Page 2
31190185 Huawei Technologies Co., Ltd. provides customers with comprehensive technical support and service. If you purchase the products from the sales agent of Huawei Technologies Co., Ltd., please contact our sales agent. If you purchase the products from Huawei Technologies Co., Ltd. directly, Please feel free to contact our local office, customer care center or company headquarters.
It is used for assisting the users in data Switches Operation Manual configurations and typical applications. Organization There are 14 modules in the manual. Getting Started This module introduces the commands used for accessing the Ethernet Switch. Port Huawei Technologies Proprietary...
Page 5
This module introduces the commands used for system management and maintenance. Auto Detecting This module introduces the commands used for auto-detecting configuration. Appendix This module includes all the commands in this command manual, which are arranged alphabetically. Intended Audience Huawei Technologies Proprietary...
Page 6
Optional alternative items are grouped in square brackets [ x | y | ... ] * and separated by vertical bars. Many or none can be selected. A line starting with the # sign is comments. Huawei Technologies Proprietary...
Page 7
VI. Symbols Eye-catching symbols are also used in the manual to highlight the points worthy of special attention during the operation. They are defined as follows: Caution, Warning, Danger: Means reader be extremely careful during the operation. Huawei Technologies Proprietary...
Page 8
Note, Comment, Tip, Knowhow, Thought: Means a complementary description. Huawei Technologies Proprietary...
By default, users logging in via the Console port do not need to pass any terminal authentication, whereas the password is required for authenticating the Modem and Telnet users when they log in. Example # Configure local password authentication. [Quidway-ui-aux0] authentication-mode password 1.1.2 auto-execute command Syntax auto-execute command text Huawei Technologies Proprietary...
XMODEM, TFTP and commands for file system operations are at management level (3). Example # Configure the precedence of the command "interface" as 0. [Quidway] command-privilege level 0 view system interface 1.1.4 databits Syntax databits { 7 | 8 } undo databits View User interface view Huawei Technologies Proprietary...
View Any view Parameter None Description Using display history-command command, you can view the saved history commands. For the related command, see history-command max-size. Example # Display history commands. <Quidway> display history-command quit display his Huawei Technologies Proprietary...
Table 1-1 Output description of the display user-interface command Field Description Current user interface is in use Current user interface is in use and work in asynchronous mode Absolute index of user interface Type Type and relative index of user interface Tx/Rx User interface speed Huawei Technologies Proprietary...
Indicates the interval from the latest input till now in seconds. Type User type Displays initial connection location, namely the host IP address of IPaddress the incoming connection. Display the name of the user using this user interface, namely the Username login username of the user. Huawei Technologies Proprietary...
Specifies the absolute/relative number of the user interface. Configured together with the type, it will specify the user interface number of the corresponding type. If the type is not specified, number will specify an absolute user interface number. Huawei Technologies Proprietary...
After inputting the end character, press the <Enter> key to exit the interact process. Description Using header command, you can configure to display header when user login. Using undo header command, you can configure not to display the header. Huawei Technologies Proprietary...
Page 19
Go on inputting the rest text and end your input with the first letter: Hello! Welcome % (Press the <Enter> key) [Quidway] When you log on the switch again, the terminal displays the configured session establishment title. [Quidway] quit <Quidway> quit Huawei Technologies Proprietary...
Using language-mode command, you can switch between different language environments of command line interface for convenience of different users. By default, the value is English. Example # Switch from English mode to Chinese mode. <Quidway> language-mode chinese 1.1.14 lock Syntax lock View User view Huawei Technologies Proprietary 1-11...
Using undo parity command, you can restore the default parity mode. This command can only be performed in AUX user interface view. By default, the mode is set to none. Example # Set mark parity on the AUX (Console) port. [Quidway-ui-aux0] parity mark Huawei Technologies Proprietary 1-12...
Using quit command, you can return to the lower level view from the current view. If the current view is user view, you can quit the system. There are three levels of views, which are listed from low to high as follows: User view Huawei Technologies Proprietary 1-13...
Combination key <Ctrl+Z> performs the same function with the return command. For the related command, see quit. Example # Return to user view from system view. [Quidway] return <Quidway> 1.1.19 screen-length Syntax screen-length screen-length undo screen-length View User interface view Huawei Technologies Proprietary 1-14...
Description Using send command, you can send messages between different user interfaces. Example # Send message to all the user interfaces. <Quidway> send all 1.1.21 service-type Syntax For S3552 series, S3528 series, S3526E series and S3526C: Huawei Technologies Proprietary 1-15...
Page 26
Management level: These are commands that influence the basic operation of the system and system support module, which plays a supporting role on service. Huawei Technologies Proprietary 1-16...
The result is determined by the input. A plain text password is a sequential character string of no more than 16 digits, for example, huawei918. The length of an encrypted password must be 24 digits and in encrypted text, for example, _(TT8F]Y\5SQ=^Q`MAF4<1!!. Huawei Technologies Proprietary 1-17...
Modem or Telnet. If no password has been set, the following prompt will be displayed “Login password has not been set !” Example # Configure the local authentication password on VTY 0 to huawei. [Quidway-ui-vty0] set authentication password simple huawei 1.1.23 shell...
This command can only be performed in AUX user interface view. Example # Configure the transmission speed on the AUX (Console) port as 9600bit/s. [Quidway-ui-aux0] speed 9600 1.1.25 stopbits Syntax stopbits { 1 | 1.5 | 2 } undo stopbits Huawei Technologies Proprietary 1-19...
Login users are classified into four levels that correspond to the four command levels respectively. After users of different levels log in, they can only use commands at the levels that are equal to or lower than its own level. For the related commands, see super password, quit. Huawei Technologies Proprietary 1-20...
The password in plain text is required when performing authentication, regardless whether the configuration is plain text or encrypted text. Example # Configure the password to zbr for changing the user from the current level to level 3. Huawei Technologies Proprietary 1-21...
# Configure the hostname of switch to Switch. [Quidway] sysname Switch [Switch] 1.1.29 system-view Syntax system-view View User view Parameter None Description Using system-view command, you can enter system view from user view. For the related commands, see quit, return. Huawei Technologies Proprietary 1-22...
For the related command, see display tcp status. Example # Log in to switch Quidway2 at 129.102.0.1 from the current Quidway1 switch. <Quidway1> telnet 129.102.0.1 <Quidway2> 1.1.31 user-interface Syntax user-interface [ type ] first-number [ last-number ] View System view Huawei Technologies Proprietary 1-23...
By default, a user can access the commands at Level 3 after logging in through the AUX user interface, and the commands at Level 0 after logging in through the VTY user interface. Example # Configure to use commands level 0 after logging in from VTY 0 user interface. Huawei Technologies Proprietary 1-24...
Page 35
User view commands: cluster Run cluster command language-mode Specify the language environment ping Ping function quit Exit from current command view super Privilege specified user priority level telnet Establish one TELNET connection tracert Trace route function Huawei Technologies Proprietary 1-25...
Page 36
HUAWEI Quidway S3500 Series Ethernet Switches Command Manual Port Huawei Technologies Proprietary...
Page 37
Chapter 2 Ethernet Port Link Aggregation Commands............. 2-1 2.1 Ethernet Port Link Aggregation Commands ..............2-1 2.1.1 display link-aggregation ..................2-1 2.1.2 link-aggregation....................... 2-2 Chapter 3 Port Isolation Configuration Commands ..............3-1 3.1 Port Isolation Configuration Commands................3-1 3.1.1 port-isolate enable....................3-1 Huawei Technologies Proprietary...
Page 38
Command Manual - Port Quidway S3500 Series Ethernet Switches Table of Contents 3.1.2 port-isolate uplink-port vlan ..................3-1 Huawei Technologies Proprietary...
100% broadcast traffic is allowed to pass through. Example # Enable 20% broadcast cast to pass, i.e. 80% broadcast storm suppression is made on broadcast traffic of port. [Quidway-Ethernet0/1] broadcast-suppression 20 1.1.2 description Syntax description text undo description Huawei Technologies Proprietary...
If only the port type is specified, all the information of the ports of this type will be displayed. If both port type and port number are specified, the information of the designated port will be displayed. Huawei Technologies Proprietary...
- aborts, 0 deferred, 0 collisions, 0 late collisions - lost carrier, - no carrier Table 1-1 Output description of the display interface command Field Description The current state of Ethernet port (enabled or Ethernet0/1 current state disabled) IP Sending Frames' Format Ethernet frame format Huawei Technologies Proprietary...
Page 42
Untagged VLAN ID The VLANs with packets untagged Last 5 minutes output: packets/sec 0 bytes/sec The input/output rate and the passing packet number on this port in the last 5 minutes. Last minutes input: packets/sec 0 bytes/sec Huawei Technologies Proprietary...
If it has been enabled, then the time interval of the detection and the current port loopback information will also be displayed. Note that S3526/S3526 FS/S3526 FM/S3526E/S3526C Ethernet Switches support this command in S3500 series switches. Example # Display if the port loopback detection is enabled. Huawei Technologies Proprietary...
<Quidway> display port hybrid Now, the following hybrid ports exist: Ethernet0/1 Ethernet0/2 The above information displays that the current system has two Hybrid ports, Ethernet0/1 and Ethernet0/2. 1.1.6 duplex Syntax duplex { auto | full | half } Huawei Technologies Proprietary...
5. flow-value: Traffic threshold on the port, in the range of 0 to 4294967295. It defaults to bps: Bytes per second. pps: Packets per second. Description Use the flow-constrain command to define traffic threshold on the port. Huawei Technologies Proprietary...
By default, only trap messages are sent when actual traffic on the port exceeds the threshold. Example # Configure the system to disable the port and send trap messages when actual traffic on the port exceeds the threshold. <Quidway> system-view System View: return to User View with Ctrl+Z. Huawei Technologies Proprietary...
# Enable flow control on Ethernet0/1. [Quidway-Ethernet0/1] flow-control 1.1.10 flow-interval Syntax flow-interval interval undo flow-interval View Ethernet port view Parameter interval: Specifies time interval, ranging from 5 to 300 in seconds. The step is 5. The default value is 300. Huawei Technologies Proprietary...
1 to 4. For S3552F Ethernet Switch, the slot number ranges from 1 to 7. Slot 1 to 6 represent the 100M Ethernet ports provided by the six modules on front panel respectively and the port number range from 1 to 8. Huawei Technologies Proprietary 1-10...
By default, the port will not perform the loopback test. Example # Perform the internal loop test for Ethernet0/1. [Quidway-Ethernet0/1] loopback internal 1.1.13 loopback-detection control enable Syntax loopback-detection control enable Huawei Technologies Proprietary 1-11...
Using loopback-detection enable command, you can enable the port loopback detection. If there is a loopback port found, the switch will put it under control. Using undo loopback-detection enable command, you can disable the port loopback detection. Huawei Technologies Proprietary 1-12...
For the related command, see display loopback-detection. Example # Configure the detection interval for the external loopback condition of each port to 10 seconds. [Quidway] loopback-detection interval-time 10 1.1.16 loopback-detection per-vlan enable Syntax loopback-detection per-vlan enable undo loopback-detection per-vlan enable Huawei Technologies Proprietary 1-13...
Using mdi command, you can configure the network cable type of the Ethernet ports. Using undo mdi command, you can restore the default type. By default, the network cable type will be recognized automatically. Note that this command only has effect 10/100Base-TX and 1000Base-T ports. Huawei Technologies Proprietary 1-14...
1.1.19 port hybrid pvid vlan Syntax port hybrid pvid vlan vlan_id undo port hybrid pvid View Ethernet port view Parameter vlan_id: VLAN ID defined in IEEE802.1Q, ranging from1 to 4094 and the default vlan_id is 1. Huawei Technologies Proprietary 1-15...
Hybrid port can belong to multiple VLANs. If the port hybrid vlan vlan_id_list { tagged | untagged } command is used for many times, the VLANs carried by the hybrid port is the set of vlan_id_list. Huawei Technologies Proprietary 1-16...
For example, you cannot configure a trunk port directly as hybrid port, but first set it as access port and then as hybrid port. By default, the port is access port. Example # Configure Ethernet port Ethernet0/1 as trunk port. [Quidway-Ethernet0/1] port link-type trunk Huawei Technologies Proprietary 1-17...
# Join the trunk port Ethernet0/1 to VLAN 2, 4 and 50-100. [Quidway-Ethernet0/1] port trunk permit vlan 2 4 50 to 100 1.1.23 port trunk pvid vlan Syntax port trunk pvid vlan vlan_id undo port trunk pvid View Ethernet port view Huawei Technologies Proprietary 1-18...
If only the port type is specified, all the information on the ports of this type will be cleared. If both port type and port number are specified, the information on the designated port will be cleared. Huawei Technologies Proprietary 1-19...
{ 10 | 100 | auto } For 1000M Ethernet port, this command is in the following format: speed { 10 | 100 | 1000 | auto } The undo form of this command is: undo speed View Ethernet port view Huawei Technologies Proprietary 1-20...
Note that S3552G/S3552P/S3528G/S3528P/S3552F Ethernet Switches support this configuration in S3500 series switches. Example # Display the information of the cable test. [Quidway-Ethernet0/1] virtual-cable-test Cable pair: RX Status:Open Cable Error lenth:5 metres Cable pair: TX Status:Open Cable Error lenth:5 metres Huawei Technologies Proprietary 1-21...
Note that if anyone of GVRP, GMRP, STP, 802.1x, NTDP and NDP has been enabled on a port, VLAN VPN cannot be enabled on it. S3552G/S3552P/S3528G/S3528P/S3552F Ethernet Switches support this configuration in S3500 series switches. Example # Enable VLAN VPN on Ethernet0/1. [Quidway-Ethernet0/1] vlan-vpn enable Huawei Technologies Proprietary 1-22...
For the related command, see link-aggregation. Example # Display the related information of the aggregation group with the master port number as Ethernet0/1. <Quidway> display link-aggregation ethernet0/1 Master port: Ethernet0/1 Other sub-ports: Ethernet0/2 Mode: both Huawei Technologies Proprietary...
For satisfactory payload balance effect, it is recommended that you configure the Ethernet ports to be aggregated to operate at the same speed and with the same duplex attribute. For the related command, see display link-aggregation. Huawei Technologies Proprietary...
Page 63
Command Manual - Port Quidway S3500 Series Ethernet Switches Chapter 2 Ethernet Port Link Aggregation Commands Example # Configure outgoing load balance on the port depending on the source and destination MAC addresses. [Quidway] link-aggregation ethernet0/1 to ethernet0/2 both Huawei Technologies Proprietary...
By default, port L2 isolation is not enabled in a VLAN, that is, L2 forwarding is available between the ports in a VLAN. Example # Enable port L2 isolation in the VLAN. [Quidway-vlan1] port-isolate enable 3.1.2 port-isolate uplink-port vlan Syntax port-isolate uplink-port vlan vlan-id undo port-isolate uplink-port vlan vlan-id Huawei Technologies Proprietary...
Page 65
Trunk port and that it is the only uplink port in that VLAN. You cannot enable port isolation and link aggregation concurrently on a port. Example # Configure the Ethernet0/1 port as uplink port. [Quidway-Ethernet0/1] port-isolate uplink-port vlan 1 Huawei Technologies Proprietary...
# Specify a description character string “RESEARCH” for current VLAN. [Quidway-vlan1] description RESEARCH 1.1.2 display interface vlan-interface Syntax display interface vlan-interface [ vlan_id ] View Any view Parameter vlan_id: ID of VLAN interface, ranging from 1 to 4094. Huawei Technologies Proprietary...
Using display vlan command, you can view related information about the specified or all VLANs. If vlan_id or all is specified, information of specified VLAN or all VLANs is displayed. It includes: VLAN ID, VLAN state, whether the routing function has been enable on this Huawei Technologies Proprietary...
Using interface vlan-interface command, you can configure VLAN interface or enter VLAN interface view. Using undo interface vlan-interface command, you can cancel one VLAN interface. For the related command, see display interface vlan-interface. Example # Enter VLAN-interface 1 view of VLAN interface. [Quidway] interface vlan-interface 1 Huawei Technologies Proprietary...
IP address. For the related command, see display vlan, display interface vlan-interface. Example # Specify IP address and mask for VLAN interface 1. [Quidway-Vlan-interface1] ip address 1.1.1.1 255.0.0.0 1.1.6 name Syntax name string undo name Huawei Technologies Proprietary...
10 is the maximal. Description Using port command, you can add one port or one group of ports to VLAN. Using undo port command, you can cancel one port or one group of ports from VLAN. Huawei Technologies Proprietary...
Shutting down or starting VLAN interface will not take any effect on any Ethernet port of this VLAN. Example # Restart interface after shutting down the interface. [Quidway-Vlan-interface1] shutdown [Quidway-Vlan-interface1] undo shutdown Huawei Technologies Proprietary...
{ enable | disable } View System view Parameter enable: Enable VLAN features of equipment. disable: Disable the VLAN features of equipment. Description Using vlan { enable | disable } command, you can enable/disable the VLAN features of equipment. Huawei Technologies Proprietary...
Using the display protocol-vlan interface command, you can view the protocol information and protocol index configured on the specific port, to which you can refer when you use the protocol-based VLAN and add/delete a protocol. For the related commands, see display interface. Huawei Technologies Proprietary...
For the related commands, see display vlan. Example # Display the protocol information and protocol index configured on the VLANs from VLAN10 to VLAN20 [Quidway] display protocol-vlan vlan 10 to 20 VLAN ID: 10 VLAN Type: Protocol-based VLAN Huawei Technologies Proprietary...
VLAN before you associate it with the protocol-based VLAN. Otherwise, it cannot be associated with the VLAN. For the related commands, see display protocol-vlan interface. Example # Associate Ethernet0/1 with protocols 0 to 6 in VLAN 3 [Quidway-Ethernet0/1] port hybrid protocol-vlan vlan 3 0 to 6 Huawei Technologies Proprietary 1-10...
Note that the format of mode llc dsap ff ssap ff is the same as that of ipx raw, and the system first matches ipx raw, so the configuration of vlan-type protocol mode llc dsap ff ssap ff does not function. For the related commands, see display protocol-vlan vlan. Huawei Technologies Proprietary 1-11...
Page 80
Quidway S3500 Series Ethernet Switches Chapter 1 VLAN Configuration Commands Example # Specify VLAN 3 to be based on IP protocol. [Quidway-vlan3] protocol-vlan ip # Specify VLAN 5 to be based on the 123.34.56.0 network segment. [Quidway-vlan5] protocol-vlan ip 123.34.56.0 Huawei Technologies Proprietary 1-12...
By default, there is no any corresponding relationship between isolate-user-vlan and Secondary vlan created by the user. Before the command is run, isolate-user-vlan and Secondary vlan must include ports. After the command is run, the mapping relationship between isolate-user-vlan and Huawei Technologies Proprietary...
Ethernet switch, the Trunk port cannot be configured. If the Trunk port is configured, then the isolate-user-vlan cannot be configured. For the related commands, see display isolate-user-vlan. Example # Configure VLAN 5 as isolate-user-vlan. [Quidway-vlan5] isolate-user-vlan enable Huawei Technologies Proprietary...
Number Of GMRP Frames Received Number Of GVRP Frames Received Number Of GMRP Frames Transmitted Number Of GVRP Frames Transmitted Number Of Frames Discarded The above information indicates that the numbers of GVRP/GMRP packets received/sent and discarded on Ethernet0/1 are 0. Huawei Technologies Proprietary...
For the related command, see display garp timer. Example # Set Join timer of GARP as 300ms. [Quidway-Ethernet0/1] garp timer join 30 3.1.4 garp timer leaveall Syntax garp timer leaveall timer_value undo garp timer leaveall View System view Huawei Technologies Proprietary...
Using reset garp statistics command, you can reset the GARP statistics information (such as the received/sent packets or discarded packets by GVRP/GMRP). If the command has no parameter, it will clear the GARP statistics information of all the ports. Huawei Technologies Proprietary...
# Display the GVRP statistics information about Ethernet0/1. <Quidway> display gvrp statistics interface ethernet0/1 GVRP statistics on port Ethernet0/1 GVRP Status : Enabled GVRP Failed Registrations GVRP Last Pdu Origin : 0000-0000-0000 GVRP Registration Type : Normal Huawei Technologies Proprietary...
This command can be used to enable/disable global GVRP in System view or enable/disable port GVRP in Ethernet port view. Before enabling port GVRP, the user must enable global GVRP first and port GVRP must be enabled/disabled on Trunk port. Huawei Technologies Proprietary...
By default, the registration type is normal. This command can be only used on Trunk port. For the related commands, see display gvrp statistics. Example # Set the GVRP registration type of Ethernet0/1 as fixed. [Quidway-Ethernet0/1] gvrp registration fixed Huawei Technologies Proprietary...
# view the mapping relationship between Super VLAN and Sub VLAN. [Quidway] display supervlan 2 Supervlan ID : ARP proxy: enabled Subvlan ID : VLAN ID: 2 VLAN Type: static It is a Super VLAN. ARP proxy enabled. Huawei Technologies Proprietary...
Page 92
Broadcast MAX-ratio: 100% Tagged Ports: none Untagged Ports: Ethernet0/4 VLAN ID: 5 VLAN Type: static It is a Sub VLAN. Route Interface: not configured Description: VLAN 0005 Name: VLAN 0005 Broadcast MAX-ratio: 100% Tagged Ports: none Untagged Ports: Ethernet0/5 Huawei Technologies Proprietary...
Page 93
VLAN and the specific sub VLAN. For the related commands, see display supervlan. Example # Establish the mapping relationship between sub VLAN 3, 4, 5, 9 and super VLAN 10. [Quidway-vlan10] subvlan 3 to 5 9 4.1.3 supervlan Syntax supervlan undo supervlan Huawei Technologies Proprietary...
Page 94
Using supervlan commmand, you can set current VLAN to super VLAN. Using undo supervlan commmand, you can cancel the super VLAN type of current VLAN. For the related commands, see display supervlan. Example # Set the VLAN 2 to super VLAN. [Quidway-vlan2] supervlan Huawei Technologies Proprietary...
<Quidway> display ip host Host Flags Address(es) static 1.1.1.1 static 2.2.2.4 1.1.2 display ip interface Syntax display ip interface interface-type interface-number View Any view Parameter interface-type: Port type. Interface-number: Port number. See the description of the interface command for details. Huawei Technologies Proprietary...
By default, all interfaces’ IP addresses are null. Generally, it is enough to configure one IP address for an interface. You can also configure 10 IP addresses for an interface at most, so that it can be connected to Huawei Technologies Proprietary...
Using ip host command, you can configure the host name and the host IP address. Using undo ip host command, you can cancel the host name and the host IP address. By default, Host name and corresponding IP address are null. For the related command, see display ip host. Huawei Technologies Proprietary...
Page 103
Command Manual - Network Protocol Quidway S3500 Series Ethernet Switches Chapter 1 IP Address Configuration Commands Example # Set Lanswtich1’s IP address to be 202.38.0.8. [Quidway] ip host Lanswitch1 202.38.0.8 Huawei Technologies Proprietary...
# Configure that the device learns the ARP entry where the MAC address is multicast MAC address. [Quidway] undo arp check enable 2.1.2 arp probe ip Syntax arp probe ip ip-address undo arp probe ip [ ip-address ] View VLAN interface view Huawei Technologies Proprietary...
For the related command, see display arp source-suppression. In S3500 Series Ethernet Switches, only S3552G, S3552P, S3528G, S3528P and S3552F supports this command. Example # Configure the number of source IP addresses to be suppressed is 10. Huawei Technologies Proprietary...
In S3500 Series Ethernet Switches, only S3552G, S3552P, S3528G, S3528P and S3552F supports this command. For the related command, see display arp source-suppression. Example # Enable ARP source address suppression. [Quidway] arp source-suppression enable 2.1.5 arp source-suppression limit Syntax arp source-suppression limit limit-value undo arp source-suppression limit Huawei Technologies Proprietary...
Using arp timer probe command, you can configure the ARP probing interval. Using undo arp timer probe command, you can restore the default ARP probing interval. In S3500 Series Ethernet Switches, only S3526, S3526 FM, S3526 FS supports this command. For the related command, see display arp probe. Huawei Technologies Proprietary...
The parameter vlan-id must be the ID of a VLAN that has been created by the user, and the Ethernet port specified behind this parameter must belong to the VLAN. For the related command, see reset arp, display arp, debugging arp. Huawei Technologies Proprietary...
Target Ethernet address. If the packet is ARP request packet, target_eth_addr the target IP address will be 0 target_ip_addr Target IP address 2.1.10 display arp Syntax display arp [ dynamic | static | ip-address ] View Any view Huawei Technologies Proprietary...
Port to which the static ARP entry belongs Aging Aging time of dynamic ARP entry in minutes Type Type of ARP entry 2.1.11 display arp probe Syntax display arp probe [ interface vlan-interface vlan-id ] View Any view Parameter vlan-id: VLAN interface. Huawei Technologies Proprietary...
Clear the static ARP mapping entries interface interface-name: Clear the ARP mapping entries that are related to the specified. port, represented with interface-name= interface-type interface-number. interface-type is port type and interface-number is port number. For details about Huawei Technologies Proprietary 2-10...
IP address conflict. Use the undo arp send-gratuitous enable command to disable this function. By default, the gratuitous ARP packet sending is enabled. Gratuitous ARP function is to implement the following functions by sending out gratuitous ARP packets: Huawei Technologies Proprietary 2-11...
By default, gratuitous ARP packet learning is disabled. Related command: arp send-gratuitous enable, debugging arp packet. Example # Enable gratuitous ARP packet learning on the switch Quidway A. <QuidwayA> system-view System View: return to User View with Ctrl+Z. [QuidwayA] gratuitous-arp-learning enable Huawei Technologies Proprietary 2-12...
See arp proxy enable for related configuration. Example # Display the ARP proxy status of interface VLAN 2 [Quidway] display arp proxy 3.1.2 arp proxy Syntax arp proxy enable undo arp proxy enable View VLAN virtual interface view Parameter None Huawei Technologies Proprietary...
Page 117
Use the arp proxy enable command to enable ARP proxy. Use the undo arp proxy enable command to disable ARP proxy. See display arp proxy for related configuration. Example # Enable the ARP proxy of VLAN 2 virtual interface. [Quidway-Vlan-interface2] arp proxy enable Huawei Technologies Proprietary...
Using the debugging dhcp client command, you can enable DHCP client debugging. Using the undo debugging dhcp client command, you can disable DHCP client debugging. By default, all DHCP client debugging is disabled. Example # Enable DHCP client event debugging. <Quidway> debugging dhcp client event Huawei Technologies Proprietary...
2002.09.21 01:05:03 Server IP: 169.254.0.1 Transaction ID = 0x3d8a7431 Default router: 2.2.2.2 DNS server: 1.1.1.1 Domain name: huawei.com Client ID: HUAWEI-00e0.fc0a.c3ef-Ethernet0/0 Next timeout will happen after 0 days 11 hours 56 minutes 1 seconds. 4.1.3 ip address dhcp-alloc Syntax ip address dhcp-alloc...
Page 120
IP address using DHCP. Using the undo ip address dhcp-alloc command, you can remove the configuration. By default, the VLAN interface doest not obtain IP address using DHCP. Example # Configure VLAN interface to obtain IP address using DHCP. [Quidway-Vlan-interface1] ip address dhcp-alloc Huawei Technologies Proprietary...
VLAN interface. By default, the switch disables DHCP security features function. Example # Enable the security features of DHCP relay on VLAN1 interface. [Quidway-Vlan-interface1] address-check enable 5.1.2 debugging dhcp-relay Syntax debugging dhcp-relay undo debugging dhcp-relay Huawei Technologies Proprietary...
Page 122
ClientHardAddress: 0010-dc19-695d DHCP ServerIpAddress: 192.168.1.2 *0.7200230-DHCP-8-dhcp_debug: From DHCP Server to client: Interface: VLAN-Interface 1 ServerGroupNo: 0 Type: dhcp-ack ClientHardAddress: 0010-dc19-695d AllocatedIpAddress: 10.1.1.1 *0.7200580-DHCP-8-largehop: Discard DHCP request packet because of too large hop count! *0.7200725-DHCP-8-invalidpkt: Wrong DHCP packet! Huawei Technologies Proprietary...
DHCP Server group before you change corresponding IP address of the DHCP Server group. For the related command, see display dhcp-security. Example # Configure the user IP address and MAC address of DHCP Server group as 1.1.1.1 and 0005-5D02-F2B3 respectively. [Quidway] dhcp-security static 1.1.1.1 0005-5D02-F2B3 Huawei Technologies Proprietary...
1.1.1.1 and 2.2.2.2 respectively. [Quidway] dhcp-server 1 ip 1.1.1.1 2.2.2.2 # Delete the IP addresses of the master/slave DHCP Server in DHCP Server group1. [Quidway] undo dhcp-server 1 5.1.7 display dhcp-security Syntax display dhcp-security [ ip_address ] View Any view Huawei Technologies Proprietary...
View Any view Parameter groupNo: DHCP Server group. Description Using display dhcp-server command, you can view the related information of DHCP Server group. For the related command, see dhcp-server ip, dhcp-server, display dhcp-server interface vlan-interface, debugging dhcp-relay. Huawei Technologies Proprietary...
Page 127
Number of OFFER packets received by DHCP DHCP_OFFER messages relay Number of ACK packets received by DHCP DHCP_ACK messages relay Number of NAK packets received by DHCP DHCP_NAK messages relay Number of DECLINE packets received by DHCP_DECLINE messages DHCP relay Huawei Technologies Proprietary...
# View the information of the DHCP Server group corresponding to VLAN-Interface 2. <Quidway> display dhcp-server interface vlan-interface 2 The DHCP Server group of this interface is 0 The information shown above indicates that vlan-interface 2 is configured with a DHCP Server group with ID as 0. Huawei Technologies Proprietary...
By default, the DHCP service is enabled. Only after the DHCP service is enabled can other DHCP configurations take effect. This configuration is essential to both DHCP server and DHCP relay. Example # Enable the DHCP service. [Quidway] dhcp enable Huawei Technologies Proprietary...
Example # Allocate addresses selected from a global address pool on the local DHCP server to the clients sending DHCP messages destined to the current device. [Quidway-Vlan-interface1] dhcp select global Huawei Technologies Proprietary...
All DHCP server debugging. error: Debugging of the DHCP server on such errors as occurring in DHCP message processing and address allocation. events: Debugging of the DHCP server on such events as address allocation and timeout of a ping attempt. Huawei Technologies Proprietary...
[ to vlan-interface vlan_id ]: specifies VLAN interfaces. all: All VLAN interfaces or IP addresses. Description Using the dhcp server dns-list command, you can define a list of DNS server addresses in one or multiple DHCP address pools on the specified VLAN interface(s). Huawei Technologies Proprietary...
Domain name to be allocated to the clients using the DHCP address pool on the VLAN interface, which is a string of 3 to 50 characters. interface vlan-interface vlan_id [ to vlan-interface vlan_id ]: Specifies VLAN interfaces. all: All VLAN interfaces. Huawei Technologies Proprietary...
Number of hours in the range of 0 to 23. minute minute: Number of minutes in the range of 0 to 59. unlimited: Unlimited address lease. interface vlan-interface vlan_id [ to vlan-interface vlan_id ]: Specifies VLAN interfaces. Huawei Technologies Proprietary...
By default, all IP addresses in address pools participate in automatic address allocation. For the related commands, see dhcp server ip-pool, network, static-bind ip-address, and dhcp server static-bind. Huawei Technologies Proprietary...
[ ip-address ] undo dhcp server nbns-list { ip-address | all } Following is the command for configuring in system view a NetBIOS server address list in DHCP address pools on multiple VLAN interfaces: Huawei Technologies Proprietary...
{ b-node | h-node | m-node | p-node } undo dhcp server netbios-type Following is the command for configuring in system view the NetBIOS node type of the clients using the DHCP address pools on multiple VLAN interfaces: Huawei Technologies Proprietary...
Following is the command for configuring in VLAN interface view a DHCP option for the DHCP address pool on the current VLAN interface: dhcp server option code { ascii ascii-string | hex hex-string | ip-address ip-address [ ip-address ] } undo dhcp server option code Huawei Technologies Proprietary 6-10...
DHCP address pool on the current VLAN interface. Using the undo dhcp server static-bind command, you can remove the binding. By default, no static address binding is configured in any VLAN interface address pool. Huawei Technologies Proprietary 6-12...
Address Discover Time 10.110.1.2 Jan 11 2003 11:57: 7 PM Table 6-1 Description of the output information of display dhcp server conflict Field Description Address Conflicted IP address Discover Time Time when the conflict is discovered Huawei Technologies Proprietary 6-13...
Information of expired address leases in global address pools Information of expired address leases in VLAN interface Interface pool address pools IP address IP address in a binding Hardware address MAC address in a binding Lease expiration Lease expiration time Huawei Technologies Proprietary 6-14...
[ vlan-interface vlan_id ] | all } View Any view Parameter ip ip-address: Specifies an IP address. pool [ pool-name ]: Name of a global address pool. If no address pool is specified, all the global address pools apply. Huawei Technologies Proprietary 6-15...
IP address IP address in a binding Hardware address MAC address in a binding Lease expiration Lease expiration time Type Address binding type 6.2.16 display dhcp server statistics Syntax display dhcp server statistics View Any view Huawei Technologies Proprietary 6-16...
Page 145
Table 6-4 Description of the output of display dhcp server statistics Field Description Global Pool Statistics information about global address pools Statistics information about VLAN interface address Interface Pool pools Pool Number Number of address pools Huawei Technologies Proprietary 6-17...
VLAN interface. If no interface is specified, address pools on all VLAN interfaces apply. all: All DHCP address pools. Description Using the display dhcp server tree command, you can view the tree of DHCP address pools. Example # Display the tree of DHCP address pools. Huawei Technologies Proprietary 6-18...
Page 147
Table 6-5 Description of the output of display dhcp server tree Field Description Global pool Information about global address pools Interface pool Information about VLAN interface address pools Pool Name Address pool name network Address ranges available for allocation Huawei Technologies Proprietary 6-19...
{ ip-address | all } View DHCP address pool view Parameter ip-address: IP address of DNS server. You can configure up to eight IP addresses separated by spaces in a command. all: IP addresses of all the configured DNS servers. Huawei Technologies Proprietary 6-20...
For the related commands, see dhcp server ip-pool and dhcp server domain-name. Example # Specify “mydomain.com” as the domain name to be assigned to the clients using global DHCP address pool 0. [Quidway] dhcp server ip-pool 0 [Quidway-dhcp-0] domain-name mydomain.com Huawei Technologies Proprietary 6-21...
DHCP address pool. Using the undo nbns-list command, you can remove one or all NetBIOS server addresses from the global address pool. By default, no NetBIOS server address is configured. If you configure NetBIOS server list for multiple times, the latest NetBIOS server list will replace the previous one. Huawei Technologies Proprietary 6-23...
By default, clients are h-nodes. For the related commands, see dhcp server ip-pool, dhcp server netbios-byte, and nbns-list. Example # Specify clients using global DHCP address pool 0 to be b-nodes. [Quidway] dhcp server ip-pool 0 [Quidway-dhcp-0] netbios-type b-node Huawei Technologies Proprietary 6-24...
Using the reset dhcp server conflict command, you can clear the statistics information about DHCP address conflict. For the related command, see display dhcp server conflict. Example # Clear statistics information about all the address conflicts. <Quidway> reset dhcp server conflict all Huawei Technologies Proprietary 6-26...
Using the reset dhcp server statistics command, you can clear statistic information about the DHCP server, including such information as the number of DHCP address pools, automatic and manual address bindings and expired ones, and the number of unknown messages, DHCP requests, and responses. Huawei Technologies Proprietary 6-27...
Example # Bind the MAC address 0000-e03f-0305 with the IP address 10.1.1.1 using the mask 255.255.255.0. [Quidway-dhcp-0] static-bind ip-address 10.1.1.1 mask 255.255.255.0 [Quidway-dhcp-0] static-bind mac-address 0000-e03f-0305 6.2.30 static-bind mac-address Syntax static-bind mac-address mac-address undo static-bind mac-address Huawei Technologies Proprietary 6-28...
VLAN interface view Parameter None Description Use the address-check dhcp-relay enable command to activate the dynamic entries generated by the DHCP relay. Use the address-check dhcp-relay disable command to deactivate the dynamic entries generated by the DHCP relay Huawei Technologies Proprietary 6-29...
The so called unknown machine is a device which IP and MAC addresses are not contained in any DHCP security table entry. This configuration takes effect only when the DHCP security feature is enabled on the VLAN interface. Huawei Technologies Proprietary 6-30...
View VLAN interface view Parameter None Description Using the dhcp relay security address-check enable command, you can enable the security feature of DHCP relay to check the validity of user addresses on the VLAN Huawei Technologies Proprietary 6-32...
{ ip-address | all } Following is the command for configuring in system view DHCP server address to which multiple VLAN interfaces relay packets: ip relay address ip-address { interface vlan-interface vlan_id [ to vlan-interface vlan_id ] | all } Huawei Technologies Proprietary 6-35...
Using the undo ip relay address cycle command, you can disable DHCP servers to share the load. By default, DHCP servers do not share the load and requests from DHCP clients are only sent to the DHCP server configured first. Huawei Technologies Proprietary 6-36...
Using the reset dhcp relay statistics command, you can clear the statistics information about DHCP relay. For the related command, see display dhcp relay statistics. Example # Clear the statistics information about DHCP relay. <Quidway> reset dhcp relay statistics Huawei Technologies Proprietary 6-37...
By default, DHCP snooping function is not enabled. Related command: display dhcp-snooping. Note that: You must first disable DHCP relay (no DHCP server is configured on any Layer 3 port) before enabling DHCP snooping on the switch. Example # Enable DHCP snooping. <Quidway> system-view Huawei Technologies Proprietary...
Use the display dhcp-snooping command to view the association table recorded by DHCP snooping, including the user IP address allocated by the DHCP server, MAC address, lease time of the IP address, VLAN where the switch port for the user belong. Huawei Technologies Proprietary...
DHCP-Snooping function and the information about the trusted ports. For the related command, see dhcp-snooping trust. Example # Display the status of the DHCP-Snooping function and the information about the trusted ports. <Quidway> display dhcp-snooping trust dhcp-snooping is enabled Huawei Technologies Proprietary...
IP address using BOOTP. Using the undo ip address bootp-alloc command, you can remove the configuration. By default, the VLAN interface does not obtain IP address using BOOTP. For the related command, see display bootp client. Huawei Technologies Proprietary...
Page 172
Command Manual - Network Protocol Quidway S3500 Series Ethernet Switches Chapter 8 BOOTP Client Configuration Commands Example # Configure VLAN interface 1 to obtain IP address using BOOTP. [Quidway-Vlan-interface1] ip address bootp-alloc Huawei Technologies Proprietary...
ARP setting. Example # Enable the access management function. [Quidway] am enable 9.1.2 am ip-pool Syntax am ip-pool address-list undo am ip-pool { all | address-list } Huawei Technologies Proprietary...
Syntax am isolate interface-list undo am isolate interface-list View Ethernet port view Parameter interface-list: Specifies a list of ports isolated from the specified port in the { { interface-type interface-number | interface-name } [ to { interface-type Huawei Technologies Proprietary...
Using am trap enable command, you can enable the access management trap function. Using undo am trap enable command, you can disable the access management trap function. By default, The access management trap disabled. Example # Enable the access management trap. [Quidway] am trap enable Huawei Technologies Proprietary...
Do not perform “Port+IP+MAC” and “Port+IP” on the same port. S3526E/S3526C switches support this command. Example # Bind port Ethernet0/1 and IP address 192.10.1.1. [Quidway] am user-bind interface ethenet0/1 ip-addr 192.10.1.1 9.1.6 display am Syntax display am [ interface-list ] Huawei Technologies Proprietary...
Page 177
X.X.X.X (number), of these, “X.X.X.X” IP Pools represents the first address, and “number” represents that “number” consecutive IP addresses from the beginning of this address are within the IP pools Isolate Ports Isolate ports. NULL represents no configuration Huawei Technologies Proprietary...
If the uplink port is the kind of trunk port, it is recommended configure the trunk port to allow all the VLAN traffic to pass through and configure it to be the only uplink port in the VLAN where the port isolation is enabled. Huawei Technologies Proprietary...
Page 180
Command Manual - Network Protocol Quidway S3500 Series Ethernet Switches Chapter 9 Access Management Configuration Commands Example # Configure the port Ethernet1/0/1 as an uplink port. [Quidway-Ethernet1/0/1] port-isolate uplink-port vlan 1 Huawei Technologies Proprietary...
D – Dynamic route G – Gateway route Flag H – Local host route S – Static route U – Route in UP status R – Unreachable route L – Route generated by ARP or ESIS Huawei Technologies Proprietary 10-1...
Table 10-2 Description of the output information of the display icmp statistics command Field Description bad formats Number of input packets in bad format bad checksum Number of input packets with wrong checksum echo Number of input/output echo request packets Huawei Technologies Proprietary 10-2...
Using the display ip socket command, you can display the information about the sockets in the current system. Example # Display the information about the socket of TCP type. <Quidway> display ip socket socktype 1 SOCK_STREAM: Task = VTYD(18), socketid = 1, Proto = 6, Huawei Technologies Proprietary 10-3...
TCP is able to cache data rb_cc The current data size in the receiving buffer socket option The option of the socket socket state The state of the socket 10.1.4 display ip statistics Syntax display ip statistics View Any view Huawei Technologies Proprietary 10-4...
Page 185
Number of packets that are sent by the local device Output: dropped Number of dropped packets during transmission no route Number of packets that cannot be routed compress fails Number of packets that cannot be compressed Huawei Technologies Proprietary 10-5...
All these displayed information are measured in packet. For the related commands, see display tcp status, reset tcp statistics. Example # View statistics about TCP packets. [Quidway]display tcp statistics Received packets: Total: 753 Huawei Technologies Proprietary 10-6...
Closed connections: 0 (dropped: 0, initiated dropped: 0) 10.1.6 display tcp status Syntax display tcp status View Any view Parameter None Description Using display tcp status command, you can view the TCP connection state. Example # Display the state of all TCP connections. Huawei Technologies Proprietary 10-7...
Using reset ip statistics command, you can reset the IP statistics information. For the related commands, see display ip interface, display ip statistics. Example # Reset the IP statistics information. <Quidway> reset ip statistics 10.1.8 reset tcp statistics Syntax reset tcp statistics View User view Parameter None Huawei Technologies Proprietary 10-8...
Socket. Using undo tcp window command, you can restore the default size of the buffer. For the related command, see tcp timer fin-timeout, tcp timer syn-timeout. Example # Configure the size of the transmission and receiving buffers as 3KB. Huawei Technologies Proprietary 10-10...
Only current used route, i.e., best route, is displayed using display ip routing-table command. Example # View the summary of routing table. <Quidway> display ip routing-table Routing Table: public net Destination/Mask Protocol Pre Cost Nexthop Interface 10.153.25.0/24 DIRECT 10.153.25.200 Vlan-interface1 Huawei Technologies Proprietary...
This command is used in track display of route policy to display the route that passed the filtering rule according the input basic ACL number or name. The command is only applicable to display the route that passed basic ACL filtering rules. Huawei Technologies Proprietary...
Page 200
*NextHop: 127.0.0.1 Interface: 127.0.0.1(InLoopBack0) Vlinkindex: 0 State: <NoAdvise Int ActiveU Retain Gateway Unicast> Age: 7:24 Cost: 0/0 Table 1-2 Description of information generated by the command display ip routing-table acl verbose Field Description Destination Destination address Mask Mask Huawei Technologies Proprietary...
Page 201
Chapter 1 Static Route Configuration Commands Field Description Protocol Routing protocol Preference Routing preference Nexthop Next hop address Output interface, through which the data packet destined for the Interface destination network segment is sent Vlinkindex Virtual link index Huawei Technologies Proprietary...
Page 202
The route with Static flag will not be cleared from the routing table after you save it and reboot the router. Static Generally, the static route configured manually in the router belongs to a Static route. Unicast Unicast route Time to live Cost Value of the cost Huawei Technologies Proprietary...
# There is corresponding route in natural mask range. Display the summary. <Quidway> display ip routing-table 169.0.0.0 Destination/Mask Protocol Pre Cost Nexthop Interface 169.0.0.0/16 Static 2.1.1.1 LoopBack1 For detailed description of the output information, see Table 1-1. Huawei Technologies Proprietary...
<Quidway>display ip routing-table 1.1.1.0 24 2.2.2.0 24 Routing tables: Summary count: 3 Destination/Mask Protocol Pre Cost Nexthop Interface 1.1.1.0/24 DIRECT 1.1.1.1 Vlan-interface1 1.1.1.1/32 DIRECT 127.0.0.1 InLoopBack0 2.2.2.0/24 DIRECT 2.2.2.1 Vlan-interface2 For detailed description of the output information, see Table 1-1. Huawei Technologies Proprietary...
[Quidway] display ip routing-table ip-prefix abc2 verbose Routes matched by ip-prefix abc2: Generate Default: no + = Active Route, - = Last Active, # = Both * = Next hop in use Summary count: 2 **Destination: 10.1.1.0 Mask: 255.255.255.0 Huawei Technologies Proprietary...
The statistics of routing information includes total route amount, the route amount added or deleted by protocol, amount of the routes that are labeled deleted but not deleted, the active route amount and inactive route amount. Huawei Technologies Proprietary 1-12...
Number of deleted routes (such routes will be freed in a period of time) freed Number of freed routes 1.1.9 display ip routing-table verbose Syntax display ip routing-table verbose View Any view Parameter None Huawei Technologies Proprietary 1-13...
Specify the next hop IP address of the route. preference-value: Preference level of the route in the range from 1 to 255. reject: Indicate an unreachable route. blackhole: Indicate a blackhole route. Huawei Technologies Proprietary 1-15...
Page 213
If it is failed to detect the routing table, a packet will be forwarded along the default route. For different configuration of preference level, flexible routing management policy can be adopted. For the related commands, see display ip routing-table, delete static-routes all and ip route-static default-preference. Huawei Technologies Proprietary 1-16...
For the related commands, see display ip routing-table, ip route-static. Example # Configure the default preference of static routes as 120. [Quidway] ip route-static default-preference 120 Huawei Technologies Proprietary 1-17...
This command is ineffective to RIP-2 since RIP-2 packets have no zero fields. Example # Configure not to perform zero check for RIP-1 packet. [Quidway-rip] undo checkzero Huawei Technologies Proprietary...
View Any view Parameter None Description Using display rip command, you can view the current RIP running state and its configuration information. Example # Display the current running state and configuration information of the RIP. Huawei Technologies Proprietary...
Name of address prefix list used for filtering the destination addresses of the routing information. route-policy-name: Route policy name that filters routing information. After enabling RIP protocol, you can determine which routes are to be sent/received based on acl/cost/interface/ip/ip-prefix/tag fields. Huawei Technologies Proprietary...
Name of address prefix list used for filtering the destination addresses of the routing information. gateway ip-prefix-name: Name of address prefix list used for filtering the addresses of the neighboring routers advertising the routing information. Huawei Technologies Proprietary...
In some special cases, RIP receives a great number of host routes in the same network segment. These routes cannot help the path searching much but occupy a lot of resources. In this case, the undo host-route command can be used to reject a host route. Huawei Technologies Proprietary...
However, this router can still forward packets until the Garbage Collection timer times out (defaults to 120 seconds). For the related commands, see default cost. Example # Import a static route with cost 4. [Quidway-rip] import-route static cost 4 Huawei Technologies Proprietary...
129.102.1.1 with both the display current-configuration command and the display rip command are shown as the network 129.102.0.0. For the related commands, see rip work . Example # Enable the RIP on the interface with the network address as 129.102.0.0. Huawei Technologies Proprietary...
Usually, it is not recommended to use this command. Example # Specify the sending destination address 202.38.165.1. [Quidway-rip] peer 202.38.165.1 2.1.10 preference Syntax preference value undo preference View RIP view Parameter value: Preference level, ranging from 1 to 255. By default, the value is 100. Huawei Technologies Proprietary...
Using reset command, you can reset the system configuration parameters of RIP. When you need to re-configure parameters of RIP, this command can be used to restore to the default setting. Example # Reset the RIP system. [Quidway-rip] reset 2.1.12 rip Syntax undo rip View system view Huawei Technologies Proprietary...
Interface view Parameter simple: Simple text authentication mode. password: Simple text authentication key. md5: MD5 cipher text authentication mode. usual: Specify the MD5 cipher text authentication packet to use the general packet format (RFC1723 standard format). Huawei Technologies Proprietary 2-10...
# Set MD5 authentication at Vlan-interface 1 with the key string as aaa and the packet type as usual. [Quidway] interface Vlan-interface 1 [Quidway-Vlan-interface1] rip version 2 [Quidway-Vlan-interface1] rip authentication-mode md5 usual aaa 2.1.14 rip input Syntax rip input undo rip input Huawei Technologies Proprietary 2-11...
Using rip metricin command, you can configure the additional route metric added to the route when an interface receives RIP packets. Using undo rip metricin command, you can restore the default value of this additional route metric. For the related commands, see rip metricout. Huawei Technologies Proprietary 2-12...
By default, an interface is enabled to use split horizon when transmitting RIP packets. Normally, split horizon is necessary for reducing route loop. Only in some special cases, split horizon should be disabled to ensure the correct execution of protocols. Huawei Technologies Proprietary 2-14...
When running RIP-2 in multicast mode, the interface only receives and transmits RIP-2 multicast packets, receives RIP-2 broadcast packets, but does not receive RIP-1 packets. Example # Configure the interface Vlan-interface 1 as RIP-2 broadcast mode. [Quidway] interface Vlan-interface 1 [Quidway-Vlan-interface1] rip version 2 broadcast Huawei Technologies Proprietary 2-15...
For the related commands, see network, rip input, rip output. Example # Disable the interface Vlan-interface 1 to run the RIP. [Quidway] interface Vlan-interface 1 [Quidway-Vlan-interface1] undo rip work 2.1.21 summary Syntax summary undo summary View RIP view Parameter None Huawei Technologies Proprietary 2-16...
Page 231
For the related commands, see rip version. Example # Set RIP version on the interface Vlan-interface 1 as RIP-2 and disable the route aggregation. [Quidway] interface Vlan-interface 1 [Quidway-Vlan-interface1] rip version 2 [Quidway-Vlan-interface1] quit [Quidway] rip [Quidway-rip] undo summary Huawei Technologies Proprietary 2-17...
The ABR only transmits an aggregated route to other areas. Route aggregation refers to that the routing information is processed in the ABR and for each network segment configured with route aggregation, there is only one route transmitted to other areas. Huawei Technologies Proprietary...
Use simple text authentication mode. md5: Use MD5 cipher text authentication mode. Description Using authentication-mode command, you can configure one area of OSPF to support the authentication attribute. Using undo authentication-mode command, you can cancel the authentication attribute of this area. Huawei Technologies Proprietary...
3.1.7 default limit Syntax default limit routes undo default limit View OSPF view Parameter routes: Default value to the imported external routes in a unit time, ranging from 200 to 2147483647. By default, the value is 1000. Huawei Technologies Proprietary...
For the related commands, see default type. Example # Set the default tag of OSPF imported external route of the autonomous system as 10. [Quidway-ospf] default tag 10 Huawei Technologies Proprietary...
View OSPF Area view Parameter value: Specify the cost value of the default route transmitted by OSPF to the STUB or NSSA area, ranging from 0 to 16777214. The default value is 1. Huawei Technologies Proprietary...
2. route-policy route-policy-name: if the default route match the route-policy specified by route-policy-name, route-policy will affect the value in ase lsa. The length of route-policy-name parameter ranges from 1 to 16 character string. Huawei Technologies Proprietary...
OSPF and all processes. For related commands, see debugging ospf. Example # Display the debugging states of global OSPF and all processes. <Quidway> display debugging ospf OSPF EVENT debugging switch is on 3.1.13 display ospf abr-asbr Syntax display ospf abr-asbr Huawei Technologies Proprietary...
The local output interface 3.1.14 display ospf asbr-summary Syntax display ospf asbr-summary [ ip-address mask ] View Any view Parameter ip-address: Matched IP address in dotted decimal format. mask: IP address mask in dotted decimal format. Huawei Technologies Proprietary 3-10...
Page 242
Destination network segment mask Mask Status information, including two values: The summary routing information to the network DoNotAdvertise status segment will not be advertised The summary routing information to the network Advertise segment will be advertised Huawei Technologies Proprietary 3-11...
Table 3-3 Description of information generated by the command display ospf brief Field Description RouterID Router ID of the router Border routers for connection to the area, including Border Router autonomous system border router (ASBR) and area border router (ABR) spf-schedule-interval Interval of SPF schedule Huawei Technologies Proprietary 3-12...
Interval of hello packet Timers Dead Interval of dead neighbors Poll Interval of poll Retransmit Interval of retransmitting LSA Transmit Delay Delay time of transmitting LSA 3.1.16 display ospf cumulative Syntax display ospf cumulative View Any view Huawei Technologies Proprietary 3-13...
Page 245
Inter Area: 0 ASE: 0 Table 3-4 Description of information generated by the command display ospf cumulative Field Description Type Type of input/output OSPF packet IO Statistics Input Number of received packets Output Number of transmitted packets Huawei Technologies Proprietary 3-14...
Using display ospf error command, you can view the OSPF error information. Example # Display the OSPF error information. <Quidway> display ospf error OSPF packet error statistics: 0: IP: received my own packet 0: OSPF: wrong packet type Huawei Technologies Proprietary 3-15...
Page 247
OSPF: packet size > ip length OSPF packet size exceeds IP packet length OSPF: transmit error OSPF transmission error OSPF: interface down OSPF interface is down, unavailable OSPF: unknown neighbor OSPF neighbors are unknown HELLO: netmask mismatch Network mask mismatch Huawei Technologies Proprietary 3-16...
Page 248
LS UPD: unknown LSA type Link state update packet: unknown LSA type OSPF routing: next hop not Next hop of OSPF routing does not exist exist DD: MTU option mismatch MTU option of DD packet is mismatched Huawei Technologies Proprietary 3-17...
Backup Designated Router BDR on the network in which the interface resides OSPF timers, defining as follows: Hello Interval of hello packet Timers Dead Interval of dead neighbors Poll Interval of poll Retransmit Interval of retransmitting LSA Huawei Technologies Proprietary 3-18...
<Quidway> display ospf lsdb Link State Database Area: 0.0.0.0 Type LinkState ID AdvRouter Age Len Sequence Metric Where 2.2.2.2 2.2.2.2 465 36 8000000c SpfTree 1.1.1.1 1.1.1.1 449 36 80000004 SpfTree 10.153.17.89 2.2.2.2 465 32 80000004 SpfTree Huawei Technologies Proprietary 3-19...
Page 251
Link State Data Base type : ASE ls id : 2.2.0.0 adv rtr: 1.1.1.1 ls age: len: 36 seq#: 80000001 chksum: 0xfcaf Options: (DC) Net mask:255.255.0.0 Tos 0 metric: 1 E type : 2 Forwarding Address: 0.0.0.0 Huawei Technologies Proprietary 3-20...
Syntax display ospf nexthop View Any view Parameter None Description Using display ospf nexthop command, you can view the information about the next-hop Example # Display the OSPF next-hop information. <Quidway> display ospf nexthop Next hops: Huawei Technologies Proprietary 3-21...
# View the information of OSPF peer. <Quidway> display ospf peer Area 0.0.0.0 interface 10.153.17.88(Vlan-interface1)'s neighbor(s) RouterID: 2.2.2.2 Address: 10.153.17.89 State: Full Mode: Nbr is Master Priority: 1 DR: 10.153.17.89 BDR: 10.153.17.88 Dead timer expires in 31s Huawei Technologies Proprietary 3-22...
Page 254
ATM. It indicates that OSPF router does not receive the message from Attempt a certain neighbor router within a period of time, but still attempts to send Hello packet to the adjacent routers for their communications with a lower frequency. Huawei Technologies Proprietary 3-23...
Using display ospf request-queue command, you can view the information about the OSPF request-queue. Example # Display the information of OSPF request-queue. <Quidway> display ospf request-queue The Router's Neighbors is RouterID: 1.1.1.1 Address: 1.1.1.1 Interface: 1.1.1.3 Area: 0.0.0.0 LSID:1.1.1.3 AdvRouter:1.1.1.3 Sequence:80000017 Age:35 Huawei Technologies Proprietary 3-24...
OSPF retransmission queue. Example # Display the information of OSPF retransmission queue. <Quidway> display ospf retrans-queue Retransmit List The Router's Neighbors is RouterID: 162.162.162.162 Address: 103.169.2.2 Interface: 103.169.2.5 Area: 0.0.0.1 Retrans list: Type: ASE LSID:129.11.77.0 AdvRouter:103.160.1.1 Huawei Technologies Proprietary 3-25...
Using filter-policy export command, you can configure the rule of OSPF filtering the advertised routing information. Using undo filter-policy export command, you can cancel the filtering rules that have been set. By default, no filtering of the distributed routing information is performed. Huawei Technologies Proprietary 3-28...
In some cases, it may be required that only the routing information meeting some conditions can be received. Then, the filter-policy command can be used to set the filtering conditions for the routing information to be received. Only the routing information passing the filtration can be received. Huawei Technologies Proprietary 3-29...
By default, the routing information of other protocols is not imported. Note: You are recommended to configure the route type, cost and tag together in one command; otherwise, the new configuration overwrites the old one. Huawei Technologies Proprietary 3-30...
# Specify the interfaces whose master IP addresses are in the segment range of 10.110.36.0 to run the OSPF protocol and specify the number of the OSPF area (where these interfaces are located) as 6. [Quidway-ospf] area 6 [Quidway-ospf-area-0.0.0.6] network 10.110.36.0.0 0.0.0.255 Huawei Technologies Proprietary 3-31...
On ASBR, the no-import-route parameter enables the external route imported by OSPF through import-route command not to be advertised to NSSA area. Example # Configure area 1 as NSSA area. [Quidway-ospf] area 1 [Quidway-ospf-area-0.0.0.1] network 36.0.0.0 0.255.255.255 [Quidway-ospf-area-0.0.0.1] nssa 3.1.31 ospf Syntax ospf undo ospf Huawei Technologies Proprietary 3-32...
16 characters. And it will be displayed in a cipher text form in a length of 24 characters when display current-configuration command is executed. Inputting the MD5 key in a cipher text form with 24 characters is also supported. Huawei Technologies Proprietary 3-33...
# Set the area 1 where the network segment 131.119.0.0 of Interface Vlan-interface 1 is located to support MD5 cipher text authentication. The authentication key identifier is set to 15 and the authentication key is Huawei. [Quidway-ospf] area 1 [Quidway-ospf-area-0.0.0.1] network 131.119.0.0 0.0.255.255 [Quidway-ospf-area-0.0.0.1] authentication-mode md5...
Using undo ospf network-type command, you can restore the default network type of the OSPF interface. OSPF divides networks into four types by link layer protocol: Broadcast: If Ethernet or FDDI is adopted, OSPF defaults the network type to broadcast. Huawei Technologies Proprietary 3-36...
[Quidway-Vlan-interface1] ospf network-type nbma 3.1.37 ospf timer dead Syntax ospf timer dead seconds undo ospf timer dead View Interface view Parameter seconds: Dead interval of the OSPF neighbor. It is in second and ranges from 1 to 65535. Huawei Technologies Proprietary 3-37...
By default, the interval is 10 seconds for an interface of p2p or broadcast type to transmit Hello messages, and 30 seconds for an interface of nbma or p2mp type. For the related commands, see ospf timer dead. Huawei Technologies Proprietary 3-38...
Poll seconds should be no less than 3 times of Hello. Example # Configure to transmit poll Hello packet from interface Vlan-interface 2 every 120 seconds. [Quidway-Vlan-interface2] ospf timer poll 120 3.1.40 ospf timer retransmit Syntax ospf timer retransmit interval undo ospf timer retransmit Huawei Technologies Proprietary 3-39...
1 second. Description Using ospf trans-delay command, you can configure the LSA transmitting delay on an interface. Using undo ospf trans-delay command, you can restore the default value of the LSA transmitting delay on an interface. Huawei Technologies Proprietary 3-40...
NBMA type. Using undo peer command, you can cancel the configured neighboring point. Example # Configure the IP address of neighboring router as 10.1.1.1. [Quidway-ospf] peer 10.1.1.1 3.1.43 preference Syntax preference [ ase ] value undo preference [ ase ] Huawei Technologies Proprietary 3-41...
Using reset ospf all command, you can reset all the OSPF process. The reset ospf all command can be used to reset the OSPF process and the following results are expected: Clear invalid LSA immediately without waiting for LSA timeout. Huawei Technologies Proprietary 3-42...
When the router ID is configured manually, the IDs of any two routers cannot be same in the autonomous system. So, the IP address of certain interface might as well be selected as the ID of this router. Huawei Technologies Proprietary 3-43...
OSPF routing information. On a switch, this command can disable/enable the specified VLAN interface to send OSPF packets Example # Disable interface Vlan-interface 2 to transmit OSPF packet. [Quidway-ospf] silent-interface Vlan-interface 2 Huawei Technologies Proprietary 3-44...
By default, the switch does not send TRAP packets in case of OSPF anomalies. For detailed configuration of SNMP TRAP, refer to the module “System Management" in this manual. Example # Enable the TRAP function for OSPF process 100. [Quidway] snmp-agent trap enable ospf 100 Huawei Technologies Proprietary 3-45...
# Set the OSPF route calculation interval of Quidway to 6 seconds. [Quidway-ospf] spf-schedule-interval 6 3.1.49 stub Syntax stub [ no-summary ] undo stub View OSPF Area view Parameter no-summary: ABR is disabled to transmit Summary LSAs to the STUB area. Huawei Technologies Proprietary 3-46...
4 times of the hello seconds. The default value is 40 seconds. simple password: Specify the simple text authentication password, not exceeding 8 characters, of the interface. This value must equal the authentication key of the virtually linked peer. Huawei Technologies Proprietary 3-47...
Page 279
For the related commands, see authentication-mode, display ospf. Example # Create a virtual link to 10.110.0.3 and use the MD5 cipher authentication mode. [Quidway-ospf] area 10.0.0.0 [Quidway-ospf-area-10.0.0.0] vlink-peer 10.110.0.3 md5 3 345 Huawei Technologies Proprietary 3-48...
The same work can be done attribute-policy by using peer route-policy, etc. Example # Create an aggregated record in BGP routing table. [Quidway-bgp] aggregate 168.328.0.0 255.255.0.0 4.1.2 bgp Syntax bgp as-number undo bgp [as-number ] Huawei Technologies Proprietary...
If there are several routes available to one destination address, the route with smaller MED parameter can be selected as the final route item. Do not use this command unless it is determined that the same IGP and routing selection mode are adopted by different autonomous systems. Huawei Technologies Proprietary...
AS confederation. For external members, Confederation 9 is a unified AS domain. [Quidway] bgp 41 [Quidway-bgp] confederation id 9 [Quidway-bgp] confederation peer-as 38 39 40 [Quidway-bgp] group Confed38 external [Quidway-bgp] peer Confed38 as-number 38 Huawei Technologies Proprietary...
The penalty value of a route when it start to be reused. The range is 1 to 20000. By default, the value is 750. suppress: The penalty threshold of a route when it start to be suppressed. The range is 1 to 20000. By default, the value is 2000. Huawei Technologies Proprietary...
Indicating to enable BGP Open packet information debugging. packet: Indicating to enable BGP packet information debugging. route-refresh: Indicating to enable BGP route-refresh packet information debugging. update: Indicating to enable BGP Update packet information debugging. receive: Information of receiving packets. Huawei Technologies Proprietary...
Configuring different local preferences will affect BGP routing selection. When a router running BGP gets routes with the same destination address but different next hops through different internal peers, it will select the route of highest local preference to this destination. Huawei Technologies Proprietary...
RTB and RTC is Ethernet. So the MED of RTA can be configured as 25 to allow RTC to select the route transmitted by RTB first. [Quidway-bgp] default med 25 4.1.11 display bgp group Syntax display bgp group [ group-name ] View Any view Huawei Technologies Proprietary...
Members in this peer group route-policy Name of configured route policy filter-policy Configured export and import route filter for BGP Configured access control list ip-prefix Configured IP address prefix list 4.1.12 display bgp network Syntax display bgp network Huawei Technologies Proprietary 4-10...
Configured route policy 4.1.13 display bgp paths Syntax display bgp paths as-regular-expression View Any view Parameter as-regular-expression: Matched AS path regular expression. Description Using display bgp paths command, you can view the information about AS paths Huawei Technologies Proprietary 4-11...
With it, route loop can be avoided 4.1.14 display bgp peer Syntax display bgp peer peer-address verbose display bgp peer [ verbose ] View Any view Parameter peer-address: Specify the peer to be displayed. Huawei Technologies Proprietary 4-12...
Page 292
Type of peer: Internal for IBGP, and External for EBGP State State of peer Flags Flags of peer Last State Last state before entering current state Last Event Last event of neighbor state machine Last Error Last error of neighbor state machine Options Options Huawei Technologies Proprietary 4-13...
As-path passes. With it, route loop can be avoided 4.1.16 display bgp routing-table as-path-acl Syntax display bgp routing-table as-path-acl acl-number View Any view Parameter acl-number: Specify matched AS path list number ranging from 1 to 199. Huawei Technologies Proprietary 4-15...
Page 295
22.1.0.0/16 200.1.7.2 88.1.0.0/16 0.0.0.0 Table 4-7 Description of information generated by the command display bgp routing-table as-path-acl Field Description Dest/Mask Destination address/Mask Pref Preference Nexthop IP address of next hop MULTI_EXIT_DISC attribute value Local-pref Local preference Huawei Technologies Proprietary 4-16...
S – aggregate suppressed Dest/Mask Pref Next-Hop Local-pref Origin As-path -------------------------------------------------------------------- 1.0.0.0/8 172.10.0.2 2.0.0.0/8 172.10.0.2 For detailed description of the output information, see Table 5-6. 4.1.19 display bgp routing-table community-list Syntax display bgp routing-table community-list community-list-number [ whole-match ] Huawei Technologies Proprietary 4-18...
Page 298
10.10.10.1 4.4.4.0/24 10.10.10.1 9.9.9.0/24 10.10.10.1 10.10.10.0/24 0 10.10.10.2 10.10.10.0/24 256 10.10.10.1 For detailed description of the output information, see Table 5-6. 4.1.20 display bgp routing-table dampened Syntax display bgp routing-table dampened View Any view Parameter None Huawei Technologies Proprietary 4-19...
Page 299
The route is learned from exterior gateway protocol (EGP). Short for INCOMPLETE: indicates that the original source of the route information is unknown (learned by other methods). BGP sets the origin of the route imported through other IGP protocols as INCOMPLETE Huawei Technologies Proprietary 4-20...
For detailed description of the output information, see Table 5-6. 4.1.22 display bgp routing-table flap-info Syntax display bgp routing-table flap-info [ { regular-expression as-regular-expression } | { as-path-acl acl-number } | { network-address [ mask [ longer-match ] ] } ] View Any view Huawei Technologies Proprietary 4-21...
Page 301
The dampened route to the destination network 11.1.0.0 Source The nexthop of the route Keepup-time The time that route damping has continued Damping-lim The time before dampening turns invalid and the route can be reused. Flap-times The times of the route flap Huawei Technologies Proprietary 4-22...
# Import routes of RIP. [Quidway-bgp] import-route rip 4.1.29 ip as-path-acl Syntax ip as-path-acl acl-number { permit | deny } as-regular-expression undo ip as-path-acl acl-number View System view Parameter acl-number: Number of AS path list ranging from 1 to 199. Huawei Technologies Proprietary 4-27...
Used not to send the matched route to any peer. no-export: Does not announce the route to the AS or the association outside, but can advertise to other sub-ASs. as-regular-expression: Community attribute of the regular expression. Huawei Technologies Proprietary 4-28...
BGP. Using undo network command, you can cancel the existing configuration. By default, there is no networks sent through BGP Example # Advertise routes to network segment 10.0.0.0/16. [Quidway-bgp] network 10.0.0.0 255.255.0.0 4.1.32 peer advertise-community Syntax peer { group-name | peer-address } advertise-community Huawei Technologies Proprietary 4-29...
Using peer allow-as-loop command, you can configure the repeating time of local AS. Using undo peer allow-as-loop command, you can remove the repeating time of local For the related commands, see display current-configuration, display bgp routing-table peer, display bgp routing-table group Huawei Technologies Proprietary 4-30...
Usually, BGP uses the optimal route to update the source interface of the packets. However, you can set the mode of the interface to Loopback in order to send route updates even if the interface is not work normally. Huawei Technologies Proprietary 4-32...
Description Using peer ebgp-max-hop command, you can allow to establishing EBGP connection with the peer on indirectly connected network. Using undo peer ebgp-max-hop command, you can cancel the existing configuration. By default, this feature is disabled. Huawei Technologies Proprietary 4-34...
24 characters in the event of inputting the password in cipher text mode when parameter cipher is configured in the command. Huawei Technologies Proprietary 4-38...
# Adopt MD5 authentication on the TCP connection set up between the local router at 10.1.100.1 and the peer router at 10.1.100.2. [Quidway-bgp] peer 10.1.100.2 password simple huawei # Perform the similar configuration on the peer. [Quidway-bgp] peer 10.1.100.1 password simple huawei 4.1.46 peer public-as-only...
30 seconds for external peer/peer group. Description Using peer route-update-interval command, you can configure the interval for the transmission route of a peer/peer group. Using undo peer route-update-interval command, you can restore the interval to the default value. Huawei Technologies Proprietary 4-41...
The timer configured by using this command has a higher priority than the one configured by using the timer command. Example # Configure Keepalive and Holdtime intervals of the peer group “test”. [Quidway-bgp] peer test timer keep-alive 60 hold 180 4.1.51 reflect between-clients Syntax reflect between-clients undo reflect between-clients Huawei Technologies Proprietary 4-42...
By default, each route reflector uses its Router ID as the cluster ID. For the related commands, see reflect between-clients, peer reflect-client. Example # Set the cluster ID of the route reflector as 80. Huawei Technologies Proprietary 4-43...
{ all | peer-address [ flap-info ] } View User view Parameter peer-address: Reset connection with a specified BGP peer. all: Reset all the connections with BGP. flap-info: Reset the flap-info of a record at this peer address. Huawei Technologies Proprietary 4-44...
Using reset bgp group command, you can reset the connections between the BGP and all the members of a group. For the related commands, see peer group. Example # Reset BGP connections of all members from group1. <Quidway> reset bgp group group1 4.1.58 summary automatic Syntax summary automatic Huawei Technologies Proprietary 4-46...
Using timer command, you can configure the Keep-alive and Hold-time timer of BGP. Using undo timer command, you can restore the default value of the Keep-alive and Hold-time of the timer. Example # Configure the Keep-alive timer as 30 seconds and Hold-time timer as 90 seconds. Huawei Technologies Proprietary 4-47...
This command means BGP does not synchronize with IGP in current system. You need not configure it for S3500 Series Ethernet Switches don’t support synchronization of BGP and IGP at present. Example # Cancel the synchronization of BGP and IGP. [Quidway-bgp] undo synchronization Huawei Technologies Proprietary 4-48...
AS sequence number added in front of the original AS path. By default, no AS number is set. If the match condition of Route-policy is matched, the AS attribute of the transmitting route will be changed. Huawei Technologies Proprietary...
# Configure one Route-policy applycommunity, whose node serial number is 16 and match mode is permit, and enter Route policy view to set match conditions and attribute modification actions to be executed. [Quidway] route-policy applycommunity permit node 16 [Quidway-route-policy] if-match as-path 8 [Quidway-route-policy] apply community no-export Huawei Technologies Proprietary...
View Route policy View Parameter internal: Use the cost type of IGP as MED value of BGP to advertise route to EBGP peer. external: external cost type of IS-IS. S3500 series don’t support this parameter at present. Huawei Technologies Proprietary...
Example # Set the next hop address of route information as 193.1.1.8 when it is used for setting route information attribute. [Quidway-route-policy] apply ip next-hop 193.1.1.8 Huawei Technologies Proprietary...
Set the BGP route information source as internal route egp: Set the BGP route information source as external route as-number: Specifies AS number of external route. incomplete: Setting the BGP route information source as unknown source. Huawei Technologies Proprietary...
Example # Define one apply sub-statement. When it is used for setting route information attribute, it sets the tag area of route information as 100. [Quidway-route-policy] apply tag 100 Huawei Technologies Proprietary...
Parameter acl-number: The access control list number used for matching the destination address field of the routing information. ip-prefix ip-prefix-name: The prefix address list name. Its matching object is the destination address field of the routing information. Huawei Technologies Proprietary...
Using if-match { acl | ip-prefix } command, you can configure the IP address range to match the Route-policy. Using undo if-match { acl | ip-prefix } command, you can cancel the setting of the match rule. Huawei Technologies Proprietary 5-10...
200. Then the route-policy named test is defined. The node No.10 of this route-policy defines a if-match sub-statement, which quotes the definition of as-path. [Quidway] ip as-path-acl 2 permit 100:200 [Quidway] route-policy test permit node 10 [Quidway-route-policy] if-match as-path 2 Huawei Technologies Proprietary 5-11...
The node No.10 of the route-policy defines a if-match sub-statement, which quotes the definition of the community-list. [Quidway] ip community-list 1 permit 100:200 [Quidway] route-policy test permit node 10 [Quidway-route-policy] if-match community 1 5.1.16 if-match cost Syntax if-match cost value undo if-match cost Huawei Technologies Proprietary 5-12...
Using undo if-match interface command, you can cancel the setting of matching condition. By default, no if-match sub-statement is defined. It matches the corresponding interface of route next hop when filtering route. Huawei Technologies Proprietary 5-13...
Example # Define a if-match sub-statement. It permits the routing information, whose route next hop address passes the filtration of the prefix address list p1, to pass this if-match sub-statement. [Quidway-route-policy] if-match ip next-hop ip-prefix p1 Huawei Technologies Proprietary 5-14...
View System view Parameter ip-prefix-name: The specified address prefix list name. It identifies one address prefix list uniquely. index-number: Identify an item in the prefix address list. The item with smaller index-number will be tested first. Huawei Technologies Proprietary 5-15...
Page 344
Example # Configured one Route-policy policy1, whose node number is 10 and if-match mode is permit, and enter Route policy view. [Quidway] route-policy policy1 permit node 10 [Quidway-route-policy] Huawei Technologies Proprietary 5-17...
System Total The total number of the Ethernet switch memory in byte. Memory(bytes) Total Used The total number of the used Ethernet switch memory in byte. Memory(bytes) Used Rate The used rate of the Ethernet switch memory Huawei Technologies Proprietary...
The information displayed by this command includes the Ethernet switch memory limit, the size of the idle memory, the times of the connection disconnecting, the times of the connection reestablishment and the current state. The displayed information is described specifically in the following table: Huawei Technologies Proprietary...
By default, when the idle memory of the Ethernet switch recovers to a safety value, connections of all the routing protocols will always recover (when the idle memory of the Ethernet switch reduces to a lower limit, the connection will be disconnected forcibly). You shall use the command cautiously. Huawei Technologies Proprietary...
# Enable memory resume of the current Ethernet switch and recover connections of all the protocols automatically. [Quidway] memory auto-establish enable 6.1.5 memory { safety | limit } Syntax memory { safety safety-value | limit limit-value }* undo memory [ safety | limit ] Huawei Technologies Proprietary...
Page 349
For the related commands, see memory auto-establish disable, memory auto-establish enable and display memory limit. Example # Set the lower limit of the Ethernet switch idle memory to 1Mbytes and the safety value to 3Mbytes. [Quidway] memory safety 3 limit 1 Huawei Technologies Proprietary...
Table 1-1 Description of information generated by the command debugging gmrp event Field Description GMRP: Max number of GMRP Maximum number of entries reached for GMRP entries reached local database 1.1.2 display gmrp statistics Syntax display gmrp statistics [ interface interface-list ] Huawei Technologies Proprietary...
1.1.3 display gmrp status Syntax display gmrp status View Any view Parameter None Description Using display gmrp status command, you can view the status of global GMRP. This command can be used for displaying the enabled/disabled status of global GMRP. Huawei Technologies Proprietary...
Ethernet port view, GMRP will be enabled on a port. Before enabling GMRP on a port, you shall enable GMRP globally. For the related command, see display gmrp status, display gmrp statistics. Example # Enable GMRP globally. [Quidway] gmrp Huawei Technologies Proprietary...
# Display the IGMP Snooping configuration information of the switch. <Quidway> display igmp-snooping configuration Enable IGMP-Snooping. The router port timeout is 300 second(s). The max response timeout is 50 second(s). The member port timeout is 500 second(s). Huawei Technologies Proprietary...
IP group(s):the following ip group(s) match to one mac group. IP group address:230.45.45.1 Member port(s):Ethernet0/12 MAC group(s): MAC group address:01-00-5e-2d-2d-01 Member port(s):Ethernet0/12 We can know from the information listed above that : There is a multicast group in VLAN 2; The router port is Ethernet 0/1; Huawei Technologies Proprietary...
After waiting for a period of time, if it receives no respond, igmp-snooping then removes the port form the group. By configuring this command, igmp-snooping Huawei Technologies Proprietary...
By default, the maximum number of multicast groups permited on a port is unlimited. Example # Set the maximum number of multicast groups permited on Ethernet0/1 is 256. [Quidway-Ethernet0/1] igmp-snooping group-limit 256 2.1.7 igmp-snooping group-policy Syntax igmp-snooping group-policy acl_number vlan vlanid undo igmp-snooping group-policy vlan vlanid View Ethernet port view Huawei Technologies Proprietary...
Page 361
Most devices just broadcast unknown multicast packets, s o to prevent the case where multicast data flow is sent as unknown multicast packets to the filtered ports, this function is generally configured in combination with the unknown multicast dropping function. For the related command, see unknown-multicast drop enable. Huawei Technologies Proprietary...
2.1.8 igmp-snooping host-aging-time Syntax igmp-snooping host-aging-time seconds undo igmp-snooping host-aging-time View System view Parameter seconds: Specifies the port aging time of the multicast group member, ranging from 200 to 1000 and measured in seconds; By default, 260. Huawei Technologies Proprietary...
The set maximum response time decides the time limit for the switch to respond to IGMP Snooping general query packets. For the related command, see igmp-snooping, igmp-snooping router-aging-time. Example # Configure to respond the IGMP Snooping packet within 50s. [Quidway] igmp-snooping max-response-time 50 Huawei Technologies Proprietary...
# Set the aging time of the IGMP Snooping router port to 500 seconds. [Quidway] igmp-snooping router-aging-time 500 2.1.11 reset igmp-snooping statistics Syntax reset igmp-snooping statistics View User view Parameter None Description Using reset igmp-snooping statistics command, you can reset the IGMP Snooping statistics information. Huawei Technologies Proprietary...
Page 365
Command Manual - Multicast Quidway S3500 Series Ethernet Switches Chapter 2 IGMP Snooping Configuration Commands For the related command, see igmp-snooping. Example # Clear IGMP Snooping statistics information. <Quidway> reset igmp-snooping statistics Huawei Technologies Proprietary 2-10...
Page 368
Table 3-1 Description of information generated by the command display multicast forwarding-table Field Description Multicast Forwarding Cache Table Multicast forwarding cache table Total 2 entries Total number of entries 00002 Sequence number of entries (4.4.4.4, 224.2.149.17) (s,g) Huawei Technologies Proprietary...
Register interface of PIM-SM. Description Using display multicast routing-table command, you can view the information of IP multicast routing table. This command displays the multicast routing table information, while the display multicast forwarding-table command displays the multicast forwarding table information. Huawei Technologies Proprietary...
Page 370
Downstream interface list: Downstream interface list: has an interface Vlan-interface 2 (its IP address Vlan-interface2(2.2.2.4), Protocol is 2.2.2.4). The downstream interface is 0x1: IGMP configured with IGMP groups. Matched 3 entries 3 entries in total meeting the requirement Huawei Technologies Proprietary...
Page 372
IP multicast routing. By default, IP multicast routing is disabled. For the related commands, see pim dm and pim sm. Example # Enable IP multicast routing. <Quidway> system-view [Quidway] multicast routing-enable Huawei Technologies Proprietary...
By default, IGMP debugging functions are disabled. Example # Enable all IGMP debugging functions <Quidway> debugging igmp all 4.1.2 display igmp group Syntax display igmp group [ group-address | interface interface-type interface-number ] View Any view Huawei Technologies Proprietary...
Time passed since multicast group is discovered (hh: mm: ss). Specifies when the member will be removed from the multicast Expires group (hh: mm: ss). 4.1.3 display igmp interface Syntax display igmp interface [ interface-type interface-number ] View Any view Huawei Technologies Proprietary...
If no parameter is specified, this command displays the information of all the ports. The IGMP configuration information of all the ports will be displayed. For the related command, see igmp host-join, igmp group-policy. Huawei Technologies Proprietary...
Description Using igmp group-policy command, you can set the filter of multicast groups on an interface to control the accessing to the IP multicast groups. Using undo igmp group-policy command, you can remove the filter configured. Huawei Technologies Proprietary...
VLAN, and the IGMP protocol must be enabled on this port; otherwise, the configuration does not function. For the related command, see igmp host-join, igmp host-join vlan, igmp host-join port. Huawei Technologies Proprietary...
Example # Add port Ethernet 0/1 in VLAN-interface10 to the multicast group at 225.0.0.1. [Quidway-Vlan-interface10] igmp host-join 225.0.0.1 port Ethernet 0/1 4.1.8 igmp host-join vlan Syntax igmp host-join group-address vlan vlanid undo igmp host-join group-address vlan vlanid Huawei Technologies Proprietary...
4.1.9 igmp max-response-time Syntax igmp max-response-time seconds undo igmp max-response-time View Interface view Parameter seconds: Maximum response time in the IGMP query messages in second in the range from 1 to 25. By default, the value is 10 seconds. Huawei Technologies Proprietary...
In IGMP version 1, the selection of a query is determined by the multicast routing protocol. In IGMP version 2, the router with the lowest IP address on the shared network segment acts as the querier. For the related commands, see igmp timer query and display igmp interface. Huawei Technologies Proprietary...
For the related command, see igmp timer other-querier-present. Example # Configure to transmit the host-query message every 60 seconds via VLAN-interface2. [Quidway-Vlan-interface2] igmp timer query 60 4.1.12 igmp version Syntax igmp version { 1 | 2 } undo igmp version View Interface view Huawei Technologies Proprietary...
Page 382
All routers on a subnet must support the same version of IGMP. After detecting the presence of IGMP Version 1 system, a router cannot automatically switch to Version 1. Example # Run IGMP Version 1 on VLAN-interface10. [Quidway-Vlan-interface10] igmp version 1 Huawei Technologies Proprietary 4-10...
For the related command, see pim sm. Example # Configure the Ethernet switch as C-BSR with priority 2 (and the C-BSR address is designated as the IP address of VLAN-interface10). [Quidway] pim [Quidway-pim] c-bsr vlan-interface 10 24 2 Huawei Technologies Proprietary...
Using debugging pim sm command, you can enable PIM-SM debugging functions. Using undo debugging pim sm command, you can disable the debugging functions. By default, PIM-SM debugging functions are disabled. Example # Enable all PIM-SM debugging functions <Quidway> debugging pim sm all Huawei Technologies Proprietary...
IP address of the multicast source. incoming-interface interface-type interface-number: Route entry with the specified incoming interface. null: Specifies the incoming interface type as Null. dense-mode: Specifies the multicast routing protocol as PIM-DM. sparse-mode: Specifies the multicast routing protocol as PIM-SM. Huawei Technologies Proprietary...
Priority: 0 Uptime: 00:39:50 Expires: 00:01:40 5.1.11 pim Syntax undo pim View System view Parameter None Description Using pim command, you can enter the PIM view. Using undo pim command, you can clear the configurations in PIM view. Huawei Technologies Proprietary...
BSR domains. By default, no domain border is set. For the related command, see c-bsr. Example # Configure domain border on VLAN-interface10. [Quidway-Vlan-interface10] pim bsr-boundary 5.1.13 pim dm Syntax pim dm undo pim dm Huawei Technologies Proprietary 5-10...
PIM-SM protocol. By default, PIM-SM is disabled. Once enabled PIM-SM on an interface, PIM-DM cannot be enabled on the same interface and vice versa. Example # Enable PIM-SM on VLAN-interface10. [Quidway-Vlan-interface10] pim sm Huawei Technologies Proprietary 5-11...
Using register-policy command, you can configure a RP to filter the register messages sent by the DR in the PIM-SM network and to accept the specified messages only. Using undo register-policy command, you can remove the configured message filtering. Huawei Technologies Proprietary 5-12...
PIM leaf router switches from the RPT to the SPT. Using undo spt-switch-threshold command, you can restore the default setting. Example # Configure the threshold for switching from RPT to source SPT as 0kbps. [Quidway] pim [Quidway-pim] spt-switch-threshold 0 Huawei Technologies Proprietary 5-13...
The new configuration overwrites the old one if you run the command for a second time. For related command, see display pim rp-info. Example # Configure 10.110.0.6 as a static RP. [Quidway] multicast routing-enable [Quidway] pim [Quidway-pim] static-rp 10.110.0.6 Huawei Technologies Proprietary 5-14...
VLAN, and therefore the bandwidth is saved. Additionally, the absolute isolation between the multicast VLAN and the user VLANs guarantees the security of the network. Example # Set VLAN 2 to multicast VLAN. <Quidway> system-view [Quidway] vlan 2 [Quidway-vlan2] service-type multicast Huawei Technologies Proprietary...
# Create a multicast MAC address entry on the switch, with its multicast address as 0100-5e0a-0805, forwarding port as Ethernet 1/0/1 and it belonging to VLAN1. <Quidway> system-view System View: return to User View with Ctrl+Z. [Quidway] mac-address multicast 0100-5e0a-0805 interface Ethernet 1/0/1 vlan Huawei Technologies Proprietary...
Using acl command, you can configure a numbered or named ACL, and enter the corresponding ACL view. Using undo acl command, you can cancel all the rules of a numbered or named ACL or all the ACLs. By default, the ACLs are matched in config order. Huawei Technologies Proprietary...
Page 404
For related configurations, refer to the command rule. Example # Configure to follow depth-first order to match the rules of ACL 1. [Quidway] acl number 1 match-order auto Huawei Technologies Proprietary...
<Quidway> display acl running-packet-filter all acl std1 rule 0 running acl std1 rule 1 running The display information shows all the activated ACLs of the switch. 1.1.4 display time-range Syntax display time-range { all | name } View Any view Huawei Technologies Proprietary...
Page 407
, the last time is the ending time. # Display the time range named tm1. <Quidway> display time-range tm1 Current time is 14:37:31 4-3-2003 Thursday Time-range : tm1 ( Inactive ) from 08:30 2-5-2005 to 18:00 2-19-2005 Huawei Technologies Proprietary...
ACL will be activated. Description Using packet-filter command, you can activate the ACL. Using undo packet-filter command, you can disable the ACL. Example # Activate ACL 2000. [Quidway] packet-filter ip-group 2000 Huawei Technologies Proprietary...
Commonly, this command is used reset traffic-statistic to reset the statistics information of the traffic-statistic command. Example # Clear the statistics information of ACL 2000. <Quidway> reset acl counter 2000 Huawei Technologies Proprietary...
Name of a time range, during which a rule takes effect. Note: The following parameters are attributes carried by the data packets. The ACL rules are defined according to the values of these parameters. The parameter for define a basic ACL Huawei Technologies Proprietary...
Page 411
ICMP packet. type specifies the ICMP packet type with a number in the range of 0 to 255 or characters. code, ranging from 0 to 255, is used for icmp when ICMP packet type are not specified with characters. Huawei Technologies Proprietary...
Page 412
S3526 has some restrictions on ACL configuration in implementing QOS function using traffic classification. The restriction details are listed in the following table. Huawei Technologies Proprietary 1-10...
Page 413
} [ rule rule ] } ANY-NET. local-precedence pre-value For the ACL used in priority tag, if the destination addresses destination MAC addresses for two rules are the same, the new rule will overwrite the previous one. Huawei Technologies Proprietary 1-11...
Page 414
MAC-any stands for lay-2 ACL rule from source MAC address to any destination MAC address, such as “rule 0 permit ingress 00e0-fc01-0101 1 egress any time-range huawei”, and so do any-MAC, IP-any, any-IP, NET-any and any-NET rules. For the MAC-MAC rule, the source and destination MAC addresses must be configured in the same VLAN.
End time of the special time range, format as hh:mm. days-of-the-week: Determines in which day(s) of a week in the special time range a command takes effect. You can specify this parameter with any of the following values. Numbers (ranging from 0 to 6); Huawei Technologies Proprietary 1-13...
{ number acl-number | name acl-name | all } View System view Parameter number acl-number: Access list number, ranging from: 2000 to 2999: Basic ACL. 3000 to 3999: Advanced ACL. 4000 to 4999: L2 ACL. 5000 to 5999: User-defined ACL. Huawei Technologies Proprietary 1-14...
Page 417
An ACL is configured with multiple sub-rules. The latest S3526E and S3526C sub-rule will be matched first. For related configurations, refer to the command rule. Example # Configure to follow depth-first order to match the rules of ACL 2000. Huawei Technologies Proprietary 1-15...
<Quidway> display acl running-packet-filter all acl std1 rule 0 running acl std1 rule 1 running The display information shows all the activated ACLs of the switch. 1.2.4 display time-range Syntax display time-range { all | name } View Any view Huawei Technologies Proprietary 1-17...
Page 420
, the last time is the ending time. # Display the time range named tm1. <Quidway> display time-range tm1 Current time is 14:37:31 4-3-2003 Thursday Time-range : tm1 ( Inactive ) from 08:30 2-5-2005 to 18:00 2-19-2005 Huawei Technologies Proprietary 1-18...
English letters (that is [a to z, A to Z]), excluding space and quotation marks. rule rule: Specifies the rule in the ACL to be activated, ranging from 0 to 127. If it is not specified, all the rules in the ACL will be activated. Huawei Technologies Proprietary 1-19...
The case includes: ACL cited by route policy function, ACL used for control logon user, etc. The ACL number ranges from 2000 to 3999. Huawei Technologies Proprietary 1-20...
{ interface-name | interface-type interface-num } }* | any } ] [ time-range name ] undo rule rule-id IV. define/delete a rule for user-defined acl rule [ rule-id ] { permit | deny } { rule-string rule-mask offset }&<1-8> [ time-range name ] undo rule rule-id Huawei Technologies Proprietary 1-21...
Page 424
UDP. port1 [ port2 ]: TCP or UDP port number of packets, expressed with characters or numbers. The numbers are in the range of 0 to 65535 and refer to mnemonic symbol table for character values. Huawei Technologies Proprietary 1-22...
Page 425
32 bits (corresponding to the 0s in wildcard) of the destination MAC address. interface { interface-name | interface-type interface-num } the L2 port forwarding the packets. any represents all the packets forwarded by all the ports. The parameter of user-defined ACL Huawei Technologies Proprietary 1-23...
S3552 Series Ethernet Switches include S3552G, S3552P, S3528G, and S3528P Ethernet Switches. 1.3.1 acl Syntax acl { number acl-number | name acl-name [advanced | basic | link ] } [ match-order { config | auto } ] Huawei Technologies Proprietary 1-25...
Page 428
ACL is cited by software to filter and classify data. Due the chips installed, the hardware match order of ACL’s sub-rule is different in different switch models. The details are listed in the following table. Huawei Technologies Proprietary 1-26...
# Display the ACL running state on all the interfaces. <Quidway> display acl running-packet-filter all acl std1 rule 0 running acl std1 rule 1 running The display information shows all the activated ACLs of the switch. Huawei Technologies Proprietary 1-28...
Configures to display all the time range. name: Specifies the name of the time range. Description Using display time-range command, you can view the configuration and status of the current time range. You will see the active or inactive state outputs respectively. Huawei Technologies Proprietary 1-29...
Page 432
08:30 2-5-2005 The content of time-range: the first time is the 18:00 2-19-2005 beginning time , the last time is the ending time. Huawei Technologies Proprietary 1-30...
Destination MAC domain in the Ethernet packet header, in the length of 6 bytes. dport: Destination port domain, in the length of 2 bytes. dscp: DSCP domain in the IP packet header, in the length of 1 byte. Huawei Technologies Proprietary 1-31...
Page 434
The dscp, ip-precedence and tos fields jointly occupy one byte. One byte is occupied no matter you define one, two or three of these fields. The fragment field is 0 in length in flow template, so it can be ignored in calculating the total length of template elements. Huawei Technologies Proprietary 1-32...
ACL, only the rules including these elements defined in template can be sent to target hardware and referenced for such QoS functions as packet filtering, traffic policing, priority re-labeling. Otherwise, the rules cannot be activated on the hardware. The ACL combined mode is following. Huawei Technologies Proprietary 1-33...
Page 436
This command supports activating the Layer-2 and Layer-3 ACLs. However the actions of the ACLs should be consistent. If the actions conflict (one is permit and the other is deny), they cannot be activated. Example # Activate ACL 2000 on Ethernet0/1. [Quidway-Ethernet0/1] packet-filter ip-group 2000 Huawei Technologies Proprietary 1-34...
Commonly, this command is used to reset the statistics information of the traffic-statistic command. Example # Clear the statistics information of ACL 2000. <Quidway> reset acl counter 2000 Huawei Technologies Proprietary 1-35...
Name of a time range, during which a rule takes effect. Note: The following parameters are attributes carried by the data packets. The ACL rules are defined according to the values of these parameters. The parameter for define a basic ACL Huawei Technologies Proprietary 1-36...
Page 439
S3552 series switch does not support icmp-type type code parameters when configure ACL rules. established: Used when protocol is tcp to indicate that the rule takes effect on the first SYN packet to establish TCP connection. Huawei Technologies Proprietary 1-37...
Page 440
[Quidway-acl-adv-3000] rule 1 permit tcp established source 1.1.1.1 0 destination 2.2.2.2 0 # Add a rule to a basic ACL. [Quidway-acl-basic-2000] rule 1 permit source 1.1.1.1 0 fragment # Add a rule to an L2 ACL. [Quidway-acl-link-4000] rule 1 permit ingress 1 egress any Huawei Technologies Proprietary 1-38...
Example # Configure a time range being effective since zero hour on January 1, 2000 and forever. [Quidway] time-range test from 0:0 1-1-2000 Huawei Technologies Proprietary 1-39...
Description Using display cos-local-precedence-map command, view “COS->Local-precedence” map. Example # Display “COS->Local -precedence” map. <Quidway> display qos cos-local-precedence-map cos-local-precedence-map: cos : ------------------------------------------------------------------------- local-precedence : 2.1.2 display qos-global all Syntax display qos-global all View Any view Parameter None Huawei Technologies Proprietary...
Page 443
Priority action: Local precedence 0 traffic. Matches: acl std1 rule 1 running “Priority action: Local precedence 0” indicates the action of resetting the priority Priority action: Local precedence 0 of the packets matching the classification rule. Huawei Technologies Proprietary...
ACL of traffic to be mirrored and the observing port. For the related command, see mirrored-to. Example # Display the settings of traffic mirror. <Quidway> display qos-global mirrored-to mirrored-to Matches: acl std1 rule 0 running Mirrored to: Ethernet0/1 Huawei Technologies Proprietary...
For the related command, see traffic-priority. Example # Display the settings of traffic priority. <Quidway> display qos-global traffic-priority traffic-priority Matches: acl std1 rule 0 running Priority action: Local precedence 0 Matches: acl std1 rule 1 running Priority action: Local precedence 0 Huawei Technologies Proprietary...
For the related command, see queue-scheduler. Example # Display the queue scheduling mode and parameters. <Quidway> display qos-interface queue-scheduler Queue scheduling mode: strict-priority The display information shows the queue scheduling mode of the switch is strict-priority. Huawei Technologies Proprietary...
For the related command, see display qos-global mirrored-to. Example # Mirrors the packets matching the ACL 2000 rules, whose action is permit, to the port Ethernet0/1. [Quidway] mirrored-to ip-group 2000 interface e0/1 Huawei Technologies Proprietary...
Example # Set the priority of Ethernet0/1 port to 7. [Quidway-Ethernet0/1] priority 7 2.1.9 priority trust Syntax priority trust undo priority View Ethernet port view Parameter None Huawei Technologies Proprietary...
Specifies the mapping value of “COS 3->local-prec”, which ranges from 0 to 7. cos4-map-local-prec: Specifies the mapping value of “COS 4->local-prec”, which ranges from 0 to 7. cos5-map-local-prec: Specifies the mapping value of “COS 5->local-prec”, which ranges from 0 to 7. Huawei Technologies Proprietary...
Page 451
If needed, you can change “COS->Local-precedence” map using the command. Example # Configure “COS->Local-precedence” map. [Quidway] qos cos-local-precedence-map 0 1 2 3 4 5 6 7 After the configuration, the “COS->Local-precedence” map is shown in Table 1-6. Table 2-6 “COS->Local-precedence” map COS Value Local Precedence Huawei Technologies Proprietary 2-10...
Page 452
For WRR, the sum of all the weights should equal 100. For the related command, see display qos-interface queue-scheduler. Example # Configure to perform WRR with the weights of the four queues as 20, 20, 30 and 30 respectively. [Quidway-Ethernet0/1] queue-scheduler wrr 20 20 30 30 Huawei Technologies Proprietary 2-11...
Reset statistic information of traffic. This command is used in the case of filtering or classifying the data transmitted by the reset traffic-statistic hardware of switch. Commonly, this command is used to reset the statistics information of the traffic-statistic command. Huawei Technologies Proprietary 2-12...
For the related command, see display qos-global traffic-priority. Example # Marks the priority for the packets matching the permit rules of ACL 2000. It sets the local preference to 0: [Quidway] traffic-priority ip-group 2000 local-precedence 0 Huawei Technologies Proprietary 2-13...
For the related command, see display qos-global traffic-statistic. Note: S3526, S3026 FM, S3026 FS only support the statistics for the data matching the IP-IP or MAC-MAC rule. Example # Count the packets matching the ACL 2000 rules with action permit. Huawei Technologies Proprietary 2-14...
<Quidway> display qos cos-local-precedence-map cos-local-precedence-map: cos : ------------------------------------------------------------------------- local-precedence : 2.2.2 display qos-global all Syntax display qos-global all View Any view Parameter None Description Using display qos-global all command, you can view the settings of all the QoS parameters. Huawei Technologies Proprietary 2-15...
Page 457
Priority action: dscp ef the classification rule to the traffic. Matches: acl std1 rule 1 running “Priority action: dscp ef” indicates the action of resetting the priority of the packets matching Priority action: dscp ef the classification rule. Huawei Technologies Proprietary 2-16...
Using display qos-global mirrored-to command, you can view the settings of the traffic mirror. This command is used for displaying the settings of traffic mirror. The information displayed includes the ACL of traffic to be mirrored and the observing port. For the related command, see mirrored-to. Huawei Technologies Proprietary 2-17...
This command is used for displaying the settings of traffic priority. The information displayed includes the ACL corresponding to the traffic tagged with priority, priority type and value. For the related command, see traffic-priority. Example # Display the settings of traffic priority. Huawei Technologies Proprietary 2-18...
ACL corresponding to the traffic to be redirected, the destination port of redirection. For the related command, see traffic-redirect. Example # Display the settings of the redirection. <Quidway> display qos-global traffic-redirect traffic-redirect Matches: acl std1 rule 0 running Huawei Technologies Proprietary 2-19...
Page 461
The statistics information of traffic-statistic command includes the matched times of the transmitted data by switch. User can use display qos-global traffic-statistic command to display the statistics information. For the related command, see traffic-statistic. Example # Display the traffic statistics information. <Quidway> display qos-global traffic-statistic Huawei Technologies Proprietary 2-20...
If you set the port parameters, the configuration information about the specified port will be displayed. Example # Display the QoS settings of all the ports. <Quidway> display qos-interface all Huawei Technologies Proprietary 2-21...
| interface-type interface-num: Specifies a port of the switch. For detailed information, refer to the port command manual. Description Using display qos-interface line-rate command, you can view the settings of outgoing line rate on the port. Huawei Technologies Proprietary 2-22...
If you set the port parameters, the configuration information about the specified port will be displayed. The information displayed includes the ACL of the traffic to be limited, the limited average rate and the settings of some related policing action. For the related command, see traffic-limit. Huawei Technologies Proprietary 2-23...
The action can be “drop” or “remark-dscp”. 2.2.10 display queue-scheduler Syntax display queue-scheduler View Any view Parameter None Description Using display queue-scheduler command, you can view the queue scheduling mode and parameters. Huawei Technologies Proprietary 2-24...
Page 467
For the related command, see display qos-global mirrored-to. Example # Mirrors the packets matching the ACL 2000 rules, whose action is permit, to the port Ethernet0/1. [Quidway] mirrored-to ip-group 2000 interface e0/1 Huawei Technologies Proprietary 2-26...
Example # Set the priority of Ethernet0/1 port to 7. [Quidway-Ethernet0/1] priority 7 2.2.14 priority trust Syntax priority trust undo priority View Ethernet port view Parameter None Huawei Technologies Proprietary 2-27...
Specifies the mapping value of “COS 3->local-prec”, which ranges from 0 to 7. cos4-map-local-prec: Specifies the mapping value of “COS 4->local-prec”, which ranges from 0 to 7. cos5-map-local-prec: Specifies the mapping value of “COS 5->local-prec”, which ranges from 0 to 7. Huawei Technologies Proprietary 2-28...
Page 470
If needed, you can change “COS->Local-precedence” map using the command. Example # Configure “COS->Local-precedence” map. [Quidway] qos cos-local-precedence-map 0 1 2 3 4 5 6 7 After the configuration, the “COS->Local-precedence” map is shown in Table 1-6. Table 2-17 “COS->Local-precedence” map COS Value Local Precedence Huawei Technologies Proprietary 2-29...
Using undo queue-scheduler command, you can restore the default queue scheduler. By default, the value is strict-priority. For WRR and Delay bounded WRR, the sum of all the weights should equal 100. For the related command, see display queue-scheduler. Huawei Technologies Proprietary 2-30...
0 to 127. If you do not set this parameter, all the rules will be considered. Description Using reset traffic-statistic command, you can reset the traffic statistics information. This command is used for clearing the statistics information about all the traffic or a specified one. Huawei Technologies Proprietary 2-31...
{ acl-number | acl-name } [ rule rule ]: Specifies a basic or advanced ACL. acl-number: Specifies the ACL sequence number, ranging from 2000 to 3999. acl-name: Specifies the ACL name with a character string starting with English letters ([a-z, A-Z]) Huawei Technologies Proprietary 2-32...
Page 475
For the related command, see display qos-global traffic-priority. Example # Marks the priority for the packets matching the permit rules of ACL 2000. It sets the local preference to 0: [Quidway] traffic-priority ip-group 2000 local-precedence 0 Huawei Technologies Proprietary 2-34...
Description Using traffic-redirect command, you can activate the ACL to recognize and redirect the traffic(whose action is permit). Using undo traffic-redirect command, you can cancel the redirection. For the related command, see display qos-global traffic-redirection. Huawei Technologies Proprietary 2-35...
0 to 127. If you do not set this parameter, all the rules will be considered. Description Using traffic-statistic command, you can activate the ACL to recognize and count the traffic(whose action is permit). Using undo traffic-statistic command, you can cancel the traffic statistics. Huawei Technologies Proprietary 2-36...
Using the display mirror command, you can view port mirroring configuration, including monitored ports, monitor port and monitor direction, etc. For the related command, see mirroring-port, monitor-port. Example # Display port mirroring configuration. [Quidway] display mirror Monitor port: Ethernet0/1 Mirroring port: Ethernet0/3 inbound Ethernet0/4 outbound Huawei Technologies Proprietary 2-37...
Using the display qos-global all command, you can view all QoS configuration items. Example # Display all QoS configuration items. <Quidway> display qos-global all 2.3.6 display qos-interface all Syntax display qos-interface [ interface-name | interface-type interface-num ] all Huawei Technologies Proprietary 2-40...
For the related command, see drop-mode. Example # Display drop mode of all ports. <Quidway>display qos-interface drop-mode 2.3.8 display qos-interface queue-scheduler Syntax display qos-interface interface-name interface-type interface-num queue-scheduler Huawei Technologies Proprietary 2-41...
Page 483
For the related command, see queue-scheduler. Example # Display queue scheduling mode. <Quidway>display qos-interface queue-scheduler Ethernet0/1 Port scheduling: QID: scheduling-group weight ----------------------------------- wrr , group1 wrr , group2 Ethernet0/2 Port scheduling: QID: scheduling-group weight ----------------------------------- … Huawei Technologies Proprietary 2-42...
| interface-type interface-num: Port of the switch Description Using the display qos-interface mirrored-to command, you can view traffic mirroring configuration. For the related command, see mirrored-to. Example # Display traffic mirroring configuration. <Quidway>display qos-interface mirrored-to Huawei Technologies Proprietary 2-43...
Using the display qos-interface traffic-priority command, you can view priority re-labeling configuration, including the corresponding ACL, priority type and priority level. For the related command, see traffic-priority. Example # Display priority re-labeling configuration. <Quidway> display qos-interface traffic-priority Huawei Technologies Proprietary 2-44...
| interface-type interface-num: Port of the switch Description Using the display qos-interface traffic-statistic command, you can view traffic statistics, including the corresponding ACL and packet counts. For the related command, see traffic-statistic. Example # Display traffic statistics. <Quidway> display qos-interface traffic-statistic Huawei Technologies Proprietary 2-45...
Example # Select WRED drop mode for the port Ethernet0/1, use the threshold of WRED 0. [Quidway-Ethernet0/1] drop-mode wred 0 2.3.16 dscp Syntax dscp dscp-list : dscp-value cos-value local-precedence-value drop-precedence undo dscp [ dscp-list ] Huawei Technologies Proprietary 2-46...
802.1p priority value corresponding to Local-precedence 3, in the range of cos-value4: 802.1p priority value corresponding to Local-precedence 4, in the range of cos-value5: 802.1p priority value corresponding to Local-precedence 5, in the range of Huawei Technologies Proprietary 2-48...
The following is a configured “Local-precedence + Conform-level → 802.1p priority” mapping table. Table 2-20 “Local-precedence + Conform-level → 802.1p priority” mapping table Local-precedence 802.1p 2.3.18 mirrored-to Syntax mirrored-to inbound acl-rule { cpu | monitor-interface } undo mirrored-to inbound acl-rule Huawei Technologies Proprietary 2-49...
Page 491
Specifies the rule in the ACL to be activated, ranging from 0 to 127. If it is not specified, all the rules in the ACL will be activated. cpu: Mirrors the traffic to the CPU. monitor-interface : Mirrors data stream to the monitoring port. Huawei Technologies Proprietary 2-50...
| outbound | both: Indicates to monitor the packets of which direction. Inbound means to monitor inbound packets; outbound means to monitor outbound packets; both means to monitor packets of both directions. Huawei Technologies Proprietary 2-51...
You can only specify one monitor port. You should first remove the setting of all corresponding monitored ports before canceling the configuration of the monitor port. For the related command, see display mirror. Huawei Technologies Proprietary 2-52...
“DSCP + Conform-level → Service group” and “Local-precedence + Conform-level → 802.1p priority” mapping tables. Example # Create and enter conform-level 0 view. [Quidway] qos conform-level 0 [Quidway-conform-level-0] 2.3.24 qos cos-drop-precedence-map Syntax cos-drop-precedence-map cos0-map-drop-prec cos1-map-drop-prec cos2-map-drop-prec cos3-map-drop-prec cos4-map-drop-prec cos5-map-drop-prec cos6-map-drop-prec cos7-map-drop-prec Huawei Technologies Proprietary 2-54...
Page 496
The allocation rule is based on the packet 802.1p priority: use the 802.1p priority value as the CoS value, obtain local precedence value and drop-precedence respectively from “CoS → Local-precedence” mapping table and “CoS → Drop-precedence” mapping table. Huawei Technologies Proprietary 2-55...
CoS 5 → Local precedence mapping value, in the range of 0~7. cos6-map-local-prec: CoS 6 → Local precedence mapping value, in the range of 0~7. cos7-map-local-prec: CoS 7 → Local precedence mapping value, in the range of 0~7. Huawei Technologies Proprietary 2-56...
Page 498
“CoS → Drop-precedence” mapping table. Example # Configure “CoS → Local-precedence” mapping table. [Quidway] qos cos-local-precedence-map 0 1 2 3 4 5 6 7 The following is the configured "CoS → Local-precedence” mapping table. Huawei Technologies Proprietary 2-57...
Page 499
Minimum average queue length to trigger random yellow packet dropping, in the range of 0~65535. yellow-max-threshold: Maximum average queue length to trigger complete yellow packet dropping, in the range of 0~65535. Huawei Technologies Proprietary 2-58...
Page 501
# Set queues 0~5 in WRR algorithm, queues 0, 1 and 2 belong to group 2, with weight respectively as 20, 20 and 10; queues 3, 4 and 5 belong to group 1, with weight respectively as 20, 20 and 10. Set queues 6 and 7 in SP algorithm, the default one. Huawei Technologies Proprietary 2-60...
2.3.29 traffic-limit Syntax traffic-limit inbound acl-rule cir cbs ebs [ pir ] [ conform { { remark-cos | remark-drop-priority }* | remark-policed-service } ] [ exceed { forward | drop } ] undo traffic-limit inbound acl-rule Huawei Technologies Proprietary 2-61...
Page 503
Excess burst size, in units of byte, with the value ranging 0~10000000. pir: Peak information rate, in units of kbps, with the value ranging 8~1000000. remark-cos: Sets 802.1p priority based on conform-level and local precedence. Huawei Technologies Proprietary 2-62...
Page 504
# Initiate traffic limit on the packets match the permitted rules in ACL 4000, the detailed setting: CIR is 200 kbps; CBS is 25000 bytes; EBS is 25000bytes; drop the over-threshold packets. [Quidway-Ethernet0/1] traffic-limit inbound link-group 4000 200 25000 25000 conform remark-policed-service exceed-action drop Huawei Technologies Proprietary 2-63...
{ acl-number | acl-name }: activate the L2 ACL. acl-number: Specifies the ACL number, ranging from 4000 to 4999. acl-name: Specifies the ACL name with a character string started with English letters (that is [a to z, A to Z]), excluding space and quotation marks. Huawei Technologies Proprietary 2-64...
Page 506
"DSCP + Conform-Level → Service group mapping table. For more information about this mapping table, see the qos conform-level and dscp commands. In DSCP + conform-level to service map used by packet priority remark function, the conform-level equal 0. Huawei Technologies Proprietary 2-65...
Link ACL { acl-number | acl-name } rule rule One rule in IP ACL and ip-group { acl-number | acl-name } rule rule link-group one rule in Link ACL { acl-number | acl-name } rule rule Huawei Technologies Proprietary 2-66...
Page 508
Note: The redirection configuration is valid only when the action taken by ACLs is permit. You can use the next-hop ip-addr1 ip-addr2 parameter realizing the policy routing function. For the related command, see display qos-interface traffic-redirection. Huawei Technologies Proprietary 2-67...
You can also run traffic shaping for a specific outbound queue, i.e. all traffic in this queue, by selecting the queue queue-id parameter in the command. It is recommended to configure traffic shaping on all the traffic at the port. Huawei Technologies Proprietary 2-68...
Only one rule in IP ACL ip-group { acl-number | acl-name } rule rule All rules in Link ACL link-group { acl-number | acl-name } Only one rule in Link ACL link-group { acl-number | acl-name } rule rule Huawei Technologies Proprietary 2-69...
Page 511
If you choose traffic-limit and traffic-statistic, however, then the untrusted mode is invalid. For the related command, see display qos-interface traffic-statistic. Example # Count the packets match the permitted rules in ACL 2000. [Quidway-Ethernet0/1] traffic-statistic inbound ip-group 2000 Huawei Technologies Proprietary 2-70...
See the QoS/ACL module in Operation Manual for more information about red, yellow and green packets. Example # Create and enter WRED 0 view. [Quidway] wred 0 [Quidway-wred-0] Huawei Technologies Proprietary 2-71...
# Performs ACL control over the users that telnet to the local switch. (Suppose ACL 2020 has been defined.) [Quidway] user-interface vty 0 4 [Quidway-user-interface-vty0-4] acl 2020 inbound 3.1.2 ip http acl Syntax ip http acl acl-number undo ip http acl View System view Huawei Technologies Proprietary...
Using snmp-agent community command, you can configure the community name, and perform the ACL control over the network management user through the parameter acl acl-number. Using undo snmp-agent community command, you can cancel the configuration of community name. Huawei Technologies Proprietary...
Chapter 3 Logon user’s ACL control commands Example # Configures huawei as the community name, allows read-only access to the switch by the name, meanwhile, performs the ACL control to the network management user by ACL 2020. (Suppose ACL 2020 has been defined.) [Quidway] snmp-agent community read huawei acl 2020 3.1.4 snmp-agent group...
SNMP group. Example # Creates a new SNMP group: huawei, and perform the ACL control to the group through ACL 2021. (Suppose ACL 2021 has been defined.) [Quidway] snmp-agent group v1 huawei acl 2021 3.1.5 snmp-agent usm-user...
Page 517
SNMP group, meanwhile delete the configuration of ACL control. Example # Adds a user huawei for huaweigroup (an SNMP group), configures to authenticate with HMAC-MD5-96 and sets authentication password as hello, meanwhile perform the ACL control to the user through ACL 2020 . (Suppose ACL 2020 has been defined.)
# Display the stack information on the master switch. <stack_0.Quidway> display stacking Main device for stack. Total members:2 # Display the stack member information on the master switch. <stack_0.Quidway> display stacking members Member number: 0 Name:stack_0.Quidway Device:Quidway S3526 Huawei Technologies Proprietary...
This command can only be used to switch from the master switch to a slave switch and the user level remains the same while switching. To switch from a slave switch back to a master switch, input <quit>. Huawei Technologies Proprietary...
After a stack has been established, the slave switch will exit the stack automatically if the stack port is disconnected. Example # Establish a stack. [Quidway] stacking enable 1.1.4 stacking ip-pool Syntax stacking ip-pool from-ip-address ip-address-number [ ip-mask ] undo stacking ip-pool Huawei Technologies Proprietary...
Page 524
Otherwise, some switches cannot be added into the stack automatically. Example # Set the optional IP address range in public network for a stack. [Quidway] stacking ip-pool 129.10.1.1 5 Huawei Technologies Proprietary...
Page 527
The current device transmits NDP packet every 60 Hello Timer: 60(s) seconds. A neighbor keeps the NDP information of the current Aging Timer: 180(s) device for 180 seconds. Interface: Ethernet0/1 Port number, specify a port Status: Enabled NDP is enabled on the port Huawei Technologies Proprietary...
Ethernet port view. Using undo ndp enable command, you can disable NDP on a system in system view, or disable it on a port in Ethernet port view. Example # Enable system NDP. [Quidway] ndp enable Huawei Technologies Proprietary...
5 to 255 in units of second. By default, NDP is aged in 180 seconds. Description Using ndp timer aging command, you can configure how long a device will hold the NDP packets received from the local device. After the aging timer expires, the device Huawei Technologies Proprietary...
Key word to helps specify a port range. Description Using reset ndp statistics command, you can reset the NDP counters to clear the NDP statistics information. Example # Clear NDP statistics information. <Quidway> reset ndp statistics Huawei Technologies Proprietary...
Hops for topology collection. Timer Interval of periodic topology collection. Delay that the device forwards topology collection Hop Delay request. Port Delay Delay that the port forwards topology collection request. Last collection total time Time taken by last collection. Huawei Technologies Proprietary...
IP address and mask length of the VLAN1 on the device # Display the detailed device information collected through NTDP. <Quidway> display ntdp device-list verbose Hostname : Quidway : 00e0-fc10-0000 Platform : Quidway S3026 Version: Huawei Versatile Routing Platform Software Huawei Technologies Proprietary...
In this case, NTDP is supposed to be disabled on the uplink ports. Example # Enable NTDP on Ethernet0/1. [Quidway-Ethernet0/1] ntdp enable 2.2.4 ntdp explore Syntax ntdp explore View User view Parameter None Huawei Technologies Proprietary 2-10...
This command is only effective on the topology-collecting device. The broader collection scope requires more memory of the topology-collecting device. Example # Set a limit of 5 hops for topology collection. [Quidway] ntdp hop 5 Huawei Technologies Proprietary 2-11...
View System view Parameter time: The time that the collected device wait before forwarding the topology-collection request, ranging from 1 to 1000 milliseconds. By default, the value is 200ms. Huawei Technologies Proprietary 2-12...
To avoid network congestion resulted from collecting device’s receiving large amount of responses simultaneously, you can configure each collected device to delay response for a period of time after receiving the topology request. Then, the first port will start to forward the topology request packet. Huawei Technologies Proprietary 2-13...
Otherwise, the user has to input the password before adding the candidate. Its device password will become the administrator device password if the candidate device is added to the cluster system. Huawei Technologies Proprietary 2-14...
Quidway S3500 Series Ethernet Switches Chapter 2 HGMP V2 Configuration Commands Example # Add the candidate device, with MAC address 00E0-fc00-35e7 and super-password huawei, to the cluster, and its member number is 6. [Huawei_0.Quidway-cluster] add-member 6 mac-address 00E0-fc00-35e7 password huawei 2.3.2 administrator-address...
Page 540
# Set up a cluster automatically. [Quidway-cluster] auto-build 2.3.4 build Syntax build name undo build View Cluster view Parameter name: Cluster name with no more than 8 characters, including and only including letters, numerals, subtraction sign “-” and underline “_”. Huawei Technologies Proprietary 2-16...
Using it on an administrator device, you can rename a cluster. Using it on a candidate device, you can create a cluster. Example # Configure the current switch as the administrator device and specifies HUAWEI as the cluster name. [Quidway-cluster] build HUAWEI 2.3.5 cluster...
Using cluster switch-to command, you can switch between administrator device and member devices for convenient management. A member device in a cluster can be managed through the administrator device. The user can operate on an administrator device and switchover to a specified member Huawei Technologies Proprietary 2-18...
If the administrator device and the member device still cannot intercommunicate, the member will be deleted, however, the cluster information on the member device may not be deleted. Huawei Technologies Proprietary 2-19...
# Display information about cluster on the administrator device. <Quidway> display cluster Cluster name:"sss" Role:Administrator Handshake timer:10 sec Handshake hold-time:60 sec IP-Pool:1.1.1.1/20 No logging host configured No SNMP host configured No FTP server configured No TFTP server configured. Huawei Technologies Proprietary 2-20...
Page 545
Member state Member status Member number Number of member device Handshake timer Value of handshake timer Handshake hold-time Value of handshake hold-time Administrator device mac address MAC address of administrator device Administrator status Status of administrator device Huawei Technologies Proprietary 2-21...
This command can only be performed on the administrator device. Using member-num or verbose parameter to display detail information of a certain member or all the members Example # Display configuration information about the member devices. Huawei Technologies Proprietary 2-23...
Page 548
Member status:Cmdr Hops to administrator device:0 IP: 1.1.200.210/16 Version: Huawei Versatile Routing Platform Software VRP (tm) Software, Version 3.10 Copyright (c) 2000-2002 By HUAWEI TECH CO., LTD. Quidway S3526 3526-003 Member number: 1 Name:Huawei_1.Quidway Device:Quidway S3026 MAC Address:00e0-fc00-a01f Member status:Up...
The commands can only be executed on the administrator device, which will advertise the cluster timer value to the member devices. Example # Set the cluster holdtime as 50 seconds. [Huawei_0.Quidway-cluster] holdtime 50 Huawei Technologies Proprietary 2-26...
The commands can only be executed on a switch of non-cluster member. The IP address pool of an existing cluster cannot be modified. Example # Configure the IP address pool of a cluster. [Quidway-cluster] ip-pool 10.200.0.1 20 2.3.15 logging-host Syntax logging-host ip-address undo logging-host View Cluster view Huawei Technologies Proprietary 2-27...
Using undo port-tagged command, you can cancel VLAN check for the communication inside a cluster on the administrator device. By default, VLAN check is performed. Example # Configure VLAN check for the communication inside a cluster. [Huawei_0.Quidway-cluster] port-tagged vlan 1 Huawei Technologies Proprietary 2-28...
Example # Reset the cluster member 2. [Huawei_0.Quidway-cluster] reboot member 2 2.3.18 snmp-host Syntax snmp-host ip-address undo snmp-host View Cluster view Parameter ip-address: IP address of the SNMP host configured for the cluster. Huawei Technologies Proprietary 2-29...
Assign an IP address for TFTP server of the cluster, then the member devices can access the server via the administrator device. Example # Configure IP address for TFTP server on the administrator device. [Huawei_0.Quidway-cluster] tftp-server 1.0.0.9 Huawei Technologies Proprietary 2-30...
This command can only be executed on the administrator device, which will advertise the cluster timer value to the member devices. Example # Configure to send handshake packets once every 3 seconds. [Huawei_0.Quidway-cluster] timer 5 Huawei Technologies Proprietary 2-31...
For the related command, see instance, region-name, revision-level, vlan-mapping modulo, check region-configuration . Example # Manually activate MST region configurations. [Quidway-mst-region] active region-configuration 1.1.2 check region-configuration Syntax check region-configuration Huawei Technologies Proprietary...
Page 560
Table 1-1 the display Information Field Description Format selector Factor to selelct protocol type prescribed in MSTP Region name Region name of MST region Revision level MSTP revision level of MST region Instance Vlans Mapped VLAN mapping table of MST region Huawei Technologies Proprietary...
CIST common root, region root, internal path cost of the switch to the CIST common root, CIST root port of the switch, and whether to enable BPDU protection; Huawei Technologies Proprietary...
Page 562
Table 1-2 the display Information Field Description MSTID MST instance ID of the port Port Port number STP State STP State of the port, which can be up or down. Guard Type Guard Type of the port, which can be Huawei Technologies Proprietary...
Table 1-3 the display Information Field Description Format selector Selection factor descripted in the MSTP protocol Region name Region name of MST region Revision level MSTP revision level of MST region Instance Vlans Mapped VLAN mapping table of MST region Huawei Technologies Proprietary...
MSTP revision level, is used for determining the region to which the switch belongs. For the related command, see instance, revision-level, check region-configuration , vlan-mapping modulo, active region-configuration . Example # Set the MST region name of the switch as huawei. [Quidway-mst-region] region-name huawei 1.1.7 reset stp Syntax...
Page 566
MST region to which the switch belongs. For the related command, see instance, region-name, check region-configuration , vlan-mapping modulo and active region-configuration . Example # Set the MSTP revision level of the switch MST region to 5. [Quidway-mst-region] revision-level 5 Huawei Technologies Proprietary...
System view Parameter bridgenum: Ranges from 2 to 7 and defaults to 7. Description Using stp bridge-diameter command, you can configure the switching network diameter. Using undo stp bridge-diameter command, you can restore the default network diameter. Huawei Technologies Proprietary 1-10...
Using stp edged-port disable command, you can configure the current Ethernet port as a non-edge port. Using undo stp edged-port command, you can restore the default state, i.e., non-edge port. By default, all the switch ports are configured as non-edge port. Huawei Technologies Proprietary 1-11...
By default, the path costs of a port on different STIs take the values associated with the port speeds. For more description, refer to the table offered in the configuration guideline of the stp interface cost command. Huawei Technologies Proprietary 1-12...
MSTIs. Thus the traffic from different VLANs can run over different physical links, thereby implementing the VLAN-based load-balancing. MSTP will recalculate the port role and transit its state, upon the port priority changes. Huawei Technologies Proprietary 1-14...
(Hello time, Forward Delay and Max Age). The Hello time got in this way may not be as good as expected. You can specify the hello-time centi-senconds Huawei Technologies Proprietary 1-15...
Configure the current switch as the secondary root of the designated STI. bridge-diameter bridgenum: Specify the network diameter of the spanning tree, ranging from 2 to 7. hello-time centi-senconds: Specify the Hello Time of the spanning tree, ranging from 100 to 1000 and measured in centiseconds. Huawei Technologies Proprietary 1-16...
| interface_name } ] }&<1-10>. For detail descriptions of interface_type, interface_num and interface_name parameters, refer to the corresponding descriptions in Port Command Manual. &<1-10> means that the preceding parameters can be entered up to 10 times. Huawei Technologies Proprietary 1-17...
| interface_name } ] }&<1-10>. For detail descriptions of interface_type, interface_num and interface_name parameters, refer to the corresponding descriptions in Port Command Manual. &<1-10> means that the preceding parameters can be entered up to 10 times. enable: Configure the current port as an edge port. Huawei Technologies Proprietary 1-18...
Ethernet port list, containing multiple Ethernet ports and expressed as interface _list = { { interface_type interface_num | interface_name } [ to { interface_type interface_num | interface_name } ] }&<1-10>. For detail descriptions of interface_type, interface_num and interface_name parameters, refer to the corresponding descriptions Huawei Technologies Proprietary 1-19...
Page 578
Above 10G/s 1-200000 For the related command, see stp cost . Example # Set the path cost of Ethernet 0/3 on STI 2 to 400 in system view. [Quidway] stp interface ethernet 0/3 instance 2 cost 400 Huawei Technologies Proprietary 1-20...
For the related command, see stp port priority. Example # Set the priority of Ethernet 0/3 on STI 2 to 16 in system view. [Quidway] stp interface ethernet 0/3 instance 2 port priority 16 Huawei Technologies Proprietary 1-21...
Indicates the Ethernet port connected to a point-to-point link. force-false: Indicates the Ethernet port not connected to a point-to-point link. auto: Configure to automatically check if the link to the Ethernet port is a point-to-point link. Huawei Technologies Proprietary 1-23...
| interface_name } ] }&<1-10>. For detail descriptions of interface_type, interface_num and interface_name parameters, refer to the corresponding descriptions in Port Command Manual. &<1-10> means that the preceding parameters can be entered up to 10 times. Huawei Technologies Proprietary 1-24...
| interface_name } ] }&<1-10>. For detail descriptions of interface_type, interface_num and interface_name parameters, refer to the corresponding descriptions in Port Command Manual. &<1-10> means that the preceding parameters can be entered up to 10 times. Huawei Technologies Proprietary 1-25...
Using stp loop-protection command, you can enable loop protection function. Using undo stp loop-protection command, you can restore the restore setting. By default, the loop protection function is not enabled. Example # Enable loop protection function in Ethernet 0/1. [Quidway-Ethernet0/1] stp loop-protection Huawei Technologies Proprietary 1-26...
Hops configured on the root bridge in an MST region will be adopted by other switches in the same region. Example # Set the Max Hops of an MST region to 35. [Quidway] stp max-hops 35 1.1.29 stp mcheck Syntax stp mcheck View System view\Ethernet port view Parameter None Huawei Technologies Proprietary 1-27...
In MSTP mode, the switch ports send MSTP BPDU packets (when connected to the STP switch) and the switch provides multiple spanning tree function. For the related command, see stp mcheck, stp, stp interface, stp interface mcheck. Huawei Technologies Proprietary 1-28...
For the related command, see stp interface point-to-point. Example # Configure Ethernet 0/3 to be connected to the point-to-point link. [Quidway-Ethernet0/3] stp point-to-point force-true Huawei Technologies Proprietary 1-29...
Using the stp tc-protection enable command, you can enable the protection function from being attacked by TC-BPDU packets on the switch. Using the stp tc-protection disable command, you can disable the protection function. By default, the protection from TC-BPDU packet attack is enabled. Huawei Technologies Proprietary 1-31...
The root bridge will determine the state transition time according to the configured values, while the other switches will apply the forward delay configured on it. When configuring Hello time, Forward Delay and Max Age, please guarantee the following equations: Huawei Technologies Proprietary 1-32...
Hello Time configured on the root bridge. When configuring Hello time, Forward Delay and Max Age, remember to guarantee the following equations: 2 * (Forward Delay -1.0 seconds) >= Max Age Max Age >= 2 * (Hello Time + 1.0 seconds) Huawei Technologies Proprietary 1-33...
Max Age configured on the CIST root bridge. When you configure Hello time, Forward Delay and Max Age, ensure the following formulas equal: 2 * (Forward Delay -1.0 seconds) >= Max Age Max Age >= 2 * (Hello Time + 1.0 seconds) Huawei Technologies Proprietary 1-34...
Hello Time via every port can be limited and MSTP will not occupy too many bandwidth resources when the network topology flaps. For the related command, see stp interface transit-limit. Example # Set a limit of 5 to the packets transmitted via Ethernet 0/1. [Quidway-Ethernet0/1] stp transit-limit 5 Huawei Technologies Proprietary 1-35...
1 maps to MSTI 1, vlan 2 maps to MSTI2 ...vlan 16 maps to MSTI16, vlan 17 maps to MSTI 1, and so on.) For the related command, see region-name, revision-level, display configuration, active configuration, . Example # Map VLAN to STI modulo 16. [Quidway-mst-region] vlan-mapping modulo 16 Huawei Technologies Proprietary 1-36...
BPDUs and insert corresponding configuration digests in its BPDUs destined for these switches, through which switches of different type are capable of communicating with each other in a MSTP domain. Huawei Technologies Proprietary...
Page 597
To change domain configuration, be sure to disable digest snooping first to prevent broadcast storm. Example # Enable digest snooping on GigabitEthernet1/0/1 interface. <Quidway> system-view System View: return to User View with Ctrl+Z. [Quidway] interface GigabitEthernet1/0/1 [Quidway-GigabitEthernet1/0/1] stp config-digest-snooping [Quidway-GigabitEthernet1/0/1] quit [Quidway] stp config-digest-snooping Huawei Technologies Proprietary...
The output information of this command can help the user to verify the current 802.1x configurations so as to troubleshoot 802.1x . For the related commands, see reset dot1x statistics, dot1x, dot1x retry, dot1x max-user, dot1x port-control, dot1x port-method, dot1x timer. Huawei Technologies Proprietary...
Authenticate Mode is auto Port Control Type is Mac-based ReAuthenticate is disabled Max on-line user number is 256 … (Omitted) 1.1.2 dot1x Syntax dot1x [ interface interface-list ] undo dot1x [ interface interface-list ] View System view/Ethernet port view Huawei Technologies Proprietary...
[Quidway] dot1x interface Ethernet 0/1 # Enable the 802.1x globally. [Quidway] dot1x 1.1.3 dot1x authentication-method Syntax For S3552G, S3552P, S3528G, S3528P, S3526E, S3526E FM, S3526E FS and S3526C: dot1x authentication-method { chap | pap | eap } undo dot1x authentication-method Huawei Technologies Proprietary...
Page 605
However, the S3526, S3526 FM, and S3526 FS switches support EAP-MD5 authentication only. Please note: To realize PAP, CHAP or EAP authentication, RADIUS server should support PAP, CHAP or EAP authentication respectively. For the related command, see display dot1x. Huawei Technologies Proprietary...
# Disable the switch to trigger the authentication over the users who configure static IP addresses in DHCP environment. [Quidway] dot1x dhcp-launch 1.1.5 dot1x guest-vlan Syntax dot1x guest-vlan vlan-id [ interface interface-list ] undo dot1x guest-vlan vlan-id [ interface interface-list ] View System view/Ethernet port view Huawei Technologies Proprietary...
# Configure the interface Ethernet 0/1 to hold no more than 32 users. [Quidway] dot1x max-user 32 interface Ethernet 0/1 1.1.7 dot1x port-control Syntax dot1x port-control { auto | authorized-force | unauthorized-force } [ interface interface-list ] undo dot1x port-control [ interface interface-list ] View System view/Ethernet port view Huawei Technologies Proprietary...
Page 609
Ethernet port view and it has effect only on the current interface. For the related commands, see display dot1x. Example # Configure the interface Ethernet 0/1 to be in unauthorized-force state. [Quidway] dot1x port-control unauthorized-force interface Ethernet 0/1 Huawei Technologies Proprietary...
It has effect on all the interfaces when no interface is specified. The parameter interface-list cannot be input when the command is executed in Ethernet Port view and it has effect only on the current interface. For the related commands, see display dot1x. Huawei Technologies Proprietary...
Syntax dot1x retry max-retry-value undo dot1x retry View System view Parameter max-retry-value: Specifies the maximum times an Ethernet switch can retransmit the authentication request frame to the supplicant, ranging from 1 to 10. By default, the Huawei Technologies Proprietary 1-11...
After sending client version request frame for the first time, if the switch receives no response from the client response within a certain period of time (set by the version Huawei Technologies Proprietary 1-12...
Using dot1x supp-proxy-check command, you can configure the control method for 802.1x access users via proxy logon the specified interface. Using undo dot1x supp-proxy-check command, you can cancel the control method set for the 802.1x access users via proxy. Huawei Technologies Proprietary 1-13...
Chapter 1 802.1x Configuration Commands Note that when performing this function, the user logging on via proxy need to run Huawei 802.1x client program,( Huawei 802.1x client program version V1.29 or above is needed). This command is used to set on the specified interface when executed in system view.
Page 616
86400, in seconds. By default, the value is 3600. ver-period: Client version request timeout timer. If the supplicant device failed to send the version response packet within the time set by this timer, then the authenticator device will resend the version request packet. Huawei Technologies Proprietary 1-15...
In system view, if the interface-list parameter is not specified, it means that to enable the 802.1x client version authentication feature on all interfaces; if the interface-list parameter is specified, it means that to enable the feature on the specified interfaces. In Huawei Technologies Proprietary 1-16...
If the port type and port number are specified, the 802.1x statistics on the specified port will be cleared. For the related commands, see display dot1x. Example # Clear the 802.1x statistics on Ethernet 0/1. <Quidway> reset dot1x statistics interface Ethernet 0/1 Huawei Technologies Proprietary 1-17...
Enables Portal server debugging. tcp-cheat: Enables TCP spoofing debugging. Description Use the debugging portal command to enable Portal debugging. Use the undo debugging portal command to disable Portal debugging. Example # Enable all Portal debugging. <Quidway> debugging portal all Huawei Technologies Proprietary...
# Display Portal information. <Quidway> display portal This operation may take few minutes ,please wait Run Method: Direct Free IP: 1)IP = 192.168.0.200 Net Mask = 255.255.255.255 Authenticate network: 1)IP = 1.1.1.1 Net Mask = 255.255.0.0 VLAN = 3 Huawei Technologies Proprietary...
Page 621
Note: URL = uniform resource locator HTTP = hypertext transfer protocol ARP = address resolution protocol MAC = media access control # Display Portal ACM statistics. <Quidway> display portal acm statistics ACM Statistics Running State Statistics WAIT_MAC_ACK Huawei Technologies Proprietary...
Page 622
Timeout waiting for authentication acknowledgement WAIT_LOGIN_ACK Timeout waiting for login acknowledgement Timeout waiting for ACL update. For re-DHCP WAIT_ACL_ACK authentication, it is 0. Timeout waiting for NEW IP. For direct authentication WAIT_NEW_IP and Layer 3 Portal authentication, it is 0. Huawei Technologies Proprietary...
New IP timer timeout count. For Direct authentication PT_MSG_TMR_NIP and Layer 3 Portal authentication, it is 0. Error/RCV Error information statistics, including memory errors, ERR/SND MSG ERR received and sent error messages Note: ACL = access control list 2.1.3 portal Syntax portal server-name Huawei Technologies Proprietary...
Maximum number of retries for ARP handshaking, in the range of 3 to 10. By default, it is 5. Description Use the portal arp-handshake command to configure time interval and maximum times of retries for ARP handshaking between a Portal switch and a host. Huawei Technologies Proprietary...
Use the undo portal auth-network command to remove the configuration. By default, no authentication network segments are configured. This command is only valid for Layer 3 Portal authentication. Example # Configure Portal authentication network segment 192.168.0.200/16. [Quidway] portal auth-network 192.168.0.200 255.255.0.0 vlan 1 Huawei Technologies Proprietary...
Internet service provider (ISP) as a free IP address. All users can access these free IP addresses without restriction. You can configure up to 8 free IP addresses for the system. The Portal server uses automatically a free IP address. Huawei Technologies Proprietary...
These devices can access all networks without authentication. Authentication-free user information contains the IP address, MAC address, connected switch port, and VLAN. The user whose information matches all the authentication-free user information is allowed to access the Internet without authentication. Huawei Technologies Proprietary...
Use the portal method command to specify authentication mode for Portal. Use the undo portal method command to restore the default authentication mode. By default, direct authentication is selected. Example # Set Portal authentication to redhcp. Huawei Technologies Proprietary 2-10...
Shared key for communication with Portal server, in the range of 1 to 16 characters. By default, it is huawei. port: Port from which packets are sent to Portal server, in the range of 1 to 65,534. By default, it is 50100.
An uplink refers to the port by which a switch connects to an uplink network device. Example # Configure the uplink port with Portal rate limitation as ethernet 0/1. [Quidway] portal upload interface ethernet 0/1 Huawei Technologies Proprietary 2-12...
Clears Portal ACM statistics, that is, clear the information about authentication, connection and management. server: Clears Portal server statistics. tcp-cheat: Clears TCP spoofing statistics. Description Use the reset portal command to clear Portal statistics. Example # Clear Portal ACM statistics. <Quidway> reset portal acm statistics Huawei Technologies Proprietary 2-13...
ISP domain. The supplicants may contend for the network resources. So setting a suitable limit to the amount will guarantee the reliable performance for the existing supplicants. Example # Set a limit of 500 supplicants for the ISP domain named huawei163.net. [Quidway-isp-huawei163.net] access-limit enable 500 Huawei Technologies Proprietary...
It should be noted that the argument nas-ip must be defined for a user bound with a remote port, which is unnecessary, however, in the event of a user bound with a local port. For the related command, see display local-user. Huawei Technologies Proprietary...
: Configures to cut the connection according to user name . user-name is the argument specifying the username. It is a character string not exceeding 80 characters, excluding “/”, “:”, “*”, “?”, “<” and “>”. The @ character can Huawei Technologies Proprietary...
Configures to display the user specified with IP address. The argument ip-address is in the hexadecimal format (ip-address). vlan vlanid: Configures to display the user specified with VLAN ID. Here, vlanid ranges from 1 to 4094. Huawei Technologies Proprietary...
The output information can help with ISP domain diagnosis and troubleshooting. Note that the accounting scheme to be displayed should have been created. Huawei Technologies Proprietary...
Ethernet accessing users, 802.1x supplicants for example. ssh means that: the specified user type is SSH. (S3526, S3526 FM and S3526 FS switches don’t support SSH.) Huawei Technologies Proprietary...
Table 3-1 Output description of the display local-user command Field Description State The state of the user Idle-Cut The state of the idle-cut switch Access-Limit The limit to the number of access users. Bind location Indicates whether the port is bound with or not Huawei Technologies Proprietary...
Page 639
ISP domains. Because the attributes of ISP users, such as username and password structures, service types, may be different, it is necessary to separate them by setting ISP domains. In ISP domain view, you can configure a Huawei Technologies Proprietary...
Page 640
The user template of the switch you are using may only provide user idle-cut settings. After a user is authenticated, if Huawei Technologies Proprietary...
Using local-user command, you can configure a local user and enter the local user view. Using undo local-user command, you can cancel a specified local user. By default, no local user. For the related commands, see display local-user , service-type. Huawei Technologies Proprietary 3-10...
For the related commands, see display local-user , password. Example # Force all the accessing users to display passwords in cipher text. [Quidway] local-user password-display-mode cipher-force 3.1.11 messenger Syntax messenger time { enable limit interval | disable } undo messenger time Huawei Technologies Proprietary 3-11...
# Configure to start the sending of alert messages when the user’s remaining online time is 30 minutes and send the messages at an interval of five minutes. [Quidway-isp-system] messenger time enable 30 5 3.1.12 name Syntax name string undo name Huawei Technologies Proprietary 3-12...
If local-user password-display-mode cipher-force has been adopted, the user efforts of using the password command to set the password display mode to simple text (simple) will render useless. For the related command, see display local-user. Huawei Technologies Proprietary 3-13...
The specified RADIUS server group shall have been created. For the related commands, see radius scheme, display radius. Example ! The following example designates the current ISP domain, huawei163.net, to use the RADIUS server, huawei. [Quidway-isp-huawei163.net] radius-scheme Huawei 3.1.15 self-service-url Syntax...
# In the default ISP domain "system", configure the URL address of the page used to change user password self-service server http://10.153.89.94/selfservice/modPasswd1x.jsp|userName. [Quidway] domain system [Quidway-isp-system] self-service-url enable http://10.153.89.94/selfservice/modPasswd1x.jsp|userName 3.1.16 service-type Syntax For S3552G, S3552P, S3528G, S3528P, S3526E, S3526E FM, S3526E FS and S3526C: Huawei Technologies Proprietary 3-15...
Using undo service-type command, you can cancel the specified service type for the user. Example # Set to provide the lan-access service for the user huawei1. [Quidway-luser-huawei1] service-type lan-access 3.1.17 state Syntax state { active | block } View ISP domain view/Local user view Huawei Technologies Proprietary 3-16...
# Set the user huawei1 to be in the block state. [Quidway-luser-huawei1] state block 3.1.18 vlan-assignment-mode Syntax vlan-assignment-mode { integer | string } View ISP domain view Parameter integer: Specify the dynamic VLAN delivery mode as integer. string: Specify the dynamic VLAN delivery mode as string. Huawei Technologies Proprietary 3-17...
Maximum number for sending Accounting-On packets. It ranges from 1 to 256 and defaults to 15. Interval: Time interval for sending Accounting-On packets. It ranges from 1 to 30 in seconds and defaults to 3. Huawei Technologies Proprietary 3-18...
Page 650
VLAN interface as NAS-IP. Among S3500 series ethernet switches, S3552G, S3552P, S3528G, S3528P, S3526E, S3526E FM, S3526E FS and S3526C support this function, and S3526, S3526 FM and S3526 FS don’t. Example # Enable user reauthentication at reboot. Huawei Technologies Proprietary 3-19...
By default, the data unit is byte and the data packet unit is one-packet. For the related command, see display radius. Example # Set the unit of data flow that send to RADIUS Server Huawei is kilo-byte and the data packet unit is kilo-packet. [Quidway-radius-huawei] data-flow-format data kilo-byte packet kilo-packet 3.2.4 display local-server statistics...
For the related command, see radius scheme. Example # Display the configuration information of all the RADIUS schemes. <Quidway> display radius ------------------------------------------------------------------ SchemeName =system Index=0 Type=huawei Primary Auth IP =127.0.0.1 Port=1645 State=block Primary Acct IP =127.0.0.1 Port=1646 State=block Huawei Technologies Proprietary 3-22...
Page 654
Port=1812 State=block Second Acct IP =0.0.0.0 Port=1813 State=block Auth Server Encryption Key= huawei Acct Server Encryption Key= huawei Accounting method = required Accounting method = required TimeOutValue(in second)=3 RetryTimes=3 RealtimeACCT(in minute)=12 Permitted send realtime PKT failed counts Quiet-interval(min) Retry sending times of noresponse acct-stop-PKT =500...
Page 655
The time is expressed in the format hh:mm:ss-yyyy/mm/dd. When this parameter is specified, all the stopping accounting requests saved in the time range since start-time to stop-time will be displayed. Huawei Technologies Proprietary 3-24...
Configures to set/delete the encryption key for RADIUS accounting packet. authentication: Configures to set/delete the encryption key for RADIUS authentication/authorization packet. string: Specifies the key with a character string not exceeding 16 characters. By default, the key is “huawei”. Huawei Technologies Proprietary 3-25...
Page 657
Example 1: # Set the authentication/authorization key of the RADIUS scheme, huawei, to “hello”. [Quidway-radius-huawei] key authentication hello Example 2: # Set the accounting packet key of the RADIUS scheme, huawei, to “ok”. [Quidway-radius-huawei] key accounting ok 3.2.9 local-server Syntax...
RADIUS function, i.e. realize basic RADIUS function on the switch. Caution: When using local RADIUS server function of Huawei, remember the number of UDP port used for authentication is 1645 and that for accounting is 1646. The password configured by this command must be the same as that of the RADIUS authentication/authorization packet configured by the command key authentication in RADIUS scheme view.
0.0.0.0, and the UDP port number of this server is 1813; as for the "system" RADIUS scheme created by the system, the IP address of the primary accounting server is 127.0.0.1, and the UDP port number is 1646. Huawei Technologies Proprietary 3-28...
For the related commands, see key, radius scheme, state. Example # Set the IP address of the primary accounting server of RADIUS scheme, “huawei”, to 10.110.1.2 and the UDP port 1813 to provide RADIUS accounting service. [Quidway-radius-huawei] primary accounting 10.110.1.2 1813 3.2.12 primary authentication...
For the related commands, see key, radius scheme , state. Example # Set the IP address of the primary authentication/authorization server of RADIUS scheme, “huawei”, to 10.110.1.1 and the UDP port 1812 to provide RADIUS authentication/authorization service. [Quidway-radius-huawei] primary authentication 10.110.1.1 1812 3.2.13 radius nas-ip...
Configures to delete the stopping accounting requests from the buffer according to the saving time. Start-time specifies the start time of the saving time range and stop-time specifies the stop time of the saving time range. The Huawei Technologies Proprietary 3-32...
<Quidway> reset stop-accounting-buffer time-range 0:0:0-2002/08/31 23:59:59-2002/08/31 3.2.17 retry Syntax retry retry-times undo retry View RADIUS scheme view Parameter retry-times: Specifies the maximum times of retransmission, ranging from 1 to 20. By default, the value is 3. Huawei Technologies Proprietary 3-33...
For the related command, see radius scheme. Example # Set to retransmit the RADIUS request packet no more than 5 times for the RADIUS scheme huawei. [Quidway-radius-huawei] retry 5 3.2.18 retry realtime-accounting Syntax retry realtime-accounting retry-times undo retry realtime-accounting...
For the related command, see radius scheme Example # Allow the real-time accounting request failing to be responded for up to 10 times. [Quidway-radius-huawei] retry realtime-accounting 10 3.2.19 retry stop-accounting Syntax retry stop-accounting retry-times...
For the related commands, see key, radius scheme, state. Example # Set the IP address of the second accounting server of RADIUS scheme, huawei, to 10.110.1.1 and the UDP port 1813 to provide RADIUS accounting service. [Quidway-radius-huawei] secondary accounting 10.110.1.1 1813 3.2.21 secondary authentication...
RADIUS scheme view Parameter huawei: Configures the switch system to support the RADIUS server of Huawei type, which requires the RADIUS client end (switch system) and RADIUS server to interact according to the private RADIUS protocol regulation and packet format of Huawei Technologies Co., Ltd.
Quidway Series Ethernet Switches support standard RADIUS protocol and the extended RADIUS service platform developed by Huawei Technologies. For the related command, see radius scheme. Example # Set RADIUS server type of RADIUS scheme, “huawei” to huawei. [Quidway-radius-huawei] server-type huawei 3.2.23 state Syntax...
For the related commands, see radius scheme, primary authentication, secondary authentication, primary accounting, secondary accounting. Example # Set the second authentication server of RADIUS scheme, “huawei”, to be active. [Quidway-radius-huawei] state secondary authentication active 3.2.24 stop-accounting-buffer enable Syntax...
For the related commands, see reset stop-accounting-buffer, radius scheme, display stop-accounting-buffer. Example # Indicate that, for the RADIUS scheme “Huawei”, the switch will save the stopping accounting request packets in the buffer [Quidway-radius-huawei] stop-accounting-buffer enable 3.2.25 timer...
S3526E FM, S3526E FS and S3526C support this function, and S3526, S3526 FM and S3526 FS don’t. Example # Set the quiet time interval of the RADIUS server group “huawei” to 3 minutes. [Quidway] radius scheme huawei [Quidway-radius-huawei] timer quiet 3 3.2.27 timer realtime-accounting...
500 to 999 ≥1000 ≥15 For the related commands, see retry realtime-accounting , radius scheme. Example # Set the real-time accounting interval of RADIUS scheme, “huawei”, to 15 minutes. [Quidway-radius-huawei] timer realtime-accounting 15 3.2.28 user-name-format Syntax user-name-format { with-domain | without-domain }...
Page 674
(excluding their respective domain names.) For the related command, see radius scheme. Example # Specify to send the username without domain name to RADIUS server. [Quidway-radius-huawei] user-name-format without-domain Huawei Technologies Proprietary 3-43...
RADIUS scheme. The switch only responds to packets from the authentication server and security policy server after the user gets online. Example # Configure the security policy server with IP address 192.168.0.1. <Quidway>system-view System View: return to User View with Ctrl+Z. [Quidway] radius scheme Quidway Huawei Technologies Proprietary...
# Display HABP debugging state. [Quidway] display debugging habp HABP Debugging switch is on 5.1.2 display habp Syntax display habp View Any view Parameter None Description Using the display habp command, you can view configuration information and state of HABP attribute. Huawei Technologies Proprietary...
Using the display habp table command, you can view HABP MAC address table. Example # Display HABP MAC address table. [Quidway] display habp table Holdtime Receive Port 001f-3c00-0030 Ethernet0/1 5.1.4 display habp traffic Syntax display habp traffic Huawei Technologies Proprietary...
802.1x authentication is skipped, packets will be filtered by 802.1x attribute, so the management over them is also impossible. When 802.1x attribute are enabled, HABP attribute should be enabled meanwhile. Example # Enable HABP attribute at a switch. Huawei Technologies Proprietary...
[Quidway] habp server vlan 2 5.1.7 habp timer Syntax habp timer interval undo habp timer View System view Parameter interval: Time interval to send HABP request packets, in range of 5~600 seconds. By default, the time interval is 20 seconds. Huawei Technologies Proprietary...
Page 681
The command is only available on the switch whose HABP mode is set as server. Example # Define the time interval to send HABP request packets as 50 seconds. [Quidway] habp timer 50 Huawei Technologies Proprietary...
# Display the record of the IP packets that the switch CPU receives during this detection interval.. [Quidway] display system-guard ip-record SrcIP[00]: DstIP[00]: RxPortNum: SrcIP[01]: DstIP[01]: RxPortNum: SrcIP[02]: DstIP[02]: RxPortNum: SrcIP[03]: DstIP[03]: RxPortNum: SrcIP[04]: DstIP[04]: RxPortNum: … (Omitted) Huawei Technologies Proprietary...
Disable dest IP addr learning from all ip addr in the list Table 6-2 Description of information generated by the command display system-guard state Field Description Ip-Attack threshold The max number of the learned IP addresses Deny threshold Threshold of consecutive detection time Huawei Technologies Proprietary...
For S3526E, S3526E FM, S3526E FS and S3526C: If the packets from the host with the source IP address needs to be handled by the switch CPU, the switch reduces the priority of the packets and drops the packets that has been sent to the CPU. Huawei Technologies Proprietary...
By default, the max detection count of affected hosts is 30. Example # Set the max detection count of affected hosts to 50. [Quidway] system-guard detect-maxnum 50 Huawei Technologies Proprietary...
IP address exceed 50 for consecutive 3 times. Example # Set the IP-record-threshold, record-times-threshold, isolate-time of system-guard function to 50, 3, 5 [Quidway] system-guard detect-threshold 50 3 5 6.1.6 system-guard no-learn-dip enable Syntax system-guard no-learn-dip enable undo system-guard no-learn-dip enable Huawei Technologies Proprietary...
Page 687
IP address in the response, thus preventing the hosts from the virus attacks of destination address scanning. This command is only effective to the S3526, S3526 FM and S3526 FS. Example # Enable the switch not to learn the destination IP address in the packets. [Quidway] system-guard no-learn-dip enable Huawei Technologies Proprietary...
Vlan-interface1 | Virtual Router 1 : INITIALIZE --> MASTER Table 1-1 Description of information generated by the command display vrrp Field Description Vlan-Interface1 Interface in which virtual router resides Virtual Router1 VRID of virtual router INITIALIZE Initial state MASTER New state Huawei Technologies Proprietary...
Master IP : 0.0.0.0 Table 1-2 Description of information generated by the command display vrrp Field Description Run Method Run method: real or virtual MAC method Virtual IP ping Whether to enable to ping through virtual IP Huawei Technologies Proprietary...
Indicates to perform simple character authentication. md5: Indicates to perform the AH authentication with MD5 algorithm. key: Authentication key. When simple authentication is configured, the key cannot exceed 8 characters. When md5 authentication is configured, the key cannot exceed 8 characters. Huawei Technologies Proprietary...
When the authentication type and key are set, the upper/lower cases are not necessary to be matched. Example # Specify the authentication type and key for a VRRP virtual router. [Quidway-vlan-interface2] vrrp authentication-mode simple huawei 1.1.4 vrrp method Syntax vrrp method { real-mac | virtual-mac }...
You can only use the commands before configuring the backup group. Example # Enable the function to ping the virtual IP address of the backup group. [Quidway] vrrp ping-enable 1.1.6 vrrp vrid preempt-mode Syntax vrrp vrid virtual-router-ID preempt-mode [ timer delay delay-value ] Huawei Technologies Proprietary...
View VLAN interface view. Parameter virtual-router-ID: VRRP virtual router ID, ranging from 1 to 255. priority: Priority value, ranging from 1 to 254; By default, the priority value is 100. Huawei Technologies Proprietary...
You are supposed to set the identical timer value for the switches in the same virtual router to avoid improper configuration. Example # Configure the Master to transmit VRRP packets every 15 seconds. [Quidway-vlan-interface2] vrrp vrid 1 timer advertise 15 Huawei Technologies Proprietary...
Using cd command, you can change the current user configuration path on the Ethernet Switch. Example # Change the current working directory of the switch to flash. <Quidway>cd flash: <Quidway>pwd flash: 1.1.2 copy Syntax copy fileurl-source fileurl-dest View User view Parameter fileurl-source: Source file name. fileurl-dest: Destination file name. Huawei Technologies Proprietary...
However they will be displayed, using the dir /all command. The files deleted by the delete command can be recovered with the undelete command or deleted permanently from the recycle bin, using the reset recycle-bin command. Huawei Technologies Proprietary...
Page 707
Directory of flash:/test/ -rwxrwxrwx 1 noone nogroup Sep 20 2003 14:28:52 test.txt 7932928 bytes total (4966400 bytes free) # Display all files with the names starting with "t" in the directory flash:/test/ <Quidway> dir flash:/test/t* Directory of flash:/test/ Huawei Technologies Proprietary...
If the prompt mode is set as quiet, that is, no prompt for file operations, some non-recoverable operations may lead to system damage. Example # Configure the prompt mode of file operation as quiet. [Quidway] file prompt quiet Huawei Technologies Proprietary...
Description Using mkdir command, you can create directory in the specified directory on the storage device. The directory to be created cannot have the same name as that of other directory or file in the specified directory. Huawei Technologies Proprietary...
Other users can share the project (.dsp) file, but they should export the makefiles locally. 1.1.9 move Syntax move fileurl-source fileurl-dest View User view Parameter fileurl-source: Source file name. Huawei Technologies Proprietary...
Page 711
Sep 20 2003 14:27:58 test -rwxrwxrwx 1 noone nogroup Sep 20 2003 14:41:44 sample.txt 7932928 bytes total (4963328 bytes free) <Quidway> dir flash:/test/ Directory of flash:/test/ drwxrwxrwx 1 noone nogroup Sep 20 2003 14:36:11 7932928 bytes total (4963328 bytes free) Huawei Technologies Proprietary...
If the destination file name is the same as an existing directory name, operation fails. If the destination file name is the same as an existing file name, prompt whether to overwrite. Example # Display the current directory information. <Quidway> dir Huawei Technologies Proprietary...
Name of the file to be deleted. Description Using reset recycle-bin command, you can permanently delete files from the recycle bin. The delete command only puts the file into the recycle bin, but reset recycle-bin command will delete this file permanently. Huawei Technologies Proprietary...
Parameter directory: Directory name. Description Using rmdir command, you can cancel a directory. The directory to be deleted must be empty. Example # Delete the directory huawei. <Quidway> rmdir huawei Rmdir huawei?[Y/N]:y % Removed directory huawei 1.1.14 undelete Syntax undelete file-url...
This will delete the configuration in the flash memory. The switch configurations will be erased to reconfigure. Are you sure?[Y/N] 1.2.2 save Syntax save View User view Parameter None Description Using save command, you can save the current configuration files to Flash memory. Huawei Technologies Proprietary 1-12...
Server. You can perform this command to verify the configuration after setting FTP parameters. Example # Display the configuration of FTP Server parameters. <Quidway> display ftp-server FTP server is running Max user number User count Timeout value(in minute) Huawei Technologies Proprietary 1-13...
Using undo ftp server command, you can close FTP Server and disable FTP user logon. By default, FTP Server is shut down. Perform this command to easily start or shut down FTP Server, preventing Ethernet Switch from being attacked by some unknown user. Huawei Technologies Proprietary 1-14...
Specifies to display passwords in cipher text. password: Defines a password, which is a character string of up to 16 characters if it is in simple text and of up to 24 characters if it is in cipher text. Huawei Technologies Proprietary 1-16...
Using service-type command, you can configure a service type for a particular user. Using undo service-type command, you can cancel the specified service type for the user. Example # Set to provide the lan-access service for the user huawei1. Huawei Technologies Proprietary 1-17...
# Configure to transmit data in the ASCII mode. [ftp] ascii 200 Type set to A. 1.4.2 binary Syntax binary View FTP Client view Parameter None Description Using binary command, you can configure file transmission type as binary mode. Huawei Technologies Proprietary 1-18...
Using cd command, you can change the working path on the remote FTP Server. This command is used to access another directory on FTP Server. Note that the user can only access the directories authorized by the FTP server. Huawei Technologies Proprietary 1-19...
Using close command, user can disconnect FTP client side from FTP server side without exiting FTP client side view. That is to say, you can terminate the control connection and data connection with the remote FTP Server at the same time. Related command: open. Huawei Technologies Proprietary 1-20...
View FTP Client view Parameter remotefile: File name. Description Using delete command, you can cancel the specified file. This command is used to delete a file. Example # Delete the file temp.c [ftp] delete temp.c Huawei Technologies Proprietary 1-21...
FTP client side view. This command terminates the control connection and data connection with the remote FTP Server at the same time. Example # Terminate connection with the remote FTP Server and stays in FTP Client view. [ftp] disconnect Huawei Technologies Proprietary 1-22...
Using get command, you can download a remote file and save it locally. If no local file name is specified, it will be considered the same as that on the remote FTP Server. Example # Download the file temp1.c and saves it as temp.c [ftp] get temp1.c temp.c Huawei Technologies Proprietary 1-23...
Remote file to be queried. localfile: Saved local file name. Description Using ls command, you can query a specified file. If no parameter is specified, all the files will be shown. Example # Query file temp.c [ftp] ls temp.c Huawei Technologies Proprietary 1-24...
Using open command, you can establish control connection with the remote FTP Server in the FTP Client view. Related command: close. Example # Establish control connection with the FTP Server, which IP address is 1.1.1.1. [ftp] open 1.1.1.1 Trying ... Huawei Technologies Proprietary 1-25...
By default, the data transmission mode is passive mode Example # Set the data transmission to passive mode. [ftp] passive 1.4.18 put Syntax put localfile [ remotefile ] View FTP Client view Parameter localfile: Local file name. Huawei Technologies Proprietary 1-26...
Using pwd command, you can view the current directory on the remote FTP Server. Example # Show the current directory on the remote FTP Server. [ftp] pwd "flash:/temp" is current directory. 1.4.20 quit Syntax quit View FTP Client view Parameter None Huawei Technologies Proprietary 1-27...
Example # Show the syntax of the protocol command user. [ftp] remotehelp user 214 Syntax: USER <sp> <username> 1.4.22 rmdir Syntax rmdir pathname View FTP Client view Parameter pathname: Directory name of remote FTP Server. Huawei Technologies Proprietary 1-28...
# Log in the FTP Server with username tom and password bjhw. [ftp] user tom bjhw 1.4.24 verbose Syntax verbose undo verbose View FTP Client view Parameter None Description Using verbose command, you can enable verbose. Using undo verbose command, you can disable verbose. Huawei Technologies Proprietary 1-29...
For the related commands, see tftp get, tftp put. Example # Transmit the files in text format. [Quidway] tftp ascii 1.5.2 tftp get Syntax tftp get //A.A.A.A/xxx.yyy mmm.nnn View System view Huawei Technologies Proprietary 1-30...
TFTP server (at A.A.A.A) and saving it as mmm.nnn. For the related commands, see tftp, tftp get. Example # Upload the vrpcfg.txt to the TFTP server at 1.1.3.214 and save it as Temp.txt. [Quidway] tftp ascii [Quidway] tftp put vrpcfg.txt //1.1.3.214/temp.txt Huawei Technologies Proprietary 1-31...
Page 737
# Show the information of the entry with MAC address at 00e0-fc01-0101 on S3526. [Quidway] display mac-address 00e0-fc01-0101 MAC ADDR VLAN ID STATE PORT INDEX AGING TIME(s) 00e0-fc01-0101 Learned Ethernet0/1 2.1.3 mac-address Syntax mac-address { static | dynamic } mac-addr interface { interface-name | interface-type interface-num } vlan vlan-id Huawei Technologies Proprietary...
# Configure the port number corresponding to the MAC address 00e0-fc01-0101 as Ethernet0/1 in the address table, and sets this entry as static entry. [Quidway] mac-address static 00e0-fc01-0101 interface ethernet 0/1 vlan 2 2.1.4 mac-address max-mac-count Syntax mac-address max-mac-count count undo mac-address max-mac-count Huawei Technologies Proprietary...
System view Parameter aging age: Specifies the aging time (measured in seconds) of the Layer-2 dynamic address table entry, ranging from 10 to 1000000. By default, the aging time is 300 seconds. no-aging : No aging time. Huawei Technologies Proprietary...
Page 740
If aging time is set too short, the Ethernet switch may delete valid MAC address table. Example # Configure the entry aging time of Layer-2 dynamic address table to be 500 seconds. [Quidway] mac-address timer aging 500 Huawei Technologies Proprietary...
The specifed file will be booted next time! <Quidway> 3.1.2 boot bootrom Syntax boot bootrom file-url View User view Parameter file-url: File path and file name of Bootrom. Description Using boot bootrom command, you can upgrade bootrom. Huawei Technologies Proprietary...
3.1.4 display cpu Syntax display cpu View Any view Parameter None Description Using display cpu command, you can display CPU occupancy. Example # Display CPU occupancy. <Quidway> display cpu CPU busy status: 18% in last 5 seconds Huawei Technologies Proprietary...
Example # Show the card information. <Quidway> display device SlotNo SubSNo PortNum PCBVer FPGAVer CPLDVer BootRomVer AddrLM Type REV.0 MAIN The following table describes the displaying information. Huawei Technologies Proprietary...
Perform this command to see if they work normally. Example # Display the working state of the fans. <Quidway> display fan 1 State: Normal 2 State: Normal The above information indicates that all fans work normally. Huawei Technologies Proprietary...
System Total Memory(bytes) The Total Memory of switch, unit in byte Total Used Memory(bytes) The Total used Memory of switch, unit in byte Used Rate The memory used rate 3.1.8 reboot syntax reboot View User view Parameter None. Huawei Technologies Proprietary...
Upper temperature limit, ranging from 50 to 80, unit in℃. Description Using temperature-limit command, you can configure temperature limit. Using undo temperature-limit command, you can restore temperature limit to default value. Example # Set the lower and upper temperature limit. <Quidway> temperature-limit 0 10 75 Huawei Technologies Proprietary...
# Set the summer time for z2 that starts at 06:00:00 on 08/06 and ends at 06:00:00 on 01/09 in each year from 2002 on with the time adding 1 hour. <Quidway> clock summer-time repeating 06:00:00 2002/06/08 06:00:00 2002/09/01 01:00:00 Huawei Technologies Proprietary...
# Set the name of the local time zone as Z5 with the time adding 5 hours compared with the UTC. <Quidway> clock timezone z5 add 05:00:00 4.1.4 sysname Syntax sysname sysname undo sysname View System view Huawei Technologies Proprietary...
The maximum date and time the system can display is 23:59:59 9999/12/31. For the related commands, see clock. Example # View the current system date and clock. <Quidway> display clock 15:50:45 UTC Mon 2001/2/12 Huawei Technologies Proprietary...
When there is much configuration information, you can use the regular expression to filter the output information. For specific rules about the regular expression, refer to the corresponding operation manual. For the related command, see save, reset saved-configuration and display saved-configuration. Huawei Technologies Proprietary...
Page 753
0 user-interface vty 0 4 return # View the lines containing the character string “10*” in the configuration information. The “*” indicates that the “0” before it can appear 0 times or multiple consecutive times. Huawei Technologies Proprietary...
Page 754
<Quidway> display current-configuration configuration sysname Quidway radius scheme system server-type nec primary authentication 127.0.0.1 1645 primary accounting 127.0.0.1 1646 user-name-format without-domain domain system radius-scheme system access-limit disable state active idle-cut disable self-service-url disable messenger time disable domain default enable system Huawei Technologies Proprietary...
Show all the enabled debugging when there is no parameter. For the related commands, see debugging. Example # Show all the enabled debugging. <Quidway> display debugging IP packet debugging switch is on. 4.2.4 display saved-configuration Syntax display saved-configuration Huawei Technologies Proprietary...
Page 756
127.0.0.1 1645 primary accounting 127.0.0.1 1646 user-name-format without-domain domain system radius-scheme system access-limit disable state active idle-cut disable self-service-url disable messenger time disable domain default enable system local-server nas-ip 127.0.0.1 key nec interface Aux0/0 Huawei Technologies Proprietary 4-10...
Using display users command, you can view information about users connected to the switch. Example # Display the status of the current users. <Quidway> display users Delay IPaddress Username F 0 AUX 0 00:00:00 4.2.6 display version Syntax display version Huawei Technologies Proprietary 4-12...
When the Ethernet switch does not run well, you can collect all sorts of information about the switch to locate the source of fault. However, each module has its corresponding display command, which make it difficult for you to collect all the Huawei Technologies Proprietary 4-14...
Page 762
ICMP ECHO-REPLY to the source host after receiving ICMP ECHO-REQUEST. Perform ping command to troubleshoot the network connection and line quality. The output information includes: Huawei Technologies Proprietary 4-16...
-f: Configure to verify the -f switch, first-TTL specifies an initial TTL, ranging from 0 to the maximum TTL. -m: Configure to verify the -m switch, max-TTL specifies a maximum TTL larger than the initial TTL. Huawei Technologies Proprietary 4-17...
Page 764
3 lilac-dmc.Berkeley.EDU (128.32.216.1) 39 ms 19 ms 19 ms 4 ccngw-ner-cc.Berkeley.EDU (128.32.136.23) 19 ms 39 ms 39 ms 5 ccn-nerif22.Berkeley.EDU (128.32.168.22) 20 ms 39 ms 39 ms 6 128.32.197.4 (128.32.197.4) 59 ms 119 ms 39 ms Huawei Technologies Proprietary 4-18...
Without parameter, display channel command shows the configurations of all the channels. Example # Show details about the information channel 0. <Quidway> display channel 0 channel number:0, channel name:console MODU_ID NAME ENABLE LOG LEVEL ENABLE TRAP LEVEL ENABLE DEBUGGING LEVEL ffff0000 all warning debugging debugging Huawei Technologies Proprietary 4-19...
[Quidway] info-center channel 0 name execconsole 4.5.4 info-center console channel Syntax info-center console channel { channel-number | channel-name } undo info-center console channel View System view Parameter channel-number: Channel number, ranging from 0 to 9, that is, system has ten channels. Huawei Technologies Proprietary 4-21...
Only after the system log function is enabled can the system output the log information to the info-center loghost and console, etc. For the related commands, see info-center loghost, info-center logbuffer, info-center console channel, info-center monitor channel, display info-center. Example # Enable the system log function. [Quidway] info-center enable Huawei Technologies Proprietary 4-22...
For the related commands, see info-center enable,display info-center. Example # Configure to send log information to the UNIX workstation at 202.38.160.1. [Quidway] info-center loghost 202.38.160.1 4.5.8 info-center loghost source Syntax info-center loghost source interface-name undo info-center loghost source View System view Huawei Technologies Proprietary 4-24...
Using undo info-center monitor channel command, you can restore the channel to output the log information to the user terminal to default value. By default, Ethernet switches do not output log information to user terminal. Huawei Technologies Proprietary 4-25...
Page 773
Channel number to be set. channel-name: Channel name to be set. The name can be channel6, channel7, channel8, channel9, console, logbuffer, loghost, monitor, snmpagent, trapbuffer. state: Set the state of the information. state: Specify the state as on or off. Huawei Technologies Proprietary 4-27...
Page 774
Example # Configure to enable the log information of VLAN module in SNMP channel and allows the output of the information with a level higher than emergencies. [Quidway] info-center source vlan channel snmp log level emergencies Huawei Technologies Proprietary 4-28...
[Quidway] info-center trapbuffer size 30 4.5.14 reset logbuffer Syntax reset logbuffer View User view Parameter None Description Using reset logbuffer command, you can reset information in log buffer. Example # Clear information in log buffer. <Quidway> reset logbuffer Huawei Technologies Proprietary 4-30...
Using undo terminal debugging command, you can configure not to display the debugging information on the terminal. By default, the displaying function is disabled. For the related commands, see debugging. Example # Enable the terminal display debugging. <Quidway> terminal debugging Huawei Technologies Proprietary 4-31...
Using terminal monitor command, you can enable the log debugging/log/trap on the terminal monitor. Using undo terminal monitor command, you can disable these functions. By default, enable these functions for the console user and disable them for the terminal user. Huawei Technologies Proprietary 4-32...
Using terminal trapping command, you can enable terminal trap information display. Using undo terminal trapping command, you can disable this function. By default, this function is enabled. Example # Enable trap information display. <Quidway> terminal trapping Huawei Technologies Proprietary 4-33...
# Display the currently configured community names. <Quidway> display snmp-agent community community name:public group name:public storage-type: nonVolatile community name:tom group name:huawei storage-type: nonVolatile 5.1.2 display snmp-agent Syntax display snmp-agent { local-engineid | remote-engineid } View Any view Huawei Technologies Proprietary...
Using display snmp-agent group command, you can view group name, safe mode, state of various views and storage modes. Example # Display SNMP group name and safe mode. <Quidway> display snmp-agent group Group name: huawei Security model: v2c noAuthnoPriv Readview: ViewDefault Writeview: <no specified> Notifyview :<no specified>...
MIB view configuration information of the Ethernet switch. Example # Display the information about the currently configured MIB view. <Quidway> display snmp-agent mib-view View name:mv MIB Subtree:internet Storage-type: nonVolatile -included active View name:test MIB Subtree:internet Storage-type: nonVolatile -included active Huawei Technologies Proprietary...
Indicate the line state in the table Caution: If the SNMP Agent is disabled, "Snmp Agent disabled" will be displayed after you execute the above display commands. 5.1.5 display snmp-agent statistics Syntax display snmp-agent statistics View Any view Parameter None Huawei Technologies Proprietary...
BeiJing China 5.1.8 display snmp-agent sys-info version Syntax display snmp-agent sys-info version View Any view Parameter None Description Using display snmp-agent sys-info version command, you can view the version information about the running SMNMP in the system. Huawei Technologies Proprietary...
The following table describes the output fields. Table 5-3 Output description of the display snmp-agent usm-user command Field Description User name Name of SNMP user Engine ID Character string identifying SNMP device UserStatus The status of the user, may be active or inactive. Huawei Technologies Proprietary...
{ read | write } community-name [ [ mib-view view-name ] [ acl acl-list ] ] undo snmp-agent community community-name View System view Parameter read: Indicate that MIB object can only be read. write: Indicate that MIB object can be read and written. Huawei Technologies Proprietary...
SNMP. Using undo snmp-agent community command, you can cancel the settings of community access name. Example # Configure community name as huawei and permits read-only access by this community name. [Quidway] snmp-agent community read huawei # Configure community name as mgr and permits read-write access.
Any change of the SNMP group notify view will affect all the users related to this group. Please do not specify the notify view when configuring SNMP group. Example # Create an SNMP group named huawei. [Quidway] snmp-agent group v3 huawei. 5.1.13 snmp-agent mib-view Syntax...
SNMP. Using undo snmp-agent sys-info location command, you can restore the default value. By default, the contact information is "HuaWei Beijing China", the system location is "Beijing China", the SNMP version is SNMP V3. Example # Set system location as Building 3/Room 214.
Example # Enable sending Trap message to myhost.huawei.com with community name huawei. [Quidway] snmp-agent trap enable [Quidway] snmp-agent target-host trap address udp-domain 2.2.2.2 params securityname huawei # Enable sending Trap packets to 2.2.2.2 with the community name public...
Page 793
Example # Enable to send the trap packet of SNMP authentication failure to 10.1.1.1. The community name is huawei. [Quidway] snmp-agent trap enable standard authentication [Quidway] snmp-agent target-host trap address udp-domain 10.1.1.1 params securityname huawei...
Length of queue, ranging from 1 to 1000; By default, the length is 100. Description Using snmp-agent trap queue-size command, you can configure the information queue length of Trap packet sent to destination host. Using undo snmp-agent trap queue-size command, you can restore the default value. Huawei Technologies Proprietary 5-15...
Page 796
For V1 and V2C, this command will add a new community name. For V3, it will add a new user for an SNMP group. Example # Add a user wang for huawei (an SNMP group), configures to authenticate with MD5 and sets authentication password as pass. [Quidway] snmp-agent usm-user v3 wang huawei authentication-mode md5 pass...
Using undo snmp-agent command, you can disable all versions of SNMP running on the server. Perform any command of snmp-agent will enable SNMP Agent. Example # Disable the running SNMP agents of all SNMP versions. [Quidway] undo snmp-agent Huawei Technologies Proprietary 5-18...
Using display rmon alarm command, you can view RMON alarm information. For the related commands, see rmon alarm. Example # Display the RMON alarm information. <Quidway> display rmon alarm Alarm table 1 owned by HUAWEI is VALID. Samples absolute value : 1.3.6.1.2.1.16.1.1.1.4.1 <etherStatsOctets.1> Sampling interval : 10(sec) Rising threshold...
Example # Show the RMON event. <Quidway> display rmon event Event table 1 owned by HUAWEI is VALID. Description: null. Will cause log-trap when triggered, last triggered at 0days 00h:02m:27s. Table 6-2 Output description of the display rmon event command...
Example # Show event log of RMON. <Quidway> display rmon eventlog 1 Event table 1 owned by HUAWEI is VALID. Generates eventLog 1.1 at 0days 00h:01m:39s. Description: The 1.3.6.1.2.1.16.1.1.1.4.1 defined in alarm table 1, less than(or =) 100 with alarm value 0. Alarm sample type is absolute.
For the related commands, see rmon history. Example # Show the RMON history information. <Quidway> display rmon history ethernet 2/1 History control entry 1 owned by HUAWEI is VALID Samples interface : Ethernet2/1<ifEntry.642> Sampling interval : 10(sec) with 10 buckets max...
Number of collision packets utilization Utilization 6.1.5 display rmon prialarm Syntax display rmon prialarm [ prialarm-table-entry ] View Any view Parameter prialarm-table-entry:entry of extended alarm table. Description Using display rmon prialarm command, you can view information about extended alarm table. Huawei Technologies Proprietary...
Chapter 6 RMON Configuration Commands For the related commands, see rmon prialarm. Example # display alarm information about extended RMON. <Quidway> display rmon prialarm Prialarm table 1 owned by HUAWEI is VALID. Samples absolute value : .1.3.6.1.2.1.16.1.1.1.4.1 Sampling interval : 10(sec)
Page 804
For the related commands, see rmon statistics. Example # Show RMON statistics. <Quidway> display rmon statistics Ethernet 2/1 Statistics entry 1 owned by HUAWEI is VALID. Interface : Ethernet2/1<ifEntry.642> Received octets , packets broadcast packets...
Falling threshold, ranging from 0 to 2147483647. event-entry2: Event number corresponding to the falling threshold, ranging from 0 to 65535. owner text: Specifies the creator of the alarm. Length of the character string ranges from 1 to 127. Huawei Technologies Proprietary...
Event management of RMON defines the way to deal with event number and event-log, send trap message or log while sending trap message. In this way, alarm events may obtain corresponding treatment Huawei Technologies Proprietary...
Page 808
RMON alarm table. The number of instances can be created in the table depends on the hardware resource of the product. Example # Delete line 10 from the extended RMON alarm table. [Quidway] undo rmon prialarm 10 Huawei Technologies Proprietary 6-11...
Statistics includes collision, CRC (Cyclic Redundancy Check) and queue, undersized or oversized packet, timeout, fragment, broadcast, multicast, unicast, and bandwidth utility. Example # Add the entry 20 to the statistics table of Ethernet1/1. [Quidway-ethernet1/1] rmon statistic 20 Huawei Technologies Proprietary 6-12...
NTP clock synchronization information debugging. validity: NTP remote host validity debugging. Description Using debugging ntp-service command, you can debug different NTP services. Using undo debugging ntp-service command, you can disable corresponding debugging function. By default, no debugging function is enabled. Huawei Technologies Proprietary...
Example <Quidway> display ntp-service sessions source refid poll reach delay offset disp ******************************************************************** [12345]212.125.95.4 131.188.3.221 64 377 339.8 10.8 note: 1 source(master),2 source(peer),3 selected,4 candidate,5 configured 7.1.3 display ntp-service status Syntax display ntp-service status View Any view Huawei Technologies Proprietary...
Page 812
Root delay from local equipment to the master reference clock. root dispersion Dispersion of the local clock relative to the NTP server clock peer dispersion Dispersion of the remote NTP server. reference time Reference timestamp Huawei Technologies Proprietary...
The IP address list number, ranging from 2000 to 2999. Description Using ntp-service access command, you can set the authority to access the local equipment. Using undo ntp-service access command, you can cancel the access authority settings. Huawei Technologies Proprietary...
Using undo ntp-service authentication enable command, you can disable this function. By default, the authentication is disabled. Example # Enable NTP authentication function. [Quidway] ntp-service authentication enable 7.1.7 ntp-service authentication-keyid Syntax ntp-service authentication-keyid number authentication-mode md5 value Huawei Technologies Proprietary...
NTP broadcast client mode. By default, the NTP broadcast client mode is disabled. Designate an interface on the local Ethernet Switch to receive NTP broadcast messages and operate in broadcast client mode. The local Ethernet Switch listens to Huawei Technologies Proprietary...
Example # Configure to broadcast NTP packets via Vlan-Interface1 and encrypt them with Key 4 and set the NTP version number as 3. [Quidway] interface vlan-interface1 Huawei Technologies Proprietary...
# Disable Vlan-Interface1 to receive NTP message. [Quidway] interface vlan-interface1 [Quidway-Vlan-Interface1] ntp-service in-interface disable 7.1.11 ntp-service max-dynamic-sessions Syntax ntp-service max-dynamic-sessions number undo ntp-service max-dynamic-sessions View System view Parameter number: The maximum sessions can be created locally, ranging from 0 to 100. Huawei Technologies Proprietary...
Example # Configure to receive NTP multicast packet via Vlan-Interface1 and the multicast group corresponding to these packets located at 224.0.1.1. [Quidway] interface vlan-interface 1 [Quidway-Vlan-Interface1] ntp-service multicast-client 224.0.1.1 Huawei Technologies Proprietary...
Example # Configure to transmit NTP multicast packets encrypted with Key 4 via Vlan-Interface1 at 224.0.1.1 and use NTP version 3. [Quidway] interface vlan-interface 1 [Quidway-Vlan-Interface1] ntp-service multicast-server 224.0.1.1 authentication-keyid 4 version 3 Huawei Technologies Proprietary 7-10...
# Set the local clock as the NTP master clock to provide synchronized time for its peers and locate it at stratum 3. [Quidway] ntp-service refclock-master 3 7.1.15 ntp-service reliable authentication-keyid Syntax ntp-service reliable authentication-keyid number undo ntp-service reliable authentication-keyid number View System view Huawei Technologies Proprietary 7-11...
Specify an interface. The source IP address of the packets will be taken from the address of the interface. interface-type: Specify the interface type and determine an interface with the interface-number parameter. interface-number: Specify the interface number and determine an interface with the interface-type parameter. Huawei Technologies Proprietary 7-12...
Specify the interface name. When a local device sends an NTP message to a peer, the source IP address of the message is taken from the address of the interface. interface-type: Specify the interface type and determine an interface together with the interface-number parameter. Huawei Technologies Proprietary 7-13...
NTP version number, ranging from 1 to 3. authentication-keyid: Define authentication key. keyid: Key ID used for transmitting messages to a remote server, ranging from 0 to 4294967295. source-interface: Specify the name of an interface. Huawei Technologies Proprietary 7-14...
Page 824
By operating in client mode, a local device can be synchronized by a remote server, but not synchronize any remote server. Example # Designate the server at 128.108.22.44 to synchronize the local device and use NTP version 3. [Quidway] ntp-service unicast-server 128.108.22.44 version 3 Huawei Technologies Proprietary 7-15...
By default, debugging function is disabled. For the related commands, see ssh server authentication-retries, ssh server rekey-interval, ssh server timeout. Example # Print debugging information in running SSH <Quidway> debugging ssh server vty 0 00:23:20: SSH0: starting SSH control process Huawei Technologies Proprietary...
VTY0 1.5 DES Session started 1 Quidway VTY3 1.5 DES Session started 1 switch 8.1.5 display ssh user-information Command display ssh user-information [ username ] View Any view Parameter username: Valid SSH user named defined by AAA Huawei Technologies Proprietary...
For the related commands, see rsa peer-public-key, public-key-code end. Example # Quit public key view. <Quidway>system-view System View: return to User View with Ctrl+Z. [Quidway] rsa peer-public-key quidway003 [Quidway-rsa-public-key] peer-public-key end [Quidway] Huawei Technologies Proprietary...
# Disable Telnet on vty0 through vty4, only SSH available. <Quidway>system-view System View: return to User View with Ctrl+Z. [Quidway] user-interface vty 0 4 [Quidway-ui-vty0-4] protocol inbound ssh [Quidway-ui-vty0-4] 8.1.8 public-key-code begin Command public-key-code begin View Public key edit view Huawei Technologies Proprietary...
8.1.9 public-key-code end Command public-key-code end View Public key edit view Parameter None Description Using the public-key-code end command, you can save the configured public key and return to the public key view from the public key edit view. Huawei Technologies Proprietary...
For a successful SSH logon, you must configure and generate the local RSA key pairs. To generate local key pairs, you just need to execute the command once, with no further action required even after the system is rebooted. Huawei Technologies Proprietary...
This command is just a one-time instruction, so the result will not be stored in the configuration file. For the related commands, see rsa local-key-pair create. Example # Remove all key pairs at the server. <Quidway>system-view Huawei Technologies Proprietary...
# Enter the public key view. <Quidway>system-view System View: return to User View with Ctrl+Z. [Quidway] rsa peer-public-key quidway002 [Quidway-rsa-public-key] 8.1.13 ssh server authentication-retries Command ssh server authentication-retries times undo ssh server authentication-retries View System view Huawei Technologies Proprietary 8-10...
By default, system doesn’t update the server key. For the related commands, see display ssh server. Example # Define update interval of server key pair as 3 hours. <Quidway>system-view System View: return to User View with Ctrl+Z. Huawei Technologies Proprietary 8-11...
View System view Parameter keyname: Configures client public key, consisting of 1~32 characters. username: Valid local user name or user name defined by remote RADIUS system. Huawei Technologies Proprietary 8-12...
By default, user can’t logon the switch through SSH or TELNET, so you have to specify authentication type for a new user. The new configuration takes effects at the next logon. For the related commands, see display ssh user-information. Huawei Technologies Proprietary 8-13...
Page 838
Command Manual - System Management Quidway S3500 Series Ethernet Switches Chapter 8 SSH Configuration Commands Example # Specify zhangsan’s authentication type as password. <Quidway>system-view System View: return to User View with Ctrl+Z. [Quidway] ssh user zhangsan authentication-type password [Quidway] Huawei Technologies Proprietary 8-14...
Page 839
HUAWEI Quidway S3500 Series Ethernet Switches Command Manual Auto Detecting Huawei Technologies Proprietary...
System View: return to User View with Ctrl+Z. [Quidway] detect-group 10 [Quidway-detect-group-10] detect-list 1 ip address 202.13.1.55 nexthop 1.1.1.1 1.1.3 display detect-group Syntax display detect-group [ group-number ] View Any view Parameter group-number: Specifies the detecting group number, which ranges from 1 to 100. Huawei Technologies Proprietary...
Page 843
The number of an IP address contained in the detect-list detecting group. ip address The IP address of the interface to be detected. next-hop The IP address of the interface taken as the next hop. Huawei Technologies Proprietary...
Page 844
IP address contained in the detecting group and stops detecting. By default, the and keyword is specified. Example # Specify the or keyword for detecting group 10. <Quidway> system-view System View: return to User View with Ctrl+Z. [Quidway] detect-group 10 [Quidway-detect-group-10] option or Huawei Technologies Proprietary...
15. Description Use the timer loop command to set the detecting interval, that is, the frequency to perform auto detect. Example # Set the detecting interval of detecting group 10 to 60 seconds. <Quidway> system-view Huawei Technologies Proprietary...
Use the timer wait command to set the timeout time of a detection. Example # Set the timeout time to 3 seconds for detecting group 3. <Quidway> system-view System View: return to User View with Ctrl+Z. [Quidway] detect-group 10 [Quidway-detect-group-10] timer wait 3 Huawei Technologies Proprietary...
Specifies the route to be a black hole. If you specify this keyword when executing this command, all outbound interfaces are the Null 0 interfaces regardless of Huawei Technologies Proprietary...
Use the undo standby detect-group command to disable VLAN interface backup function. You can enable VLAN interface backup function by auto detecting results in the following ways: Enable the primary interface when the result of the detecting group is reachable. Huawei Technologies Proprietary...
Decrease the preference value of a backup group when the result of the detecting group is unreachable. Restore the preference value of a backup group when the result of the detecting group is reachable. Huawei Technologies Proprietary...
Page 850
[Quidway-detect-group-10] detect-list 1 ip 202.13.1.55 # Specify to decrease the preference value of backup group 1 by 20 when the result of detecting group 10 is unreachable. [Quidway] interface vlan-interface 2 [Quidway- vlan-interface2] vrrp vrid 1 track detect-group 10 reduced 20 Huawei Technologies Proprietary...
Page 852
Command Manual - Appendix Quidway S3500 Series Ethernet Switches Table of Contents Table of Contents Appendix A Command Index .......................A-1 Huawei Technologies Proprietary...