Showing posts with label S5700. Show all posts
Showing posts with label S5700. Show all posts

Wednesday, November 23, 2016

ACL is forbidden to be modified in S5700

ACL is forbidden to be modified in S5700
If the ACl is applied to a vlan and I want to modify the ACL, I get this error:
Error: The ACL is contained by some application(s) and forbidden to be modified.

I do not want to remove the ACL from vlan, Change it and then reapply it back. It is rather inconvenient.
What should I do?
Alarm Information
The ACL is contained by some application(s) and forbidden to be modified.
Handling Process
You have 2 Solution:

1- You can use "Traffic policy" under vlan, then, You can modify ACL dynamically.
2- You can upgrade software version to V200R005 (or higher) version, You can modify ACL dynamically when using "Traffic-xxx" Commands

Example:
***********
[huawei-GigabitEthernet0/0/1]traffic-mirror inbound acl
[huawei-GigabitEthernet0/0/1]traffic-redirect inbound acl 
[huawei-GigabitEthernet0/0/1]traffic-remark inbound acl
[huawei-GigabitEthernet0/0/1]traffic-secure inbound acl 
    

MORE:

What Is the Calculation Method for Load Balancing of the Upstream Aggregation Ports of the MA5680T?

Tuesday, July 26, 2016

How to Set Huawei S5700 VLAN?

Question:
How to set VLAN on Huawei S5700-SI switch,
S5700-SI IP: 192.168.1.200
Server IP: 192.168.1.8
S1700 IP:192.168.1.X
I want to know how to separate different VLAN and how to connect different VLAN on Huawei switch?
Answer:
Set IP for each VLAN, then it can automatically generate route, then different VLAN can be accessed.


More blog:

Why Automatical configuration backup cannot work on S5700

Wednesday, July 20, 2016

Huawei switch shows global competitiveness, global market share steadily

In 2012, the global Ethernet switch market by networking, cloud computing industry development drive, continue to show steady growth trend. Ethernet switch is still the mainstream market, intelligent switch is becoming the new development direction of exchange market. Through the Infonetics Researc released the latest report, in 2012 4.7% growth in global Ethernet switch sales revenue, the fourth quarter of 2012 Ethernet switch sales revenue growth of 5%.
According to IDC, in the fourth quarter of 2012, Cisco although in Ethernet switch market still occupy the dominant position, but the market share has declined, and the loss of market share is gradually digest the Huawei Huawei, gradually expand its market share, market share steadily rising trend. And in the Dell’oro recently released a report, in 2012, Huawei in global exchange market share has been ranked third. Huawei has become one of the market share of the global exchange market mainstream competitors in a higher increase of the enterprises in 2012.
In a recent Gartner report data shows, Huawei in switch market manufacturers share in 2011 from 10 in 2012 rose to fifth outside. The report data display, Huawei in 2012 fast growth rate, mainstream competitors list from the non-mainstream competitors in a short span of 1 years. And Huawei continues to strengthen its competitiveness in the market, to seek in the growth trend in 2013 continued to maintain the company in the market.
On the other hand, in the market, brand attention pattern and changed little in 2011, in the first tier market top brand user attention more focused, the first echelon manufacturers further deepened the influence on the market. In the second tier manufacturers to fierce competition, mutual gap small, but has little effect on the market influence.
Display through the Internet Consumer Research Center recently released report, the exchange market, Huawei’s brand awareness in the past three months were all above 20%, ranked second. Huawei is working with the first attention quickly narrow the gap, and there are indications that in the next few months Huawei will overtake market has become the focus of the first.
Huawei attention in exchange market is rising day by day, high quality products are mainly benefited from the Huawei Huawei, S5700-24TP-SI (AC) products continue to pay attention to product the first absolute advantage, and it is worth mentioning that, in the products concerned before ten, Huawei has six products on the list, in the market competition, both from a single product focus ratio or from a high degree of concern the number of products, Huawei in the market to maintain absolute superiority.
In the future, driven by 40GE, data center, BYOD application and other factors, the global exchange market still has certain development potential can be dug according to depth of industry manufacturers. In the future development of the market, exchange market core growth still comes from 10GE and 40GE films, but by the edge of deployment requirements school and network increases day by day, Gigabit Ethernet requirements and attention are also greatly enhance. On the other hand, the virtual data center Ethernet switch will drive demand for more intense, the above factors will become a powerful driving force exchange market development, and will further expand the market rise space.
As the Huawei cutting-edge HG532d based on carrying on the family of excellence performance, have a more powerful WIFI coverage and 270 degrees vertical wall performance. At the same time, the higher level of security, hacker intrusion protection system, super compatible with stability and white “ease of use makes it more as diocesan. The charm of elegant posture design also gives the HG532d more clear “soul”, carrying the user thought, preferences and beautiful home life.


More blog:

What is the command lines that we can use on the OLT to detect PRTE board status

Thursday, June 30, 2016

After receiving an ICMP Request packet, a switch does not send it to the ICMP protocol stack but directly returns an ICMP Reply message. This process is called fast ICMPM reply. Switches cannot accurately calculate the delay or jitter of ping packets that require high real-time performance. The protocol stack adds the sending and receiving timestamps to ping packets. The packets need to enqueue frequently between the protocol stack and hardware. This task switching cannot ensure real-time performance of timestamps. In versions earlier than V100R006, fast ICMP reply is a common task. When a switch processes a large volume of service traffic, the reply delay is long due to task switching. In V100R006 and later versions, fast ICMP reply is a super task with a high priority. In most cases, the reply delay is about 1 ms. The actual delay depends on the CPU usage and is shorter than 100 ms. NOTE: By default, box switches have fast ICMP reply enabled in all versions.

The default aging time of ARP entries is 20 minutes. You can run the arp expire-time command to change the aging time.
You can also change the number of ARP probes by running the arp detect-times command. The default number of ARP probes is 3.
When the aging time of an ARP entry expires, the device sends a probe packet to the corresponding IP address every 5 seconds. If the device does not receive any response after the specified number of probes, it deletes the ARP entry.
For example, the aging time of ARP entries is set to 60s and the number of ARP probes is set to 6.
After 60s since an ARP entry is generated, the device sends an ARP probe every 5s. If the device does not receive any response after sending six probes, it deletes the ARP entry. Therefore, the actual aging time of the ARP entry is (60 + 6 x 5) = 90s.
NOTE:
For V100R002 version, the S2700/S3700/S5700/S6700 supports the 1/2 probe time and 3/4 probe time. The numbers of probes on the two time points are both 3 and cannot be changed. For example, if the aging time is 20 minutes (1200s) and the number of ARP probes is 6, the SS2700/S3700/S5700/S6700 sends three ARP probes at an interval of 5s after 10 minutes. After 15 minutes, the S2700/S3700/S5700/S6700 also sends three ARP probes at an interval of 5s. After 20 minutes, the S2700/S3700/S5700/S6700 sends six ARP probes at an interval of 5s. If the S2700/S3700/S5700/S6700 does not receive any response, it deletes the ARP entry.


More blog:

Why Automatical configuration backup cannot work on S5700

Sunday, May 29, 2016

Configuring Single-homed Inter-Board Link Aggregation

In inter-board link aggregation, one or more ports on two boards are added to a LAG. Inter-board link aggregation provides protection for boards configured with aggregated links. In single homing, only one upstream device is available, without differentiating between primary and slave devices.

Service Requirements

The bandwidth between the access device uplink ports and the upper-layer switch (such as
LS-S5700-24TP-PWR-SI-AC)is required to increase in load sharing mode. In addition, link protection is required. If one link becomes faulty, the upstream bandwidth is decreased, and the Internet access rate is reduced. However, the Internet access service must not be interrupted, and the access rate reduction slightly degrades user experience.
Board-level protection must be implemented in the LAG. If one board becomes faulty, services are not interrupted.

Networking

Two GIU boards on the access device are used for upstream transmission, and the access device is interconnected with another device. One LAG is configured on the two GIU boards of the access device, and the other LAG is configured on two boards of the interconnected device.

Prerequisite

  • Interconnected devices, hardware, and ports support LAGs.
  • The two aggregated ports do not have a static MAC address. To check whether an aggregated port has a static MAC address, run the display mac-address command.

Data Plan

Table 1 lists data plan for configuring single-homed inter-board link aggregation.
Table 1 Data plan for configuring single-homed inter-board link aggregation
Item Data Remarks
LAG member port
  • 0/19/0 (master port)
  • 0/20/0
  • The configuration of the slave port must be the same as that of the master device. Alternatively, the slave port is not configured.
  • It is recommended that you do not configure the slave port to prevent a service failure due to data inconsistency with the master port.
Aggregation type LACP aggregation When the access device connects to a device supporting LACP, the LACP aggregation mode is recommended. When the access device connects to a device not supporting LACP, only manual aggregation can be configured.
Load sharing type Load sharing A LAG works in load sharing mode by default.

Procedure

  1. (Mandatory) Create a LAG and select an aggregation type. Run the link-aggregation command to add multiple uplink Ethernet ports to the same LAG to protect ports and share load between the ports. The port with the smallest port ID is the master port.
  2. (Optional) Add a LAG member port. Perform this step when the LAG bandwidth or link reliability is required to improve. To do so, run the link-aggregation add-member command to add an Ethernet port to a LAG.
    NOTE:
    When adding a port to or deleting a port from a LAG, if this port has connected to the peer device, run the shutdown(Ethernet) command to deactivate this port or disconnect the optical fiber from this port to prevent a link loop.

  3. (Optional) Select a load bearing type. This step is required only when the LAG works in LACP aggregation mode.
    Configuring the maximum active links in a LAG implements traffic allocation in load non-sharing mode. For example, M+N links have been configured in a LAG. Then, run the link-aggregation max-link-number command to specify N active links. The remaining M links are standby ones. If an active link is interrupted, a standby link automatically changes to the active one.

  4. (Optional) Set the system priority and port priority. This step is required only when the LAG works in LACP aggregation mode.
    • LACP system priority: Run the lacp priority system command to set the LACP system priority of the access device.
    • LACP port priority: LACP port priority must be used with the maximum number of links. If a port is required preferentially for carrying services, set its priority higher. Run the lacp priority port command to change the link priority so that the standby link and the active link can be switched over.

  5. (Optional) Select a link revertive mode. This step is required only when the LAG works in LACP aggregation mode. Run the lacp preempt command to set whether traffic is switched back to the original link when the original link recovers.
  6. (Optional) Query LAG information. Run the display link-aggregation command to query the LAG information, including the master port, number of links, aggregation type (manual or LACP aggregation), and maximum number of links.

Result

The bandwidth between the access device uplink ports and the upper-layer switch is increased in load sharing mode. In addition, link protection is implemented. If one board in the LAG becomes faulty, services are not interrupted.

Example

The following configurations are used as an example to configure single-homed inter-board link aggregation:
  • The access device transmits data upstream using two GIU boards.
  • Uplink ports 0/19/0 and 0/20/0 on the active and standby GIU boards, respectively, are added to an inter-board LAG.
  • Packets are forwarded to these ports based on source and destination MAC addresses.
  • The LAG works in LACP aggregation mode.
huawei(config)#link-aggregation 0/19 0 0/20 0 egress-ingress workmode lacp-static
huawei(config)#display link-aggregation all
  -------------------------------------------------------------------------
  Master port  Link aggregation mode  Port NUM  Work mode  Max link number 
  -------------------------------------------------------------------------
  0/19/0       egress-ingress                4  lacp-static              -
  -------------------------------------------------------------------------
  Total: 1 link aggregation(s)

Configuration File

link-aggregation 0/19 0 0/20 0 egress-ingress workmode lacp-static



More related:

How to do when Abnormal Optical Power Reporting Caused by the Coupling Exception

Thursday, May 19, 2016

display system declaration switch

Function

This command is used to query the status of the law declaration switch. When you need to query whether the law declaration switch is enabled, run this command.

Format

display system declaration switch

Parameters

None

Modes

Common user mode

Level

Common user level

Usage Guidelines

You can run the system declaration switch command to configure the law declaration switch.

Example

To query the law declaration switch, do as follows:
huawei>display system declaration switch
 Command:
         display system declaration switch
Declaration switch : On

System Response

  • The system displays the message "Declaration switch : xx" after the command is executed successfully. "xx" is "On" or "Off", depending on the actual state of the law declaration switch.
  • For more information about the error message that the system displays against a command entered with incorrect syntax, see the "Syntax Check" in Parameter

More related:

Wednesday, May 11, 2016

How Can I Obtain the Serial Number of a Modular Switch?

Obtaining the Chassis Serial Number

  • On a standalone switch:
    Log in to the switch through Telnet or the console interface, and then run the display elabel backplane command in the user view to view electronic label information. In the command output, the BarCode field indicates the chassis serial number.
    <Quidway> display elabel backplane
    Info: It is executing, please wait...
    
    [BackPlane_1]
    /$[ArchivesInfo Version]
    /$ArchivesInfoVersion=3.0
    
    [Board Properties]
    BoardType=EH02BAKK
    BarCode=2102113089P0BB000881
    Item=02113089
    ……………
  • In a CSS:
    Log in to the master switch through Telnet or the console interface, and then run the display elabel backplane chassischassis-id command (chassis-id specifies the CSS ID of a member chassis) in the user view to view electronic label information. In the command output, the BarCode field indicates the serial number of the specified chassis.
    <Quidway> display elabel backplane chassis ?
      INTEGER<1-2>  Chassis ID                                                     
     
    <Quidway> display elabel backplane chassis 2
    Info: It is executing, please wait...                                           
                                                                                    
    [BackPlane_2]                                                                  
    /$[ArchivesInfo Version]
    /$ArchivesInfoVersion=3.0
    
    [Board Properties]                                                              
    BoardType=EH02BAKK
    BarCode=2102113089P0BB000881                                                       
    Item=02113549                                                                   
    ……………
    NOTE:
    The command syntax may differ in different software versions. You can enter a question mark (?) to obtain help information about the command and set the chassis ID according to the help information.

Obtaining the Serial Number of a Card

Log in to the master switch through Telnet or the console interface, and then run the display elabel command in the user view and specify a slot ID according to help information to view the electronic label of a card. In the command output, the BarCode field indicates the serial number of the card.
<Quidway> display elabel ?
  <1-1>      The present chassis                                                
  backplane  Backplane                                                          
  brief      Display information briefly                                        
<Quidway> display elabel 1/?
  <4,6-8>                              <CMU1>
  <FAN1-FAN2>                          <PWR1-PWR2>
<Quidway> display elabel 1/6 brief
Info: It is executing, please wait...                                           
                                                                                
                                                                                
[Slot_6]                                                                       
/$[Board Integration Version]                                                   
/$BoardIntegrationVersion=3.0                                                   
                                                                                
                                                                                
[Main_Board]                                                                    
/$[ArchivesInfo Version]                                                        
/$ArchivesInfoVersion=3.0                                                       
                                                                                
                                                                                
[Board Properties]                                                              
BoardType=ET1D2S08SX1E
BarCode=020LVF6TBB000043                                                 
Item=03020LVF                                                                    
……………
NOTE:
The command syntax may differ in different software versions. You can enter a question mark (?) to obtain help information about the command and set the slot ID according to the help information.

Obtaining the Serial Number of a Power Module

Log in to the master switch through Telnet or the console interface, and then run the display elabel command in the user view and specify a slot ID according to help information to view the electronic label of a power module. In the command output, the SN field indicates the serial number of the power module.
<Quidway> display elabel ?
  <1-1>      The present chassis                                                
  backplane  Backplane                                                          
  brief      Display information briefly                                        
<Quidway> display elabel 1/?
  <5,8,13,16>                             <CMU1>
  <FAN1-FAN5>                             <PWR1-PWR4>
<Quidway> display elabel 1/PWR1
Info: It is executing, please wait...                                           
                                                                                
[Slot_21]                                                                       
/$[Board Integration Version]                                                   
/$BoardIntegrationVersion=3.0                                                   
                                                                                
                                                                                
[Main_Board]                                                                    
DATE=13_02_08                                                                   
SN=A664A0212080086V0.9A
NOTE:
The command syntax may differ in different software versions. You can enter a question mark (?) to obtain help information about the command and set the slot ID according to the help information.

Obtaining the Serial Number of a Fan Module

Log in to the master switch through Telnet or the console interface, and then run the display elabel command in the user view and specify a slot ID according to help information to view the electronic label of a fan module. In the command output, the BarCode field indicates the serial number of the fan module.
<Quidway> display elabel ?
  <1-1>      The present chassis                                                
  backplane  Backplane                                                          
  brief      Display information briefly                                        
<Quidway> display elabel 1/?
  <5,8,13,16>                             <CMU1>
  <FAN1-FAN5>                             <PWR1-PWR4>
<Quidway> display elabel 1/FAN2
Info: It is executing, please wait...                                           
                                                                                
[Slot_18]                                                                       
/$[Board Integration Version]                                                   
/$BoardIntegrationVersion=3.0                                                   
                                                                                
                                                                                
[Main_Board]                                                                    
/$[ArchivesInfo Version]                                                        
/$ArchivesInfoVersion=3.0                                                       
                                                                                
                                                                                
[Board Properties]                                                              
BoardType=LE02FCMC                                                              
BarCode=2103010JTF0123456789                                             
Item=02120995                                                                   
……………
NOTE:
The command syntax may differ in different software versions. You can enter a question mark (?) to obtain help information about the command and set the slot ID according to the help information.

More related:

When Interruption of Existing Services on Some Data Boards of OSN Products

Monday, April 18, 2016

The LQG Reports ALM_DATA_RLOS and ALM_DATA_TLOS Alarms

This is because no extended channel rear card is installed in the switch.
An S5700SI or S5700EI switch can provide only two optical interfaces for a front card. If a 4-port front card is installed, the switch must use an ES5D00ETPB00 extended channel rear card to provide the other two interfaces. Without an extended channel rear card, only two optical interfaces are displayed.
  • If a 4-port GE front card (ES5D000G4S01/ES5D00G4SA01) and an ES5D00ETPC00 rear stack card (working normally) are used together in a switch, only the first and second interfaces on the front card can work normally, and the other two interfaces cannot be used.

  • If a 4-port 10GE front card (ES5D000X4S01) and an ES5D00ETPC00 rear stack card (working normally) are used together in a switch, only the first and third interfaces on the front card can work normally, and the other two interfaces cannot be used.

NOTE:
The available interfaces on the ES5D000X4S01 front card are displayed as XGigabitEthernet */1/1 and XGigabitEthernet */1/2 on the CLI, corresponding to physical interfaces 1 and 3 on the front card.
* indicates a slot ID on the switch.


More related:

Be Aware of SSN4SL64 Board ID on MSTP Products

Wednesday, April 13, 2016

What Is the Working Temperature of the Switch? S2700

S2700

The temperature range of the S2700 is as follows:
  • Operating temperature:
    • S2710-52P-PWR-SI and S2700-52P-PWR-EI: 0°C to +50°C
    • Others: -5°C to +50°C
  • Storage temperature: -40°C to +70°C

S3700

The temperature range of the S3700-SI and S3700-EI is as follows:
  • Operating temperature: 0°C to +50°C
  • Storage temperature: -40°C to +70°C
The temperature range of the S3700-HI is as follows:
  • Operating temperature: -5°C to +55°C (altitude 0 to 1800 m)
  • Storage temperature: -40°C to +70°C
NOTE:
  • When the altitude is between 1800 m and 5000 m, the operating temperature reduces 1°C every time the altitude increases 220 m.

S5700

The temperature range of the S5710-C-LI, S5700-SI and S5700-EI is as follows:
  • Operating temperature: 0°C to +50°C
  • Storage temperature: -40°C to +70°C
The temperature range of the S5700-LI, S5700S-LI, and S5710-EI is as follows:
  • Operating temperature:
    • The operating temperature of the S5700-10P-PWR-LI-AC, S5700-28X-LI-24S-AC, S5700-28X-LI-24S-DC, S5701-28X-LI-24S-AC, S5700-52X-LI-48CS-AC, S5700S-28X-LI-AC, S5700S-52X-LI-AC, and S5700-10P-LI-AC is 0°C to +45°C at an altitude between 0 m and 1800 m.
    • Others: 0°C to +50°C (altitude 0 to 1800 m)
  • Storage temperature: -40°C to +70°C
The temperature range of the S5700-HI is as follows:
  • Operating temperature: -5°C to +55°C
  • Storage temperature: -40°C to +70°C
The temperature range of the S5710-X-LI, S5720-SI, S5720S-SI, S5720-EI, S5710-HI, and S5720-HI is as follows:
  • Operating temperature: 0°C to +45°C (altitude 0 to 1800 m)
  • Storage temperature: -40°C to +70°C
NOTE:
  • When the S5700-HI has the 40 km or longer transmission distance SFP+ module installed, the operating temperature range is -5°C to +50°C.
  • When the altitude is between 1800 m and 5000 m, the operating temperature reduces 1°C every time the altitude increases 220 m.

S6700

The temperature range of the S6700-EI is as follows:
  • Operating temperature: -5°C to +50°C
  • Storage temperature: -40°C to +70°C
The temperature range of the S6720-EI is as follows:
  • Operating temperature: 0°C to +45°C (altitude 0 to 1800 m)
  • Storage temperature: -40°C to +70°C
NOTE:
When the S6700-EI has the 40 km or longer transmission distance SFP+ module installed, the operating temperature range is -5°C to +45°C.
When the altitude is between 1800 m and 5000 m, the operating temperature reduces 1°C every time the altitude increases 220 m.

Temperature Display

The display environment command (changed into display temperaturein V200R005 and later versions) displays the monitoring temperature, which is the highest temperature in the device but not the actual ambient temperature.
If no alarm is generated, the device is working normally and the temperature is within the allowed range.
NOTE:
You can run the temperature threshold command to set the threshold for the alarm temperature. You can run the display environment command (changed into display temperaturein V200R005 and later versions) to view the threshold for the alarm temperature and the current temperature.

Thursday, April 7, 2016

Basic Configuration on the Device at First Login for Huawei Switches

Huawei Switches Basic Configuration:  How to first login the device on console port or mini USB port.
Here, we will describe how to configure the time and date, device name, management IP address, and the user level and authentication mode for Telnet users at first login through the console port or mini USB port. This configuration apply to all the Huawei switches, such as the popular switch: Huawei S5700,S3700, S2700…

Procedure


1 Set the time and date on the device.

Run:
system-view
The system view is displayed.

Run:
clock timezone time-zone-name { add | minus } offset
The time zone is set.

By default, the system uses the Coordinated Universal Time (UTC) time zone.
add: adds the specified time zone offset to the UTC. That is, the sum of the default UTC time zone and offset equals the time zone specified by time-zone-name.
minus: subtracts the specified time zone offset from the UTC. That is, the remainder obtained by subtracting offset from the default UTC time zone equals the time zone specified by time-zone-name.

Run:
quit
Return to the system view.

Run:
clock datetime HH:MM:SS YYYY-MM-DD
The current time and date are set.
If the time zone is not set, the time set using this command is considered as the UTC time. Before setting the current time, you are advised to confirm the current zone and set the correct time zone offset.

Run:
system-view
The system view is displayed.

Run:
clock daylight-saving-time time-zone-name one-year start-time start-date end-time end-date offset
Or clock daylight-saving-time time-zone-name repeating start-time { { first | second | third | fourth | last } weekday month | start-date1 } end-time { { first | second | third | fourth | last } weekday month | end-date1 } offset [ start-year [ end-year ] ]
Daylight saving time (DST) is set.
By default, DST is not configured.

NOTE:
If you configure periodic DST, the combination of the DST start time and end time can be any of the following: date+date, day of the week+day of the week, date+day of the week, and day of the week+date.
When DST is used, you can run the clock timezone time-zone-name { add | minus } offset command to set the time zone. The time zone in the output of the display clock command is, however, the name of the DST time zone. When DST ends, the system displays the original time zone.

2, Set the device name and management IP address.

Run:
sysname host-name
The device name is set.
By default, the device name is HUAWEI.
When the network management tool needs to obtain the network element (NE) name of a device, you can run the sys-netid command to set an NE name for the device.

Run:
interface interface-type interface-number
The interface view is displayed.
In addition to the management interface on the device, you can also assign the management IP address to Layer 3 interfaces such as VLANIF interfaces on the device.

Run:
ip address ip-address { mask | mask-length }
The management IP address is assigned.
NOTE:
The management IP address is used to maintain and manage the device. Configure the IP address and routes based on the network plan to ensure that the routes between the terminal and device are reachable.

3 Set the user level and authentication mode for Telnet users.

Run:
telnet [ ipv6 ] server enable
The Telnet server is enabled.
By default, the Telnet server is disabled.

Run:
user-interface vty first-ui-number [ last-ui-number ]
The VTY user interface view is displayed.

Run:
protocol inbound { all | telnet }
he VTY user interface is configured to support the Telnet protocol.
By default, a VTY user interface supports the SSH protocol.

Run:
user privilege level level
The Telnet user level is set.
By default, users who log in through the VTY user interface can access commands at level 0.

Run:
authentication-mode aaa
The authentication mode for Telnet users is set to AAA authentication.
By default, no authentication mode is configured for the VTY user interface.
NOTE:
The system provides three authentication modes: AAA authentication, password authentication, and non-authentication modes. AAA authentication requires both the user name and password, and is therefore more secure than password authentication. Non-authentication mode is not recommended because it cannot ensure system security. This section describes how to configure AAA authentication..

Run:
aaa
The AAA view is displayed.

Run:
local-user user-name password irreversible-cipher password
The user name and password for login through Telnet are configured.
The value of password can be a plain-text string of 8 to 128 characters or a cipher-text string of 68 characters.
A too simple password may cause a potential security risk. To enhance the security strength, the password entered in plain text must contain at least two of the following: uppercase letters, lowercase letters, digits, and special characters. In addition, the password cannot be the same as the user name or the mirror user name.

Run:
local-user user-name service-type telnet
The login mode is set to Telnet.

4, Save the configuration.

After basic configuration is complete, you are advised to save the configuration. If the configuration is lost, the connection and configuration for the first login must be performed again.

Run:
return
Return to the user view.

Run:
save
The configuration is saved.

More related:

Huawei Low-end Switches Boot Upgrade For BOOTROM

Tuesday, April 5, 2016

SSM and Huawei will deploy the eLTE broadband access network in Poland

Here is an example for configuring local attack defense, this configuration can be applied for all the huawei switches, such as Huawei S2700, Huawei S3700Huawei S5700

Networking Requirements

As shown in Figure 1, users on different network segments access the Internet through the Huawei Switch. Because a large number of users connect to the Switch, the CPU of Switch will receive a lot of protocol packets. If malicious users send a lot of attack packets to the Switch, the CPU usage will increase to affect services. The network administrator has the following requirements:
  • The network administrator wants to monitor CPU status. When the CPU is attacked, the Switch can promptly notify the administrator and take measures to protect the CPU.
  • When the Switch receives a lot of ARP Request packets, the CPU usage of the Switch greatly increases. The administrator wants to reduce the CPU usage to avoid impact on services.
  • Users on Net1 often initiate attacks, so the administrator wants to reject the access of Net1 users.
  • The administrator wants to upload files to the Switch through FTP, so data transmission between the administrator’s computer and Switch must be reliable and stable.
Figure 1 Networking diagram of local attack defense

networking-diagram-of-local-attack-defense

Configuration Roadmap

The configuration roadmap is as follows:
  1. Configure attack source tracing, alarms, and punishment so that the device can send an alarm to the administrator when detecting an attack source and automatically take punishment actions.
  2. Set the protocol rate threshold so that the Switch can limit the rate of protocol packets based on ports and record a log. (Port attack defense is enabled by default, so it does not need to be enabled again.)
  3. Set the CPCAR for ARP Request packets to limit the rate of ARP Request packets sent to the CPU. This reduces impact of ARP Request packets on the CPU.
  4. Add Net1 users to the blacklist to reject their access.
  5. Set the rate limit for the FTP packets sent to the CPU to ensure reliability and stability of data transmission between administrator’s computer and Switch. (ALP is enabled for FTP by default, so it does not need to be enabled again.)

Procedure

  1. Configure the rule for filtering packets sent to the CPU.
# Define ACL rules.
<HUAWEI> system-view
[HUAWEI] sysname Switch
[Switch] acl number 2001
[Switch-acl-basic-2001] rule permit source 10.1.1.0 0.0.0.255
[Switch-acl-basic-2001] quit
  1. Configure an attack defense policy.
# Create an attack defense policy.
[Switch] cpu-defend policy policy1
# Configure attack source tracing.
[Switch-cpu-defend-policy-policy1] auto-defend enable
# Enable the alarm function for attack source tracing.
[Switch-cpu-defend-policy-policy1] auto-defend alarm enable
# Set the punishment action to discard.
NOTE:
Before configuring the punishment action, ensure that the device is attacked; otherwise, the punishment action may discard a lot of valid protocol packets.
[Switch-cpu-defend-policy-policy1] auto-defend action deny
# Set the rate threshold to 40 pps. (Port attack defense is enabled by default, so it does not need to be enabled again.)
[Switch-cpu-defend-policy-policy1] auto-port-defend protocol arp-request threshold 40
# Add the network-side interface GE0/0/1 to the whitelist so that the CPU can promptly process the packets from the network-side interface.
[Switch-cpu-defend-policy-policy1] auto-port-defend whitelist 1 interface gigabitethernet 0/0/1
# Set the CPCAR of ARP Request packets to 120 kbit/s.
[Switch-cpu-defend-policy-policy1] car packet-type arp-request cir 120
# Configure the blacklist for CPU attack defense.
[Switch-cpu-defend-policy-policy1] blacklist 1 acl 2001
# Set the CIR of FTP packets sent to the CPU to 5000 kbit/s.
[Switch-cpu-defend-policy-policy1] linkup-car packet-type ftp cir 5000
[Switch-cpu-defend-policy-policy1] quit
  1. Apply the attack defense policy globally.
4.             [Switch] cpu-defend-policy policy1 global
5.             [Switch] quit
  1. Verify the configuration.
# Display the configuration of attack source tracing.
<Switch> display auto-defend configuration
 ----------------------------------------------------------------------------
 Name  : policy1
 Related slot : <0>
 auto-defend                      : enable
 auto-defend attack-packet sample : 16
 auto-defend threshold            : 128 (pps)
 auto-defend alarm                : enable
 auto-defend alarm threshold      : 128 (pps)
 auto-defend trace-type           : source-mac source-ip source-portvlan
 auto-defend protocol             : arp icmp dhcp igmp ttl-expired tcp telnet
 auto-defend action               : deny (Expired time : 300 s)
 ----------------------------------------------------------------------------
# Display the configuration of port attack defense.
<Switch> display auto-port-defend configuration 
 ----------------------------------------------------------------------------
 Name  : policy1
 Related slot : 0
 Auto-port-defend                       : enable
 Auto-port-defend sample                : 5
 Auto-port-defend aging-time            : 300 second(s)
 Auto-port-defend arp-request threshold : 40 pps(enable)
 Auto-port-defend arp-reply threshold   : 30 pps(enable)
 Auto-port-defend dhcp threshold        : 30 pps(enable)
 Auto-port-defend icmp threshold        : 30 pps(enable)
 Auto-port-defend igmp threshold        : 60 pps(enable)
 Auto-port-defend ip-fragment threshold : 30 pps(enable)
--------------------------------------------------------------------------------
# Display the configuration of the attack defense policy.
<Switch> display cpu-defend policy policy1
 Related slot : <0>
 Configuration :
   Blacklist 1 ACL number : 2001
   Car packet-type arp-request : CIR(120)  CBS(22560)
   Linkup-car packet-type  ftp : CIR(5000)  CBS(940000)
# Display the CPCAR setting.
<Switch> display cpu-defend configuration packet-type arp-request
Car configurations on slot 0.
----------------------------------------------------------------------
Packet Name           Status   Cir(Kbps)   Cbs(Byte)  Queue  Port-Type
----------------------------------------------------------------------
arp-request       Enabled       120       22560    3       UNI          
----------------------------------------------------------------------

Configuration Files

Configuration file of the Switch
#
sysname Switch
#
acl number 2001
 rule 5 permit source 10.1.1.0 0.0.0.255
#
cpu-defend policy policy1
 blacklist 1 acl 2001
 car packet-type arp-request cir 120 cbs 22560
 linkup-car packet-type ftp cir 5000 cbs 940000
 auto-defend enable
 auto-defend alarm enable
 auto-defend action deny
 auto-port-defend protocol arp-request threshold 40
 auto-port-defend whitelist 1 interface GigabitEthernet0/0/1
#
cpu-defend-policy policy1 global
#
return

More blog:

Huawei Low-end Switches Boot Upgrade For BOOTROM