Home / Networking
I keep most of my Cisco notes elsewhere, sorry.
An example of a full configuration for ASR 920 (IOS XE 16.9).
enableconf tztp disableno service configno service padno service password-encryptionno cdp runno ip source-routeno ipv6 source-routeno ip domain-lookup (optional)no ip http serverno ip http secure-serverhostname <hostname>ip domain-name <domain> (the part after the hostname)clock timezone UTC 1 0 (Norway)clock summer-time CEST recurring last Sun Mar 2:00 last Sun Oct 3:00 (Norway)clock set 10:50:00 Oct 26 2006 (example)show clockline con 0logging synchronouslogging buffered 16384 warningslogging console criticalaaa new-modelenable algorithm-type scrypt secret <secret>
username <username> privilege 15 algorithm-type scrypt secret <password>aaa authentication login default localline con 0login authentication defaultcrypto key generate rsa modulus <2048|4096>ip ssh version 2line vty 0 15transport input sshexec-timeout <minutes> <seconds> (e.g. 60 minutes)privilege level 15ip name-server <addr1> <addr2> [...]ipv6 unicast-routingip cefipv6 cefsh cef state (should show “enabled/running” for both IPv4 and IPv6)ip route <address> <mask> Null 0ipv6 route <prefix> Null 0interface GigabitEthernet 0 (example)ip route vrf Mgmt-intf 0.0.0.0 0.0.0.0 <gateway>ip route vrf Mgmt-intf ::/0 <gateway>desc <desc>ip address <address> <mask>ipv6 address <address>/<prefix-length>ipv6 nd ra suppress allip verify unicast source reachable-via rxipv6 verify unicast source reachable-via rxip route 0.0.0.0 0.0.0.0 <gateway>ip route ::/0 <gateway>lldp runip access-list standard <name-v4>permit <address> <wildcard-mask>ipv6 access-list <name-v6>permit <src-prefix> <dst-prefix>access-class <name-v4> inaccess-class <name-v4> in vrfname Mgmt-intfipv6 access-class <name-v6> inipv6 access-class <name-v6> in vrfname Mgmt-intfntp server <address>sh ntp assocsh ntp statuslogging host <address>logging facility syslogsnmp-server community public ro ipv6 <acl-name-v6> <acl-name-v4>copy run start or write memcopy start tftp://<host>/<path>bridge-domain <VID>
service instance <VID> ethernetencapsulation dot1q <VID>rewrite ingress tag pop 1 symmetricbridge-domain <VID>int BDI <VID>no shutipv6 nd ra suppress all
all, it may in certain versions still send solicited advertisements.