Thursday, June 29, 2017

Does Huawei S3700 Support Port Mirroring?

Huawie S3700 supports port mirroring. The details are as follows:

A maximum of four observing ports can be configured on an S3700. Packets from
multiple ports can be mirrored to the same observing port. You can mirror incoming
packets, outgoing packets, or both to an observing port.



The S3700 supports Remote Switched Port Analyzer (RSPAN). That is, the observing
port and mirrored port can be located on different switches. This facilitates remote
device management.


The S3700 such as S3700-52P-EI-48S-AC supports traffic mirroring. A maximum of four observing ports can be configured on an S3700. Flows can be mirrored from multiple ports to the same
observing port. Flows to be mirrored are determined by the traffic classification rule.


Configuring a GPON ONT Capacity Profile (Distributed Mode)

A GPON ONT capability profile identifies the actual capability of a GPON ONU. After an ONT is added and bound to a Huawei GPON ONT capability profile, the ONU carries the corresponding services according to parameters configured in the capability profile.

Context

All GPON ONUs must be bound to the GPON ONT capability profile. Specify the ONT capability profile when running the ont add command to add an ONU offline or running the ont confirm command to confirm an automatically discovered ONU.

Currently, the system provides seven default ONT capability profiles that are solidified in the system. The default profiles cannot be modified. The default profile IDs range from 1-7. The reserved ONT capability profile IDs are 8-16.

The contents of the capability profile restrict the port number that is used in commands for GEM port mapping, T-CONT/PQ mapping, and the ONT VLAN management.

The ONT capability profile must be configured according to the actual capability of the ONU. Different the capability profile parameters vary according to different ONUs.

Procedure

Step 1 Run the ont-profile add command to configure an ONT HG8546M capability profile.


  • When you add an ONT capability profile, if the profile ID is not specified, the system automatically allocates the least idle profile ID; if the profile name is not specified, the system adopts the default name ont-profile_x, where, x is the corresponding ONT capability profile ID.
  • The system supports up to 128 ONT capability profiles.
  • The system default profiles include the MDU profile and several common ONT (such as OT925, HG850, and HG810) profiles, which can be directly used. It is recommended to manually configure an ONT capability profile only when the default ONT capability profile fails to meet actual requirements.
  • When you add an MDU profile manually, the number of the ports must be set to zero.


Step 2  Run the display ont-profile command to query the ONT capability profile.

Tuesday, June 27, 2017

Some FAQs about Huawei S2700 S3700 S5700 S6700 Switch

Many engineer always confused Huawei switch when configuration and management, below are FAQs about Huawei S2700 S3700 S5700 S6700 Switch,

What Are the Functions of PIM Silent on a PIM Interface?

On the access layer, if the interface directly connected to a host is enabled with the PIM
protocol, PIM neighbors can be established on this interface to process various PIM protocol
packets. Such configuration, however, may bring security problems. For example, when
malicious hosts send a large number of pseudo PIM Hello packets, it may lead to the collapse
of the device.
To avoid the preceding problem, you can run the pim silent command on the interface to set
the interface to work in PIM silent state. After the interface enters the PIM silent state, it is
forbidden to receive or forward any PIM protocol packet. All PIM neighbors and the PIM
state machine on this interface are deleted and the interface automatically becomes a DR.
Meanwhile, the PIM silent function does not affect the IGMP function on the interface.
The PIM silent function is applicable only to the interface that is directly connected to the
network segment of user hosts, and only one PIM device can be connected to this network
segment.

When a Host Leaves a Group, How Does an IGMP Querier Judge Whether Any Other Members of the Group Exist on the Network Segment?

In IGMPv1, when a host leaves a multicast group, the host does not send any message. A
device considers that all multicast members have left a group when the timer of the group
expires.
In IGMPv2 and IGMPv3, a host sends a Leave message when leaving a group. After
receiving the Leave message, the querier sends a group-specific or source/group-specific
Query message to the network segment of the host. The destination address of the Query
message is the address of the multicast group and the group address in the message is also
filled in with the address of the multicast group.
If other members of the group exist on the network segment, they respond with Report
messages.
If no response is received when the timeout period ends, the querier considers that no
member of the group exists on the network segment and cancels forwarding multicast

data to the group.

Can the Hosts and Devices on the Same User Network Segment Run Different Versions of IGMP?

IGMP has three versions, namely IGMPv1, IGMPv2, and IGMPv3. Different IGMP versions
run on devices and hosts are compatible, but all the devices on the same network segment
must run IGMP of the same version. If the versions of IGMP run on the devices on the same
network segment are different, IGMP member relationships are chaotic.
Run the display igmp interface interface-type interface-number command on all the devices
on the same network segment to check the versions of IGMP run on the devices. If the
versions are not the same, modify the configuration.

Other questions about Huawei switch will be posted continually.

Monday, June 26, 2017

Introduction for TE Tunnel Protection Group on Huawei Access Network Equipment

Introduction for TE Tunnel Protection Group on Huawei Access Network Equipment.

A tunnel protection group protects end-to-end MPLS TE tunnels. If a working tunnel in a protection group fails, traffic switches to a protection tunnel, minimizing traffic interruptions.

Related Concepts
As shown in the Figure, concepts related to a tunnel protection group are as follows:
Working tunnel: a tunnel to be protected.
Protection tunnel: a tunnel that protects a working tunnel.
Protection switchover: switches traffic from a faulty working tunnel to a protection tunnel in a tunnel protection group, which improves network reliability.


Primary tunnels tunnel-1 and tunnel-2, and the bypass tunnel tunnel-3 are established on the ingress Access Node

Tunnel-3 is specified as a protection tunnel for primary tunnels tunnel-1 and tunnel-2 on Access Node. If the configured fault detection mechanism on the ingress detects a fault in tunnel-1, traffic switches to tunnel-3. Access Node attempts to reestablish tunnel-1. If tunnel-1 is successfully established, traffic switches back to the primary tunnel.

Implementation
A TE tunnel protection group uses a configured protection tunnel to protect traffic on the working tunnel to improve tunnel reliability. To ensure the improved performance of the protection tunnel, the protection tunnel must exclude links and nodes through which the working tunnel passes during network planning.

Protection mode
A tunnel protection group works in either 1:1 or N:1 mode. The 1:1 mode enables a protection tunnel to protect only a single working tunnel. The N:1 mode enables a protection tunnel to protect more than one working tunnel.

More related:

MA5600V800R00X series devices load the IO data package

P2P Access: Configuring FTTH Service








Sunday, June 25, 2017

Is Optical Amplifier board TN12OAU101 an indispensable element on Huawei DWDM Equipment?

TN12OAU101 is a WDM optical amplifier board, to amplifies C band optical signals at Gain Range 20dB to 31dB. TN12OAU101 part number is 03030LMK, some other version like TN11OAU1 and TN13OAU1 with different system compatibility and feature supported. TN12OAU1 have feature code like 03 and 05, different Gain Range.


  • Amplifies the input optical signals in C band.
  • Applied to Huawei OSN8800, OSN6800,OSN3800
  • Supports the system to transmit services over different fiber spans without electrical regeneration.
  • Gain adjustment of OAU101: 20dB to 31dB.
  • Provides an in-service monitoring port (MON).
  • Supports the gain locking and power locking modes.
  • The EDFA inside board has transient control function.
  • Detects and reports the optical power.
  • Monitors the temperature of the pump laser.
  • Detects current of pump driving, back facet and pump cooling; temperature of pump laser and ambient temperature of board.
  • Supports Optical-layer ASON.

Thursday, June 22, 2017

OT928G loopback cannot be configured due to U2000 internal problem

Issue Description
It is required to configure loopback on OT928G through U2000 management system but when it is done system
pop ups an alarm informing that operation failed.
MA5680T MA5600V800R008C01
U2000 V100R002C01SPC004
Alarm Information
Set a Local Loopback operation failed
Failure cause: The version does not match
Handling Process
Process to configure loopback through U2000 was verified and tested to confirm it is correct and it was but the failure was gotten
Versions compatibility was verified and it was confirmed U2000 supported Huawei MA5600T base version
Process was recurred to collect some info and logs that were sent to R&D who finally confirmed it was U2000 problem so, they provided a temporal solution replacing file GPON_operdesc.xml  on following path.


U2000/server/nemgr/nemgr_access/dcp/mib/gpon/GPON_operdesc.xml
However, this problem has been already solved on patch SPC501 for U2000
Root Cause         
Procedure to configure loopback is not correct
U2000 and OLT versions are not compatible
Software system problem
Suggestions

Null

Wednesday, June 21, 2017

What Is MAC Address Management?

MAC address management is a basic Layer 2 management feature that enables system administrators to use the functions listed in the following table.

Sub-function of MAC Address Management:

Setting the MAC address aging time
Limiting the number of learnable dynamic MAC addresses
Setting the static MAC address

Benefits
Benefits for Carriers
1, The system ages dynamic MAC addresses to ensure timely updates of the MAC address table. If the MAC address table is full and not updated, the system will fail to learn new MAC addresses and will consequently fail to forward data.
2, By limiting the number of learnable dynamic MAC addresses, the system administrator can limit the number of MAC addresses that can be used to enter the network and hence alleviate the load of network devices.
3, By configuring static MAC addresses, the system administrator prohibits unauthorized users from accessing the system.

Benefits for Subscribers

Improved user security: After the system administrator sets the static MAC address of a service port and sets the maximum number of learnable MAC addresses to 0, the port receives only user data carrying the specified static MAC address.
The access node provides multiple MAC address security features to protect networks against forged MAC addresses, please refer to 23 MAC Address Security Features.

Address Management Process
MAC address management includes MAC address table establishment and management.

Establishing MAC Address Tables
The system establishes a MAC address table by learning source MAC addresses or after users configure static MAC address entries.
MAC address learning
− When Huawei OLT functions as a Layer 2 switching device, it learns MAC addresses in the distributed mode. Specifically, each board learns the source MAC address of packets sent from the board of its own and then forwards packets according to their destination MAC addresses. The learned MAC addresses are stored in the system buffer. Generally, the system buffer can hold a limited number of MAC address entries. If all these entries are filled in, no more MAC addresses can be learned.
− Configuration command: mac-address learning vlan
Configuration of static MAC address entries
− A user can manually configure static MAC address entries in which user device MAC addresses are bound to ports. After this configuration, the packets whose MAC addresses are included in the MAC address entries are always forwarded through the bound ports. This configuration improves the efficiency for forwarding packets and improves the security of ports because it denies access from unauthenticated users. This method of establishing MAC address tables is widely used in private networks.
− Configuration command: mac-address static
The following table shows an example of a simplified MAC address table established by configuring static MAC address entries. The table lists the mapping between MAC addresses, ports, and VLAN IDs.

Managing MAC Address Tables

When managing MAC address tables, users can configure MAC-related attributes as allowed by system resources and network security policies against potential risks. The optimized MAC address tables can better meet requirements of a live network. These MAC-related attributes are as follows:
Maximum number of MAC addresses learned based on service flows
− After the number of access users reaches the limit, no new access user addresses will be learned. This attribute setting applies to networks, such as residential access networks and low-security internal enterprise networks, that have fixed access users but are not sufficiently secure.

Setting the function of sensing excess MAC addresses
When a lot of MAC addresses are learnt by the system, it is difficult for trouble locating. When the function of sensing excess MAC addresses is enabled, the board software queries the actual MAC address specifications of the board every 15 minutes and determines whether an alarm needs to be reported according to the query result. If the query result exceeds the upper threshold for sensing excess MAC addresses set by users, an excess MAC address alarm is generated. If the query result is smaller than the lower threshold for sensing excess MAC addresses set by users, a fault clearing alarm is generated.
Configuration command: overload-aware mac-address
MAC address aging
Generally, the system automatically establishes a MAC address table by learning source MAC addresses. The established MAC address table has to be updated according to network changes. However, after the network topology changes, the dynamic MAC address entries will not be automatically updated in a timely manner. Then the system cannot learn more MAC addresses and user data