Thursday, August 10, 2017

Do you know how to Replace a Power Module or Fan Module?

Some switch models support pluggable power modules and fan modules. Figure shows
the fan module slots and power module slots on Huawei S6700-EI switch as an example.
Before replacing a power module, ensure that the switch is powered by the other power
module. Replacing the only power module of a switch will interrupt services.
If two power modules are installed in a switch, they work in 1+1 backup mode. Replacing
one power module will not interrupt services. If you are replacing both power modules,
replace the second one only after the first replaced one is working (its indicator is steady
green).

Tools and Accessories
ESD wrist strap or ESD gloves
Phillips screwdriver
Procedure
Step 1 Wear an ESD wrist strap or ESD gloves. When wearing an ESD wrist strap, ensure that it is in
close contact with your wrist and grounded properly.
Step 2 Turn off the power module.
Step 3 Remove the power cable from the power module. The procedure for removing a power cable
is the reverse of the procedure for installing the power cable.
Step 4 Remove the power module from the Huawei switch.
1. Use a Phillips screwdriver to loosen the captive screw on the power module.
2. Holding the handle, gently pull out the power module.

Step 5 Install the replacement power module in the switch.
Step 6 Connect the power cable to the new power module.
Step 7 Turn on the power module.
Step 8 Use either of the following methods to check whether the new power module is working
normally:
Observe the STATUS indicator on the panel. If the indicator is steady green, the power
module works normally.
Run the display device command to check the running status of the new power module.

Follow-up Procedure
If the new power module does not work normally, contact the equipment supplier or local
maintenance personnel for technical support.

Huawei S1720&S2700&S3700&S5700&S6700 Switch VLAN Termination and Voice VLAN

VLAN Termination
Involved Network Elements
Other network elements are not required.

License Support
VLAN termination, that is, QinQ and Dot1q on a sub-interface, is a basic feature of a switch
and is not under license control.

Feature Dependencies and Limitations

  • Termination sub-interfaces cannot be configured on an Eth-Trunk member interface. 
  • You are advised to add member interfaces to an Eth-Trunk and configure termination sub-interfaces on the Eth-Trunk in sequence. Termination sub-interfaces can be configured successfully on an Eth-Trunk only when the device where member interfaces reside support termination sub-interfaces.
  • The VLAN IDs terminated by a sub-interface cannot be created in the system view or be displayed using a display command.
  • When VLAN IDs terminated by a sub-interface are used for Layer 3 forwarding, only the first VLAN takes effect even if multiple inner VLAN IDs are specified.
  • VLAN termination sub-interfaces cannot be created on a VCMP client.
  • The VLAN terminated by a sub-interface cannot be configured as a super-VLAN or sub VLAN.
  • If the PW-side interface is a Layer 3 interface switched by the undo portswitch command, the AC-side interface cannot be a subinterface belonging to a Layer 3 interface; otherwise, traffic forwarding is abnormal. This rule applies to Huawei S6720-EI, S6720S-EI and S5720EI.
Voice VLAN

Involved Network Elements
Other network elements are not required.

License Support
The voice VLAN can be available only after the S1720GW, S1720GWR, S1720GW-E, and
S1720GWR-E have the license loaded. The S1720GW-E and S1720GWR-E have the preconfigured
license before delivery. CFM is available on other models without loading the license.

Feature Dependencies and Limitations
  • VLAN 1 cannot be configured as a voice VLAN.
  • To transmit different services, ensure that the voice VLAN and default VLAN on an interface are different VLANs.
  • Only one VLAN on an interface can be configured as a voice VLAN at a time.
  • After a voice VLAN is configured on an interface, VLAN mapping, VLAN stacking, or traffic policies cannot be configured on the interface.
  • Do not set the VLAN ID to 0 on an IP phone.
  • The S5720-HI do not support the automatic mode.
  • In auto mode, access, negotiation-auto, or negotiation-desirable interfaces cannot be added to a voice VLAN. To add the interface to the voice VLAN, run the port link-type command to change the link type of the interface to trunk or hybrid.
  • In V200R003 and later versions, the automatic mode takes effect only when the voicevlan remark-mode mac-address command is configured to increase the priority of voice packets based on MAC addresses and the voice-vlan enable command without include-untagged specified is configured to enable voice VLAN on the interface.
  • When the remark (user group view) and voice-vlan remark commands are used together to modify the user packet priority in V200R008, if the services conflict:
– For S5720HI, the priority configured using the remark (user group view)
command takes effect.
– For S5720-EI and S6720EI, the priority configured using the voice-vlan remark
command takes effect.

Tuesday, August 8, 2017

How to Configure a General ONT VAS Profile?

After configuring a general ONT VAS profile and binding it to an ONT successfully, you can activate the ONT and directly apply the value-added service defined by the profile to the subscribers of the ONT. Each ONT can be bound to only one general ONT VAS profile.
Context
An ONT general VAS profile can incorporate multiple ONT VAS profiles for different ONT types and software versions and therefore can be referenced by those types and versions of ONTs.
An ONT HG8245H for example of V100R003 or a later version can be bound to a general ONT VAS profile only.
If an .xml file containing service configuration data already exists, right-click, and choose Add (Import File) to configure a new general ONT VAS profile.
Procedure
1.    Choose Configuration > Access Profile Management (traditional style) from the main menu or select Fix-Network NE Configuration in Application Centerand choose Access Service > Access Profile Management (application style) from the main menu.
2.    In the dialog box that is displayed, choose PON Profile > ONT VAS Profile from the navigation tree.
3.    Click the General ONT VAS Profile tab.
4.    In the information list, right-click and choose Add from the shortcut menu.

5.    In the dialog box that is displayed, set the required parameters.
6.    Click Next.
7.    In the dialog box that is displayed, set user-defined parameters for Huawei ONTs of different software versions.
Result
On the Terminal Reference tab, you can query all ONTs that are bound to this ONT VAS profile.
Follow-up Procedure
To bind an ONT to a new general ONT VAS profile, right-click, and choose Bind Other General VAS Profile from the shortcut menu



Multiple services in multiple VLANs Service Networking (GPON/10G GPON)

In home service (VLAN tag transparent transmission) networking, a distributed converged
cable access platform (D-CCAP) connects to cable modems (CMs) at user homes through
radio frequency (RF) ports and provides home services for users, including the cable TV
(CATV) service, Internet access service, and VoD service. This section describes how to
configure the optical line terminal (OLT MA5600T)  to provision the home services.

Service Requirements
Users require the provisioning of the broadcast and TV services, Internet access service, and
VoD service. Broadcast and TV services can be provisioned immediately after the distributed
converged cable access platform (D-CCAP) hardware is connected. This section only
describes how to configure the Internet access service, and VoD service.

Usage Scenario
Some carriers deploy HGWs on the lower-layer of CMs. The HGWs add different VLAN tags
to packets based on service types. This requires that the CMCs support transparent
transmission of VLAN tags. As shown in Figure 9-17, a D-CCAP is deployed on an optical
node and cable modems (CMs) are deployed at user homes. The CMs connect to radio
frequency (RF) ports on the MA5633 through cables.
-Port 1 on CM connects to a PC to provide the Internet access service. A set top box
(STB) connects to the distributor to provide a backhaul channel for the VoD service.
-Users access the Internet through Dynamic Host Configuration Protocol (DHCP) dialup.
-The IP addresses of the CM, STB, and PC are assigned by the DHCP server and in
different network segments.
-The D-CCAP is used as a GPON remote extended frame. This reduces D-CCAP
management and maintenance costs and simplifies configurations.

Home service networking (VLAN tag transparent transmission)

Configuration Process
Configuration roadmap for the home service networking
1, Add a remote extended frame to the OLT.
An MA5633 that works as a remote extended frame connects to a port on a cascading board of an Huawei optical line terminal (OLT). You can configure the remote extended frame only after adding it to the
OLT.

2, Configure radio frequency (RF) port parameters (DOCSIS 3.0). Configure radio frequency (RF)
port parameters (DOCSIS 3.1). Radio frequency (RF) port parameters define the frequency spectrum range for signal transmission and modulation mode.
The configuration of RF port parameters implements data service transmission over
cables. RF port parameters can be configured using either of the following methods:
-Use a cable initialization profile to configure the parameters.
-Customize the parameters in cable mode.

3, Configure the high-speed Internet (HSI) service.

4, Configure the DOCSIS VoD service.
If Huawei ONU MA5633 is not equipped with a built-in EQAM module, the MA5633 uses DOCSIS channels to transmit VoD data.
If the MA5633 is equipped with a builtin EQAM module, the MA5633 sets idle downstream DOCSIS channels as EQAM channels to transmit VoD data.
The DOCSIS VoD service and the EQAM VoD service are generally not concurrently used. 

5, Verify the configured services.
An OLT supports multiple remote service verification methods. This allows commissioning and configuration engineers to remotely verify services.
1. A DHCP dialup emulation test checks whether the OLT can communicate with the DHCP server and verifies CM DHCP configurations on the DHCP relay, proxy, and server.
2. The status of a CM can be queried. Based on the information, you can determine whether the CM is online.

Monday, August 7, 2017

What is the Characteristics of Huawei S2700 Switch?

Easy Operation and Maintenance

Huawei S2700 supports Easy-Operation, which implements easy installation, configuration,
monitoring, and troubleshooting. This technology greatly reduces installation and
configuration costs and engineering costs, and improves upgrade efficiency. The S2700
provides the CLI and web platform, supports alarm management and visualized configuration,
and replacement of faulty devices.
The S2700 uses the ASIC chip and fanless design, which reduces mechanical faults and
protects the equipment against damages caused by condensed water and dusts.

Flexible Service Control
The S2700 supports various ACLs. ACL rules can be applied to VLANs to flexibly control
traffic on interfaces and schedule resources in VLANs.
The S2700 supports VLAN assignment based on interfaces, MAC addresses, protocols, and
IP subnets. It applies to networks where users move frequently and networks demanding high
security.
The S2700 supports GVRP, which dynamically distributes, registers, and propagates VLAN
attributes to reduce the manual configuration workloads of network administrators and ensure
correct VLAN configuration. In addition, Huawei S2700 supports SSHv2, HWTACACS, RMON,
interface-based traffic statistics, and NQA to help in network planning and upgrading.

Various Security Measures
The S2700 supports DHCP snooping, which generates user binding entries based on MAC
addresses, IP addresses, IP address leases, VLAN IDs, and interface numbers of users. The
DHCP snooping function protects networks against common attacks such as bogus IP packet
attacks, man-in-the-middle attacks, and bogus DHCP server attacks.
The S2700 can limit the number of MAC addresses learned on an interface to prevent packet
flooding that occurs when an attacker frequently changes source MAC addresses. The S2700
supports strict ARP learning. This feature prevents ARP spoofing attackers from exhausting
ARP entries so that users can connect to the Internet normally. It provides IP source check to
prevent DoS attacks caused by IP address spoofing.
The S2700 supports centralized MAC address authentication and 802.1x authentication. It
authenticates users based on static or dynamic user binding information such as the user
name, IP address, MAC address, VLAN ID, and interface number. VLANs and ACLs can be
applied to users dynamically.

Various Reliability Mechanisms
The S2700 supports iStack, which virtualizes multiple switches into one logical switch. iStack
improves the switching capacity and enhances reliability and scalability. The stacked switches
are managed using a single IP address, which greatly reduces system operation and
maintenance costs.
Besides STP, RSTP, and MSTP, the S2700 like S2700-28TP-EI also supports enhanced Ethernet reliability
technologies such as Smart Link and RRPP, which implement millisecond-level protection
switching and ensure network reliability.
The S2700 supports the Smart Ethernet Protection (SEP) protocol, which is a ring network
protocol applied to the link layer of an Ethernet network. SEP provides fast switchover within
several milliseconds without interrupting services. SEP features simplicity, high reliability,
high switchover performance, convenient maintenance, and flexible topology and enables
users to manage and plan networks conveniently.
The S2700 supports G.8032, also called Ethernet Ring Protection Switch (ERPS). ERPS is
based on traditional Ethernet MAC and bridging functions. It uses the mature Ethernet OAM
and Ring Automatic Protection Switching (Ring APS or R-APS) technologies to implement
fast protection switching on Ethernet. ERPS supports multiple services and provides flexible
networking, reducing the OPEX and CAPEX.

Friday, August 4, 2017

Anyone knows how to configuring the Internet Access Service on Huawei OLT MA5800?

Huawei OLT MA5800 is connected to the remote ONT through a GPON port to provide users with highspeed Internet access services.

Prerequisites
The OLT is connected to the BRAS.
Related configurations are performed on the BRAS according to the authentication and
accounting requirements for dialup users. For details about the configuration, see the
configuration guide.
The ONT has been added to the OLT.
The VLAN of the LAN switch port connected to the OLT is consistent with the upstream
VLAN of the OLT.

Residential users generally access the Internet in Point-to-Point Protocol over Ethernet
(PPPoE) dial-up mode. PPPoE dial-up can be performed on personal computers (PCs) or
HGWs.

The configuration processes on HGWs of different models or in different appearances
are similar. This topic describes how to configure the Internet access service on an
HG239 that is connected to an ONT upstream through a LAN.

Procedure
l Configure Huawei OLT.
a. Configure a traffic profile.
Run the display traffic table ip command to query existing traffic profiles in the system. If the traffic profiles existing in the system do not meet the requirements, you need to run the traffic table ip command to add a traffic profile.
Set the profile ID to ftth_hsi, the CIR to 4 Mbit/s, and the priority to 0. In addition, configure the scheduling mode so that packets are scheduled according to their priorities.

huawei(config)#traffic table ip name ftth_hsi cir 4096 priority 0
priority-policy local-setting

b. Configure the mapping between a GEM port and a VLAN.
The service flow of user-side VLAN 45 is mapped to GEM port 14 in the ONT line profile.

huawei(config)#ont-lineprofile gpon profile-name ftth
huawei(config-gpon-lineprofile-1)#gem mapping 14 0 vlan 45
huawei(config-gpon-lineprofile-1)#commit
huawei(config-gpon-lineprofile-1)#quit

c. Configure the VLAN of the Ethernet port on the ONT HG8546M.
Add Ethernet port 1 to VLAN 45 in the ONT service profile.
huawei(config)#ont-srvprofile gpon profile-name ftth
huawei(config-gpon-srvprofile-1)#port vlan eth 1 45
huawei(config-gpon-srvprofile-1)#commit

d. Create an Internet access service VLAN and add an upstream port to it.
Add upstream port 0/9/0 to VLAN 100.
huawei(config)#vlan 100 smart
huawei(config)#vlan attrib 100 stacking
huawei(config)#port vlan 100 0/9 0

e. Create Internet access service flows.
Set S-VLAN ID to 100 and GEM port ID to 14. Use traffic profile ftth_hsi.
huawei(config)#service-port vlan 100 gpon 0/1/0 ont 1 gemport 14 multiservice
user-vlan 45 tag-transform translate-and-add
inner-vlan 1001 inbound traffic-table name ftth_hsi outbound traffictable
name ftth_hsi
huawei(config)#service-port vlan 100 gpon 0/1/0 ont 2 gemport 14 multiservice
user-vlan 45 tag-transform translate-and-add
inner-vlan 1002 inbound traffic-table name ftth_hsi outbound traffictable
name ftth_hsi

f. Save the data.
huawei(config)#save

Configure the HGW.
a. Log in to the web configuration window.
i. Enter the default IP address in the address bar of the browser, and then press
Enter.
ii. In the login window, enter the user name and password (the default value is
provided by ISP) of the administrator and click OK.
b. Set parameters for the Internet access service.
i. Choose Internet access service configuration from the navigation tree.
ii. Set parameters for the Internet access service.
iii. Submit the configuration.


Generation and Detection of Alarms and Performance Events in the SDH Higher Order Signal Flow

The principle for locating fault is "line first, then tributary; higher order first, then lower
order".
Therefore, this section focuses only on the alarms and performance events generated between
the SDH interface and the cross-connect unit like Huawei GXCSA during maintenance. This section describes the signal flow and the procedure for handling each overhead byte by each module.

Alarm signals generated between the SDH interface and the cross-connect unit

Based on the positions of the various overhead byte processing in the STM-64, STM-16, STM-4, STM-1 frame, the overhead
bytes are classified into four modules:
Regenerator section overheads
Multiplex section overheads
Higher order path overheads
Lower order path overheads
If a fault occurs in the first two modules, it affects all the higher order paths. If a fault occurs in
the overhead bytes of a higher order path, however, it affects only this higher order path and its
lower order paths.
The following sections describe the signal flow and the processing of each overhead byte.

Downlink Signal Flow
In the higher order downstream signal flow, overhead bytes are extracted and terminated.
Frame Synchronizer and Regenerator Section Overhead Processor

Uplink Signal Flow
The overhead bytes are extracted and then terminated in the downlink signal flow of the higher
order path. Overhead bytes are generated and alarm signals are returned to the opposite NE in
the uplink signal flow of the higher order path.