <name>source-class-usage</name> + <term> + <name>DWS</name> + <from> + <community>geant-dws</community> + </from> + <then> + <source-class>dws-out</source-class> + <next>term</next> + </then> + </term> + <term> + <name>google-out</name> + <from> + <community>geant-google</community> + </from> + <then> + <source-class>google-out</source-class> + </then> + </term> + <term> + <name>ixpeers-out</name> + <from> + <community>geant-ixpeers</community> + </from> + <then> + <source-class>ixpeers-out</source-class> + </then> + </term> + </policy-statement> + <community> + <name>CLS-vpn</name> + <members>target:20965:667</members> + </community> + <community> + <name>CLS_AGGREGATE_ROUTES</name> + <members>20965:64912</members> + </community> + <community> + <name>CLS_NREN_ROUTES</name> + <members>20965:65101</members> + </community> + <community> + <name>CLS_PROVIDER_ROUTES</name> + <members>20965:65102</members> + </community> + <community> + <name>IAS_AGGREGATE_ROUTES</name> + <members>21320:64912</members> + </community> + <community> + <name>IGP_ROUTES_DEEPFIELD</name> + <members>20965:65002</members> + </community> + <community> + <name>INFO_EAP_NREN</name> + <members>20965:65103</members> + </community> + <community> + <name>INFO_PUBLIC_PEER</name> + <members>21320:646..</members> + </community> + <community> + <name>INFO_PUBLIC_PEER_BIX.HU</name> + <members>21320:64688</members> + </community> + <community> + <name>INFO_PUBLIC_PEER_BUD</name> + <members>21320:64618</members> + </community> + <community> + <name>TE_ANNOUNCE_ALL_PRIVATE_PEERS</name> + <members>20965:65533</members> + </community> + <community> + <name>TE_ANNOUNCE_ALL_PRIVATE_PEERS_2</name> + <members>64700:65533</members> + </community> + <community> + <name>TE_ANNOUNCE_ALL_PUBLIC_PEERS</name> + <members>64700:65532</members> + </community> + <community> + <name>TE_ANNOUNCE_ALL_PUBLIC_PEERS_2</name> + <members>64712:65532</members> + </community> + <community> + <name>TE_ANNOUNCE_ALL_PUBLIC_PEERS_3</name> + <members>20965:65532</members> + </community> + <community> + <name>TE_ANNOUNCE_AS13335</name> + <members>64700:13335</members> + </community> + <community> + <name>TE_ANNOUNCE_AS13335_2</name> + <members>64712:13335</members> + </community> + <community> + <name>TE_ANNOUNCE_AS13335_3</name> + <members>origin:13335L:64700</members> + </community> + <community> + <name>TE_ANNOUNCE_AS13335_4</name> + <members>origin:13335L:64712</members> + </community> + <community> + <name>TE_ANNOUNCE_AS13335_BIX.HU</name> + <members>64788:13335</members> + </community> + <community> + <name>TE_ANNOUNCE_AS13335_BIX.HU_2</name> + <members>origin:13335L:64788</members> + </community> + <community> + <name>TE_ANNOUNCE_AS5400</name> + <members>64700:5400</members> + </community> + <community> + <name>TE_ANNOUNCE_AS5400_2</name> + <members>64712:5400</members> + </community> + <community> + <name>TE_ANNOUNCE_AS5400_3</name> + <members>origin:5400L:64700</members> + </community> + <community> + <name>TE_ANNOUNCE_AS5400_4</name> + <members>origin:5400L:64712</members> + </community> + <community> + <name>TE_ANNOUNCE_AS5400_BIX.HU</name> + <members>64788:5400</members> + </community> + <community> + <name>TE_ANNOUNCE_AS5400_BIX.HU_2</name> + <members>origin:5400L:64788</members> + </community> + <community> + <name>TE_ANNOUNCE_AS63293</name> + <members>64700:63293</members> + </community> + <community> + <name>TE_ANNOUNCE_AS63293_2</name> + <members>64712:63293</members> + </community> + <community> + <name>TE_ANNOUNCE_AS63293_3</name> + <members>origin:63293L:64700</members> + </community> + <community> + <name>TE_ANNOUNCE_AS6939</name> + <members>64700:6939</members> + </community> + <community> + <name>TE_ANNOUNCE_AS6939_2</name> + <members>64712:6939</members> + </community> + <community> + <name>TE_ANNOUNCE_AS6939_3</name> + <members>origin:6939L:64700</members> + </community> + <community> + <name>TE_ANNOUNCE_AS6939_4</name> + <members>origin:6939L:64712</members> + </community> + <community> + <name>TE_ANNOUNCE_AS6939_BIX.HU</name> + <members>64788:6939</members> + </community> + <community> + <name>TE_ANNOUNCE_AS6939_BIX.HU_2</name> + <members>origin:6939L:64788</members> + </community> + <community> + <name>TE_ANNOUNCE_AS8075</name> + <members>64700:8075</members> + </community> + <community> + <name>TE_ANNOUNCE_AS8075_2</name> + <members>64712:8075</members> + </community> + <community> + <name>TE_ANNOUNCE_AS8075_3</name> + <members>origin:8075L:64700</members> + </community> + <community> + <name>TE_ANNOUNCE_AS8075_4</name> + <members>origin:8075L:64712</members> + </community> + <community> + <name>TE_ANNOUNCE_AS8075_BIX.HU</name> + <members>64788:8075</members> + </community> + <community> + <name>TE_ANNOUNCE_AS8075_BIX.HU_2</name> + <members>origin:8075L:64788</members> + </community> + <community> + <name>TE_BLOCK_ALL_PUBLIC_PEERS</name> + <members>64512:65532</members> + </community> + <community> + <name>TE_BLOCK_ALL_PUBLIC_PEERS_2</name> + <members>20965:0012</members> + </community> + <community> + <name>TE_BLOCK_ALL_PUBLIC_PEERS_3</name> + <members>20965:0006</members> + </community> + <community> + <name>TE_BLOCK_AS13335</name> + <members>64512:13335</members> + </community> + <community> + <name>TE_BLOCK_AS13335_2</name> + <members>origin:13335L:64512</members> + </community> + <community> + <name>TE_BLOCK_AS13335_BIX.HU</name> + <members>64588:13335</members> + </community> + <community> + <name>TE_BLOCK_AS13335_BIX.HU_2</name> + <members>origin:13335L:64588</members> + </community> + <community> + <name>TE_BLOCK_AS5400</name> + <members>64512:5400</members> + </community> + <community> + <name>TE_BLOCK_AS5400_2</name> + <members>origin:5400L:64512</members> + </community> + <community> + <name>TE_BLOCK_AS5400_BIX.HU</name> + <members>64588:5400</members> + </community> + <community> + <name>TE_BLOCK_AS5400_BIX.HU_2</name> + <members>origin:5400L:64588</members> + </community> + <community> + <name>TE_BLOCK_AS63293</name> + <members>64512:63293</members> + </community> + <community> + <name>TE_BLOCK_AS6939</name> + <members>64512:6939</members> + </community> + <community> + <name>TE_BLOCK_AS6939_2</name> + <members>origin:6939L:64512</members> + </community> + <community> + <name>TE_BLOCK_AS6939_BIX.HU</name> + <members>64588:6939</members> + </community> + <community> + <name>TE_BLOCK_AS6939_BIX.HU_2</name> + <members>origin:6939L:64588</members> + </community> + <community> + <name>TE_BLOCK_AS8075</name> + <members>64512:8075</members> + </community> + <community> + <name>TE_BLOCK_AS8075_2</name> + <members>origin:8075L:64512</members> + </community> + <community> + <name>TE_BLOCK_AS8075_BIX.HU</name> + <members>64588:8075</members> + </community> + <community> + <name>TE_BLOCK_AS8075_BIX.HU_2</name> + <members>origin:8075L:64588</members> + </community> + <community> + <name>TE_BLOCK_BIX.HU</name> + <members>64588:65532</members> + </community> + <community> + <name>TE_BLOCK_LOCAL_IXES</name> + <members>64518:65532</members> + </community> + <community> + <name>TE_BLOCK_PEERS</name> + <members>20965:0013</members> + </community> + <community> + <name>TE_BLOCK_PEERS_2</name> + <members>64512:65533</members> + </community> + <community> + <name>TE_BLOCK_PEERS_3</name> + <members>20965:0011</members> + </community> + <community> + <name>TE_PREPEND_ALL_PUBLIC_PEERS_x1_PREPEND</name> + <members>64801:65532</members> + </community> + <community> + <name>TE_PREPEND_ALL_PUBLIC_PEERS_x2_PREPEND</name> + <members>64802:65532</members> + </community> + <community> + <name>TE_PREPEND_ALL_PUBLIC_PEERS_x3_PREPEND</name> + <members>64803:65532</members> + </community> + <community> + <name>TE_PREPEND_ALL_PUBLIC_PEERS_x6_PREPEND</name> + <members>64806:65532</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x1_2byte</name> + <members>64801:13335</members> + <members>64888:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x1_4byte</name> + <members>origin:13335L:64801</members> + <members>origin:13335L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x2_2byte</name> + <members>64802:13335</members> + <members>64888:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x2_4byte</name> + <members>origin:13335L:64802</members> + <members>origin:13335L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x3_2byte</name> + <members>64803:13335</members> + <members>64888:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x3_4byte</name> + <members>origin:13335L:64803</members> + <members>origin:13335L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x6_2byte</name> + <members>64806:13335</members> + <members>64888:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_BIX.HU_x6_4byte</name> + <members>origin:13335L:64806</members> + <members>origin:13335L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x1_2byte</name> + <members>64801:13335</members> + <members>64812:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x1_4byte</name> + <members>origin:13335L:64801</members> + <members>origin:13335L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x2_2byte</name> + <members>64802:13335</members> + <members>64812:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x2_4byte</name> + <members>origin:13335L:64802</members> + <members>origin:13335L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x3_2byte</name> + <members>64803:13335</members> + <members>64812:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x3_4byte</name> + <members>origin:13335L:64803</members> + <members>origin:13335L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x6_2byte</name> + <members>64806:13335</members> + <members>64812:13335</members> + </community> + <community> + <name>TE_PREPEND_AS13335_x6_4byte</name> + <members>origin:13335L:64806</members> + <members>origin:13335L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x1_2byte</name> + <members>64801:5400</members> + <members>64888:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x1_4byte</name> + <members>origin:5400L:64801</members> + <members>origin:5400L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x2_2byte</name> + <members>64802:5400</members> + <members>64888:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x2_4byte</name> + <members>origin:5400L:64802</members> + <members>origin:5400L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x3_2byte</name> + <members>64803:5400</members> + <members>64888:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x3_4byte</name> + <members>origin:5400L:64803</members> + <members>origin:5400L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x6_2byte</name> + <members>64806:5400</members> + <members>64888:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_BIX.HU_x6_4byte</name> + <members>origin:5400L:64806</members> + <members>origin:5400L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x1_2byte</name> + <members>64801:5400</members> + <members>64812:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x1_4byte</name> + <members>origin:5400L:64801</members> + <members>origin:5400L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x2_2byte</name> + <members>64802:5400</members> + <members>64812:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x2_4byte</name> + <members>origin:5400L:64802</members> + <members>origin:5400L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x3_2byte</name> + <members>64803:5400</members> + <members>64812:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x3_4byte</name> + <members>origin:5400L:64803</members> + <members>origin:5400L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x6_2byte</name> + <members>64806:5400</members> + <members>64812:5400</members> + </community> + <community> + <name>TE_PREPEND_AS5400_x6_4byte</name> + <members>origin:5400L:64806</members> + <members>origin:5400L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS63293_BUD_2byte</name> + <members>64818:63293</members> + </community> + <community> + <name>TE_PREPEND_AS63293_BUD_4byte</name> + <members>origin:63293L:64818</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x1_2byte</name> + <members>TE_PREPEND_AS63293_x1_PREPEND_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x1_2byte_BUD</name> + <members>TE_PREPEND_AS63293_x1_PREPEND_2byte</members> + <members>TE_PREPEND_AS63293_BUD_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x1_4byte</name> + <members>TE_PREPEND_AS63293_x1_PREPEND_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x1_4byte_BUD</name> + <members>TE_PREPEND_AS63293_x1_PREPEND_4byte</members> + <members>TE_PREPEND_AS63293_BUD_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x1_PREPEND_2byte</name> + <members>64801:63293</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x1_PREPEND_4byte</name> + <members>origin:63293L:64801</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x2_2byte</name> + <members>TE_PREPEND_AS63293_x2_PREPEND_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x2_2byte_BUD</name> + <members>TE_PREPEND_AS63293_x2_PREPEND_2byte</members> + <members>TE_PREPEND_AS63293_BUD_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x2_4byte</name> + <members>TE_PREPEND_AS63293_x2_PREPEND_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x2_4byte_BUD</name> + <members>TE_PREPEND_AS63293_x2_PREPEND_4byte</members> + <members>TE_PREPEND_AS63293_BUD_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x2_PREPEND_2byte</name> + <members>64802:63293</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x2_PREPEND_4byte</name> + <members>origin:63293L:64802</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x3_2byte</name> + <members>TE_PREPEND_AS63293_x3_PREPEND_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x3_2byte_BUD</name> + <members>TE_PREPEND_AS63293_x3_PREPEND_2byte</members> + <members>TE_PREPEND_AS63293_BUD_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x3_4byte</name> + <members>TE_PREPEND_AS63293_x3_PREPEND_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x3_4byte_BUD</name> + <members>TE_PREPEND_AS63293_x3_PREPEND_4byte</members> + <members>TE_PREPEND_AS63293_BUD_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x3_PREPEND_2byte</name> + <members>64803:63293</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x3_PREPEND_4byte</name> + <members>origin:63293L:64803</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x6_2byte</name> + <members>TE_PREPEND_AS63293_x6_PREPEND_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x6_2byte_BUD</name> + <members>TE_PREPEND_AS63293_x6_PREPEND_2byte</members> + <members>TE_PREPEND_AS63293_BUD_2byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x6_4byte</name> + <members>TE_PREPEND_AS63293_x6_PREPEND_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x6_4byte_BUD</name> + <members>TE_PREPEND_AS63293_x6_PREPEND_4byte</members> + <members>TE_PREPEND_AS63293_BUD_4byte</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x6_PREPEND_2byte</name> + <members>64806:63293</members> + </community> + <community> + <name>TE_PREPEND_AS63293_x6_PREPEND_4byte</name> + <members>origin:63293L:64806</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x1_2byte</name> + <members>64801:6939</members> + <members>64888:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x1_4byte</name> + <members>origin:6939L:64801</members> + <members>origin:6939L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x2_2byte</name> + <members>64802:6939</members> + <members>64888:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x2_4byte</name> + <members>origin:6939L:64802</members> + <members>origin:6939L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x3_2byte</name> + <members>64803:6939</members> + <members>64888:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x3_4byte</name> + <members>origin:6939L:64803</members> + <members>origin:6939L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x6_2byte</name> + <members>64806:6939</members> + <members>64888:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_BIX.HU_x6_4byte</name> + <members>origin:6939L:64806</members> + <members>origin:6939L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x1_2byte</name> + <members>64801:6939</members> + <members>64812:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x1_4byte</name> + <members>origin:6939L:64801</members> + <members>origin:6939L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x2_2byte</name> + <members>64802:6939</members> + <members>64812:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x2_4byte</name> + <members>origin:6939L:64802</members> + <members>origin:6939L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x3_2byte</name> + <members>64803:6939</members> + <members>64812:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x3_4byte</name> + <members>origin:6939L:64803</members> + <members>origin:6939L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x6_2byte</name> + <members>64806:6939</members> + <members>64812:6939</members> + </community> + <community> + <name>TE_PREPEND_AS6939_x6_4byte</name> + <members>origin:6939L:64806</members> + <members>origin:6939L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x1_2byte</name> + <members>64801:8075</members> + <members>64888:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x1_4byte</name> + <members>origin:8075L:64801</members> + <members>origin:8075L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x2_2byte</name> + <members>64802:8075</members> + <members>64888:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x2_4byte</name> + <members>origin:8075L:64802</members> + <members>origin:8075L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x3_2byte</name> + <members>64803:8075</members> + <members>64888:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x3_4byte</name> + <members>origin:8075L:64803</members> + <members>origin:8075L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x6_2byte</name> + <members>64806:8075</members> + <members>64888:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_BIX.HU_x6_4byte</name> + <members>origin:8075L:64806</members> + <members>origin:8075L:64888</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x1_2byte</name> + <members>64801:8075</members> + <members>64812:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x1_4byte</name> + <members>origin:8075L:64801</members> + <members>origin:8075L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x2_2byte</name> + <members>64802:8075</members> + <members>64812:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x2_4byte</name> + <members>origin:8075L:64802</members> + <members>origin:8075L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x3_2byte</name> + <members>64803:8075</members> + <members>64812:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x3_4byte</name> + <members>origin:8075L:64803</members> + <members>origin:8075L:64812</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x6_2byte</name> + <members>64806:8075</members> + <members>64812:8075</members> + </community> + <community> + <name>TE_PREPEND_AS8075_x6_4byte</name> + <members>origin:8075L:64806</members> + <members>origin:8075L:64812</members> + </community> + <community> + <name>TE_PRIVATE_COMMUNITIES</name> + <members>^(6451[2-9]|645[2-9][0-9]|64[6-9][0-9][0-9]|65[0-4][0-9][0-9]|655[0-2][0-9]|6553[0-5]).*$</members> + </community> + <community> + <name>coriant-mgmt</name> + <members>target:20965:991</members> + </community> + <community> + <name>geant-IAS-dws-block</name> + <members>64512:65534</members> + </community> + <community> + <name>geant-IAS-dws-nren</name> + <members>64700:65534</members> + </community> + <community> + <name>geant-IAS-dws-prepend1</name> + <members>64801:65534</members> + </community> + <community> + <name>geant-IAS-dws-prepend2</name> + <members>64802:65534</members> + </community> + <community> + <name>geant-IAS-dws-prepend3</name> + <members>64803:65534</members> + </community> + <community> + <name>geant-IAS-dws-prepend6</name> + <members>64806:65534</members> + </community> + <community> + <name>geant-IAS-private-peer-BUD</name> + <members>21320:64718</members> + </community> + <community> + <name>geant-RTBH</name> + <members>20965:0008</members> + </community> + <community> + <name>geant-adv2-private-peer</name> + <members>20965:65533</members> + </community> + <community> + <name>geant-adv2-public-peer</name> + <members>20965:65532</members> + </community> + <community> + <name>geant-amres-block</name> + <members>64512:13092</members> + </community> + <community> + <name>geant-anycast</name> + <members>20965:0002</members> + </community> + <community> + <name>geant-cesnet-block</name> + <members>64512:2852</members> + </community> + <community> + <name>geant-cogent</name> + <members>20965:174</members> + </community> + <community> + <name>geant-dummy</name> + <members>20965:65000</members> + </community> + <community> + <name>geant-dws</name> + <members>20965:7777</members> + </community> + <community> + <name>geant-dws-block</name> + <members>20965:7000</members> + </community> + <community> + <name>geant-dws-budapest</name> + <members>21320:64518</members> + </community> + <community> + <name>geant-dws-cogent-block</name> + <members>64512:174</members> + </community> + <community> + <name>geant-dws-cogent-block2</name> + <members>64512:174</members> + </community> + <community> + <name>geant-dws-nren</name> + <members>20965:65534</members> + </community> + <community> + <name>geant-dws-prepend1</name> + <members>20965:7010</members> + </community> + <community> + <name>geant-dws-prepend2</name> + <members>20965:7020</members> + </community> + <community> + <name>geant-dws-prepend3</name> + <members>20965:7030</members> + </community> + <community> + <name>geant-dws-prepend6</name> + <members>20965:7060</members> + </community> + <community> + <name>geant-dws-telia-block</name> + <members>64512:1299</members> + </community> + <community> + <name>geant-dws-telia-block2</name> + <members>64500:1299</members> + </community> + <community> + <name>geant-google</name> + <members>20965:15169</members> + </community> + <community> + <name>geant-grena</name> + <members>20965:20545</members> + </community> + <community> + <name>geant-helix</name> + <members>20965:65293</members> + </community> + <community> + <name>geant-hungarnet-block</name> + <members>64512:1955</members> + </community> + <community> + <name>geant-ixpeers</name> + <members>20965:0003</members> + </community> + <community> + <name>geant-m6bone</name> + <members>20965:1717</members> + </community> + <community> + <name>geant-mren-block</name> + <members>64512:40981</members> + </community> + <community> + <name>geant-nasra</name> + <members>20965:47623</members> + </community> + <community> + <name>geant-nren-bud</name> + <members>21320:64918</members> + </community> + <community> + <name>geant-nrn</name> + <members>20965:0155</members> + </community> + <community> + <name>geant-peer-RE</name> + <members>20965:65530</members> + </community> + <community> + <name>geant-peers</name> + <members>20965:0004</members> + </community> + <community> + <name>geant-private-peers-prepend</name> + <members>20965:65531</members> + </community> + <community> + <name>geant-private-peers-prepend-1</name> + <members>20965:1111</members> + </community> + <community> + <name>geant-telia</name> + <members>20965:1299</members> + </community> + <community> + <name>geant-ulakbim-block</name> + <members>64512:8517</members> + </community> + <community> + <name>ias-routes</name> + <members>target:20965:333</members> + </community> + <community> + <name>lhcone-vpn</name> + <members>target:20965:111</members> + </community> + <community> + <name>mdvpn-comm</name> + <members>target:20965:65100</members> + </community> + <community> + <name>mgmt-vpn</name> + <members>target:20965:999</members> + </community> + <community> + <name>no-export</name> + <members>no-export</members> + </community> + <community> + <name>peers-prepend-3</name> + <members>20965:0313</members> + </community> + <as-path> + <name>AS-PRIVATE</name> + <path>.* (0|64512-65535|4200000000-4294967295) .*</path> + </as-path> + <as-path> + <name>MAX-AS_PATH</name> + <path>.{41,}</path> + </as-path> + <as-path> + <name>RENATER</name> + <path>2200.*</path> + </as-path> + <as-path> + <name>ULTIMUM-IO</name> + <path>2852 198725</path> + </as-path> + <as-path> + <name>AS-SELF</name> + <path>.*(20965|21320).*</path> + </as-path> + </policy-options> + <class-of-service protect="protect"> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + <import>default</import> + <forwarding-class> + <name>best-effort</name> + <loss-priority> + <name>low</name> + <code-points>af11</code-points> + <code-points>af12</code-points> + <code-points>af13</code-points> + </loss-priority> + </forwarding-class> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + <import>default</import> + <forwarding-class> + <name>best-effort</name> + <loss-priority> + <name>low</name> + <code-points>af11</code-points> + <code-points>af12</code-points> + <code-points>af13</code-points> + </loss-priority> + </forwarding-class> + </dscp-ipv6> + <exp> + <name>GEANT-BASIC</name> + <import>default</import> + <forwarding-class> + <name>best-effort</name> + <loss-priority> + <name>low</name> + <code-points>100</code-points> + <code-points>101</code-points> + </loss-priority> + </forwarding-class> + </exp> + </classifiers> + <drop-profiles> + <name>BEST-EFFORT</name> + <interpolate> + <fill-level>75</fill-level> + <fill-level>80</fill-level> + <fill-level>85</fill-level> + <fill-level>90</fill-level> + <fill-level>95</fill-level> + <fill-level>100</fill-level> + <drop-probability>0</drop-probability> + <drop-probability>25</drop-probability> + <drop-probability>75</drop-probability> + <drop-probability>90</drop-probability> + <drop-probability>95</drop-probability> + <drop-probability>100</drop-probability> + </interpolate> + </drop-profiles> + <interfaces> + <interface> + <name>et-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>ge-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>so-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>xe-*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + <interface> + <name>ae*</name> + <scheduler-map>GEANT-BASIC</scheduler-map> + <unit> + <name>*</name> + <classifiers> + <dscp> + <name>GEANT-BASIC</name> + </dscp> + <dscp-ipv6> + <name>GEANT-BASIC</name> + </dscp-ipv6> + <exp> + <classifier-name>GEANT-BASIC</classifier-name> + </exp> + </classifiers> + </unit> + </interface> + </interfaces> + <scheduler-maps> + <name>GEANT-BASIC</name> + <forwarding-class> + <name>expedited-forwarding</name> + <scheduler>EXPEDITED-FORWARDING</scheduler> + </forwarding-class> + <forwarding-class> + <name>network-control</name> + <scheduler>NETWORK-CONTROL</scheduler> + </forwarding-class> + <forwarding-class> + <name>best-effort</name> + <scheduler>BEST-EFFORT</scheduler> + </forwarding-class> + </scheduler-maps> + <schedulers> + <name>EXPEDITED-FORWARDING</name> + <transmit-rate> + <percent>15</percent> + <rate-limit/> + </transmit-rate> + <buffer-size> + <temporal>15k</temporal> + </buffer-size> + <priority>strict-high</priority> + </schedulers> + <schedulers> + <name>BEST-EFFORT</name> + <transmit-rate> + <remainder> + </remainder> + </transmit-rate> + <buffer-size> + <remainder> + </remainder> + </buffer-size> + <priority>low</priority> + <drop-profile-map> + <loss-priority>any</loss-priority> + <protocol>any</protocol> + <drop-profile>BEST-EFFORT</drop-profile> + </drop-profile-map> + </schedulers> + <schedulers> + <name>NETWORK-CONTROL</name> + <transmit-rate> + <percent>5</percent> + </transmit-rate> + <buffer-size> + <percent>5</percent> + </buffer-size> + <priority>high</priority> + </schedulers> + </class-of-service> + <firewall> + <family> + <inet> + <filter> + <name>router-access-out</name> + <term> + <name>geant-network-control-traffic</name> + <from> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <accept/> + </then> + </term> + <term> + <name>accept</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-cogent-v4</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>urpf-filter-level3-v4</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>Cogent-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_32</name> + <then> + <next>term</next> + <dscp>32</dscp> + </then> + </term> + <term> + <name>COUNT_UDP_389</name> + <from> + <protocol>udp</protocol> + <source-port>389</source-port> + </from> + <then> + <count>cogent_src_port_389_udp</count> + <next>term</next> + </then> + </term> + <term> + <name>tmp-ddos-block</name> + <from> + <destination-address> + <name>83.171.0.144/32</name> + </destination-address> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <count>LITnet-DDOS-ATTACK</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>litnet-attack-udp</name> + <from> + <destination-address> + <name>83.171.11.56/29</name> + </destination-address> + <destination-address> + <name>193.219.128.49/32</name> + </destination-address> + <protocol>udp</protocol> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>38.229.66.20/32</name> + </source-address> + <source-address> + <name>193.231.140.82/32</name> + </source-address> + <source-address> + <name>149.6.182.113/32</name> + </source-address> + <destination-address> + <name>62.40.97.11/32</name> + </destination-address> + <destination-address> + <name>62.40.97.12/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-KENTIK</name> + <from> + <source-address> + <name>193.177.129.61/32</name> + </source-address> + <destination-address> + <name>62.40.96.0/23</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>212.113.0.10/32</name> + </source-address> + <source-address> + <name>212.113.0.9/32</name> + </source-address> + <source-address> + <name>149.6.182.113/32</name> + </source-address> + <destination-address> + <name>62.40.114.1/32</name> + </destination-address> + <destination-address> + <name>62.40.97.1/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <source-address> + <name>149.6.182.113/32</name> + </source-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + <protocol>ipv6</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>GEANT_RADIUS_Accept</name> + <from> + <source-prefix-list> + <name>GEANT_TS</name> + </source-prefix-list> + <destination-prefix-list> + <name>GEANT_RADIUS</name> + </destination-prefix-list> + <destination-port>1645</destination-port> + <destination-port>1646</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <destination-address> + <name>62.40.122.210/32</name> + </destination-address> + <destination-address> + <name>62.40.120.123/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + <port>https</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Protect_GEANT_DC</name> + <from> + <prefix-list> + <name>GEANT-DC</name> + </prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>ICMP-DWS-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GPS-access</name> + <from> + <source-address> + <name>81.140.67.218/32</name> + </source-address> + <source-address> + <name>109.204.98.42/32</name> + </source-address> + <destination-address> + <name>62.40.115.92/32</name> + </destination-address> + <destination-address> + <name>62.40.115.156/32</name> + </destination-address> + <destination-port>4001</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Iron-Mountain-Access</name> + <from> + <source-address> + <name>193.239.113.128/25</name> + </source-address> + <source-address> + <name>193.30.234.0/24</name> + </source-address> + <source-address> + <name>208.66.139.142/32</name> + </source-address> + <source-address> + <name>208.66.139.165/32</name> + </source-address> + <destination-prefix-list> + <name>GEANT-IM-backup</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <source-port>443</source-port> + <source-port>2144</source-port> + <source-port>2145</source-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Infinera-access-to-DNA</name> + <from> + <source-prefix-list> + <name>Infinera-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>Infinera-DNA-servers</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Infinera-access-to-ATC</name> + <from> + <source-prefix-list> + <name>Infinera-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>infinera-atc</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NASRA-GRE</name> + <from> + <source-address> + <name>93.187.161.54/32</name> + </source-address> + <protocol>gre</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Deepfield-access</name> + <from> + <source-prefix-list> + <name>deepfield-support</name> + </source-prefix-list> + <destination-prefix-list> + <name>deepfield-servers</name> + </destination-prefix-list> + </from> + </term> + <term> + <name>Imerja-access</name> + <from> + <source-prefix-list> + <name>imerja-external</name> + </source-prefix-list> + <destination-prefix-list> + <name>dashboard-vm</name> + </destination-prefix-list> + <destination-prefix-list> + <name>Infinera-DNA-servers</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>xantaro-support-ssh</name> + <from> + <source-prefix-list> + <name>xantaro-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>router-loopbacks</name> + </destination-prefix-list> + <destination-prefix-list> + <name>qfx-vme-interfaces</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>xantaro-space-proxy</name> + <from> + <source-address> + <name>81.209.178.241/32</name> + </source-address> + <source-address> + <name>81.89.231.9/32</name> + </source-address> + <destination-address> + <name>62.40.120.18/32</name> + </destination-address> + <port>443</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-KENTIK</name> + <from> + <source-address> + <name>193.177.128.0/22</name> + </source-address> + <destination-address> + <name>62.40.96.0/23</name> + </destination-address> + <protocol>udp</protocol> + <port>snmp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-allocated-prefixes</name> + <from> + <destination-address> + <name>208.48.23.146/32</name> + </destination-address> + <destination-address> + <name>213.248.77.90/32</name> + </destination-address> + <destination-address> + <name>207.138.144.46/32</name> + </destination-address> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>mcast-Cogent-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-Cogent-in</count> + <accept/> + </then> + </term> + <term> + <name>DWS-dscp-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <next>term</next> + </then> + </term> + <term> + <name>RUNNET</name> + <from> + <source-prefix-list> + <name>route-from-RUNNET</name> + </source-prefix-list> + </from> + <then> + <count>c-runnet-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>Cogent-out</name> + <term> + <name>as-Cogent-out</name> + <from> + <destination-prefix-list> + <name>NASA-prefixes</name> + </destination-prefix-list> + </from> + <then> + <count>as-Cogent-out</count> + <next>term</next> + </then> + </term> + <term> + <name>DWS-Cogent-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-Cogent-out</count> + <accept/> + </then> + </term> + <term> + <name>LBE-Cogent-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-Cogent-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-Cogent-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-Cogent-out</count> + <accept/> + </then> + </term> + <term> + <name>RUNNET</name> + <from> + <destination-prefix-list> + <name>route-from-RUNNET</name> + </destination-prefix-list> + </from> + <then> + <count>c-runnet-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LHCONE-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>AMRES-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>62.40.125.178/32</name> + </source-address> + <source-address> + <name>147.91.0.117/32</name> + </source-address> + <destination-address> + <name>62.40.125.177/32</name> + </destination-address> + <destination-address> + <name>62.40.96.24/32</name> + </destination-address> + <destination-address> + <name>62.40.96.23/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>147.91.0.129/32</name> + </source-address> + <destination-address> + <name>62.40.125.177/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-allow</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>JRA2_MICHAL_ACCESS</name> + <from> + <source-prefix-list> + <name>JRA2_MICHAL_ACCESS_SRCIPS</name> + </source-prefix-list> + <destination-prefix-list> + <name>JRA2_MICHAL_ACCESS_DSTIPS</name> + </destination-prefix-list> + <port inactive="inactive">22</port> + <port inactive="inactive">443</port> + <port inactive="inactive">80</port> + <port inactive="inactive">8080</port> + <port inactive="inactive">8443</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <accept/> + </then> + </term> + <term> + <name>LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>mcast-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>AMRES-out</name> + <interface-specific/> + <term> + <name>temp_DDOS_count</name> + <from> + <destination-address> + <name>91.187.132.18/32</name> + </destination-address> + <protocol>udp</protocol> + </from> + <then> + <count>DDOS_Counter</count> + <next>term</next> + </then> + </term> + <term> + <name>AMRES-DWS-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <policer>pol-AMRES-DWS-out</policer> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>AMRES-DWS-same-out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <policer>pol-AMRES-DWS-out</policer> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>LBE-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-amres</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>DWS-in</name> + <term> + <name>Iron-Mountain-Access</name> + <from> + <port>443</port> + <port>2144</port> + <port>2145</port> + </from> + </term> + </filter> + <filter> + <name>urpf-filter-cesnet</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>CESNET-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>62.40.124.30/32</name> + </source-address> + <source-address> + <name>62.40.124.14/32</name> + </source-address> + <destination-address> + <name>62.40.124.29/32</name> + </destination-address> + <destination-address> + <name>62.40.124.13/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>195.113.156.26/32</name> + </source-address> + <destination-address> + <name>62.40.124.13/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <source-address> + <name>195.113.144.2/32</name> + </source-address> + <source-address> + <name>62.40.124.30/32</name> + </source-address> + <source-address> + <name>62.40.124.14/32</name> + </source-address> + <source-address> + <name>195.113.156.26/32</name> + </source-address> + <destination-address> + <name>62.40.124.29/32</name> + </destination-address> + <destination-address> + <name>62.40.114.5/32</name> + </destination-address> + <destination-address> + <name>62.40.97.1/32</name> + </destination-address> + <destination-address> + <name>62.40.124.13/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP-server-accept</name> + <from> + <source-address> + <name>195.113.144.201/32</name> + </source-address> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-allow</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + </then> + </term> + <term> + <name>JRA2_MICHAL_ACCESS</name> + <from> + <source-prefix-list> + <name>JRA2_MICHAL_ACCESS_SRCIPS</name> + </source-prefix-list> + <destination-prefix-list> + <name>JRA2_MICHAL_ACCESS_DSTIPS</name> + </destination-prefix-list> + <port inactive="inactive">22</port> + <port inactive="inactive">443</port> + <port inactive="inactive">80</port> + <port inactive="inactive">8080</port> + <port inactive="inactive">8443</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <accept/> + </then> + </term> + <term> + <name>LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>mcast-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>CESNET-out</name> + <interface-specific/> + <term> + <name>DWS-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>DWS-same-out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>LBE-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>HUNGA-out</name> + <interface-specific/> + <term> + <name>rl-DWS-AMREJ-out</name> + <from> + <destination-address> + <name>147.91.0.0/17</name> + </destination-address> + <destination-address> + <name>160.99.0.0/16</name> + </destination-address> + <dscp>32</dscp> + </from> + <then> + <policer>pol-AMREJ-DWS-out</policer> + <count>DWS-AMREJ-out</count> + <accept/> + </then> + </term> + <term> + <name>rl-DWS-AMREJ-same-out</name> + <from> + <interface-group>1</interface-group> + <destination-address> + <name>147.91.0.0/17</name> + </destination-address> + <destination-address> + <name>160.99.0.0/16</name> + </destination-address> + </from> + <then> + <policer>pol-AMREJ-DWS-out</policer> + <count>DWS-AMREJ-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <policer>pol-HUNGA-DWS-out</policer> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>DWS-same-out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <policer>pol-HUNGA-DWS-out</policer> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>LBE-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LAN-in</name> + <term> + <name>LAN-DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <policer>pol-DWS-in</policer> + <count>dws-in</count> + <loss-priority>high</loss-priority> + <forwarding-class>best-effort</forwarding-class> + <accept/> + </then> + </term> + <term> + <name>LAN-LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>block-snmp</name> + <from> + <address> + <name>62.40.109.187/32</name> + </address> + <port>snmp</port> + <port>snmptrap</port> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LAN-out</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>gidp-in</name> + <term> + <name>GIDP-SMTP-Access</name> + <from> + <source-address> + <name>62.40.121.114/32</name> + </source-address> + <destination-address> + <name>62.40.123.146/32</name> + </destination-address> + <destination-address> + <name>62.40.104.134/31</name> + </destination-address> + <port>25</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP-accept</name> + <from> + <destination-address> + <name>62.40.114.53/32</name> + </destination-address> + <destination-address> + <name>62.40.114.54/32</name> + </destination-address> + <protocol>udp</protocol> + <port>ntp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DANTE-accept</name> + <from> + <destination-prefix-list> + <name>corporate-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-access</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>external-equipment-access</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <protocol>udp</protocol> + <port>33434-33690</port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>gidp-HU</name> + <from> + <source-address> + <name>62.40.121.114/32</name> + </source-address> + <source-port>22</source-port> + <source-port>80</source-port> + <source-port>443</source-port> + <source-port>8443</source-port> + <source-port>389</source-port> + <source-port>8000-9000</source-port> + <source-port>3306</source-port> + <source-port>3406</source-port> + <source-port>18080</source-port> + <source-port>18443</source-port> + <source-port>28080</source-port> + <source-port>28443</source-port> + <source-port>4088</source-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>snmp-access</name> + <from> + <destination-address> + <name>62.40.123.164/32</name> + </destination-address> + <destination-address> + <name>62.40.123.165/32</name> + </destination-address> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>RHN-Updates</name> + <from> + <source-address> + <name>62.40.121.114/32</name> + </source-address> + <destination-address> + <name>209.132.183.42/32</name> + </destination-address> + <destination-address> + <name>209.132.183.44/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>80</port> + <port>443</port> + <port>8080</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>gidp-out</name> + <term> + <name>GIDP-SMTP-Access</name> + <from> + <source-address> + <name>62.40.123.146/32</name> + </source-address> + <source-address> + <name>62.40.104.134/31</name> + </source-address> + <destination-address> + <name>62.40.121.114/32</name> + </destination-address> + <port>25</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP-accept</name> + <from> + <source-address> + <name>62.40.114.53/32</name> + </source-address> + <source-address> + <name>62.40.114.54/32</name> + </source-address> + <protocol>udp</protocol> + <port>ntp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>allow-DANTE</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>allow-NOC</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <protocol>udp</protocol> + <port>33434-33690</port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>gidp-out</name> + <from> + <destination-address> + <name>62.40.121.114/32</name> + </destination-address> + <port>22</port> + <port>80</port> + <port>443</port> + <port>8443</port> + <port>389</port> + <port>8000-9000</port> + <port>3306</port> + <port>3406</port> + <port>18080</port> + <port>18443</port> + <port>28080</port> + <port>28443</port> + <port>4088</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>snmp-access</name> + <from> + <source-address> + <name>62.40.123.164/32</name> + </source-address> + <source-address> + <name>62.40.123.165/32</name> + </source-address> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RHN-Updates</name> + <from> + <source-address> + <name>209.132.183.42/32</name> + </source-address> + <source-address> + <name>209.132.183.44/32</name> + </source-address> + <destination-address> + <name>62.40.121.114/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>80</port> + <port>443</port> + <port>8080</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>log</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>HUNGA-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>62.40.124.102/32</name> + </source-address> + <source-address> + <name>195.111.97.167/32</name> + </source-address> + <source-address> + <name>195.111.97.179/32</name> + </source-address> + <destination-address> + <name>62.40.124.101/32</name> + </destination-address> + <destination-address> + <name>62.40.96.23/32</name> + </destination-address> + <destination-address> + <name>62.40.96.24/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>62.40.124.102/32</name> + </source-address> + <source-address> + <name>195.111.97.7/32</name> + </source-address> + <destination-address> + <name>62.40.124.101/32</name> + </destination-address> + <destination-address> + <name>62.40.114.1/32</name> + </destination-address> + <destination-address> + <name>62.40.124.17/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <source-address> + <name>62.40.124.102/32</name> + </source-address> + <source-address> + <name>195.111.97.7/32</name> + </source-address> + <destination-address> + <name>62.40.124.101/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-allow</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <accept/> + </then> + </term> + <term> + <name>LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>mcast-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-hungarnet</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>MREN-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>test</name> + <from> + <source-address> + <name>89.188.32.126/32</name> + </source-address> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>62.40.125.210/32</name> + </source-address> + <destination-address> + <name>62.40.125.209/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>62.40.125.210/32</name> + </source-address> + <destination-address> + <name>62.40.125.209/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <source-address> + <name>62.40.125.210/32</name> + </source-address> + <destination-address> + <name>62.40.125.209/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-allow</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <accept/> + </then> + </term> + <term> + <name>LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>mcast-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>MREN-out</name> + <interface-specific/> + <term> + <name>mren-DWS-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>mren-DWS-same-out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>LBE-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-mren</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>mgen-in</name> + <interface-specific/> + <term> + <name>mgen</name> + <from> + <source-address> + <name>62.40.96.0/19</name> + </source-address> + <destination-address> + <name>192.168.8.1/32</name> + </destination-address> + </from> + <then> + <count>mgen8-in</count> + </then> + </term> + <term> + <name>mgen9</name> + <from> + <source-address> + <name>62.40.96.0/19</name> + </source-address> + <destination-address> + <name>192.168.9.1/32</name> + </destination-address> + </from> + <then> + <count>mgen9-in</count> + </then> + </term> + <term> + <name>def</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>mgen-out</name> + <interface-specific/> + <term> + <name>mgen8</name> + <from> + <destination-address> + <name>192.168.8.1/32</name> + </destination-address> + </from> + <then> + <count>mgen8-out</count> + </then> + </term> + <term> + <name>mgen9</name> + <from> + <destination-address> + <name>192.168.9.1/32</name> + </destination-address> + </from> + <then> + <count>mgen9-out</count> + </then> + </term> + <term> + <name>def</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-ulakbim</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>ULAKB-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>62.40.125.130/32</name> + </source-address> + <destination-address> + <name>62.40.125.129/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>62.40.125.130/32</name> + </source-address> + <destination-address> + <name>62.40.125.129/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <source-address> + <name>62.40.125.130/32</name> + </source-address> + <destination-address> + <name>62.40.125.129/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-allow</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <accept/> + </then> + </term> + <term> + <name>LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>mcast-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ULAKB-out</name> + <interface-specific/> + <term> + <name>DWS-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <policer>pol-ULAKBIM-DWS-out</policer> + <count>DWS-out</count> + <next>term</next> + </then> + </term> + <term> + <name>LBE-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL190-IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>53</port> + <port>43</port> + <port>80</port> + <port>4321</port> + <port>4823</port> + <port>5000-6200</port> + <port>861</port> + <port>8760-8960</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL190-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>80</port> + <port>4321</port> + <port>4823</port> + <port>5000-6200</port> + <port>861</port> + <port>8760-8960</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>RTBH-count</name> + <term> + <name>count</name> + <then> + <count>RTBH-count</count> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL200-IN</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <destination-prefix-list> + <name>EXTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>80</port> + <port>53</port> + <port>1194</port> + <port>2114</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL200-OUT</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>443</port> + <port>80</port> + <port>53</port> + <port>1194</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access-out</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL170-IN</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <destination-prefix-list> + <name>EXTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term inactive="inactive"> + <name>VLAN-Access_Allow</name> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL170-OUT</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <source-prefix-list> + <name>camera-server</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access-out</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL7-IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>corporate-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT_TS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>corporate-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL7-OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT_TS</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>BWCTL_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>22</destination-port> + <destination-port>25</destination-port> + <destination-port>53</destination-port> + <destination-port>80</destination-port> + <destination-port>88</destination-port> + <destination-port>139</destination-port> + <destination-port>389</destination-port> + <destination-port>443</destination-port> + <destination-port>445</destination-port> + <destination-port>464</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>8140</destination-port> + <destination-port>10051</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <port>53</port> + <port>88</port> + <port>123</port> + <port>139</port> + <port>137</port> + <port>389</port> + <port>464</port> + <port>3000-65535</port> + <port>10051</port> + <port>10050</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BWCTL_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>22</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>4823</destination-port> + <destination-port>5000-5900</destination-port> + <destination-port>6001-6200</destination-port> + <destination-port>8090</destination-port> + <destination-port>5001-5900</destination-port> + <destination-port>10050</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <port>53</port> + <port>5000-5900</port> + <port>6001-6200</port> + <port>33434-33634</port> + <port>10050-10051</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP_ALLOW</name> + <from> + <source-prefix-list> + <name>GEANT_NTP</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_AMRES_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>AMRES_blocking_service</name> + <from> + <destination-prefix-list> + <name>AMRES-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>AMRES-blocking-service</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>83.97.88.6/32</name> + </source-address> + <destination-address> + <name>83.97.88.5/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>83.97.88.6/32</name> + </source-address> + <destination-address> + <name>83.97.88.5/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>83.97.88.6/32</name> + </source-address> + <destination-address> + <name>83.97.88.5/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>83.97.88.6/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_AMRES_OUT</name> + <interface-specific/> + <term> + <name>DWS_out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS_same_out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_CESNET_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>CESNET_blocking_service</name> + <from> + <destination-prefix-list> + <name>CESNET-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>CESNET-blocking-service</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>83.97.88.38/32</name> + </source-address> + <destination-address> + <name>83.97.88.37/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>83.97.88.38/32</name> + </source-address> + <destination-address> + <name>83.97.88.37/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>83.97.88.38/32</name> + </source-address> + <destination-address> + <name>83.97.88.37/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>83.97.88.38/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_CESNET_OUT</name> + <interface-specific/> + <term> + <name>DWS_out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS_same_out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_HUNGARNET_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>HUNGARNET_blocking_service</name> + <from> + <destination-prefix-list> + <name>HUNGARNET-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>HUNGARNET-blocking-service</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>83.97.88.82/32</name> + </source-address> + <source-address> + <name>195.111.97.179/32</name> + </source-address> + <destination-address> + <name>83.97.88.81/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>83.97.88.82/32</name> + </source-address> + <destination-address> + <name>83.97.88.81/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>83.97.88.82/32</name> + </source-address> + <destination-address> + <name>83.97.88.81/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>83.97.88.82/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_HUNGARNET_OUT</name> + <interface-specific/> + <term> + <name>DWS_out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS_same_out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_MREN_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>MREN_blocking_service</name> + <from> + <destination-prefix-list> + <name>MREN-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>MREN-blocking-service</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>83.97.88.110/32</name> + </source-address> + <destination-address> + <name>83.97.88.109/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>83.97.88.110/32</name> + </source-address> + <destination-address> + <name>83.97.88.109/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>83.97.88.110/32</name> + </source-address> + <destination-address> + <name>83.97.88.109/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>83.97.88.110/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_MREN_OUT</name> + <interface-specific/> + <term> + <name>DWS_out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <policer>pol-mren-dws-out</policer> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS_same_out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ULAKBIM_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>ULAKBIM_blocking_service</name> + <from> + <destination-prefix-list> + <name>ULAKBIM-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>ULAKBIM-blocking-service</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>83.97.88.162/32</name> + </source-address> + <destination-address> + <name>83.97.88.161/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>83.97.88.162/32</name> + </source-address> + <destination-address> + <name>83.97.88.161/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>83.97.88.162/32</name> + </source-address> + <destination-address> + <name>83.97.88.161/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>83.97.88.162/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ULAKBIM_OUT</name> + <interface-specific/> + <term> + <name>DWS_out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS_same_out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL07_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>corporate-address-space</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT_TS</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT_NTP</name> + </destination-prefix-list> + <destination-prefix-list> + <name>superpop-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP_External</name> + <from> + <destination-prefix-list> + <name>GEANT_NTP_APPLIANCES_USERS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <policer>GEANT_NTP_APPLIANCES_POLICER</policer> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL07_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT_TS</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT_NTP</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT_SUPERPOP_ESXI</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT_SUPERPOP_DRAC</name> + </source-prefix-list> + <source-prefix-list> + <name>superpop-address-space</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <destination-port>22</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP_External</name> + <from> + <source-prefix-list> + <name>GEANT_NTP_APPLIANCES_USERS</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <policer>GEANT_NTP_APPLIANCES_POLICER</policer> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_GRENA_OUT</name> + <term> + <name>MCAST_out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-grena</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>nren_GRENA_IN</name> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>GRENA_blocking_service</name> + <from> + <destination-prefix-list> + <name>GRENA-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>GRENA-blocking-service</count> + <discard> + </discard> + </then> + </term> + <term> + <name>KEEPALIVES_IN</name> + <from> + <source-address> + <name>62.40.125.34/32</name> + </source-address> + <destination-address> + <name>255.255.255.255/32</name> + </destination-address> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-src</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-dst</count> + <discard> + </discard> + </then> + </term> + <term> + <name>Transit_network_control_traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>GRE_ALLOW</name> + <from> + <protocol>gre</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>62.40.125.34/32</name> + </source-address> + <destination-address> + <name>62.40.125.33/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP_protect</name> + <from> + <source-address> + <name>62.40.125.34/32</name> + </source-address> + <destination-address> + <name>62.40.125.33/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM_protect</name> + <from> + <source-address> + <name>62.40.125.34/32</name> + </source-address> + <destination-address> + <name>62.40.125.33/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>62.40.125.34/32</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External_project_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_allow</name> + <from> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>MCAST_in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_HEAD_IN</name> + <term> + <name>EXTERNAL_filter</name> + <from> + <destination-prefix-list> + <name>EXTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Established</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_HEAD_OUT</name> + <term> + <name>EXTERNAL_filter</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Established</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC_DANTE_access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>DANTE-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>83.97.92.0/22</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_TAIL_IN</name> + <term> + <name>GEANT_SRV_SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_TAIL_OUT</name> + <term> + <name>GEANT_SRV_SSH_Access-out</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>VL023_MIDDLE_IN</name> + <term inactive="inactive"> + <name>VLAN_Access_Allow</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL023_MIDDLE_OUT</name> + <term> + <name>VLAN_Access_Allow</name> + <from> + <port>443</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PSMGMT_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>22</destination-port> + <destination-port>53</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>8090</destination-port> + <destination-port>8096</destination-port> + <destination-port>4505-4506</destination-port> + <destination-port>8140</destination-port> + <destination-port>10051</destination-port> + <destination-port>5222</destination-port> + <destination-port>5269</destination-port> + <destination-port>5693</destination-port> + <destination-port>69</destination-port> + <destination-port>161</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <port>53</port> + <port>33434-33634</port> + <port>10050-10051</port> + <port>69</port> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP_ALLOW</name> + <from> + <prefix-list> + <name>GEANT_NTP</name> + </prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PSMGMT_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>22</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>8090</destination-port> + <destination-port>10050</destination-port> + <destination-port>5222</destination-port> + <destination-port>5347</destination-port> + <destination-port>5693</destination-port> + <destination-port>5666</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <port>53</port> + <port>33434-33634</port> + <port>10050-10051</port> + <port>161</port> + <port>162</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP_ALLOW</name> + <from> + <source-prefix-list> + <name>GEANT_NTP</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>OWAMP_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>861</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>OWAMP_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <protocol>tcp</protocol> + <destination-port>861</destination-port> + <destination-port>8090</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <protocol>udp</protocol> + <destination-port>8760-9960</destination-port> + <destination-port>33434-33634</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>FACEBOOK-out</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>FACEBOOK-in</name> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_41</name> + <then> + <next>term</next> + <dscp>41</dscp> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogon-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-source-filtering</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>83.97.89.80/32</name> + </source-address> + <destination-address> + <name>83.97.89.6/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.120.123/32</name> + </destination-address> + <destination-address> + <name>62.40.123.11/32</name> + </destination-address> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ROUTER_access</name> + <term> + <name>TCP_established_accept</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SSH_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space-short</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>pref-list-router-access</name> + </source-prefix-list> + <source-prefix-list> + <name>cnis-server</name> + </source-prefix-list> + <source-prefix-list> + <name>ncc-oob-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>space-local</name> + </source-prefix-list> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <source-prefix-list> + <name>restena-access</name> + </source-prefix-list> + <source-prefix-list> + <name>nmteam-dev-servers</name> + </source-prefix-list> + <source-prefix-list> + <name>vuln-scanner</name> + </source-prefix-list> + <source-prefix-list> + <name>renater-access</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-JUNOSSPACE</name> + </source-prefix-list> + <source-prefix-list> + <name>xantaro-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-lg</name> + </source-prefix-list> + <source-prefix-list> + <name>dashboard-servers</name> + </source-prefix-list> + <source-prefix-list> + <name>opennsa-servers</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-rancid</name> + </source-prefix-list> + <protocol>tcp</protocol> + <destination-port>ssh</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_accept</name> + <from> + <source-prefix-list> + <name>RE_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_DUMMY_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>CLS_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>lhcone-l3vpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>taas-control_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>mgmt-l3vpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>GWS_GRNET_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn-nren-gn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>confine-l3vpn_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>VPN-PROXY_BGP_inet</name> + </source-prefix-list> + <source-prefix-list> + <name>VRR_BGP_inet</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>FTP_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space-short</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>ncc-oob-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>xantaro-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RADIUS_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>1812</port> + <port>1813</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP_accept</name> + <from> + <source-prefix-list> + <name>geant-routers</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-cameras</name> + </source-prefix-list> + <source-prefix-list> + <name>ddos-scrubbing</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>ntp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Netconf_accept</name> + <from> + <source-prefix-list> + <name>GEANT-JUNOSSPACE</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Superpop-v4</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>830</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP_accept</name> + <from> + <source-prefix-list> + <name>GEANT-SNMP</name> + </source-prefix-list> + <destination-port>161</destination-port> + </from> + <then> + <policer>lo0-flood</policer> + <accept/> + </then> + </term> + <term> + <name>DNS_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DNS</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-DNS-EXT</name> + </source-prefix-list> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>LDP_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-LDP</name> + </source-prefix-list> + <destination-port>646</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MPLS_LSP_echo_accept</name> + <from> + <source-prefix-list> + <name>geant-routers</name> + </source-prefix-list> + <protocol>udp</protocol> + <port>3503</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>RSVP_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>rsvp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM_access</name> + <from> + <protocol>pim</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BFD_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <port>3784</port> + <port>3785</port> + <port>4784</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>IGMP_accept</name> + <from> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>MSDP_accept</name> + <from> + <source-prefix-list> + <name>GEANT-MSDP</name> + </source-prefix-list> + <port>msdp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TRACEROUTE_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33534</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + <icmp-type>echo-reply</icmp-type> + <icmp-type>echo-request</icmp-type> + <icmp-type>unreachable</icmp-type> + <icmp-type>time-exceeded</icmp-type> + <icmp-type>timestamp</icmp-type> + <icmp-type>timestamp-reply</icmp-type> + </from> + <then> + <policer>lo0-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_HEAD_IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <next>term</next> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GOC_accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_HEAD_OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <next>term</next> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GOC_GEANT_accept</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>83.97.92.0/22</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_TAIL_OUT</name> + <term> + <name>GEANT_SSH_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_TAIL_IN</name> + <term> + <name>GEANT_SSH_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_HEAD_IN</name> + <term> + <name>INTERNAL_filter</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-space</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Established</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_HEAD_OUT</name> + <term> + <name>INTERNAL_filter</name> + <from> + <source-prefix-list> + <name>INTERNAL-address-space</name> + </source-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>Allow_Established</name> + <from> + <protocol>tcp</protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC_GEANT_access</name> + <from> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_TAIL_IN</name> + <term> + <name>GEANT_SRV_SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_TAIL_OUT</name> + <term> + <name>GEANT_SRV_SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space</name> + </source-prefix-list> + <protocol>tcp</protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard> + </discard> + </then> + </term> + </filter> + <filter> + <name>Telia-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_32</name> + <then> + <next>term</next> + <dscp>32</dscp> + </then> + </term> + <term> + <name>COUNT_UDP_389</name> + <from> + <protocol>udp</protocol> + <source-port>389</source-port> + </from> + <then> + <count>telia_src_port_389_udp</count> + <next>term</next> + </then> + </term> + <term> + <name>tmp-ddos-block</name> + <from> + <destination-address> + <name>83.171.0.144/32</name> + </destination-address> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <count>LITnet-DDOS-ATTACK</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>litnet-attack-udp</name> + <from> + <destination-address> + <name>83.171.11.56/29</name> + </destination-address> + <destination-address> + <name>193.219.128.49/32</name> + </destination-address> + <protocol>udp</protocol> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>80.239.135.138/32</name> + </source-address> + <source-address> + <name>38.229.66.20/32</name> + </source-address> + <source-address> + <name>193.231.140.82/32</name> + </source-address> + <destination-address> + <name>80.239.135.139/32</name> + </destination-address> + <destination-address> + <name>62.40.97.11/32</name> + </destination-address> + <destination-address> + <name>62.40.97.12/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-KENTIK</name> + <from> + <source-address> + <name>193.177.129.61/32</name> + </source-address> + <destination-address> + <name>62.40.96.0/23</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>MSDP-protect</name> + <from> + <source-address> + <name>212.113.0.10/32</name> + </source-address> + <source-address> + <name>212.113.0.9/32</name> + </source-address> + <source-address> + <name>80.239.135.138/32</name> + </source-address> + <destination-address> + <name>62.40.114.1/32</name> + </destination-address> + <destination-address> + <name>80.239.135.139/32</name> + </destination-address> + <destination-address> + <name>62.40.97.1/32</name> + </destination-address> + <destination-address> + <name>62.40.97.7/32</name> + </destination-address> + <destination-address> + <name>62.40.97.12/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-accept</count> + <accept/> + </then> + </term> + <term> + <name>MSDP-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>msdp</port> + </from> + <then> + <count>msdp-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>PIM-protect</name> + <from> + <source-address> + <name>80.239.135.138/32</name> + </source-address> + <destination-address> + <name>80.239.135.139/32</name> + </destination-address> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>PIM-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>pim</protocol> + <protocol>igmp</protocol> + </from> + <then> + <count>pim-attack</count> + <syslog/> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <prefix-list> + <name>geant-address-space</name> + </prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + <protocol>ipv6</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + <source-prefix-list> + <name>geantncc-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>GEANT_RADIUS_Accept</name> + <from> + <source-prefix-list> + <name>GEANT_TS</name> + </source-prefix-list> + <destination-prefix-list> + <name>GEANT_TS</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT_RADIUS</name> + </destination-prefix-list> + <destination-port>1645</destination-port> + <destination-port>1646</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <destination-address> + <name>62.40.122.210/32</name> + </destination-address> + <destination-address> + <name>62.40.120.123/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + <port>https</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-DWS-accept</name> + <from> + <destination-address> + <name>80.239.135.138/32</name> + </destination-address> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>GPS-access</name> + <from> + <source-address> + <name>81.140.67.218/32</name> + </source-address> + <source-address> + <name>109.204.98.42/32</name> + </source-address> + <destination-address> + <name>62.40.115.92/32</name> + </destination-address> + <destination-address> + <name>62.40.115.156/32</name> + </destination-address> + <destination-port>4001</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Iron-Mountain-Access</name> + <from> + <source-prefix-list> + <name>Iron-Mountain</name> + </source-prefix-list> + <destination-prefix-list> + <name>GEANT-IM-backup</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>443</port> + <port>2144</port> + <port>2145</port> + <port>2147</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Infinera-access-to-DNA</name> + <from> + <source-prefix-list> + <name>Infinera-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>Infinera-DNA-servers</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Infinera-access-to-ATC</name> + <from> + <source-prefix-list> + <name>Infinera-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>infinera-atc</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Deepfield-access</name> + <from> + <source-prefix-list> + <name>deepfield-support</name> + </source-prefix-list> + <destination-prefix-list> + <name>deepfield-servers</name> + </destination-prefix-list> + </from> + </term> + <term> + <name>Imerja-access</name> + <from> + <source-prefix-list> + <name>imerja-external</name> + </source-prefix-list> + <destination-prefix-list> + <name>dashboard-vm</name> + </destination-prefix-list> + <destination-prefix-list> + <name>Infinera-DNA-servers</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Protect_GEANT_DC</name> + <from> + <prefix-list> + <name>GEANT-DC</name> + </prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>xantaro-support-ssh</name> + <from> + <source-prefix-list> + <name>xantaro-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>router-loopbacks</name> + </destination-prefix-list> + <destination-prefix-list> + <name>qfx-vme-interfaces</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>xantaro-space-proxy</name> + <from> + <source-address> + <name>81.209.178.241/32</name> + </source-address> + <source-address> + <name>81.89.231.9/32</name> + </source-address> + <destination-address> + <name>62.40.120.18/32</name> + </destination-address> + <port>443</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SNMP-KENTIK</name> + <from> + <source-address> + <name>193.177.128.0/22</name> + </source-address> + <destination-address> + <name>62.40.96.0/23</name> + </destination-address> + <protocol>udp</protocol> + <port>snmp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-allocated-prefixes</name> + <from> + <destination-address> + <name>208.48.23.146/32</name> + </destination-address> + <destination-address> + <name>213.248.77.90/32</name> + </destination-address> + <destination-address> + <name>207.138.144.46/32</name> + </destination-address> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>mcast-telia-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-telia-in</count> + <accept/> + </then> + </term> + <term> + <name>DWS-dscp-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <next>term</next> + </then> + </term> + <term> + <name>RUNNET</name> + <from> + <source-prefix-list> + <name>route-from-RUNNET</name> + </source-prefix-list> + </from> + <then> + <count>runnet-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>Telia-out</name> + <term> + <name>DWS-telia-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-telia-out</count> + <accept/> + </then> + </term> + <term> + <name>LBE-telia-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-telia-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-telia-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-telia-out</count> + <accept/> + </then> + </term> + <term> + <name>RUNNET</name> + <from> + <destination-prefix-list> + <name>route-from-RUNNET</name> + </destination-prefix-list> + </from> + <then> + <count>runnet-out</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>bone-out</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>bone-in</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BIX.HU-out</name> + <term> + <name>DWS-out</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>DWS-same-out</name> + <from> + <interface-group>1</interface-group> + </from> + <then> + <count>DWS-out</count> + <accept/> + </then> + </term> + <term> + <name>LBE-out</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>LBE-out</count> + <accept/> + </then> + </term> + <term> + <name>mcast-out</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-out</count> + <accept/> + </then> + </term> + <term> + <name>MS-MAIL-LOG</name> + <from> + <source-address> + <name>62.40.123.146/32</name> + </source-address> + <source-address> + <name>62.40.104.134/31</name> + </source-address> + <protocol>tcp</protocol> + <port>smtp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BIX.HU-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_41</name> + <then> + <next>term</next> + <dscp>41</dscp> + </then> + </term> + <term> + <name>tmp-ddos-block</name> + <from> + <destination-address> + <name>83.171.0.144/32</name> + </destination-address> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <count>LITnet-DDOS-ATTACK</count> + <discard> + </discard> + </then> + </term> + <term> + <name>bogon-test</name> + <from> + <source-address> + <name>10.28.225.0/24</name> + </source-address> + </from> + <then> + <count>bogon-1028</count> + <discard> + </discard> + </then> + </term> + <term> + <name>BOGON-filter</name> + <from> + <source-prefix-list> + <name>bogons-list</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-source-counting</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>dos-destination-filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>External-Projects</name> + <from> + <destination-prefix-list> + <name>external-project</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>External-project-interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces</name> + </destination-prefix-list> + </from> + <then> + <discard> + </discard> + </then> + </term> + <term> + <name>transit-network-control-traffic</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <dscp>48</dscp> + <dscp>56</dscp> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <next>term</next> + </then> + </term> + <term> + <name>BGP-protect</name> + <from> + <source-address> + <name>193.188.137.1/32</name> + </source-address> + <source-address> + <name>193.188.137.2/32</name> + </source-address> + <source-address> + <name>193.188.137.175/32</name> + </source-address> + <source-address> + <name>193.188.137.53/32</name> + </source-address> + <source-address> + <name>193.188.137.27/32</name> + </source-address> + <source-address> + <name>193.188.137.21/32</name> + </source-address> + <source-address> + <name>193.188.137.51/32</name> + </source-address> + <destination-address> + <name>62.40.97.1/32</name> + </destination-address> + <destination-address> + <name>193.188.137.37/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-filter</name> + <from> + <destination-address> + <name>185.1.47.34/32</name> + </destination-address> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>tcp</protocol> + <port>bgp</port> + </from> + <then> + <count>bgp-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>TUNNEL-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>gre</protocol> + <protocol>ipip</protocol> + <protocol>ipv6</protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SPOOF-filter</name> + <from> + <source-prefix-list> + <name>corporate-address-space</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic</count> + <discard> + </discard> + </then> + </term> + <term> + <name>GEANT_RADIUS_Accept</name> + <from> + <source-prefix-list> + <name>GEANT_TS</name> + </source-prefix-list> + <destination-prefix-list> + <name>GEANT_RADIUS</name> + </destination-prefix-list> + <destination-port>1645</destination-port> + <destination-port>1646</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>62.40.122.147/32</name> + </destination-address> + <protocol>tcp</protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP-server-accept</name> + <from> + <source-address> + <name>138.96.64.10/32</name> + </source-address> + <protocol>udp</protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-accept</name> + <from> + <destination-prefix-list> + <name>geantncc-address-space</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS-server-accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS</name> + </destination-prefix-list> + <protocol>udp</protocol> + <protocol>tcp</protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>icmp</protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + <protocol>udp</protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>MS-MAIL-LOG</name> + <from> + <destination-address> + <name>62.40.123.146/32</name> + </destination-address> + <destination-address> + <name>62.40.104.134/31</name> + </destination-address> + <protocol>tcp</protocol> + <port>smtp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Deepfield-access</name> + <from> + <source-prefix-list> + <name>deepfield-support</name> + </source-prefix-list> + <destination-prefix-list> + <name>deepfield-servers</name> + </destination-prefix-list> + </from> + </term> + <term> + <name>Imerja-access</name> + <from> + <source-prefix-list> + <name>imerja-external</name> + </source-prefix-list> + <destination-prefix-list> + <name>dashboard-vm</name> + </destination-prefix-list> + <destination-prefix-list> + <name>Infinera-DNA-servers</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Infinera-access-to-DNA</name> + <from> + <source-prefix-list> + <name>Infinera-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>Infinera-DNA-servers</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Infinera-access-to-ATC</name> + <from> + <source-prefix-list> + <name>Infinera-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>infinera-atc</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>xantaro-support-ssh</name> + <from> + <source-prefix-list> + <name>xantaro-address-space</name> + </source-prefix-list> + <destination-prefix-list> + <name>router-loopbacks</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>xantaro-space-proxy</name> + <from> + <source-address> + <name>81.209.178.241/32</name> + </source-address> + <source-address> + <name>81.89.231.9/32</name> + </source-address> + <destination-address> + <name>62.40.120.18/32</name> + </destination-address> + <port>443</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space</name> + </destination-prefix-list> + </from> + <then> + <count>core-attack</count> + <discard> + </discard> + </then> + </term> + <term> + <name>DWS-in</name> + <from> + <dscp>32</dscp> + </from> + <then> + <count>dws-in</count> + <accept/> + </then> + </term> + <term> + <name>LBE-in</name> + <from> + <dscp>8</dscp> + </from> + <then> + <count>lbe-in</count> + <accept/> + </then> + </term> + <term> + <name>mcast-in</name> + <from> + <destination-address> + <name>224.0.0.0/4</name> + </destination-address> + </from> + <then> + <count>mcast-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + </inet> + <inet6> + <filter> + <name>router-access-ipv6</name> + <term> + <name>nren-access-ssh</name> + <from> + <source-prefix-list> + <name>restena-access-v6</name> + </source-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>allow-ssh-ftp</name> + <from> + <comment>/* RANCID Instances */</comment> + <source-address> + <name>2001:798:f99b:14::/64</name> + </source-address> + <comment>/* MRLG Instances */</comment> + <source-address> + <name>2001:798:ff9a:28::/64</name> + </source-address> + <comment>/* LG Instances */</comment> + <source-address> + <name>2001:798:22:96::/64</name> + </source-address> + <source-address> + <name>2001:798:2::/35</name> + </source-address> + <source-address> + <name>2001:630:280::/48</name> + </source-address> + <source-address> + <name>2001:799:3::/64</name> + </source-address> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + <destination-port>ssh</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>discard</name> + <from> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + <destination-port>ssh</destination-port> + <destination-port>telnet</destination-port> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>ubfd-block</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>6784</destination-port> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>bone6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpf-filter-cogent-v6</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>urpf-filter-level3-v6</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>Cogent6-out</name> + <term> + <name>RUNNET</name> + <from> + <destination-prefix-list> + <name>route-from-RUNNET6</name> + </destination-prefix-list> + </from> + <then> + <count>c-runnet6-out</count> + <accept/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>AMRES6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:1b:10aa::2/128</name> + </source-address> + <destination-address> + <name>2001:798:1b:10aa::1/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects-interfaces6</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <count>extv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>external-project-interfaces6</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>AMRES6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpfv6-filter-amres</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>urpfv6-filter-cesnet</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>CESNET6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:13:10aa::2/128</name> + </source-address> + <source-address> + <name>2001:798:1b:10aa::1a/128</name> + </source-address> + <destination-address> + <name>2001:798:13:10aa::1/128</name> + </destination-address> + <destination-address> + <name>2001:798:1b:10aa::19/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <destination-address> + <name>2001:798:13:10ff::1/128</name> + </destination-address> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects-interfaces6</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <count>extv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>CESNET6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpfv6-filter-hungarnet</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>HUNGA6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:1b:10aa::6/128</name> + </source-address> + <source-address> + <name>2001:798:2018:10aa::a/128</name> + </source-address> + <source-address> + <name>2001:738::179:1/128</name> + </source-address> + <destination-address> + <name>2001:798:2018:10aa::9/128</name> + </destination-address> + <destination-address> + <name>2001:798:1b:10aa::5/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects-interfaces6</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <count>extv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>external-project-interfaces6</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>HUNGA6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>MREN6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:1b:10aa::a/128</name> + </source-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects-interfaces6</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <count>extv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>external-project-interfaces6</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>MREN6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>urpfv6-filter-mren</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>urpfv6-filter-ulakbim</name> + <apply-groups>urpf-template</apply-groups> + </filter> + <filter> + <name>ULAKB6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:2c:10aa::6/126</name> + </source-address> + <destination-address> + <name>2001:798:2c:10aa::5/126</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>NREN-router-accept</name> + <from> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>workstations-SSHv6-accept</name> + <from> + <source-address> + <name>2001:0798:5e00::/48</name> + </source-address> + <source-address> + <name>2001:0798:5e01::/48</name> + </source-address> + <destination-address> + <name>2001:798:2028:006e::10/64</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:0047::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects-interfaces6</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <count>extv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ULAKB6-out</name> + <interface-specific/> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>LHCONE6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VIX6-in</name> + <term> + <name>BGP6-protect</name> + <from> + <destination-address> + <name>2001:798:22:20ff::3/128</name> + </destination-address> + </from> + </term> + </filter> + <filter> + <name>VM-RANGE-VL200-V6-IN</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <destination-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>443</port> + <port>53</port> + <port>80</port> + <port>1194</port> + <port>2114</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard/> + </then> + </term> + </filter> + <filter> + <name>VM-RANGE-VL200-V6-OUT</name> + <term> + <name>EXTERNAL-filter</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </source-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <port>443</port> + <port>53</port> + <port>80</port> + <port>1194</port> + <port>2114</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <log/> + <discard/> + </then> + </term> + </filter> + <filter> + <name>BWCTL_V6_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>22</destination-port> + <destination-port>25</destination-port> + <destination-port>53</destination-port> + <destination-port>80</destination-port> + <destination-port>88</destination-port> + <destination-port>139</destination-port> + <destination-port>389</destination-port> + <destination-port>443</destination-port> + <destination-port>445</destination-port> + <destination-port>464</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>8140</destination-port> + <destination-port>10051</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <port>53</port> + <port>88</port> + <port>123</port> + <port>139</port> + <port>137</port> + <port>389</port> + <port>464</port> + <port>3000-65535</port> + <port>10051</port> + <port>10050</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow</name> + <from> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BWCTL_V6_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>22</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>4823</destination-port> + <destination-port>5000-5900</destination-port> + <destination-port>6001-6200</destination-port> + <destination-port>8090</destination-port> + <destination-port>5001-5900</destination-port> + <destination-port>10050</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <port>5000-5900</port> + <port>6001-6200</port> + <port>33434-33634</port> + <port>53</port> + <port>10050</port> + <port>10051</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NTP_ALLOW</name> + <from> + <source-prefix-list> + <name>GEANT_NTP</name> + </source-prefix-list> + <payload-protocol>udp</payload-protocol> + <port>123</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL022_V6_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>861</destination-port> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL022_V6_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>861</destination-port> + <destination-port>8090</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>8760-9960</destination-port> + <destination-port>33434-33634</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_HEAD_IN</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-spaceV6</name> + </destination-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Outbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_TAIL_IN</name> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + <term> + <name>GEANT_SSH_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_HEAD_OUT</name> + <term> + <name>PROTECTED_EXTERNAL_TO_INTERNAL</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </source-prefix-list> + </from> + <then> + <policer>pol-rate-limiting</policer> + <next>term</next> + </then> + </term> + <term> + <name>Allow_Inbound_Established</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC-DANTE-access</name> + <from> + <source-prefix-list> + <name>geantnoc-address-space-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT-DC-INFRASTRUCTURE-Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GOC_GEANT_accept</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>2001:798:3::0/64</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PROTECTED_EXTERNAL_V6_TAIL_OUT</name> + <term> + <name>GEANT-SRV-SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + <term> + <name>GEANT_SRV_SSH_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + </filter> + <filter> + <name>bone6-in</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_AMRES_V6_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>AMRES_blocking_service</name> + <from> + <destination-prefix-list> + <name>AMRES6-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>AMRES-blocking-service6</count> + <discard/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-src</count> + <discard/> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-dst</count> + <discard/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>2001:798:1::a/128</name> + </source-address> + <destination-address> + <name>2001:798:1::9/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>2001:798:1::a/128</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External_Projects_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_AMRES_V6_OUT</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_CESNET_V6_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>CESNET_blocking_service</name> + <from> + <destination-prefix-list> + <name>CESNET6-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>CESNET-blocking-service6</count> + <discard/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-src</count> + <discard/> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-dst</count> + <discard/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>2001:798:1::2a/128</name> + </source-address> + <destination-address> + <name>2001:798:1::29/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>2001:798:1::2a/128</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External_Projects_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_CESNET_V6_OUT</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_HUNGARNET_V6_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>HUNGARNET_blocking_service</name> + <from> + <destination-prefix-list> + <name>HUNGARNET6-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>HUNGARNET-blocking-service6</count> + <discard/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-src</count> + <discard/> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-dst</count> + <discard/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>2001:798:1::66/128</name> + </source-address> + <source-address> + <name>2001:738::179:1/128</name> + </source-address> + <destination-address> + <name>2001:798:1::65/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>2001:798:1::66/128</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External_Projects_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_HUNGARNET_V6_OUT</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_MREN_V6_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>MREN_blocking_service</name> + <from> + <destination-prefix-list> + <name>MREN6-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>MREN-blocking-service6</count> + <discard/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-src</count> + <discard/> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-dst</count> + <discard/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>2001:798:1::86/128</name> + </source-address> + <destination-address> + <name>2001:798:1::85/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>2001:798:1::86/128</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External_Projects_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_MREN_V6_OUT</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ULAKBIM_V6_IN</name> + <interface-specific/> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term inactive="inactive"> + <name>ULAKBIM_blocking_service</name> + <from> + <destination-prefix-list> + <name>ULAKBIM6-blocking-list</name> + </destination-prefix-list> + </from> + <then> + <count>ULAKBIM-blocking-service6</count> + <discard/> + </then> + </term> + <term> + <name>BOGON_filter</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DOS_source_filtering</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-src</count> + <discard/> + </then> + </term> + <term> + <name>DOS_destination_filtering</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6-dst</count> + <discard/> + </then> + </term> + <term> + <name>BGP_protect</name> + <from> + <source-address> + <name>2001:798:1::c6/128</name> + </source-address> + <destination-address> + <name>2001:798:1::c5/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF_filter</name> + <from> + <source-address> + <name>2001:798:1::c6/128</name> + <except/> + </source-address> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-ias-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NREN_router_accept</name> + <from> + <source-prefix-list> + <name>nren-access</name> + </source-prefix-list> + <destination-prefix-list> + <name>geant-routers</name> + </destination-prefix-list> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNS_server_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DNS-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP_traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External_Projects_interfaces</name> + <from> + <destination-prefix-list> + <name>external-project-interfaces6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>External_Projects</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE_filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>geant-ias-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>nren_IAS_ULAKBIM_V6_OUT</name> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>ROUTER_access_V6</name> + <term> + <name>SSH_accept</name> + <from> + <source-address> + <name>2001:798:f99b:14::/64</name> + </source-address> + <source-address> + <name>2001:798:ff9a:28::/64</name> + </source-address> + <source-address> + <name>2001:798:22:96::/64</name> + </source-address> + <source-address> + <name>2001:798:5e00::/48</name> + </source-address> + <source-address> + <name>2001:798:2::/35</name> + </source-address> + <source-address> + <name>2001:630:280::/48</name> + </source-address> + <source-address> + <name>2001:799:3::/64</name> + </source-address> + <source-address> + <name>2001:799:7::fe/128</name> + </source-address> + <source-address> + <name>2001:798:ffb4:6f::/64</name> + </source-address> + <source-address> + <name>2001:798:15:a2::/64</name> + </source-address> + <source-address> + <name>2001:610:9d8:7:8000::/112</name> + </source-address> + <source-address> + <name>2001:610:9d8:1::4/128</name> + </source-address> + <source-address> + <name>2001:798:64::/64</name> + </source-address> + <source-address> + <name>2001:799:64::/64</name> + </source-address> + <source-prefix-list> + <name>restena-access-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>dashboard-servers-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>opennsa-servers-v6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Netconf_accept</name> + <from> + <source-prefix-list> + <name>GEANT-Superpop-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geant-address-space-v6</name> + </source-prefix-list> + <payload-protocol>tcp</payload-protocol> + <destination-port>830</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SSH_discard</name> + <from> + <port>22</port> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>FTP_accept</name> + <from> + <source-address> + <name>2001:798:f99b:14::/64</name> + </source-address> + <source-address> + <name>2001:798:ff9a:28::/64</name> + </source-address> + <source-address> + <name>2001:798:22:96::/64</name> + </source-address> + <source-address> + <name>2001:798:5e00::/48</name> + </source-address> + <source-address> + <name>2001:798:2::/35</name> + </source-address> + <source-address> + <name>2001:630:280::/48</name> + </source-address> + <source-address> + <name>2001:799:3::/64</name> + </source-address> + <destination-port>ftp</destination-port> + <destination-port>ftp-data</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_accept</name> + <from> + <source-prefix-list> + <name>RE_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_DUMMY_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>IAS_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>CLS_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>lhcone-l3vpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>taas-control_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>mgmt-l3vpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>GWS_GRNET_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>mdvpn-nren-gn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>confine-l3vpn_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>VPN-PROXY_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>VRR_BGP_inet6</name> + </source-prefix-list> + <source-prefix-list> + <name>VPN-PROXY_RI_BGP_inet6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DENY</name> + <from> + <next-header>tcp</next-header> + <next-header>udp</next-header> + <port>bgp</port> + <port>ftp</port> + <port>ftp-data</port> + <port>ssh</port> + <port>telnet</port> + <port>6784</port> + </from> + <then> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_V6_HEAD_IN</name> + <term> + <name>EXTERNAL_filter</name> + <from> + <destination-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>Allow_Established</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_Access</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_V6_HEAD_OUT</name> + <term> + <name>EXTERNAL_filter</name> + <from> + <source-prefix-list> + <name>EXTERNAL-address-spaceV6</name> + </source-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>Allow_Established</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC_DANTE_access</name> + <from> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>dante-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_Access</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>SuperPoP_DC_accept</name> + <from> + <source-address> + <name>2001:798:3::0/64</name> + </source-address> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <payload-protocol>tcp</payload-protocol> + <port>88</port> + <port>389</port> + <port>445</port> + <port>464</port> + <port>3268</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_V6_TAIL_IN</name> + <term> + <name>GEANT_SRV_SSH_Access</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + </filter> + <filter> + <name>INTERNAL_V6_TAIL_OUT</name> + <term> + <name>GEANT_SRV_SSH_Access</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + </filter> + <filter> + <name>VL023_V6_MIDDLE_IN</name> + <term inactive="inactive"> + <name>VLAN_Access_Allow</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>VL023_V6_MIDDLE_OUT</name> + <term> + <name>VLAN_Access_Allow</name> + <from> + <port>443</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PSMGMT_V6_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>22</destination-port> + <destination-port>53</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>8090</destination-port> + <destination-port>8096</destination-port> + <destination-port>4505-4506</destination-port> + <destination-port>8140</destination-port> + <destination-port>10051</destination-port> + <destination-port>5222</destination-port> + <destination-port>5269</destination-port> + <destination-port>5693</destination-port> + <destination-port>69</destination-port> + <destination-port>161</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <port>53</port> + <port>33434-33634</port> + <port>10050-10051</port> + <port>69</port> + <port>161</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>PSMGMT_V6_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>22</destination-port> + <destination-port>80</destination-port> + <destination-port>443</destination-port> + <destination-port>8090</destination-port> + <destination-port>10050</destination-port> + <destination-port>10051</destination-port> + <destination-port>5222</destination-port> + <destination-port>5347</destination-port> + <destination-port>5693</destination-port> + <destination-port>5666</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <port>53</port> + <port>33434-33634</port> + <port>10050-10051</port> + <port>161</port> + <port>162</port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>OWAMP_V6_MIDDLE_IN</name> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>3000-65535</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>861</destination-port> + <destination-port>3000-65535</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>OWAMP_V6_MIDDLE_OUT</name> + <term> + <name>VLAN-Access_Allow_TCP</name> + <from> + <payload-protocol>tcp</payload-protocol> + <destination-port>861</destination-port> + <destination-port>8090</destination-port> + <destination-port>443</destination-port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>VLAN-Access_Allow_UDP</name> + <from> + <payload-protocol>udp</payload-protocol> + <destination-port>8760-9960</destination-port> + <destination-port>33434-33634</destination-port> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>Cogent6-in</name> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_32</name> + <then> + <traffic-class>32</traffic-class> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter_v6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DoS-filtering_v6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>BGP_v6-protect</name> + <from> + <source-address> + <name>2001:b30:1000:19::2/128</name> + </source-address> + <source-address> + <name>2620:0:6b0::26e5:4207/128</name> + </source-address> + <destination-address> + <name>2001:798:14:20ff::1/128</name> + </destination-address> + <destination-address> + <name>2001:798:22:20ff::3/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-KENTIK</name> + <from> + <source-address> + <name>2a0c:dec0:f100:1::179/128</name> + </source-address> + <destination-address> + <name>2001:798::/32</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_v6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter_v6</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>2001:798:28:50::11/128</name> + </destination-address> + <destination-address> + <name>2001:798:ff10:a5::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + <port>https</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Protect_GEANT_DC</name> + <from> + <prefix-list> + <name>GEANT-DC-v6</name> + </prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>External-Projects_v6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + </from> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>Allow_Inbound_Established_v6</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>RUNNET</name> + <from> + <source-prefix-list> + <name>route-from-RUNNET6</name> + </source-prefix-list> + </from> + <then> + <count>c-runnet6-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>FACEBOOKV6-out</name> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>FACEBOOKV6-in</name> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_41</name> + <then> + <traffic-class>41</traffic-class> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>ICMPv6-check</name> + <from> + <icmp-type>packet-too-big</icmp-type> + </from> + <then> + <count>ICMPv6-PTB</count> + <next>term</next> + </then> + </term> + <term> + <name>PIM-V6-log</name> + <from> + <next-header>pim</next-header> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:798:1:1::10/128</name> + </source-address> + <destination-address> + <name>2001:798:1::/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <destination-address> + <name>2001:798:28:50::11/64</name> + </destination-address> + <destination-address> + <name>2001:798:14:96::3/128</name> + </destination-address> + <destination-address> + <name>2001:798:ff10:a5::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>router-access-out_V6</name> + <term> + <name>geant-network-control-traffic</name> + <from> + <traffic-class>48</traffic-class> + <traffic-class>56</traffic-class> + </from> + <then> + <loss-priority>low</loss-priority> + <forwarding-class>network-control</forwarding-class> + <accept/> + </then> + </term> + <term> + <name>accept</name> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_V6_HEAD_IN</name> + <term> + <name>INTERNAL_filter</name> + <from> + <destination-prefix-list> + <name>INTERNAL-address-spaceV6</name> + </destination-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <destination-prefix-list> + <name>GEANT-DC-v6</name> + </destination-prefix-list> + <destination-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_V6_HEAD_OUT</name> + <term> + <name>INTERNAL_filter</name> + <from> + <source-prefix-list> + <name>INTERNAL-address-spaceV6</name> + </source-prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>Established_accept</name> + <from> + <next-header>tcp</next-header> + <tcp-established/> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>NOC_GEANT_accept</name> + <from> + <source-prefix-list> + <name>geantnoc-address-space-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>GEANT_DC_INFRASTRUCTURE_accept</name> + <from> + <source-prefix-list> + <name>GEANT-DC-v6</name> + </source-prefix-list> + <source-prefix-list> + <name>GEANT-Infrastructure-v6</name> + </source-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_V6_TAIL_IN</name> + <term> + <name>GEANT_SSH_accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + </filter> + <filter> + <name>EXTERNAL_V6_TAIL_OUT</name> + <term> + <name>GEANT_SSH_accept</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + <next-header>tcp</next-header> + <port>ssh</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP_accept</name> + <from> + <next-header>icmpv6</next-header> + </from> + <then> + <policer>ICMP-flood</policer> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <discard/> + </then> + </term> + </filter> + <filter> + <name>Telia6-in</name> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_32</name> + <then> + <traffic-class>32</traffic-class> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter_v6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>DoS-filtering_v6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>BGP_v6-protect</name> + <from> + <source-address> + <name>2001:2000:3080:14f2::1/126</name> + </source-address> + <source-address> + <name>2001:b30:1000:19::2/128</name> + </source-address> + <source-address> + <name>2620:0:6b0::26e5:4207/128</name> + </source-address> + <destination-address> + <name>2001:2000:3080:14f2::2/126</name> + </destination-address> + <destination-address> + <name>2001:798:14:20ff::1/128</name> + </destination-address> + <destination-address> + <name>2001:798:22:20ff::3/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP-KENTIK</name> + <from> + <source-address> + <name>2a0c:dec0:f100:1::179/128</name> + </source-address> + <destination-address> + <name>2001:798::/32</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP_v6-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <syslog/> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter_v6</name> + <from> + <source-prefix-list> + <name>geant-address-space-V6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>WEB-server-accept</name> + <from> + <destination-address> + <name>2001:798:28:50::11/128</name> + </destination-address> + <destination-address> + <name>2001:798:ff10:a5::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + <port>https</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>Protect_GEANT_DC</name> + <from> + <prefix-list> + <name>GEANT-DC-v6</name> + </prefix-list> + </from> + <then> + <discard/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>External-Projects_v6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + </from> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>Allow_Inbound_Established_v6</name> + <from> + <payload-protocol>tcp</payload-protocol> + <tcp-established/> + </from> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>RUNNET</name> + <from> + <source-prefix-list> + <name>route-from-RUNNET6</name> + </source-prefix-list> + </from> + <then> + <count>runnet6-in</count> + <accept/> + </then> + </term> + <term> + <name>default</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>Telia6-out</name> + <term> + <name>RUNNET</name> + <from> + <destination-prefix-list> + <name>route-from-RUNNET6</name> + </destination-prefix-list> + </from> + <then> + <count>runnet6-out</count> + <accept/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BIX.HU-V6-out</name> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + <filter> + <name>BIX.HU-V6-in</name> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>MARK_DSCP_41</name> + <then> + <traffic-class>41</traffic-class> + <next>term</next> + </then> + </term> + <term> + <name>BOGON-filter6</name> + <from> + <source-prefix-list> + <name>bogons-list6</name> + </source-prefix-list> + </from> + <then> + <count>bogons-source6</count> + <discard/> + </then> + </term> + <term> + <name>PIM-V6-log</name> + <from> + <next-header>pim</next-header> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>dos-source-counting6</name> + <from> + <source-prefix-list> + <name>dos-attack-source-count6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-destination-counting6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination-count6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic-count6</count> + <next>term</next> + </then> + </term> + <term> + <name>dos-source-filtering6</name> + <from> + <source-prefix-list> + <name>dos-attack-source6</name> + </source-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>dos-destination-filtering6</name> + <from> + <destination-prefix-list> + <name>dos-attack-destination6</name> + </destination-prefix-list> + </from> + <then> + <count>dos-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>SPOOF-filter6</name> + <from> + <source-prefix-list> + <name>corporate-address-space6</name> + </source-prefix-list> + <source-prefix-list> + <name>geantnoc-address-space6</name> + </source-prefix-list> + </from> + <then> + <count>spoofed-attack-traffic6</count> + <discard/> + </then> + </term> + <term> + <name>NOC6-accept</name> + <from> + <destination-prefix-list> + <name>geantnoc-address-space6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-tcp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>9142</port> + <port>10259</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>BGP6-protect</name> + <from> + <source-address> + <name>2001:7f8:35::5507:1/128</name> + </source-address> + <source-address> + <name>2001:7f8:35::5507:2/128</name> + </source-address> + <source-address> + <name>2001:7f8:35::6939:1/128</name> + </source-address> + <source-address> + <name>2001:7f8:35::5400:1/128</name> + </source-address> + <source-address> + <name>2001:7f8:35::1:3335:1/128</name> + </source-address> + <source-address> + <name>2001:7f8:35::8075:1/128</name> + </source-address> + <source-address> + <name>2001:7f8:35::8075:2/128</name> + </source-address> + <destination-address> + <name>2001:7f8:35::2:1320:1/128</name> + </destination-address> + <port>bgp</port> + </from> + <then> + <count>bgpv6-accept</count> + <accept/> + </then> + </term> + <term> + <name>BGP6-filter</name> + <from> + <destination-address> + <name>2001:7f8:36::51e5:0:1/128</name> + </destination-address> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <port>bgp</port> + </from> + <then> + <count>bgpv6-attack</count> + <discard/> + </then> + </term> + <term> + <name>WEB6-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::60/128</name> + </destination-address> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <destination-address> + <name>2001:798:ff10:a5::2/128</name> + </destination-address> + <payload-protocol>tcp</payload-protocol> + <port>http</port> + <port>443</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>DNSv6-server-accept</name> + <from> + <destination-address> + <name>2001:798:2:284d::30/128</name> + </destination-address> + <destination-address> + <name>2001:798:ff23:28::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + <payload-protocol>tcp</payload-protocol> + <port>domain</port> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>TTM-allow-udp</name> + <from> + <destination-address> + <name>2001:798:2012:47::2/128</name> + </destination-address> + <payload-protocol>udp</payload-protocol> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>ICMP-accept</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>icmp6</payload-protocol> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>UDP-traceroute6</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + <payload-protocol>udp</payload-protocol> + <destination-port>33434-33690</destination-port> + </from> + <then> + <policer>ICMPv6-flood</policer> + <accept/> + </then> + </term> + <term> + <name>External-Projects6</name> + <from> + <destination-prefix-list> + <name>external-project6</name> + </destination-prefix-list> + </from> + <then> + <accept/> + </then> + </term> + <term> + <name>CORE-filter</name> + <from> + <destination-prefix-list> + <name>geant-address-space-V6</name> + </destination-prefix-list> + </from> + <then> + <count>corev6-attack</count> + <discard/> + </then> + </term> + <term> + <name>count-ipv6</name> + <then> + <count>ipv6-counter</count> + <accept/> + </then> + </term> + </filter> + </inet6> + <mpls> + <filter> + <name>NREN-MDVPN-MPLS-in</name> + <term> + <name>sample</name> + <then> + <sample/> + <next>term</next> + </then> + </term> + <term> + <name>default</name> + <then> + <accept/> + </then> + </term> + </filter> + </mpls> + </family> + <policer> + <name>pol-DWS-in</name> + <if-exceeding> + <bandwidth-limit>5m</bandwidth-limit> + <burst-size-limit>625k</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>ICMP-flood</name> + <if-exceeding> + <bandwidth-limit>10m</bandwidth-limit> + <burst-size-limit>1m</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>ICMPv6-flood</name> + <if-exceeding> + <bandwidth-limit>10m</bandwidth-limit> + <burst-size-limit>1m</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-AMRES-DWS-out</name> + <if-exceeding> + <bandwidth-limit>3g</bandwidth-limit> + <burst-size-limit>6250000</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-HUNGA-DWS-out</name> + <filter-specific/> + <if-exceeding> + <bandwidth-limit>1577500000</bandwidth-limit> + <burst-size-limit>6250000</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-AMREJ-DWS-out</name> + <filter-specific/> + <if-exceeding> + <bandwidth-limit>200m</bandwidth-limit> + <burst-size-limit>6250000</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-rate-limiting</name> + <if-exceeding> + <bandwidth-limit>10m</bandwidth-limit> + <burst-size-limit>125k</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-ULAKBIM-DWS-out</name> + <if-exceeding> + <bandwidth-limit>4g</bandwidth-limit> + <burst-size-limit>2500000</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>GEANT_NTP_APPLIANCES_POLICER</name> + <if-exceeding> + <bandwidth-limit>250k</bandwidth-limit> + <burst-size-limit>4500</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>lo0-flood</name> + <if-exceeding> + <bandwidth-limit>12m</bandwidth-limit> + <burst-size-limit>900k</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + <policer> + <name>pol-mren-dws-out</name> + <if-exceeding> + <bandwidth-limit>77m</bandwidth-limit> + <burst-size-limit>50k</burst-size-limit> + </if-exceeding> + <then> + <discard/> + </then> + </policer> + </firewall> + <routing-instances> + <instance inactive="inactive"> + <name>CLEAN_IAS</name> + <description>Clean IAS VRF traffic returned from scrubber</description> + <instance-type>vrf</instance-type> + <route-distinguisher> + <rd-type>20965:334</rd-type> + </route-distinguisher> + <vrf-import>ps-into-clean-ias-vrf</vrf-import> + <vrf-export>ps-from-clean-ias-vrf</vrf-export> + <vrf-target> + <community>target:20965:334</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <rib> + <name>CLEAN_IAS.inet6.0</name> + <static> + <route> + <name>2001:7f8:3c::/48</name> + <discard/> + </route> + </static> + </rib> + <static> + <route> + <name>83.97.88.0/23</name> + <discard/> + </route> + </static> + </routing-options> + </instance> + <instance> + <name>CLS</name> + <description>L3 BGP/MPLS VPN for Cloud Services (CLS)</description> + <instance-type>vrf</instance-type> + <route-distinguisher> + <rd-type>62.40.97.1:667</rd-type> + </route-distinguisher> + <vrf-import>ps-into-CLS-vrf</vrf-import> + <vrf-export>ps-from-CLS-vrf</vrf-export> + <vrf-target> + <community>target:20965:667</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <rib> + <name>CLS.inet.0</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>CLS.inet6.0</name> + <static> + <route> + <name>::/0</name> + <discard/> + </route> + <route> + <name>0100::/64</name> + <discard/> + <no-readvertise/> + </route> + </static> + <aggregate> + <route> + <name>2001:798::/64</name> + <community>20965:64912</community> + </route> + </aggregate> + </rib> + <static> + <route> + <name>0.0.0.0/0</name> + <discard/> + </route> + <route> + <name>192.0.2.101/32</name> + <discard/> + <no-readvertise/> + </route> + </static> + <aggregate> + <route> + <name>62.40.100.0/24</name> + <community>20965:64912</community> + </route> + </aggregate> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + <protocols> + <bgp> + <log-updown/> + <group> + <name>CLS-NRENS-ipv6</name> + <description>NRENS</description> + </group> + <group> + <name>CLS-NRENS</name> + <description>NRENS</description> + </group> + <group> + <name>CLS-PROVIDERS</name> + <description>PROVIDERS</description> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>cls-to-geant-geant-rtbh</ribgroup-name> + </rib-group> + </unicast> + </inet> + </family> + </group> + <group> + <name>CLS-PROVIDERS-ipv6</name> + <description>PROVIDERS</description> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>cls-to-geant-geant-rtbh6</ribgroup-name> + </rib-group> + </unicast> + </inet6> + </family> + </group> + </bgp> + </protocols> + </instance> + <instance> + <name>IAS</name> + <description>GEANT IAS Internet VRF</description> + <instance-type>vrf</instance-type> + <interface> + <name>lt-0/0/0.61</name> + </interface> + <interface> + <name>xe-5/1/6.0</name> + </interface> + <interface> + <name>ae10.333</name> + </interface> + <interface> + <name>ae11.333</name> + </interface> + <interface> + <name>ae13.333</name> + </interface> + <interface> + <name>ae14.0</name> + </interface> + <interface> + <name>ae15.333</name> + </interface> + <interface> + <name>ae16.333</name> + </interface> + <interface> + <name>ae17.0</name> + </interface> + <interface> + <name>ae18.10</name> + </interface> + <interface> + <name>ae18.11</name> + </interface> + <interface> + <name>ae19.0</name> + </interface> + <route-distinguisher> + <rd-type>20965:333</rd-type> + </route-distinguisher> + <vrf-import>ps-into-ias-vrf</vrf-import> + <vrf-export>ps-from-ias-vrf</vrf-export> + <vrf-target> + <community>target:20965:333</community> + </vrf-target> + <vrf-table-label> + <source-class-usage/> + </vrf-table-label> + <routing-options> + <rib> + <name>IAS.inet6.0</name> + <static> + <route> + <name>0100::/64</name> + <discard/> + <no-readvertise/> + </route> + <route> + <name>2001:798:1:1::/64</name> + <next-hop>2001:798:1::1</next-hop> + <install/> + <tag> + <metric-value>63293</metric-value> + </tag> + </route> + <route> + <name>2001:798:1::/48</name> + <discard/> + <community>21320:64912</community> + </route> + </static> + </rib> + <static> + <route> + <name>83.97.89.64/26</name> + <next-hop>83.97.89.7</next-hop> + <install/> + <tag> + <metric-value>63293</metric-value> + </tag> + </route> + <route> + <name>83.97.88.0/21</name> + <discard/> + <community>21320:64912</community> + <community>64700:65532</community> + <community>64700:65533</community> + <community>64700:65534</community> + </route> + <route> + <name>192.0.2.101/32</name> + <discard/> + <no-readvertise/> + </route> + </static> + <label> + <allocation>ps-direct-route-label</allocation> + </label> + </routing-options> + <protocols> + <bgp> + <log-updown/> + <group> + <name>IAS-NRENS</name> + <family> + <inet> + <unicast> + <rib-group> + <ribgroup-name>ias-to-geant-cls-rtbh</ribgroup-name> + </rib-group> + </unicast> + </inet> + </family> + <neighbor> + <name>83.97.88.6</name> + <description>-- Peering with AMRES --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-IAS-from-AMRES-nren</import> + <family> + <inet> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet> + </family> + <export>ps-advertise-default</export> + <export>ps-BOGONS</export> + <export>ps-IAS-to-AMRES-nren</export> + <peer-as>13092</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>83.97.88.38</name> + <description>-- Peering with CESNET --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-IAS-from-CESNET-backup-nren</import> + <family> + <inet> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-IAS-to-CESNET-backup-nren</export> + <peer-as>2852</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>83.97.88.82</name> + <description>-- Peering with HUNGARNET --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-IAS-from-HUNGARnet1-nren</import> + <family> + <inet> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-IAS-to-HUNGARnet1-nren</export> + <peer-as>1955</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>83.97.88.110</name> + <description>-- Peering with MREN --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-IAS-from-MREN-nren</import> + <family> + <inet> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-IAS-to-MREN</export> + <peer-as>40981</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>83.97.88.162</name> + <description>-- Peering with ULAKBIM --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-IAS-from-ULAKBIM-nren</import> + <family> + <inet> + <unicast> + <prefix-limit inactive="inactive"> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-IAS-to-ULAKBIM-nren</export> + <peer-as>8517</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>IAS-NRENS-ipv6</name> + <family> + <inet6> + <unicast> + <rib-group> + <ribgroup-name>ias-to-geant-cls-rtbh6</ribgroup-name> + </rib-group> + </unicast> + </inet6> + </family> + <neighbor> + <name>2001:798:1::a</name> + <description>-- IPv6 Peering with AMRES --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-IAS-from-AMRES-V6-nren</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet6> + </family> + <export>ps-advertise-default-v6</export> + <export>ps-BOGONS-V6</export> + <export>ps-IAS-to-AMRES-V6-nren</export> + <peer-as>13092</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:798:1::2a</name> + <description>-- IPv6 Peering with CESNET --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-IAS-from-CESNET-V6-backup-nren</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-IAS-to-CESNET-V6-backup-nren</export> + <peer-as>2852</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:798:1::c6</name> + <description>-- IPv6 Peering with ULAKBIM --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-IAS-from-ULAKBIM-V6-nren</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-IAS-to-ULAKBIM-V6-nren</export> + <peer-as>8517</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:798:1::86</name> + <description>-- IPv6 Peering with MREN --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-IAS-from-MREN-V6-nren</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-IAS-to-MREN-V6-nren</export> + <peer-as>40981</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:798:1::66</name> + <description>-- IPv6 Peering with HUNGARNET --</description> + <accept-remote-nexthop/> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-IAS-from-HUNGARnet-V6-nren</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>125000</maximum> + </prefix-limit> + </unicast> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-IAS-to-HUNGARnet-V6-nren</export> + <peer-as>1955</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>DWS</name> + <type>external</type> + <description>--- Commodity Traffic Peerings ---</description> + <family> + <inet> + <any> + </any> + </inet> + </family> + <neighbor> + <name>80.239.135.138</name> + <description>--- DWS Traffic peering with Telia ---</description> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-IAS-from-DWS-Telia</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-IAS-to-DWS-Telia</export> + <peer-as>1299</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>149.6.182.113</name> + <description>--DWS Traffic peering Cogent |</description> + <out-delay>30</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-IAS-from-DWS-Cogent</import> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-IAS-to-DWS-Cogent</export> + <peer-as>174</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>DWS6</name> + <neighbor> + <name>2001:2000:3080:14f2::1</name> + <description>-- IPv6 Peering with Telia --</description> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-IAS-from-DWS-Telia-v6</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-IAS-to-DWS-Telia-v6</export> + <peer-as>1299</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:978:2:26::1</name> + <description>-- IPv6 Peering with Cogent --</description> + <out-delay>10</out-delay> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-IAS-from-DWS-Cogent-v6</import> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-IAS-to-DWS-Cogent-v6</export> + <peer-as>174</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>GEANT-Peers</name> + <type>external</type> + <family> + <inet> + <any> + </any> + </inet> + </family> + <neighbor inactive="inactive"> + <name>83.97.89.80</name> + <description>FACEBOOK AS63293</description> + <multihop> + <ttl>15</ttl> + </multihop> + <local-address>83.97.89.6</local-address> + <out-delay>10</out-delay> + <import>ps-deny-all</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-IAS-from-FACEBOOK</import> + <family inactive="inactive"> + <inet> + <any> + <prefix-limit> + <maximum>150</maximum> + <teardown> + <limit-threshold>90</limit-threshold> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-IAS-to-FACEBOOK</export> + <peer-as>63293</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + <graceful-restart> + </graceful-restart> + </neighbor> + </group> + <group> + <name>GEANT-Peers-V6</name> + <type>external</type> + <family> + <inet6> + <any> + </any> + </inet6> + </family> + <neighbor inactive="inactive"> + <name>2001:798:1:1::10</name> + <description>FACEBOOK AS63293</description> + <multihop> + <ttl>15</ttl> + </multihop> + <out-delay>10</out-delay> + <import>ps-deny-all</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-IAS-from-FACEBOOK</import> + <family inactive="inactive"> + <inet6> + <any> + <prefix-limit> + <maximum>30</maximum> + <teardown> + <limit-threshold>90</limit-threshold> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-IAS-to-FACEBOOK</export> + <peer-as>63293</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + <graceful-restart> + </graceful-restart> + </neighbor> + </group> + <group> + <name>20965-to-21320-v4</name> + <type>internal</type> + <description>20965-to-21320 BGP Peering IPv4</description> + <local-address>83.97.88.225</local-address> + <import>ps-20965-v4</import> + <export>ps-deny-all</export> + <neighbor> + <name>83.97.88.224</name> + <peer-as>20965</peer-as> + </neighbor> + </group> + <group> + <name>20965-to-21320-v6</name> + <type>internal</type> + <description>20965-to-21320 BGP Peering IPv6</description> + <local-address>2001:798:1::fe</local-address> + <import>ps-20965-v6</import> + <export>ps-deny-all</export> + <neighbor> + <name>2001:798:1::fd</name> + <peer-as>20965</peer-as> + </neighbor> + </group> + <group> + <name>RTBH</name> + <type>external</type> + <family> + <inet> + <unicast> + </unicast> + </inet> + </family> + <neighbor> + <name>195.111.97.179</name> + <description>HUNGARNET_RTBH_IAS</description> + <multihop> + </multihop> + <local-address>83.97.88.81</local-address> + <out-delay>10</out-delay> + <import>PS_HUNGARNET_RTBH_IMPORT</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-deny-all</export> + <peer-as>1955</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>RTBH_V6</name> + <type>external</type> + <family> + <inet6> + <unicast> + </unicast> + </inet6> + </family> + <neighbor> + <name>2001:738::179:1</name> + <description>HUNGARNET_RTBH_IAS</description> + <multihop> + </multihop> + <local-address>2001:798:1::65</local-address> + <out-delay>10</out-delay> + <import>PS_HUNGARNET_RTBH_V6_IMPORT</import> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-deny-all</export> + <peer-as>1955</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>GEANT-IX-BIX.HU</name> + <type>external</type> + <description>BIX.HU - Public IPv4 Peering Group</description> + <out-delay>10</out-delay> + <import>ps-deny-all</import> + <family> + <inet> + <unicast> + <prefix-limit> + <maximum>150000</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </unicast> + <any> + </any> + </inet> + </family> + <export>ps-deny-all</export> + <neighbor> + <name>193.188.137.1</name> + <description>BIX.HU Route Server AS5507</description> + <import>ps-deny-all</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>125000</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-deny-all</export> + <peer-as>5507</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>193.188.137.2</name> + <description>BIX.HU Route Server AS5507</description> + <import>ps-deny-all</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>125000</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-deny-all</export> + <peer-as>5507</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>193.188.137.175</name> + <description>Hurricane_Electric AS6939</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS6939_Hurricane_Electric</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>253500</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS6939_Hurricane_Electric</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>6939</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>193.188.137.53</name> + <description>BT AS5400</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS5400_BT</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>7350</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS5400_BT</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>5400</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>193.188.137.27</name> + <description>Cloudflare AS13335</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS13335_Cloudflare</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>750</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS13335_Cloudflare</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>13335</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>193.188.137.21</name> + <description>Microsoft_Corporation AS8075</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS8075_Microsoft_Corporation</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>2250</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS8075_Microsoft_Corporation</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>8075</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>193.188.137.51</name> + <description>Microsoft_Corporation AS8075</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS8075_Microsoft_Corporation</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet> + <any> + <prefix-limit> + <maximum>2250</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet> + </family> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS8075_Microsoft_Corporation</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>8075</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + <group> + <name>GEANT-IXv6-BIX.HU</name> + <type>external</type> + <description>BIX.HU - Public IPv6 Peering Group</description> + <import>ps-deny-all</import> + <family> + <inet6> + <unicast> + <prefix-limit> + <maximum>150000</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </unicast> + </inet6> + </family> + <export>ps-deny-all</export> + <neighbor> + <name>2001:7f8:35::5507:1</name> + <description>BIX.HU Route Server AS5507</description> + <import>ps-deny-all</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>125000</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-deny-all</export> + <peer-as>5507</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:7f8:35::5507:2</name> + <description>BIX.HU Route Server AS5507</description> + <import>ps-deny-all</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>125000</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-deny-all</export> + <peer-as>5507</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:7f8:35::6939:1</name> + <description>Hurricane_Electric AS6939</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS6939_Hurricane_Electric</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>253500</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS6939_Hurricane_Electric</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>6939</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:7f8:35::5400:1</name> + <description>BT AS5400</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS5400_BT</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>7350</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS5400_BT</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>5400</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:7f8:35::1:3335:1</name> + <description>Cloudflare AS13335</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS13335_Cloudflare</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>750</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS13335_Cloudflare</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>13335</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:7f8:35::8075:1</name> + <description>Microsoft_Corporation AS8075</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS8075_Microsoft_Corporation</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>2250</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS8075_Microsoft_Corporation</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>8075</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + <neighbor> + <name>2001:7f8:35::8075:2</name> + <description>Microsoft_Corporation AS8075</description> + <import>ps-AS-SELF-REJECT</import> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_HEAD</import> + <import>IAS_PS-FROM-PUBLIC-PEER_AS8075_Microsoft_Corporation</import> + <import>IAS_PS-FROM-PUBLIC-PEERS_BIX.HU_TAIL</import> + <family> + <inet6> + <any> + <prefix-limit> + <maximum>2250</maximum> + <teardown> + <limit-threshold>80</limit-threshold> + <idle-timeout> + <timeout>30</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </any> + </inet6> + </family> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_HEAD</export> + <export>IAS_PS-TO-PUBLIC-PEER_AS8075_Microsoft_Corporation</export> + <export>IAS_PS-TO-PUBLIC-PEERS_BIX.HU_TAIL</export> + <peer-as>8075</peer-as> + <local-as> + <as-number>21320</as-number> + <private/> + <no-prepend-global-as/> + </local-as> + </neighbor> + </group> + </bgp> + </protocols> + </instance> + <instance> + <name>coriant-mgmt</name> + <description>L3VPN for Coriant Groove Management</description> + <instance-type>vrf</instance-type> + <route-distinguisher> + <rd-type>20965:991</rd-type> + </route-distinguisher> + <vrf-import>ps-to-coriant-vrf</vrf-import> + <vrf-export>ps-from-coriant-vrf</vrf-export> + <vrf-target> + <community>target:20965:991</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + </instance> + <instance> + <name>lhcone-l3vpn</name> + <description>L3 BGP/MPLS VPN for LHCONE</description> + <instance-type>vrf</instance-type> + <route-distinguisher> + <rd-type>62.40.97.1:111</rd-type> + </route-distinguisher> + <vrf-import>ps-into-lhcone-vrf</vrf-import> + <vrf-export>ps-from-lhcone-vrf</vrf-export> + <vrf-target> + <community>target:20965:111</community> + </vrf-target> + <routing-options> + <rib> + <name>lhcone-l3vpn.inet.0</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <rib> + <name>lhcone-l3vpn.inet6.0</name> + <aggregate> + <route> + <name>2001:798:111:1::/64</name> + <community>20965:0155</community> + </route> + </aggregate> + </rib> + <static> + <route> + <name>62.40.126.0/24</name> + <discard/> + <community>20965:0155</community> + </route> + </static> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + <protocols> + <bgp> + <log-updown/> + <group> + <name>lhcone-peers</name> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-peer</import> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-lhcone-peer</export> + </group> + <group> + <name>lhcone-nrens</name> + <import>ps-BOGONS</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-nren</import> + <export>ps-BOGONS</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-lhcone-nren</export> + </group> + <group> + <name>lhcone6-nrens</name> + <import>ps-BOGONS-V6</import> + <import>ps-PRIVATE-AS-BLOCK</import> + <import>ps-from-lhcone-nren</import> + <export>ps-BOGONS-V6</export> + <export>ps-PRIVATE-AS-BLOCK</export> + <export>ps-to-lhcone-nren-v6</export> + </group> + </bgp> + </protocols> + </instance> + <instance> + <name>mdvpn</name> + <instance-type>vrf</instance-type> + <interface> + <name>ae10.911</name> + </interface> + <interface> + <name>ae16.10</name> + </interface> + <route-distinguisher> + <rd-type>62.40.97.1:65100</rd-type> + </route-distinguisher> + <vrf-import>mdvpn-import</vrf-import> + <vrf-export>mdvpn-export</vrf-export> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <static> + <route> + <name>62.40.102.0/26</name> + <discard/> + </route> + </static> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + <protocols> + <bgp> + <log-updown/> + <group> + <name>BGPLU</name> + <type>external</type> + <neighbor> + <name>62.40.102.7</name> + <description>MD VPN CoC - AMRES</description> + <out-delay>10</out-delay> + <family> + <inet> + <labeled-unicast> + <prefix-limit> + <maximum>1000</maximum> + <teardown> + <limit-threshold>90</limit-threshold> + <idle-timeout> + <timeout>15</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </labeled-unicast> + </inet> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <peer-as>13092</peer-as> + </neighbor> + <neighbor> + <name>62.40.102.27</name> + <description>MD VPN CoC - HUNGARNET</description> + <out-delay>10</out-delay> + <family> + <inet> + <labeled-unicast> + <prefix-limit> + <maximum>1000</maximum> + <teardown> + <limit-threshold>90</limit-threshold> + <idle-timeout> + <timeout>15</timeout> + </idle-timeout> + </teardown> + </prefix-limit> + </labeled-unicast> + </inet> + </family> + <authentication-key>/* SECRET-DATA */</authentication-key> + <peer-as>1955</peer-as> + </neighbor> + </group> + </bgp> + </protocols> + </instance> + <instance> + <name>mgmt-l3vpn</name> + <description>L3 BGP/MPLS VPN for management</description> + <instance-type>vrf</instance-type> + <interface> + <name>irb.999</name> + </interface> + <route-distinguisher> + <rd-type>62.40.97.1:999</rd-type> + </route-distinguisher> + <vrf-import>ps-into-mgmt-vrf</vrf-import> + <vrf-export>ps-from-mgmt-vrf</vrf-export> + <vrf-target> + <community>target:20965:999</community> + </vrf-target> + <vrf-table-label> + </vrf-table-label> + <routing-options> + <rib> + <name>mgmt-l3vpn.inet.0</name> + <martians> + <address>128.0.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>191.255.0.0/16</address> + <orlonger/> + <allow/> + </martians> + <martians> + <address>223.255.255.0/24</address> + <orlonger/> + <allow/> + </martians> + </rib> + <static> + <route> + <name>10.0.4.1/32</name> + <next-hop>10.0.4.1</next-hop> + </route> + </static> + <autonomous-system> + <as-number>20965</as-number> + </autonomous-system> + </routing-options> + </instance> + </routing-instances> + <bridge-domains> + <domain> + <name>mgmt-bridge</name> + <domain-type>bridge</domain-type> + <vlan-id>999</vlan-id> + <routing-interface>irb.999</routing-interface> + </domain> + </bridge-domains> +</configuration> diff --git a/test/data/qfx.fra.de.geant.net-netconf.xml b/test/data/qfx.fra.de.geant.net-netconf.xml new file mode 100644 index 0000000000000000000000000000000000000000..3f3756a3d9f6b4fb628c2b718ee1918256a42790 --- /dev/null +++ b/test/data/qfx.fra.de.geant.net-netconf.xml @@ -0,0 +1,1614 @@ +<configuration changed-seconds="1571158483" changed-localtime="2019-10-15 16:54:43 UTC"> + <version>17.3R3-S3.3</version> + <groups> + <name>juniper-ais</name> + <system> + </system> + </groups> + <apply-groups>juniper-ais</apply-groups> + <system> + <host-name>qfx.fra.de</host-name> + <domain-name>geant.net</domain-name> + <authentication-order>radius</authentication-order> + <authentication-order>password</authentication-order> + <location> + <country-code>DE</country-code> + </location> + <root-authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </root-authentication> + <radius-server> + <name>62.40.120.136</name> + <timeout>2</timeout> + <source-address>62.40.117.162</source-address> + </radius-server> + <radius-server> + <name>62.40.121.121</name> + <timeout>2</timeout> + <source-address>62.40.117.162</source-address> + </radius-server> + <login> + <class> + <name>NOC-Class</name> + <idle-timeout>60</idle-timeout> + <permissions>all</permissions> + </class> + <class> + <name>dante</name> + <idle-timeout>20</idle-timeout> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>readonly-permissions</name> + <permissions>view</permissions> + <permissions>view-configuration</permissions> + <allow-commands>show .*|quit|ping .*|monitor .*|traceroute .*</allow-commands> + </class> + <user> + <name>Monit0r</name> + <full-name>Monitor</full-name> + <uid>2003</uid> + <class>dante</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>python</name> + <uid>2001</uid> + <class>NOC-Class</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>remote</name> + <full-name>All users via RADIUS</full-name> + <uid>2005</uid> + <class>NOC-Class</class> + </user> + <user> + <name>reporting</name> + <uid>2000</uid> + <class>readonly-permissions</class> + </user> + <user> + <name>space15.2R2.4-paris</name> + <uid>2004</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>space17.1R1.7-london</name> + <uid>2006</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>xantaro</name> + <uid>2002</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <password> + <minimum-length>10</minimum-length> + <minimum-numerics>1</minimum-numerics> + <minimum-upper-cases>1</minimum-upper-cases> + <minimum-lower-cases>1</minimum-lower-cases> + <minimum-punctuations>1</minimum-punctuations> + </password> + </login> + <services> + <ssh> + <root-login>deny</root-login> + <no-tcp-forwarding/> + <protocol-version>v2</protocol-version> + <max-sessions-per-connection>32</max-sessions-per-connection> + <connection-limit>100</connection-limit> + <rate-limit>50</rate-limit> + </ssh> + <netconf> + <ssh> + </ssh> + </netconf> + </services> + <syslog> + <user> + <name>*</name> + <contents> + <name>any</name> + <emergency/> + </contents> + </user> + <host> + <name>83.97.94.11</name> + <contents> + <name>any</name> + <any/> + </contents> + <port>515</port> + </host> + <comment>/* XantaroXSE - London2 - Slough */</comment> + <host> + <name>62.40.99.47</name> + <contents> + <name>any</name> + <any/> + </contents> + </host> + <file> + <name>messages</name> + <contents> + <name>any</name> + <notice/> + </contents> + <contents> + <name>authorization</name> + <info/> + </contents> + <match>!(RPD_MSDP_SRC_ACTIVE.*|.*bgp_rt_send_msg_attr.*)</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>interactive-commands</name> + <contents> + <name>interactive-commands</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>conf-history</name> + <contents> + <name>conflict-log</name> + <any/> + </contents> + <contents> + <name>change-log</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>default-log-messages</name> + <contents> + <name>any</name> + <any/> + </contents> + <match>(requested 'commit' operation)|(requested 'commit synchronize' operation)|(copying configuration to juniper.save)|(commit complete)|ifAdminStatus|(FRU power)|(FRU removal)|(FRU insertion)|(link UP)|transitioned|Transferred|transfer-file|(license add)|(license delete)|(package -X update)|(package -X delete)|(FRU Online)|(FRU Offline)|(plugged in)|(unplugged)|QF_NODE|QF_SERVER_NODE_GROUP|QF_INTERCONNECT|QF_DIRECTOR|QF_NETWORK_NODE_GROUP|(Master Unchanged, Members Changed)|(Master Changed, Members Changed)|(Master Detected, Members Changed)|(vc add)|(vc delete)|(Master detected)|(Master changed)|(Backup detected)|(Backup changed)|(interface vcp-)|(AIS_DATA_AVAILABLE)</match> + <structured-data> + </structured-data> + </file> + <file> + <name>authorization</name> + <contents> + <name>authorization</name> + <any/> + </contents> + </file> + <file> + <name>firewall-log</name> + <contents> + <name>firewall</name> + <critical/> + </contents> + </file> + <file> + <name>daemon</name> + <contents> + <name>daemon</name> + <error/> + </contents> + </file> + <file> + <name>net-alarms</name> + <contents> + <name>daemon</name> + <warning/> + </contents> + </file> + <file> + <name>low-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <notice/> + </contents> + <contents> + <name>kernel</name> + <notice/> + </contents> + <contents> + <name>user</name> + <notice/> + </contents> + <contents> + <name>pfe</name> + <notice/> + </contents> + </file> + <file> + <name>high-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <error/> + </contents> + <contents> + <name>kernel</name> + <error/> + </contents> + <contents> + <name>user</name> + <error/> + </contents> + <contents> + <name>pfe</name> + <error/> + </contents> + <match>(!PCF8584) | (!CHASSISD_VOLTAGE_SENSOR_INIT)</match> + </file> + <file> + <name>commands-log</name> + <contents> + <name>interactive-commands</name> + <info/> + </contents> + </file> + <file> + <name>dnoc-events</name> + <contents> + <name>daemon</name> + <info/> + </contents> + <match>.*SNMP_TRAP_LINK_.*|.*RPD_BGP_NEIGHBOR_STATE_CHANGED.*|.*SNMPD_TRAP_COLD_START.*</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <source-address>62.40.117.162</source-address> + </syslog> + <extensions> + <providers> + <name>juniper</name> + <license-type> + <name>juniper</name> + <deployment-scope>commercial</deployment-scope> + </license-type> + </providers> + <providers> + <name>chef</name> + <license-type> + <name>juniper</name> + <deployment-scope>commercial</deployment-scope> + </license-type> + </providers> + </extensions> + <commit> + <synchronize/> + </commit> + <processes> + <dhcp-service> + <traceoptions> + <file> + <filename>dhcp_logfile</filename> + <size>10m</size> + </file> + <level>all</level> + <flag> + <name>all</name> + </flag> + </traceoptions> + </dhcp-service> + <app-engine-virtual-machine-management-service> + <traceoptions> + <level>notice</level> + <flag> + <name>all</name> + </flag> + </traceoptions> + </app-engine-virtual-machine-management-service> + </processes> + <ntp> + <authentication-key> + <name>10</name> + <type>md5</type> + <value>/* SECRET-DATA */</value> + </authentication-key> + <server> + <name>62.40.123.21</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.123.23</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.123.103</name> + <key>/* SECRET-DATA */</key> + </server> + <trusted-key>10</trusted-key> + </ntp> + </system> + <chassis> + <redundancy> + <graceful-switchover> + </graceful-switchover> + </redundancy> + <aggregated-devices> + <ethernet> + <device-count>15</device-count> + </ethernet> + </aggregated-devices> + <auto-image-upgrade inactive="inactive"/> + </chassis> + <interfaces> + <interface> + <name>xe-0/0/0</name> + <description>PHY INFRASTRUCTURE LAN P_ae5 | 730xd-1 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae5</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/1</name> + <description>PHY INFRASTRUCTURE LAN P_ae9 | 730xd-1 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae9</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/2</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-2 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-0/0/3</name> + <description>PHY INFRASTRUCTURE LAN P_ae7 | 730xd-3 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/4</name> + <description>PHY INFRASTRUCTURE LAN P_ae11 | 730xd-3 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/5</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-4 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-0/0/6</name> + <description>PHY INFRASTRUCTURE LAN P_ae12 | 730xd-4 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/7</name> + <description>PHY INFRASTRUCTURE LAN P_ae10 | 730xd-2 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/8</name> + <description>PHY INFRASTRUCTURE LAN P_ae9 | 730xd-1 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae9</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/9</name> + <description>PHY INFRASTRUCTURE LAN P_ae1 | 730xd-1 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/10</name> + <description>PHY INFRASTRUCTURE LAN P_ae2 | 730xd-2 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/11</name> + <description>PHY INFRASTRUCTURE LAN P_ae11 | 730xd-3 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/12</name> + <description>PHY INFRASTRUCTURE LAN P_ae3 | 730xd-3 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae3</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/13</name> + <description>PHY INFRASTRUCTURE LAN P_ae4 | 730xd-4 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/14</name> + <description>PHY INFRASTRUCTURE LAN P_ae8 | 730xd-4 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/15</name> + <description>PHY INFRASTRUCTURE LAN P_ae6 | 730xd-2 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae6</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/16</name> + <description>PHY INFRASTRUCTURE LAN P_ae13 | FRA-PAR-BRIDGE 1-1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/18</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-2/0/0</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/19</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-10/3/0</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/44</name> + <description>PHY INFRASTRUCTURE LAN P_ae14 | QFX.LON2.UK 0/0/44</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/0</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-1 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <mtu>9000</mtu> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-1/0/1</name> + <description>PHY INFRASTRUCTURE LAN P_ae6 | 730xd-2 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae6</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/2</name> + <description>PHY INFRASTRUCTURE LAN P_ae10 | 730xd-2 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/3</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-3 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-1/0/4</name> + <description>PHY INFRASTRUCTURE LAN P_ae8 | 730xd-4 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/5</name> + <description>PHY INFRASTRUCTURE LAN P_ae12 | 730xd-4 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/6</name> + <description>PHY INFRASTRUCTURE LAN P_ae9 | 730xd-1 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae9</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/7</name> + <description>PHY INFRASTRUCTURE LAN P_ae11 | 730xd-3 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/8</name> + <description>PHY INFRASTRUCTURE LAN P_ae1 | 730xd-1 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/9</name> + <description>PHY INFRASTRUCTURE LAN P_ae10 | 730xd-2 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/10</name> + <description>PHY INFRASTRUCTURE LAN P_ae2 | 730xd-2 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/11</name> + <description>PHY INFRASTRUCTURE LAN P_ae3 | 730xd-3 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae3</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/12</name> + <description>PHY INFRASTRUCTURE LAN P_ae12| 730xd-4 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/13</name> + <description>PHY INFRASTRUCTURE LAN P_ae4 | 730xd-4 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/14</name> + <description>PHY INFRASTRUCTURE LAN P_ae5 | 730xd-1 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae5</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/15</name> + <description>PHY INFRASTRUCTURE LAN P_ae7 | 730xd-3 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/16</name> + <description>PHY INFRASTRUCTURE LAN P_ae13 | FRA-PAR-BRIDGE 2-2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/18</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-2/0/1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/19</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-10/3/1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/44</name> + <description>PHY INFRASTRUCTURE LAN P_ae14 | QFX.LON2.UK 1/0/44</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>ae0</name> + <description>LAG INFRASTRUCTURE LAN | MX AE30</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + <members>VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae1</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-1 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae2</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-2 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae3</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-3 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae4</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-4 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae5</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-1 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae6</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-2 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae7</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-3 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae8</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-4 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae9</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-1 VM Traffic LAG</description> + <vlan-tagging/> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae10</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-2 VM Traffic LAG</description> + <vlan-tagging/> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <inter-switch-link/> + <vlan> + <members>VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae11</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-3 VM Traffic LAG</description> + <vlan-tagging/> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <inter-switch-link/> + <vlan> + <members>VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae12</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-4 VM Traffic LAG</description> + <vlan-tagging/> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <inter-switch-link/> + <vlan> + <members>VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae13</name> + <description>LAG INFRASTRUCTURE LAN | QFX.PAR.FR AE13</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VM</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_TNMS</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae14</name> + <description>LAG INFRASTRUCTURE LAN | QFX.LON2.UK AE30</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VM</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + <members>VL_TNMS</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface inactive="inactive"> + <name>em0</name> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>62.40.117.163/29</name> + </address> + </inet> + </family> + </unit> + </interface> + <interface> + <name>vme</name> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>62.40.117.162/29</name> + </address> + </inet> + </family> + </unit> + </interface> + </interfaces> + <comment>/* trap-group */</comment> + <snmp> + <community> + <name>0pBiFbD</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.120.18/32</name> + </clients> + <clients> + <name>62.40.123.180/32</name> + </clients> + <clients> + <name>62.40.104.51/32</name> + </clients> + <clients> + <name>62.40.104.155/32</name> + </clients> + <clients> + <name>62.40.104.157/32</name> + </clients> + <clients> + <name>62.40.104.154/32</name> + </clients> + <clients> + <name>62.40.104.50/32</name> + </clients> + <clients> + <name>62.40.113.88/29</name> + </clients> + <clients> + <name>62.40.104.28/32</name> + </clients> + <clients> + <name>83.97.93.195/32</name> + </clients> + <clients> + <name>83.97.93.196/32</name> + </clients> + <clients> + <name>83.97.93.22/32</name> + </clients> + <clients> + <name>83.97.93.152/32</name> + </clients> + <clients> + <name>83.97.93.153/32</name> + </clients> + <clients> + <name>83.97.93.239/32</name> + </clients> + <clients> + <name>83.97.94.52/32</name> + </clients> + <clients> + <name>83.97.94.97/32</name> + </clients> + <clients> + <name>83.97.94.98/32</name> + </clients> + </community> + <community> + <name>XantaroXSE</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.99.47/32</name> + </clients> + </community> + <trap-group> + <name>geantnms</name> + <categories> + <chassis/> + <link/> + <routing/> + </categories> + <targets> + <name>62.40.104.50</name> + </targets> + <targets> + <name>62.40.104.51</name> + </targets> + <targets> + <name>62.40.104.155</name> + </targets> + <targets> + <name>62.40.104.157</name> + </targets> + <targets> + <name>62.40.104.154</name> + </targets> + <targets> + <name>62.40.114.3</name> + </targets> + <targets> + <name>62.40.114.2</name> + </targets> + <targets> + <name>62.40.114.18</name> + </targets> + <targets> + <name>62.40.114.19</name> + </targets> + <targets> + <name>83.97.92.238</name> + </targets> + <targets> + <name>83.97.92.239</name> + </targets> + </trap-group> + </snmp> + <forwarding-options> + <storm-control-profiles> + <name>default</name> + <all> + </all> + </storm-control-profiles> + <cut-through/> + </forwarding-options> + <routing-options> + <static> + <route> + <name>0.0.0.0/0</name> + <next-hop>62.40.117.161</next-hop> + </route> + </static> + </routing-options> + <protocols> + <lacp> + <traceoptions> + <file> + <filename>lacp_qfx</filename> + <size>10m</size> + <files>10</files> + <world-readable/> + </file> + <flag> + <name>all</name> + </flag> + </traceoptions> + </lacp> + <lldp> + <interface> + <name>all</name> + </interface> + <interface> + <name>em0</name> + <disable/> + </interface> + <interface> + <name>em1</name> + <disable/> + </interface> + <interface> + <name>em2</name> + <disable/> + </interface> + </lldp> + <lldp-med> + <interface> + <name>all</name> + </interface> + </lldp-med> + <igmp-snooping> + <vlan> + <name>default</name> + </vlan> + </igmp-snooping> + </protocols> + <policy-options> + <prefix-list> + <name>geant-address-space-short</name> + <prefix-list-item> + <name>62.40.96.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.98.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.0/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.100.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.101.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.102.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.40/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.120/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.105.117/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.109.16/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.27/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.112.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.116.0/23</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.118.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.109.16/29</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.112.0/22</name> + </prefix-list-item> + <prefix-list-item> + <name>64.40.116.0/23</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>geantncc-address-space</name> + <prefix-list-item> + <name>62.40.108.192/27</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.125.250/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>corporate-address-space</name> + <prefix-list-item> + <name>62.40.99.194/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.99.201/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.119.128/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.90.0/24</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.0/25</name> + </prefix-list-item> + <prefix-list-item> + <name>193.63.211.136/32</name> + </prefix-list-item> + <prefix-list-item> + <name>195.169.24.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>pref-list-router-access</name> + <prefix-list-item> + <name>62.40.106.232/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.72/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.121.102/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.197.70/32</name> + </prefix-list-item> + <prefix-list-item> + <name>128.139.227.249/32</name> + </prefix-list-item> + <prefix-list-item> + <name>130.104.230.45/32</name> + </prefix-list-item> + <prefix-list-item> + <name>139.165.223.48/32</name> + </prefix-list-item> + <prefix-list-item> + <name>193.136.7.100/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>ncc-oob-address-space</name> + <prefix-list-item> + <name>172.16.5.252/30</name> + </prefix-list-item> + <prefix-list-item> + <name>172.16.14.0/24</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>space-local</name> + <prefix-list-item> + <name>127.0.0.1/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>nmteam-dev-servers</name> + <prefix-list-item> + <name>62.40.106.202/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.253/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.111.254/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.12/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-JUNOSSPACE</name> + <prefix-list-item> + <name>62.40.113.90/32</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.120.18/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>xantaro-address-space</name> + <prefix-list-item> + <name>213.86.104.34/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-lg</name> + <prefix-list-item> + <name>83.97.92.82/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.141/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.39/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.62/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.93.63/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>dashboard-servers</name> + <prefix-list-item> + <name>62.40.104.48/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.104.152/29</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.0/28</name> + </prefix-list-item> + <prefix-list-item> + <name>62.40.114.16/28</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.238/32</name> + </prefix-list-item> + <prefix-list-item> + <name>83.97.92.239/32</name> + </prefix-list-item> + </prefix-list> + <prefix-list> + <name>GEANT-Superpop-v4</name> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + </prefix-list> + </policy-options> + <virtual-chassis> + <preprovisioned/> + <no-split-detection/> + <member> + <name>0</name> + <role>routing-engine</role> + <serial-number>TA3716210677</serial-number> + </member> + <member> + <name>1</name> + <role>routing-engine</role> + <serial-number>TA3715110277</serial-number> + </member> + </virtual-chassis> + <vlans> + <vlan> + <name>VL_MANAGEMENT</name> + <description>ESXi management - vCenter, vMotion</description> + <vlan-id>2001</vlan-id> + </vlan> + <vlan> + <name>VL_NAGIOS_GTS</name> + <description>GTS Interface of Nagios server</description> + <vlan-id>3001</vlan-id> + </vlan> + <vlan> + <name>VL_RHPS_1</name> + <vlan-id>3002</vlan-id> + </vlan> + <vlan> + <name>VL_RHPS_2</name> + <vlan-id>3003</vlan-id> + </vlan> + <vlan> + <name>VL_TAAS_RANCID</name> + <vlan-id>3004</vlan-id> + </vlan> + <vlan> + <name>VL_TNMS</name> + <description>For Coriant TNMS VM</description> + <vlan-id>991</vlan-id> + </vlan> + <vlan> + <name>VL_VSAN</name> + <vlan-id>1000</vlan-id> + </vlan> + <vlan> + <name>VM</name> + <vlan-id>3000</vlan-id> + </vlan> + <vlan> + <name>default</name> + <vlan-id>1</vlan-id> + </vlan> + </vlans> +</configuration> + diff --git a/test/data/qfx.lon2.uk.geant.net-netconf.xml b/test/data/qfx.lon2.uk.geant.net-netconf.xml new file mode 100644 index 0000000000000000000000000000000000000000..19f3a86bda887eac86a68c3406e27223675f65a1 --- /dev/null +++ b/test/data/qfx.lon2.uk.geant.net-netconf.xml @@ -0,0 +1,1816 @@ +<configuration changed-seconds="1571158483" changed-localtime="2019-10-15 16:54:43 UTC"> + <version>17.3R3-S3.3</version> + <groups> + <name>juniper-ais</name> + <system> + </system> + </groups> + <apply-groups>juniper-ais</apply-groups> + <system> + <host-name>qfx.lon2.uk</host-name> + <domain-name>geant.net</domain-name> + <authentication-order>radius</authentication-order> + <authentication-order>password</authentication-order> + <location> + <country-code>UK</country-code> + </location> + <root-authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </root-authentication> + <radius-server> + <name>62.40.120.136</name> + <timeout>2</timeout> + <source-address>62.40.117.178</source-address> + </radius-server> + <radius-server> + <name>62.40.121.121</name> + <timeout>2</timeout> + <source-address>62.40.117.178</source-address> + </radius-server> + <login> + <class> + <name>NOC-Class</name> + <idle-timeout>60</idle-timeout> + <permissions>all</permissions> + </class> + <class> + <name>dante</name> + <idle-timeout>20</idle-timeout> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>readonly-permissions</name> + <permissions>view</permissions> + <permissions>view-configuration</permissions> + <allow-commands>show .*|quit|ping .*|monitor .*|traceroute .*</allow-commands> + </class> + <user> + <name>Monit0r</name> + <full-name>Monitor</full-name> + <uid>2003</uid> + <class>dante</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>ncc</name> + <full-name>NOC Team Backup Account</full-name> + <uid>2007</uid> + <class>super-user</class> + <authentication> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>python</name> + <uid>2000</uid> + <class>NOC-Class</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>remote</name> + <full-name>All users via RADIUS</full-name> + <uid>2005</uid> + <class>NOC-Class</class> + </user> + <user> + <name>reporting</name> + <uid>2001</uid> + <class>readonly-permissions</class> + </user> + <user> + <name>space15.2R2.4-paris</name> + <uid>2004</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>space17.1R1.7-london</name> + <uid>2006</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>xantaro</name> + <uid>2002</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <password> + <minimum-length>10</minimum-length> + <minimum-numerics>1</minimum-numerics> + <minimum-upper-cases>1</minimum-upper-cases> + <minimum-lower-cases>1</minimum-lower-cases> + <minimum-punctuations>1</minimum-punctuations> + </password> + </login> + <services> + <ssh> + <root-login>deny</root-login> + <no-tcp-forwarding/> + <protocol-version>v2</protocol-version> + <max-sessions-per-connection>32</max-sessions-per-connection> + <connection-limit>100</connection-limit> + <rate-limit>50</rate-limit> + </ssh> + <netconf> + <ssh> + </ssh> + </netconf> + </services> + <syslog> + <user> + <name>*</name> + <contents> + <name>any</name> + <emergency/> + </contents> + </user> + <host> + <name>83.97.94.11</name> + <contents> + <name>any</name> + <any/> + </contents> + <port>515</port> + </host> + <comment>/* XantaroXSE - London2 - Slough */</comment> + <host> + <name>62.40.99.47</name> + <contents> + <name>any</name> + <any/> + </contents> + </host> + <file> + <name>messages</name> + <contents> + <name>any</name> + <notice/> + </contents> + <contents> + <name>authorization</name> + <info/> + </contents> + <match>!(RPD_MSDP_SRC_ACTIVE.*|.*bgp_rt_send_msg_attr.*)</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>interactive-commands</name> + <contents> + <name>interactive-commands</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>conf-history</name> + <contents> + <name>conflict-log</name> + <any/> + </contents> + <contents> + <name>change-log</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>default-log-messages</name> + <contents> + <name>any</name> + <any/> + </contents> + <match>(requested 'commit' operation)|(requested 'commit synchronize' operation)|(copying configuration to juniper.save)|(commit complete)|ifAdminStatus|(FRU power)|(FRU removal)|(FRU insertion)|(link UP)|transitioned|Transferred|transfer-file|(license add)|(license delete)|(package -X update)|(package -X delete)|(FRU Online)|(FRU Offline)|(plugged in)|(unplugged)|QF_NODE|QF_SERVER_NODE_GROUP|QF_INTERCONNECT|QF_DIRECTOR|QF_NETWORK_NODE_GROUP|(Master Unchanged, Members Changed)|(Master Changed, Members Changed)|(Master Detected, Members Changed)|(vc add)|(vc delete)|(Master detected)|(Master changed)|(Backup detected)|(Backup changed)|(interface vcp-)|(AIS_DATA_AVAILABLE)</match> + <structured-data> + </structured-data> + </file> + <file> + <name>authorization</name> + <contents> + <name>authorization</name> + <any/> + </contents> + </file> + <file> + <name>firewall-log</name> + <contents> + <name>firewall</name> + <critical/> + </contents> + </file> + <file> + <name>daemon</name> + <contents> + <name>daemon</name> + <error/> + </contents> + </file> + <file> + <name>net-alarms</name> + <contents> + <name>daemon</name> + <warning/> + </contents> + </file> + <file> + <name>low-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <notice/> + </contents> + <contents> + <name>kernel</name> + <notice/> + </contents> + <contents> + <name>user</name> + <notice/> + </contents> + <contents> + <name>pfe</name> + <notice/> + </contents> + </file> + <file> + <name>high-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <error/> + </contents> + <contents> + <name>kernel</name> + <error/> + </contents> + <contents> + <name>user</name> + <error/> + </contents> + <contents> + <name>pfe</name> + <error/> + </contents> + <match>(!PCF8584) | (!CHASSISD_VOLTAGE_SENSOR_INIT)</match> + </file> + <file> + <name>commands-log</name> + <contents> + <name>interactive-commands</name> + <info/> + </contents> + </file> + <file> + <name>dnoc-events</name> + <contents> + <name>daemon</name> + <info/> + </contents> + <match>.*SNMP_TRAP_LINK_.*|.*RPD_BGP_NEIGHBOR_STATE_CHANGED.*|.*SNMPD_TRAP_COLD_START.*</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <source-address>62.40.117.178</source-address> + </syslog> + <extensions> + <providers> + <name>juniper</name> + <license-type> + <name>juniper</name> + <deployment-scope>commercial</deployment-scope> + </license-type> + </providers> + <providers> + <name>chef</name> + <license-type> + <name>juniper</name> + <deployment-scope>commercial</deployment-scope> + </license-type> + </providers> + </extensions> + <commit> + <synchronize/> + </commit> + <processes> + <dhcp-service> + <traceoptions> + <file> + <filename>dhcp_logfile</filename> + <size>10m</size> + </file> + <level>all</level> + <flag> + <name>all</name> + </flag> + </traceoptions> + </dhcp-service> + <app-engine-virtual-machine-management-service> + <traceoptions> + <level>notice</level> + <flag> + <name>all</name> + </flag> + </traceoptions> + </app-engine-virtual-machine-management-service> + </processes> + <ntp> + <authentication-key> + <name>10</name> + <type>md5</type> + <value>/* SECRET-DATA */</value> + </authentication-key> + <server> + <name>62.40.123.21</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.123.23</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.123.103</name> + <key>/* SECRET-DATA */</key> + </server> + <trusted-key>10</trusted-key> + </ntp> + </system> + <chassis> + <redundancy> + <graceful-switchover> + </graceful-switchover> + </redundancy> + <aggregated-devices> + <ethernet> + <device-count>40</device-count> + </ethernet> + </aggregated-devices> + </chassis> + <interfaces> + <interface-range> + <name>IDRACS</name> + <member-range> + <name>ge-0/0/36</name> + <end-range>ge-0/0/45</end-range> + </member-range> + <member-range> + <name>ge-1/0/36</name> + <end-range>ge-1/0/45</end-range> + </member-range> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>INT-INFRA</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface-range> + <interface-range inactive="inactive"> + <name>VSAN</name> + <member-range> + <name>xe-0/0/24</name> + <end-range>xe-0/0/35</end-range> + </member-range> + <member-range> + <name>xe-1/0/24</name> + <end-range>xe-1/0/35</end-range> + </member-range> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VSAN1</members> + <members>VSAN2</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface-range> + <interface-range inactive="inactive"> + <name>VM_TRAFFIC</name> + <member-range> + <name>xe-0/0/12</name> + <end-range>xe-0/0/23</end-range> + </member-range> + <member-range> + <name>xe-1/0/12</name> + <end-range>xe-1/0/23</end-range> + </member-range> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>INT-INFRA</members> + <members>INT-SERVER</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface-range> + <interface-range inactive="inactive"> + <name>MANAGEMENT</name> + <member-range> + <name>xe-0/0/0</name> + <end-range>xe-0/0/11</end-range> + </member-range> + <member-range> + <name>xe-1/0/0</name> + <end-range>xe-1/0/11</end-range> + </member-range> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>INT-INFRA</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface-range> + <interface> + <name>xe-0/0/0</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX01 NIC1 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/1</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX02 NIC1 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/2</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX03 NIC1 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae3</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/3</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX10 NIC1 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae6</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/4</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX11 NIC1 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/5</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX12 NIC1 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/6</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX20 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/7</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX21 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae5</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/12</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX01 NIC1 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/13</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX02 NIC1 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/14</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX03 NIC1 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/15</name> + <description>PHY INFRASTRUCTURE LAN P_AE16 | LON2-PRD-ESX10 NIC1 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae16</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/16</name> + <description>PHY INFRASTRUCTURE LAN P_AE17 | LON2-PRD-ESX11 NIC1 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae17</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/17</name> + <description>PHY INFRASTRUCTURE LAN P_AE18 | LON2-PRD-ESX12 NIC1 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae18</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/18</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX20 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/19</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX21 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae15</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/24</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX01 NIC1 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae21</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/25</name> + <ether-options> + <ieee-802.3ad> + <bundle>ae22</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/26</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX03 NIC1 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae23</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/27</name> + <description>PHY INFRASTRUCTURE LAN P_AE26 | LON2-PRD-ESX10 NIC1 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae26</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/28</name> + <description>PHY INFRASTRUCTURE LAN P_AE27 | LON2-PRD-ESX11 NIC1 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae27</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/29</name> + <description>PHY INFRASTRUCTURE LAN P_AE28 | LON2-PRD-ESX12 NIC1 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae28</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>ge-0/0/36</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX01 IDRAC</description> + </interface> + <interface> + <name>ge-0/0/37</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX02 IDRAC</description> + </interface> + <interface> + <name>ge-0/0/38</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX03 IDRAC</description> + </interface> + <interface> + <name>xe-0/0/44</name> + <description>PHY INFRASTRUCTURE LAN | QFX.FRA.DE 0/0/44</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae30</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/45</name> + <description>PHY INFRASTRUCTURE LAN | QFX.PAR.FR 0/0/45</description> + <disable/> + </interface> + <interface> + <name>xe-0/0/46</name> + <description>PHY INFRASTRUCTURE LAN | MX1.LON2.UK xe-1/2/1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae31</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/47</name> + <description>PHY INFRASTRUCTURE LAN | MX1.LON2.UK xe-3/2/3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae31</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/0</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX01 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/1</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX02 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/2</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX03 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae3</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface inactive="inactive"> + <name>xe-1/0/3</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX10 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae6</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface inactive="inactive"> + <name>xe-1/0/4</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX11 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface inactive="inactive"> + <name>xe-1/0/5</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX12 NIC2 PORT1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/6</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX20 NIC2 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/7</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX21 NIC2 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae5</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/12</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX01 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/13</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX02 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/14</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX03 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/15</name> + <description>PHY INFRASTRUCTURE LAN P_AE16 | LON2-PRD-ESX10 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae16</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/16</name> + <description>PHY INFRASTRUCTURE LAN P_AE17 | LON2-PRD-ESX11 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae17</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/17</name> + <description>PHY INFRASTRUCTURE LAN P_AE18 | LON2-PRD-ESX12 NIC2 PORT2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae18</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/18</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX20 NIC2 PORT4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae14</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/19</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX21 NIC2 PORT4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae15</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/24</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX01 NIC2 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae21</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/25</name> + <ether-options> + <ieee-802.3ad> + <bundle>ae22</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/26</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX03 NIC2 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae23</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/27</name> + <description>PHY INFRASTRUCTURE LAN P_AE26 | LON2-PRD-ESX10 NIC2 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae26</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/28</name> + <description>PHY INFRASTRUCTURE LAN P_AE27 | LON2-PRD-ESX11 NIC2 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae27</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/29</name> + <description>PHY INFRASTRUCTURE LAN P_AE28 | LON2-PRD-ESX12 NIC2 PORT3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae28</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>ge-1/0/36</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX10 IDRAC</description> + </interface> + <interface> + <name>ge-1/0/37</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX11 IDRAC</description> + </interface> + <interface> + <name>ge-1/0/38</name> + <description>PHY INFRASTRUCTURE LAN | LON2-PRD-ESX12 IDRAC</description> + </interface> + <interface> + <name>xe-1/0/44</name> + <description>PHY INFRASTRUCTURE LAN | QFX.FRA.DE 1/0/44</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae30</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/45</name> + <description>PHY INFRASTRUCTURE LAN | QFX.PAR.FR 1/0/45</description> + <disable/> + </interface> + <interface> + <name>xe-1/0/46</name> + <description>PHY INFRASTRUCTURE LAN | MX1.LON2.UK xe-1/2/3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae31</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/47</name> + <description>PHY INFRASTRUCTURE LAN | MX1.LON2.UK xe-4/0/2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae31</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>ae1</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX01 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>INT-INFRA</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae2</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX02 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>INT-INFRA</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae3</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX03 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>INT-INFRA</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae4</name> + <description>LAG INFRASTRUCTURE LAN | LON2-SEC-ESX20 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>INT-INFRA</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae5</name> + <description>LAG INFRASTRUCTURE LAN | LON2-SEC-ESX21 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>INT-INFRA</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae6</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX10 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>DEV_ESX_MGMT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae7</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX11 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>DEV_ESX_MGMT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae8</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX12 ESXI Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>DEV_ESX_MGMT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae11</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX01 VM Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>INT-SERVER</members> + <members>INT-INFRA</members> + <members>EXT-SERVER</members> + <members>INT-VPN</members> + <members>eduvpn-slough</members> + <members>eduvpn-link</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae12</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX02 VM Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>INT-SERVER</members> + <members>INT-INFRA</members> + <members>EXT-SERVER</members> + <members>INT-VPN</members> + <members>eduvpn-slough</members> + <members>eduvpn-link</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae13</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX03 VM Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>INT-SERVER</members> + <members>INT-INFRA</members> + <members>EXT-SERVER</members> + <members>INT-VPN</members> + <members>eduvpn-slough</members> + <members>eduvpn-link</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae14</name> + <description>LAG INFRASTRUCTURE LAN | LON2-SEC-ESX20 VM Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>FW-WAN</members> + <members>FW-VRF</members> + <members>INT-INFRA</members> + <members>INT-SERVER</members> + <members>EXT-SERVER</members> + <members>INT-VPN</members> + <members>eduvpn-slough</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae15</name> + <description>LAG INFRASTRUCTURE LAN | LON2-SEC-ESX21 VM Traffic LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>FW-WAN</members> + <members>FW-VRF</members> + <members>INT-SERVER</members> + <members>INT-INFRA</members> + <members>EXT-SERVER</members> + <members>INT-VPN</members> + <members>eduvpn-slough</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae16</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX10 VM TRAFFIC LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>DEV_VM</members> + <members>DEV_NAGIOS_GTS</members> + <members>DEV_RHPS_1</members> + <members>DEV_RHPS_2</members> + <members>DEV_TAAS_RANCID</members> + <members>DEV_TNMS</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae17</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX11 VM TRAFFIC LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>DEV_VM</members> + <members>DEV_NAGIOS_GTS</members> + <members>DEV_RHPS_1</members> + <members>DEV_RHPS_2</members> + <members>DEV_TAAS_RANCID</members> + <members>DEV_TNMS</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae18</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX12 VM TRAFFIC LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>DEV_VM</members> + <members>DEV_NAGIOS_GTS</members> + <members>DEV_RHPS_1</members> + <members>DEV_RHPS_2</members> + <members>DEV_TAAS_RANCID</members> + <members>DEV_TNMS</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae21</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX01 VSAN LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VSAN1</members> + <members>VSAN2</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae22</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX02 VSAN LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VSAN1</members> + <members>VSAN2</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae23</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX03 VSAN LAG - No LACP</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VSAN1</members> + <members>VSAN2</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae26</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX10 VSAN LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <link-speed>10g</link-speed> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>DEV_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae27</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX11 VSAN LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>DEV_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae28</name> + <description>LAG INFRASTRUCTURE LAN | LON2-PRD-ESX12 VSAN LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>DEV_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae30</name> + <description>LAG INFRASTRUCTURE LAN | QFX.FRA.DE AE14</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>DEV_VM</members> + <members>DEV_NAGIOS_GTS</members> + <members>DEV_RHPS_1</members> + <members>DEV_RHPS_2</members> + <members>DEV_TAAS_RANCID</members> + <members>DEV_TNMS</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae31</name> + <description>LAG INFRASTRUCTURE LAN | MX1.LON2 LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>FW-WAN</members> + <members>FW-VRF</members> + <members>DEV_ESX_MGMT</members> + <members>eduvpn-link</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface inactive="inactive"> + <name>em0</name> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>62.40.117.180/29</name> + </address> + </inet> + </family> + </unit> + </interface> + <interface> + <name>vme</name> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>62.40.117.178/29</name> + </address> + </inet> + </family> + </unit> + </interface> + </interfaces> + <snmp> + <community> + <name>0pBiFbD</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.120.18/32</name> + </clients> + <clients> + <name>62.40.123.180/32</name> + </clients> + <clients> + <name>62.40.104.51/32</name> + </clients> + <clients> + <name>62.40.104.155/32</name> + </clients> + <clients> + <name>62.40.104.157/32</name> + </clients> + <clients> + <name>62.40.104.154/32</name> + </clients> + <clients> + <name>62.40.104.50/32</name> + </clients> + <clients> + <name>62.40.113.88/29</name> + </clients> + <clients> + <name>62.40.104.28/32</name> + </clients> + <clients> + <name>83.97.93.195/32</name> + </clients> + <clients> + <name>83.97.93.196/32</name> + </clients> + <clients> + <name>83.97.93.152/32</name> + </clients> + <clients> + <name>83.97.93.153/32</name> + </clients> + <clients> + <name>83.97.93.239/32</name> + </clients> + <clients> + <name>83.97.94.52/32</name> + </clients> + <clients> + <name>83.97.94.97/32</name> + </clients> + <clients> + <name>83.97.94.98/32</name> + </clients> + </community> + <community> + <name>XantaroXSE</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.99.47/32</name> + </clients> + </community> + <trap-group> + <name>geantnms</name> + <categories> + <chassis/> + <link/> + <routing/> + </categories> + <targets> + <name>62.40.104.50</name> + </targets> + <targets> + <name>62.40.104.51</name> + </targets> + <targets> + <name>62.40.104.155</name> + </targets> + <targets> + <name>62.40.104.157</name> + </targets> + <targets> + <name>62.40.104.154</name> + </targets> + <targets> + <name>62.40.114.3</name> + </targets> + <targets> + <name>62.40.114.2</name> + </targets> + <targets> + <name>62.40.114.18</name> + </targets> + <targets> + <name>62.40.114.19</name> + </targets> + <targets> + <name>83.97.92.238</name> + </targets> + <targets> + <name>83.97.92.239</name> + </targets> + </trap-group> + </snmp> + <forwarding-options> + <storm-control-profiles> + <name>default</name> + <all> + </all> + </storm-control-profiles> + <cut-through/> + </forwarding-options> + <routing-options> + <static> + <route> + <name>0.0.0.0/0</name> + <next-hop>62.40.117.177</next-hop> + </route> + </static> + </routing-options> + <protocols> + <lacp> + <traceoptions> + <file> + <filename>lacp.log</filename> + <size>40000</size> + </file> + <flag> + <name>all</name> + </flag> + </traceoptions> + </lacp> + <lldp> + <interface> + <name>all</name> + </interface> + <interface> + <name>em0</name> + <disable/> + </interface> + </lldp> + <lldp-med> + <interface> + <name>all</name> + </interface> + </lldp-med> + <igmp-snooping> + <vlan> + <name>default</name> + </vlan> + </igmp-snooping> + </protocols> + <policy-options> + <prefix-list> + <name>GEANT-Superpop-v4</name> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + </prefix-list> + </policy-options> + <virtual-chassis> + <preprovisioned/> + <no-split-detection/> + <member> + <name>0</name> + <role>routing-engine</role> + <serial-number>TA3718040596</serial-number> + </member> + <member> + <name>1</name> + <role>routing-engine</role> + <serial-number>TA3718040433</serial-number> + </member> + </virtual-chassis> + <vlans> + <vlan> + <name>DEV_ESX_MGMT</name> + <description>ESXi management - vCenter, vMotion</description> + <vlan-id>2001</vlan-id> + </vlan> + <vlan> + <name>DEV_NAGIOS_GTS</name> + <vlan-id>3001</vlan-id> + </vlan> + <vlan> + <name>DEV_RHPS_1</name> + <vlan-id>3002</vlan-id> + </vlan> + <vlan> + <name>DEV_RHPS_2</name> + <vlan-id>3003</vlan-id> + </vlan> + <vlan> + <name>DEV_TAAS_RANCID</name> + <vlan-id>3004</vlan-id> + </vlan> + <vlan> + <name>DEV_TNMS</name> + <vlan-id>991</vlan-id> + </vlan> + <vlan> + <name>DEV_VM</name> + <vlan-id>3000</vlan-id> + </vlan> + <vlan> + <name>DEV_VSAN</name> + <vlan-id>1002</vlan-id> + </vlan> + <vlan> + <name>EXT-SERVER</name> + <description>For GEANT IT External Servers</description> + <vlan-id>114</vlan-id> + </vlan> + <vlan> + <name>FW-VRF</name> + <description>For linking Firewall and GEANT VRF on MX1.LON2</description> + <vlan-id>300</vlan-id> + </vlan> + <vlan> + <name>FW-WAN</name> + <description>For WAN Link to Fortigate Cluster</description> + <vlan-id>100</vlan-id> + </vlan> + <vlan> + <name>INT-INFRA</name> + <description>Internal Infrastructure, idracs etc</description> + <vlan-id>103</vlan-id> + </vlan> + <vlan> + <name>INT-SERVER</name> + <description>Internal Servers, VMs etc - RFC1918 addressing</description> + <vlan-id>104</vlan-id> + </vlan> + <vlan> + <name>INT-VPN</name> + <description>For GEANT IT VPN Users</description> + <vlan-id>108</vlan-id> + </vlan> + <vlan> + <name>VSAN1</name> + <vlan-id>1000</vlan-id> + </vlan> + <vlan> + <name>VSAN2</name> + <vlan-id>1001</vlan-id> + </vlan> + <vlan> + <name>default</name> + <vlan-id>1</vlan-id> + <l3-interface inactive="inactive">irb.0</l3-interface> + </vlan> + <vlan> + <name>eduvpn-link</name> + <vlan-id>101</vlan-id> + </vlan> + <vlan> + <name>eduvpn-slough</name> + <description>For eduVPN-01 servers</description> + <vlan-id>115</vlan-id> + </vlan> + </vlans> +</configuration> + diff --git a/test/data/qfx.par.fr.geant.net-netconf.xml b/test/data/qfx.par.fr.geant.net-netconf.xml new file mode 100644 index 0000000000000000000000000000000000000000..f4672ff4298a1fbcc3716d36c97bbe84f1db3e31 --- /dev/null +++ b/test/data/qfx.par.fr.geant.net-netconf.xml @@ -0,0 +1,1364 @@ +<configuration changed-seconds="1571158483" changed-localtime="2019-10-15 16:54:43 UTC"> + <version>17.3R3-S3.3</version> + <groups> + <name>juniper-ais</name> + <system> + </system> + </groups> + <apply-groups>juniper-ais</apply-groups> + <system> + <host-name>qfx.par.fr</host-name> + <domain-name>geant.net</domain-name> + <time-zone>UTC</time-zone> + <authentication-order>radius</authentication-order> + <authentication-order>password</authentication-order> + <location> + <country-code>FR</country-code> + </location> + <root-authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </root-authentication> + <radius-server> + <name>62.40.120.136</name> + <timeout>2</timeout> + <source-address>62.40.117.170</source-address> + </radius-server> + <radius-server> + <name>62.40.121.121</name> + <timeout>2</timeout> + <source-address>62.40.117.170</source-address> + </radius-server> + <login> + <class> + <name>NOC-Class</name> + <idle-timeout>60</idle-timeout> + <permissions>all</permissions> + </class> + <class> + <name>dante</name> + <idle-timeout>20</idle-timeout> + <permissions>admin</permissions> + <permissions>firewall</permissions> + <permissions>firewall-control</permissions> + <permissions>interface</permissions> + <permissions>network</permissions> + <permissions>routing</permissions> + <permissions>snmp</permissions> + <permissions>system</permissions> + <permissions>trace</permissions> + <permissions>trace-control</permissions> + <permissions>view</permissions> + </class> + <class> + <name>readonly-permissions</name> + <permissions>view</permissions> + <permissions>view-configuration</permissions> + <allow-commands>show .*|quit|ping .*|monitor .*|traceroute .*</allow-commands> + </class> + <user> + <name>Monit0r</name> + <full-name>Monitor</full-name> + <uid>2003</uid> + <class>dante</class> + <authentication> + <ssh-dsa> + <name>/* SECRET-DATA */</name> + </ssh-dsa> + </authentication> + </user> + <user> + <name>python</name> + <uid>2001</uid> + <class>NOC-Class</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + <ssh-rsa> + <name>/* SECRET-DATA */</name> + </ssh-rsa> + </authentication> + </user> + <user> + <name>remote</name> + <full-name>All users via RADIUS</full-name> + <uid>2005</uid> + <class>NOC-Class</class> + </user> + <user> + <name>reporting</name> + <uid>2000</uid> + <class>readonly-permissions</class> + </user> + <user> + <name>space15.2R2.4-paris</name> + <uid>2004</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>space17.1R1.7-london</name> + <uid>2006</uid> + <class>super-user</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <user> + <name>xantaro</name> + <uid>2002</uid> + <class>readonly-permissions</class> + <authentication> + <encrypted-password>/* SECRET-DATA */</encrypted-password> + </authentication> + </user> + <password> + <minimum-length>10</minimum-length> + <minimum-numerics>1</minimum-numerics> + <minimum-upper-cases>1</minimum-upper-cases> + <minimum-lower-cases>1</minimum-lower-cases> + <minimum-punctuations>1</minimum-punctuations> + </password> + </login> + <services> + <ssh> + <root-login>deny</root-login> + <no-tcp-forwarding/> + <protocol-version>v2</protocol-version> + <max-sessions-per-connection>32</max-sessions-per-connection> + <connection-limit>100</connection-limit> + <rate-limit>50</rate-limit> + </ssh> + <netconf> + <ssh> + </ssh> + </netconf> + </services> + <syslog> + <user> + <name>*</name> + <contents> + <name>any</name> + <emergency/> + </contents> + </user> + <host> + <name>83.97.94.11</name> + <contents> + <name>any</name> + <any/> + </contents> + <port>515</port> + </host> + <comment>/* XantaroXSE - London2 - Slough */</comment> + <host> + <name>62.40.99.47</name> + <contents> + <name>any</name> + <any/> + </contents> + </host> + <file> + <name>messages</name> + <contents> + <name>any</name> + <notice/> + </contents> + <contents> + <name>authorization</name> + <info/> + </contents> + <match>!(RPD_MSDP_SRC_ACTIVE.*|.*bgp_rt_send_msg_attr.*)</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>interactive-commands</name> + <contents> + <name>interactive-commands</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>conf-history</name> + <contents> + <name>conflict-log</name> + <any/> + </contents> + <contents> + <name>change-log</name> + <any/> + </contents> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <file> + <name>default-log-messages</name> + <contents> + <name>any</name> + <any/> + </contents> + <match>(requested 'commit' operation)|(requested 'commit synchronize' operation)|(copying configuration to juniper.save)|(commit complete)|ifAdminStatus|(FRU power)|(FRU removal)|(FRU insertion)|(link UP)|transitioned|Transferred|transfer-file|(license add)|(license delete)|(package -X update)|(package -X delete)|(FRU Online)|(FRU Offline)|(plugged in)|(unplugged)|QF_NODE|QF_SERVER_NODE_GROUP|QF_INTERCONNECT|QF_DIRECTOR|QF_NETWORK_NODE_GROUP|(Master Unchanged, Members Changed)|(Master Changed, Members Changed)|(Master Detected, Members Changed)|(vc add)|(vc delete)|(Master detected)|(Master changed)|(Backup detected)|(Backup changed)|(interface vcp-)|(AIS_DATA_AVAILABLE)</match> + <structured-data> + </structured-data> + </file> + <file> + <name>authorization</name> + <contents> + <name>authorization</name> + <any/> + </contents> + </file> + <file> + <name>firewall-log</name> + <contents> + <name>firewall</name> + <critical/> + </contents> + </file> + <file> + <name>daemon</name> + <contents> + <name>daemon</name> + <error/> + </contents> + </file> + <file> + <name>net-alarms</name> + <contents> + <name>daemon</name> + <warning/> + </contents> + </file> + <file> + <name>low-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <notice/> + </contents> + <contents> + <name>kernel</name> + <notice/> + </contents> + <contents> + <name>user</name> + <notice/> + </contents> + <contents> + <name>pfe</name> + <notice/> + </contents> + </file> + <file> + <name>high-messages</name> + <contents> + <undocumented><name>cron</name></undocumented> + <error/> + </contents> + <contents> + <name>kernel</name> + <error/> + </contents> + <contents> + <name>user</name> + <error/> + </contents> + <contents> + <name>pfe</name> + <error/> + </contents> + <match>(!PCF8584) | (!CHASSISD_VOLTAGE_SENSOR_INIT)</match> + </file> + <file> + <name>commands-log</name> + <contents> + <name>interactive-commands</name> + <info/> + </contents> + </file> + <file> + <name>dnoc-events</name> + <contents> + <name>daemon</name> + <info/> + </contents> + <match>.*SNMP_TRAP_LINK_.*|.*RPD_BGP_NEIGHBOR_STATE_CHANGED.*|.*SNMPD_TRAP_COLD_START.*</match> + <archive> + <size>10m</size> + <files>10</files> + </archive> + </file> + <source-address>62.40.117.170</source-address> + </syslog> + <extensions> + <providers> + <name>juniper</name> + <license-type> + <name>juniper</name> + <deployment-scope>commercial</deployment-scope> + </license-type> + </providers> + <providers> + <name>chef</name> + <license-type> + <name>juniper</name> + <deployment-scope>commercial</deployment-scope> + </license-type> + </providers> + </extensions> + <commit> + <synchronize/> + </commit> + <processes> + <dhcp-service> + <traceoptions> + <file> + <filename>dhcp_logfile</filename> + <size>10m</size> + </file> + <level>all</level> + <flag> + <name>all</name> + </flag> + </traceoptions> + </dhcp-service> + <app-engine-virtual-machine-management-service> + <traceoptions> + <level>notice</level> + <flag> + <name>all</name> + </flag> + </traceoptions> + </app-engine-virtual-machine-management-service> + </processes> + <ntp> + <authentication-key> + <name>10</name> + <type>md5</type> + <value>/* SECRET-DATA */</value> + </authentication-key> + <server> + <name>62.40.123.21</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.123.23</name> + <key>/* SECRET-DATA */</key> + </server> + <server> + <name>62.40.123.103</name> + <key>/* SECRET-DATA */</key> + </server> + <trusted-key>10</trusted-key> + </ntp> + </system> + <chassis> + <redundancy> + <graceful-switchover> + </graceful-switchover> + </redundancy> + <aggregated-devices> + <ethernet> + <device-count>15</device-count> + </ethernet> + </aggregated-devices> + <auto-image-upgrade inactive="inactive"/> + </chassis> + <interfaces> + <interface> + <name>xe-0/0/0</name> + <description>PHY INFRASTRUCTURE LAN P_ae5 | 730xd-1 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae5</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/1</name> + <description>PHY INFRASTRUCTURE LAN P_ae9 | 730xd-1 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae9</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/2</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-2 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-0/0/3</name> + <description>PHY INFRASTRUCTURE LAN P_ae7 | 730xd-3 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/4</name> + <description>PHY INFRASTRUCTURE LAN P_ae11 | 730xd-3 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/5</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-4 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-0/0/6</name> + <description>PHY INFRASTRUCTURE LAN P_ae12 | 730xd-4 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/7</name> + <description>PHY INFRASTRUCTURE LAN P_ae10 | 730xd-2 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/8</name> + <description>PHY INFRASTRUCTURE LAN P_ae9 | 730xd-1 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae9</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/9</name> + <description>PHY INFRASTRUCTURE LAN P_ae1 | 730xd-1 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/10</name> + <description>PHY INFRASTRUCTURE LAN P_ae2 | 730xd-2 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/11</name> + <description>PHY INFRASTRUCTURE LAN P_ae11 | 730xd-3 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/12</name> + <description>PHY INFRASTRUCTURE LAN P_ae3 | 730xd-3 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae3</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/13</name> + <description>PHY INFRASTRUCTURE LAN P_ae4 | 730xd-4 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/14</name> + <description>PHY INFRASTRUCTURE LAN P_ae8 | 730xd-4 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/15</name> + <description>PHY INFRASTRUCTURE LAN P_ae6 | 730xd-2 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae6</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/16</name> + <description>PHY INFRASTRUCTURE LAN P_ae13 | FRA-PAR-BRIDGE 1-1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/18</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-9/0/2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/19</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-2/1/0</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-0/0/45</name> + <description>PHY INFRASTRUCTURE LAN P_ae14 | QFX.LON2.UK 0/0/45</description> + </interface> + <interface> + <name>xe-1/0/0</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-1 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <mtu>9000</mtu> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-1/0/1</name> + <description>PHY INFRASTRUCTURE LAN P_ae6 | 730xd-2 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae6</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/2</name> + <description>PHY INFRASTRUCTURE LAN P_ae10 | 730xd-2 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/3</name> + <description>PHY INFRASTRUCTURE LAN | 730xd-3 Slot0 Port1 VMNIC0</description> + <flexible-vlan-tagging/> + <unit> + <name>2001</name> + <vlan-id>2001</vlan-id> + <family> + <ethernet-switching> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>xe-1/0/4</name> + <description>PHY INFRASTRUCTURE LAN P_ae8 | 730xd-4 Slot4 Port4 VMNIC7</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae8</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/5</name> + <description>PHY INFRASTRUCTURE LAN P_ae12 | 730xd-4 Slot0 Port2 VMNIC1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/6</name> + <description>PHY INFRASTRUCTURE LAN P_ae9 | 730xd-1 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae9</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/7</name> + <description>PHY INFRASTRUCTURE LAN P_ae11 | 730xd-3 Slot4 Port2 VMNIC5</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae11</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/8</name> + <description>PHY INFRASTRUCTURE LAN P_ae1 | 730xd-1 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae1</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/9</name> + <description>PHY INFRASTRUCTURE LAN P_ae10 | 730xd-2 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae10</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/10</name> + <description>PHY INFRASTRUCTURE LAN P_ae2 | 730xd-2 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae2</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/11</name> + <description>PHY INFRASTRUCTURE LAN P_ae37 | 730xd-3 Slot0 Port3 VMNIC2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae3</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/12</name> + <description>PHY INFRASTRUCTURE LAN P_ae12| 730xd-4 Slot4 Port3 VMNIC6</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae12</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/13</name> + <description>PHY INFRASTRUCTURE LAN P_ae4 | 730xd-4 Slot0 Port4 VMNIC3</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae4</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/14</name> + <description>PHY INFRASTRUCTURE LAN P_ae5 | 730xd-1 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae5</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/15</name> + <description>PHY INFRASTRUCTURE LAN P_ae7 | 730xd-3 Slot4 Port1 VMNIC4</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae7</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/16</name> + <description>PHY INFRASTRUCTURE LAN P_ae13 | FRA-PAR-BRIDGE 2-2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae13</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/18</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-2/1/1</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/19</name> + <description>PHY INFRASTRUCTURE LAN P_ae0 | MX xe-2/2/2</description> + <ether-options> + <ieee-802.3ad> + <bundle>ae0</bundle> + </ieee-802.3ad> + </ether-options> + </interface> + <interface> + <name>xe-1/0/45</name> + <description>PHY INFRASTRUCTURE LAN P_ae14 | QFX.LON2.UK 1/0/45</description> + </interface> + <interface> + <name>ae0</name> + <description>LAG INFRASTRUCTURE LAN | MX AE30</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + <members>VL_VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae1</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-1 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae2</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-2 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae3</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-3 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae4</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-4 ESXI Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_MANAGEMENT</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae5</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-1 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae6</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-2 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae7</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-3 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae8</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-4 vSAN Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>access</interface-mode> + <vlan> + <members>VL_VSAN</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae9</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-1 VM Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <inter-switch-link/> + <vlan> + <members>VL_VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae10</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-2 VM Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <inter-switch-link/> + <vlan> + <members>VL_VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae11</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-3 VM Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <inter-switch-link/> + <vlan> + <members>VL_VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae12</name> + <description>LAG INFRASTRUCTURE LAN | 730xd-4 VM Traffic LAG</description> + <mtu>9216</mtu> + <aggregated-ether-options> + <minimum-links>1</minimum-links> + <lacp> + <active/> + <periodic>slow</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <inter-switch-link/> + <vlan> + <members>VL_VM</members> + <members>VL_TNMS</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface> + <name>ae13</name> + <description>LAG INFRASTRUCTURE LAN | QFX.FRA.DE AE13</description> + <mtu>9192</mtu> + <aggregated-ether-options> + <lacp> + <active/> + <periodic>fast</periodic> + </lacp> + </aggregated-ether-options> + <unit> + <name>0</name> + <family> + <ethernet-switching> + <interface-mode>trunk</interface-mode> + <vlan> + <members>VL_VM</members> + <members>VL_RHPS_1</members> + <members>VL_RHPS_2</members> + <members>VL_NAGIOS_GTS</members> + <members>VL_TNMS</members> + <members>VL_TAAS_RANCID</members> + </vlan> + </ethernet-switching> + </family> + </unit> + </interface> + <interface inactive="inactive"> + <name>em0</name> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>62.40.117.171/29</name> + </address> + </inet> + </family> + </unit> + </interface> + <interface> + <name>vme</name> + <unit> + <name>0</name> + <family> + <inet> + <address> + <name>62.40.117.170/29</name> + </address> + </inet> + </family> + </unit> + </interface> + </interfaces> + <snmp> + <community> + <name>0pBiFbD</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.120.18/32</name> + </clients> + <clients> + <name>62.40.123.180/32</name> + </clients> + <clients> + <name>62.40.104.50/32</name> + </clients> + <clients> + <name>62.40.104.51/32</name> + </clients> + <clients> + <name>62.40.104.155/32</name> + </clients> + <clients> + <name>62.40.104.157/32</name> + </clients> + <clients> + <name>62.40.104.154/32</name> + </clients> + <clients> + <name>62.40.113.88/29</name> + </clients> + <clients> + <name>83.97.93.195/32</name> + </clients> + <clients> + <name>83.97.93.196/32</name> + </clients> + <clients> + <name>83.97.93.22/32</name> + </clients> + <clients> + <name>83.97.93.152/32</name> + </clients> + <clients> + <name>83.97.93.153/32</name> + </clients> + <clients> + <name>83.97.93.239/32</name> + </clients> + <clients> + <name>83.97.94.52/32</name> + </clients> + <clients> + <name>83.97.94.97/32</name> + </clients> + <clients> + <name>83.97.94.98/32</name> + </clients> + </community> + <community> + <name>XantaroXSE</name> + <authorization>read-only</authorization> + <clients> + <name>62.40.99.47/32</name> + </clients> + </community> + <trap-group> + <name>geantnms</name> + <categories> + <chassis/> + <link/> + <routing/> + </categories> + <targets> + <name>62.40.104.50</name> + </targets> + <targets> + <name>62.40.104.51</name> + </targets> + <targets> + <name>62.40.104.155</name> + </targets> + <targets> + <name>62.40.104.157</name> + </targets> + <targets> + <name>62.40.104.154</name> + </targets> + <targets> + <name>62.40.114.3</name> + </targets> + <targets> + <name>62.40.114.2</name> + </targets> + <targets> + <name>62.40.114.18</name> + </targets> + <targets> + <name>62.40.114.19</name> + </targets> + <targets> + <name>83.97.92.238</name> + </targets> + <targets> + <name>83.97.92.239</name> + </targets> + </trap-group> + </snmp> + <forwarding-options> + <storm-control-profiles> + <name>default</name> + <all> + </all> + </storm-control-profiles> + <cut-through/> + </forwarding-options> + <routing-options> + <static> + <route> + <name>0.0.0.0/0</name> + <next-hop>62.40.117.169</next-hop> + </route> + </static> + </routing-options> + <protocols> + <lacp> + <traceoptions> + <file> + <filename>lacp.log</filename> + </file> + <flag> + <name>all</name> + </flag> + </traceoptions> + <ppm>centralized</ppm> + </lacp> + <lldp> + <interface> + <name>all</name> + </interface> + <interface> + <name>em0</name> + <disable/> + </interface> + <interface> + <name>em1</name> + <disable/> + </interface> + <interface> + <name>em2</name> + <disable/> + </interface> + </lldp> + <lldp-med> + <interface> + <name>all</name> + </interface> + </lldp-med> + <igmp-snooping> + <vlan> + <name>default</name> + </vlan> + </igmp-snooping> + </protocols> + <policy-options> + <prefix-list> + <name>GEANT-Superpop-v4</name> + <prefix-list-item> + <name>83.97.92.0/22</name> + </prefix-list-item> + </prefix-list> + </policy-options> + <virtual-chassis> + <preprovisioned/> + <no-split-detection/> + <undocumented><vcp-snmp-statistics/></undocumented> + <member> + <name>0</name> + <role>routing-engine</role> + <serial-number>TA3716210302</serial-number> + </member> + <member> + <name>1</name> + <role>routing-engine</role> + <serial-number>TA3716210063</serial-number> + </member> + </virtual-chassis> + <vlans> + <vlan> + <name>VL_MANAGEMENT</name> + <description>ESXi management - vCenter, vMotion</description> + <vlan-id>2001</vlan-id> + </vlan> + <vlan> + <name>VL_NAGIOS_GTS</name> + <description>GTS Interface of Nagios server</description> + <vlan-id>3001</vlan-id> + </vlan> + <vlan> + <name>VL_RHPS_1</name> + <vlan-id>3002</vlan-id> + </vlan> + <vlan> + <name>VL_RHPS_2</name> + <vlan-id>3003</vlan-id> + </vlan> + <vlan> + <name>VL_TAAS_RANCID</name> + <vlan-id>3004</vlan-id> + </vlan> + <vlan> + <name>VL_TNMS</name> + <description>For Coriant TNMS VM</description> + <vlan-id>991</vlan-id> + </vlan> + <vlan> + <name>VL_VM</name> + <description>default VM VLAN 83.97.92</description> + <vlan-id>3000</vlan-id> + </vlan> + <vlan> + <name>VL_VSAN</name> + <vlan-id>1000</vlan-id> + </vlan> + <vlan> + <name>default</name> + <vlan-id>1</vlan-id> + </vlan> + </vlans> +</configuration> + diff --git a/test/test_classifier_routes.py b/test/test_classifier_routes.py index 92c418fce483bd89aa228d42bcdf72174b94214d..81fa8e87c906dea82d927129bc595c7e8e71eced 100644 --- a/test/test_classifier_routes.py +++ b/test/test_classifier_routes.py @@ -140,6 +140,26 @@ def test_juniper_link_info(client): jsonschema.validate(response_data, JUNIPER_LINK_METADATA) +def test_juniper_link_info_not_found(client): + rv = client.get( + '/classifier/juniper-link-info/' + 'mx1.ams.nl.geant.net/unknown-interface-name', + headers=DEFAULT_REQUEST_HEADERS) + assert rv.status_code == 200 + assert rv.is_json + response_data = json.loads(rv.data.decode('utf-8')) + jsonschema.validate(response_data, JUNIPER_LINK_METADATA) + assert response_data == { + 'interface': { + 'name': 'unknown-interface-name', + 'description': '', + 'ipv4': [], + 'ipv6': [], + 'bundle': [] + } + } + + VPN_RR_PEER_INFO_KEYS = {'vpn-rr-peer-info'} IX_PUBLIC_PEER_INFO_KEYS = {'ix-public-peer-info', 'interfaces'} @@ -279,7 +299,9 @@ def test_peer_not_found(client): rv = client.get( '/classifier/peer-info/1.2.3.4', headers=DEFAULT_REQUEST_HEADERS) - assert rv.status_code == 404 + assert rv.status_code == 200 + response_data = json.loads(rv.data.decode('utf-8')) + assert response_data == {} @pytest.mark.parametrize('id_,equipment,entity_name,card_id,port_number', [ diff --git a/test/test_general_routes.py b/test/test_general_routes.py index f7c4dda49f2a1711d3b38104af3df1ec1f698775..a6a915e95e0412641280c155f09d0d31f519c90f 100644 --- a/test/test_general_routes.py +++ b/test/test_general_routes.py @@ -7,9 +7,26 @@ DEFAULT_REQUEST_HEADERS = { } -def test_version_request(client): +def test_version_request(client, mocked_redis): + version_schema = { "$schema": "http://json-schema.org/draft-07/schema#", + + "definitions": { + "latch": { + "type": "object", + "properties": { + "current": {"type": "integer"}, + "next": {"type": "integer"}, + "this": {"type": "integer"}, + "failure": {"type": "boolean"}, + "pending": {"type": "boolean"}, + }, + "required": ["current", "next", "this", "pending", "failure"], + "additionalProperties": False + } + }, + "type": "object", "properties": { "api": { @@ -19,7 +36,8 @@ def test_version_request(client): "module": { "type": "string", "pattern": r'\d+\.\d+' - } + }, + "latch": {"$ref": "#/definitions/latch"} }, "required": ["api", "module"], "additionalProperties": False diff --git a/test/test_netconf_validation.py b/test/test_netconf_validation.py new file mode 100644 index 0000000000000000000000000000000000000000..3eca33cf7840f6e524bc6e8b76a4a7fd91fab007 --- /dev/null +++ b/test/test_netconf_validation.py @@ -0,0 +1,50 @@ +import os +import pytest +from lxml import etree +from inventory_provider.juniper import validate_netconf_config + + +@pytest.mark.parametrize('hostname', [ + 'mx1.ams.nl.geant.net', + 'mx1.ath2.gr.geant.net', + 'mx1.buc.ro.geant.net', + 'mx1.bud.hu.geant.net', + 'mx1.dub.ie.geant.net', + 'mx1.dub2.ie.geant.net', + 'mx1.fra.de.geant.net', + 'mx1.gen.ch.geant.net', + 'mx1.ham.de.geant.net', + 'mx1.kau.lt.geant.net', + 'mx1.lis.pt.geant.net', + 'mx1.lon.uk.geant.net', + 'mx1.lon2.uk.geant.net', + 'mx1.mad.es.geant.net', + 'mx1.mar.fr.geant.net', + 'mx1.mil2.it.geant.net', + 'mx1.par.fr.geant.net', + 'mx1.poz.pl.geant.net', + 'mx1.pra.cz.geant.net', + 'mx1.sof.bg.geant.net', + 'mx1.tal.ee.geant.net', + 'mx1.vie.at.geant.net', + 'mx2.ath.gr.geant.net', + 'mx2.bra.sk.geant.net', + 'mx2.bru.be.geant.net', + 'mx2.kau.lt.geant.net', + 'mx2.lis.pt.geant.net', + 'mx2.lju.si.geant.net', + 'mx2.rig.lv.geant.net', + 'mx2.tal.ee.geant.net', + 'mx2.zag.hr.geant.net', + 'qfx.fra.de.geant.net', + 'qfx.lon2.uk.geant.net', + 'qfx.par.fr.geant.net' +]) +def test_netconf_docs(hostname): + filename = os.path.join( + os.path.dirname(__file__), + 'data', + hostname + '-netconf.xml') + + doc = etree.parse(filename) + validate_netconf_config(doc)