-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathsample-policy.txt
157 lines (157 loc) · 3.09 KB
/
sample-policy.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
policy
sla-class Gold
loss 2
latency 350
!
sla-class Silver
loss 3
latency 350
!
sla-class Voice
loss 1
latency 350
jitter 20
!
data-policy PH_ALL_DATA-POLICY
vpn-list SERVICE_VPN_10
sequence 10
match
source-data-prefix-list RFC1918
dscp 46
!
action accept
cflowd
set
forwarding-class Queue0
!
!
!
sequence 15
match
source-data-prefix-list RFC1918
app-list VOICE_CONTROL
!
action accept
cflowd
!
!
sequence 35
match
source-data-prefix-list RFC1918
destination-data-prefix-list RFC1918
app-list MICROSOFT_APPS
destination-port 443 80
!
action accept
cflowd
set
forwarding-class Queue3
!
!
!
app-route-policy AAR_POLICY
vpn-list SERVICE_VPN_10
sequence 5
match
app-list VOICE_CONTROL
!
action
count VOICE_CONTROL
backup-sla-preferred-color biz-internet public-internet
sla-class Voice preferred-color mpls metro-ethernet
!
!
cflowd-template CFLOWD_US
flow-inactive-timeout 120
collector vpn 10 address 1.2.3.4 port 2055 transport transport_udp source-interface loopback10
!
lists
vpn-list SERVICE_VPN_10
vpn 10
!
data-prefix-list ANY
ip-prefix 0.0.0.0/0
!
data-prefix-list RFC1918
ip-prefix 10.0.0.0/8
ip-prefix 172.16.0.0/12
ip-prefix 192.168.0.0/16
!
tloc-list VZ-VCP-vEdge-TLOC
tloc 1.1.1.1 color mpls encap ipsec preference 600
tloc 1.1.1.1 color biz-internet encap ipsec preference 550
tloc 1.1.2.1 color mpls encap ipsec preference 500
tloc 1.1.2.1 color biz-internet encap ipsec preference 450
!
app-list MICROSOFT_APPS
app bing
app microsoft
app ms-office-365
app ms-services
app sharepoint_admin
app sharepoint_blog
app sharepoint_calendar
app sharepoint_document
app sharepoint_online
app xbox_video
app xboxlive
app xboxlive_marketplace
app yammer
!
app-list VOICE_CONTROL
app rtcp
app sccp
app sip
app skinny
!
color-list MPLS-METRO-COLOR
color mpls
color metro-ethernet
!
!
site-list REMOTE-ALL
site-id 11100-11999
site-id 12100-12999
site-id 13100-13999
site-id 21100-21999
site-id 22100-22999
site-id 31100-31999
site-id 32100-32999
site-id 41100-41999
site-id 42100-42999
!
prefix-list RFC1918
ip-prefix 10.0.0.0/8
ip-prefix 172.16.0.0/12
ip-prefix 192.168.0.0/16
!
control-policy PH-ALL-In
sequence 5
match route
site-list PH-NA-East
!
action accept
set
omp-tag 12000
!
!
!
sequence 10
match route
site-list PH-NA-South
!
action accept
set
omp-tag 13000
!
!
!
!
apply-policy
site-list REMOTE-ALL
control-policy PH-ALL-In in
data-policy PH_ALL_DATA-POLICY from-service
app-route-policy AAR_POLICY
cflowd-template CFLOWD_US
!
!