2013年8月14日星期三

Five ways to the Huawei switch Telnet settings

1 TELNET does not verify to the configuration
[SwitchA-ui-vty0-4]authentication-mode none BA2
2 TELNET password authentication to the configuration
1 into the user interface view
[SwitchA]user-interface vty 04
2 set the authentication mode password authentication method
[SwitchA-ui-vty0-4]authentication-mode password
3 setting the plaintext password
[SwitchA-ui-vty0-4]set authentication password simple Huawei
4 by default, can be accessed from the VTY user interface login commandlevel for the 0. Need to set the permissions of users is 3, the user can enter the system view to operate, or only 0 user permissions
[SwitchA-ui-vty0-4]user privilege level 3
3 TELNET local user name and password authentication to the configuration
1 into the user interface view
[SwitchA]user-interface vty 04
2 using the authentication-mode scheme command, said the need for local or remote user name and password authentication.
[SwitchA-ui-vty0-4]authentication-mode scheme
3 set the local user name and password
[SwitchA]local-user Huawei
[SwitchA-user-huawei]service-type telnet Level 3
[SwitchA-user-huawei]password simple Huawei
4 if TELNET does not change the logged on user permissions, user login isunable to enter the other views directly, you can set the super password, to control the user permission to enter the other view
[SwitchA]local-user Huawei
[SwitchA-user-huawei]service-type telnet
[SwitchA-user-huawei]password simple Huawei
[SwitchA]super password Level 3 simple Huawei
4 TELNET RADIUS authentication to the configuration
To use the Huawei development of the cams as the RADIUS server as an example
1 set TELNET login scheme
[SwitchA-ui-vty0-4]authentication-mode scheme
2 to configure RADIUS authentication scheme
[SwitchA]radius scheme cams
The 3 configuration RADIUS authentication server address 10.110.51.31
[SwitchA-radius-cams]primary authentication 10.110.51.31 1812
The 4 configuration RADIUS billing server address 10.110.51.31
[SwitchA-radius-cams]primary accounting 10.110.51.31 1813
The 5 configuration switches and authentication server authentication password
[SwitchA-radius-cams]key authentication expert
The 6 configuration switches with the billing server authentication password
[SwitchA-radius-cams]key accounting expert
7 server configuration is similar to Huawei, which is used in CAMS
[SwitchA-radius-cams]server-type Huawei
The message sent to the RADIUS 8 with no name
[SwitchA-radius-cams]user-name-format without-domain
9 create (into) a domain
[SwitchA]domain Huawei
10 in domain Huawei name for the "authentication scheme for cams"
[SwitchA-isp-huawei]radius-scheme cams
11 the Huawei field is set to the default domain
[SwitchA]domain default enable Huawei
5 TELNET Access control to the configuration 
The 1 is allowed only IP address switch ACL1
[SwitchA-ui-vty0-4]acl 1 inbound
2 set of rules only allow a network login
[SwitchA]acl number 1
[SwitchA-acl-basic-1]
[SwitchA-acl-basic-1]rule permit source 10.10.10.0 0.0.0.255
3 set rules prohibit a network login
[SwitchA]acl number 1
[SwitchA-acl-basic-1] BPA

[SwitchA-acl-basic-1]rule deny source 10.10.10.0 0.0.0.255

2013年8月13日星期二

Why you should choice the Huawei WS330 router ?

Huawei WS330 router, low radiation, high transmission rate
1 Does Huawei WS330 router pass safety certification?
Domestic and international BA2 multiple safety certification of environmental protection, the performance of dominant at the same time, the radiation power is only one of several similar products.
2 What Advantage of the Huawei WS330 router incoming settings?
Huawei WS330 external two 5dBi, built a 3dBi high performance antenna, and the use of three choose two smart antenna scheme, according to the wirelessaccess user equipment, the automatic selection of antenna combination,coverage blind to make up two antennas, realize the family Wi-Fi cross floorand floor full coverage. Compared to similar products, horizontal wallperformance can increase more than 10%, the security level of Wi-Fi cover at the same time, the existence of the built-in antenna, vertical wall performance can also promote more than 50%.
3 What about the Huawei WS330 router security?
Telecommunications level firewall, effectively prevent the network attack,ensure the family network security; wireless encryption mechanism of new,effective prevention of strangers loiter net.
4 How fast of the Huawei WS330 router transmission rate?

Wireless transmission rate up to 300Mbps, make the data exchange more smoothly, realize the family of multiple mobile phone, tablet computer,  buy BPA set-top boxes, notebooks and other more wireless terminal access at the same time,more suitable for home HD video on demand, high speed data transmissionand sharing.
More information,please view: http://www.huanetwork.com

2013年8月12日星期一

NE Series Router for Huawei operator oriented data communication

Networkrouter product, covering the backbone network, BA2 metropolitan area networkP/PE position, help Huawei NE5000E router operators deal with the pressure of rapid growth of network bandwidth.
Huawei NE5000E router
Support for multiple cluster model: NE5000E using nonblocking switching network architecture is advanced, single frame port capacity of bidirectionalcan reach 1.28Tbps, the future port capacity can be expanded from 1.28T to 80T to support the smooth, each slot of 40Gbps capacity, transmissioncapacity of up to 1600Mpps; multiple cluster model, cluster, 2+4 cluster, such as back-to-back 2+8 cluster, up to the 16+64 cluster system.
Supports on-demand flexible choice: NE5000E also support 40G interface andoptical interface of white color, Huawei integrated 40G lead IP and light, white light /OTN 40G support the whole scene, simultaneously has the color light40G capacity.
Huawei NE80E router
The NetEngine80E core router is the high-end network product Huaweilaunched, edge position is mainly used in the IP backbone network, IP metropolitan area network and other large IP networks, network in conjunction with the NE5000E, NE40E router, the formation of structural integrity, a clear hierarchy of IP network solutions.
As a new fifth generation of routers, NE80E uses high performance network processor technology industry-leading, fully inherited fourth generationdistributed processing hardware architecture, organic combination of highperformance software flexibility and hardware, which provide the line speed forwarding performance, and has fast good business to upgrade and expansion capability, the maximum to ensure that the user investment,accelerate the IP network to broadband, safety, service and intelligent direction.
Huawei NE40E router
NE40E is a high-end network product Huawei launched, edge position is mainly used in the IP backbone network, IP metropolitan area network and other large IP networks, network in conjunction with the NE5000E, the NE80E core router products, can form a complete structure, a clear hierarchy of IP network solutions, including NE40E-X16, NE40E-X8, and NE40E-X3 and NE40E, adaptation networking needs of different scale
Blocking NE40E switching technology without and distributed hardwareforwarding based, has good line speed forwarding performance, scalabilitygood, perfect QoS mechanism and a strong business processing ability; its latest extensible 400G based platform, smooth expansion can be realized 40G/Slot to 400G/Slot, and is compatible with the current network all card, the maximum limit protection investment; access convergence ability strong, withrich feature support, flexible deployment of L2VPN multicast, multicast, L3VPN,VPN, MPLS TE, QoS, reliability of operation level bearing; at the same time,NE40E fully supports the IPv6, smooth transition can achieve IPv4 to IPv6.Therefore, NE40E can edge, flexible application in the core of IP/MPLS network, simplify the network structure, provides a wealth of business types and reliable quality of service, is an important source for IP/MPLS carryingnetwork to broadband, safety, operational, intelligence development.
Huawei NE20E/20 router
NE20E/20 series is a high performance access edge router Huawei orientedtelecom operators and customers, including NE20E-8, NE20-8, NE20-4, NE20-2 four products, designed to meet the use requirements of enterprise networkconvergence and operator edge telecom level high, has strong scalability,configurability, support multiple interfaces and business characteristics, MPLS,VPN, QoS, traffic engineering, multicast technology integration.
Modular design of high reliable, all board, fan, power supply module support hot plug; provide mutual double power supply redundancy backup (1+1 backup) module, design of passive backplane; provides software hot patch technology, realize equipment completely smooth upgrade; supporting dynamic routing protocol, MPLS traffic engineering, provide IP/MPLS fast re routing, virtual Router Redundancy Protocol (VRRP) and other protection mechanisms, effectively BPA ensuring the whole network operation reliability of high speed.

Routing capabilities: support RIP, OSPF, BGP, IS-IS unicast routing protocol and IGMP, PIM, MBGP, MSDP, multicast routing protocol, routing strategy andpolicy based routing

2013年8月8日星期四

Huawei is a new generation of modular data center, has become the trend of the development of the industry

With the rapid development of cloud computing, mobile Internet business, OSN500 increased IT density, the energy consumption of the traditional data center to face many challenges. A new generation of modular data center, has become the trend of the development of the industry. To adapt to the futuredevelopment trend of cloud data center, Huawei in-depth study and increasing R & D modular data center inputs, the modular concept into the whole process of data center design, manufacturing and construction, which laid the foundation for a new generation of cloud data center infrastructure, become efficient modular data center leader.

Huawei modular data center has been used widely in the world, successful deployment includes: China mobile base in the south, modular data center,North China mobile base container data center, Shanghai Telecom modular data center, Venezuela Movistar modular data center, Venezuela CANTVmodular / container data center and many other famous projects. Huaweiprovide data center infrastructure stable and super intelligent maintenancemanagement means to customers, help customers to save a lot of energy loss,greatly reduce the customer TCO and improve ROI, also brought in a steadybusiness.

Huawei data communication scheme and the products and services to includeChina Telecom, China Mobile, China Unicom, France Telecom, Deutsche Telekom, British Telecom, Telefonica, Singapore Telecom and the United Arab Emirates telecommunications operators of the 35 global TOP50. OSN550 Consulting company OVUM report shows, 2012 year Huawei in global operators routermarket share ranked second.
More information, please view: http://www.huanetwork.com


ARP virus processing method of Huawei switch

The form of a ARP virus:
1, the Internet through the network all or BA2 part of the computer is not able to;
2, open the webpage garbled;
3, open the webpage that virus;
Method for find ARP virus:
If Syria fault status in the network, is likely to be the ARP virus in the computer. Specific killingmeasures are as follows:
1, to determine the fault segment of the VLAN, gateway and IP address and other information;
2, the landing of the gateway switch (must be a gateway switch, otherwise there is no ARP table.)
3, through the dis log command to view the log, if a virus is usually a warning (but not all). If the following log:
%Dec 10 13:06:18 2007 Huawei8508_1 ARP/4/DUPIFIP:Slot=4; Duplicate address10.110.70.126 on VLAN909, sourced by 0016-ec71-9996
%Dec 10 13:05:17 2007 Huawei8508_1 ARP/4/DUPIFIP:Slot=4; Duplicate address10.110.70.126 on VLAN909, sourced by 0016-ec71-9996
The above log says: VLAN 909 segment, MAC address for the ARP 0016-ec71-9996 computervirus.
4, if the log contains no information display information, you need to see the ARP address of the switch table. Through the dis ARP in VLAN, |, such as dis ARP | in 909. The following informationwill appear:
Note: all MAC addresses corresponding to the IP address are the same, is not normal. Normal ARP table should be different according to different MAC address IP address.
< Huawei8508_1>dis ARP | in 909
Type: S-Static D-Dynamic
IP Address MAC Address VLAN ID Port Name Aging Type
10.110.64.168 0016-ec71-9996 909 GigabitEthernet4/1/5 13 D CunVPN
10.110.64.200 0016-ec71-9996 909 GigabitEthernet4/1/5 14 D CunVPN
10.110.70.60 0016-ec71-9996 909 GigabitEthernet4/1/5 15 D CunVPN
10.110.70.17 0016-ec71-9996 909 GigabitEthernet4/1/5 16 D CunVPN
10.110.64.236 0016-ec71-9996 909 GigabitEthernet4/1/5 16 D CunVPN
10.110.70.18 0016-ec71-9996 909 GigabitEthernet4/1/5 16 D CunVPN
10.110.70.20 0016-ec71-9996 909 GigabitEthernet4/1/5 17 D CunVPN
10.110.64.221 0016-ec71-9996 909 GigabitEthernet4/1/5 18 D CunVPN
10.110.64.231 0016-ec71-9996 909 GigabitEthernet4/1/5 19 D CunVPN
10.110.64.225 0016-ec71-9996 909 GigabitEthernet4/1/5 20 D CunVPN
10.110.64.160 0016-ec71-9996 909 GigabitEthernet4/1/5 20 D CunVPN
The above information representation: VLAN 909 segment, MAC address for the ARP 0016-ec71-9996 computer virus.
5, using the above two methods can easily determine which MAC address poisoning, but is unable to determine the IP address. To determine the IP address is how much more difficult.Need to rely on the E shield software and the daily IP and MAC records and other tools to judge.
6, if the above tools are not, only the first landing in the layer two switch corresponding (note, is the two level of access switch). By viewing the MAC address and port of the corresponding table, in order to determine which port. Specific methods are as follows:
< Huawei3900_1>dis mac-address 0016-ec71-9996
MAC ADDR VLAN ID STATE PORT INDEX AGING TIME (s)
0016-ec71-9996 909 Learned GigabitEthernet1/0/5 AGING
From the above information can tell 0016-ec71-9996 this computer is connected to the 3900switch GigabitEthernet1/0/5 port.
7, in order to temporarily restore network, can close the switch GigabitEthernet1/0/5 port. The following:
The < Huawei3900_1>sys
System View: return to User View with Ctrl+Z.
[Huawei3900_1]int g 4/1/5
[Huawei3900_1-GigabitEthernet4/1/5]shutdown
8, then log on to the gateway switch, the corresponding VLAN restart, as follows:
[Huawei8508_1]int Vlan-interface 909
[Huawei8508_1-Vlan-interface909]shutdown
[Huawei8508_1-Vlan-interface909]undo shutdown

Normal operation 9, so you can restore the network, as for the poisoning of the machine. Users need treatment. Suggested reinstall the system directly, and immediately buy SL1Q install the patch,antivirus software, 360 security guards, E shield and other tools. To avoid duplication ofpoisoning. This is very important, because of the possibility of very large repeat poisoning.

2013年8月6日星期二

The common problems of Ping on huawei switches

1 When Ping is broken, what are the possible reasons

(1) may be due to network delay is large. You can use the ping command to "-t" option to increase response timeout;
(2) may be the high utilization rate of equipment CPU cause, OSN1500B can master view by display cpu-usage or display cpu-usage slot slot-id or the single board CPU utilization. If a taskname CPU utilization rate is too high, please check whether the module problems.
(3) if the device down link the two layer network, may be the existence of MAC drift problem in two layer network.

2 With the "-f" parameter Ping commands, why not Ping bag

The ping command with the "-f" parameter, the specified message cannot be set fragment flag.Ping bag, if more than the interface of the MTU value, it is need to be sliced, so contradictory,packets discarded directly, do not send.

3 Ping single pass phenomenon, what are the possible reasons

If it is on the Ping equipment and the terminal equipment of Ping terminal, Ping terminalequipment can pass through the barrier, Ping, may be the terminal open firewall protection.
The device Ping to end Ping barrier, from end-to-end Ping over to Ping, may be a deviceenabled fast ping function. Execute the command: undo icmp-reply fast, closed fast back to the ping function and Ping test.

4 Regularity of packet loss occurred in Ping bag, what is the reason?

(1) Regularity of packet loss occurred in Ping large, continuous through several packets lost a bag, this is usually the message rate exceeds the cpcar value, be directly discarded. The following command, if Drop fields exist count showed that car value is too small, need to adjust the cpcar value and test. Adjust the command: [Quidway]cpu-defend policy test Cpcar[Quidway-cpu-defend-policy-test]car packet-type ICMP CIR 64 / / configuration anti attackstrategy of test message CAR action rules, set the message type is ICMP, the committed information rate is 64kbit/s
(2) from the friends of business equipment Ping cassette switch when broken, what is the reason
From the friends of business equipment Ping s series switches, often through several packet after long time no, about two minutes and Ping, then through several message after a long timeout. This is because the switch default enables the Ping inhibition function results, when the number of ICMP packets per second received port exceeds a certain threshold, the port to the ICMP message will inhibit two minutes, an ICMP message is received no treatment.
The rate is relatively fast friends of business equipment in normal Ping, OSN2500 exceeded the threshold.
Ping operation with the "-m" parameter, the sending rate soon will also appear the problem.

Execute the command undo ICMP rate-limit enable to close the inhibition function, can solve this problem. Inhibition of ICMP function enable will not affect the business application, only affect the operation of the ping.