Here are the step by step configuration of implementing Access-Lists or ACL on Huawei routers such as NetEngine Series Routers utilizing the ip-pool and source-pool for simplicity and convenience. 1.Create ip-pool and source-pool acl ip-pool allowed_ip ip address 192.168.0.0 0.0.0.255 acl port-pool allowed_port eq 22 2. Create ACL acl number 88 description ACL88 rule 10 permit tcp source-pool allowed_ip destination-port-pool allowed_port rule 20 deny tcp destination-port-pool allowed_port rule 30 permit ip 3. Create traffic policy and apply ACL traffic classifier…
Category: <span>Huawei</span>
For checking transmission links on Huawei Routers, it is good to know how to find out the optical power of 100GE modules or interfaces for troubleshooting and making sure the desired or optimal range is meet. Here are the sample commands for checking the TX/RX optical power. display interface 100GE <slot number> Sample Output: <Huawei-Router>display interface 100GE 5/0/0 100GE5/0/0 current state : UP (ifindex: 146) Line protocol current state : UP Link quality grade : GOOD Description: Connection to RouterA…
Here are the steps on committing/saving and rollback configuration on Huawei Routers system-view commit or system-view commit label <String 1-256> Example: Change1: Change description on Ether-Trunk88 Change2: Enable ipv6 <Huawei>system-view [~Huawei]interface Eth-Trunk88 [*Huawei-Eth-Trunk88]description Connection to Router1 [*Huawei-Eth-Trunk88]commit label Eth88Desc description Eth88IntDesc Committing…..done. [~Huawei-Eth-Trunk88]ipv6 enable [~Huawei-Eth-Trunk88]commit label Eth88v6Enable Verification: display configuration commit list display configuration commit list verbose Example: [~Huawei-Eth-Trunk88]display configuration commit list ——————————————————————————– No. CommitId Label User TimeStamp ——————————————————————————– 1 1000000044 Eth88v6Enable admin 2023-07-06 22:34:42 2 1000000043 Eth88Desc admin 2023-07-06…
Option1: If the current line cards installed support your PC/laptop’s 1GE UTP port, then you can install SFP-1000BaseT(SFP-T) transceiver directly to be used as the observing port. Fig.1 interface <interface name> port-mirroring inbound port-mirroring outbound port-mirroring to observe-index 1<1-255> interface <interface name> port-observing observe-index <1-255> Sample Configuration: Objective: To further do analysis on all traffic going to the Web server by port mirroring the interface going to the server. Port to mirror: Gi2/0/0 Port to observe:Gi1/0/0 <HW-Router>sys Enter system…
Here is a simple tutorial on tracing access users on Huawei Router. There are few ways to trace access-user based on the given information and most common are circuit-id, ip-address,ipv6-address and mac-address. [~Huawei]trace access-user object 1 ? access-mode The access mode calling-number The Calling Number ce-vlan The CE VLAN ID circuit-id User’s circuit-id interface The interface ip-address The IP address ipv6-address IPv6 address mac-address The MAC address pe-vlan The PE VLAN ID remote-id User’s remote-id tunnel-id User Tunnel ID user-name…
Here’s the basic BGP (eBGP) configuration of connecting 3 different router vendors namely Huawei, Juniper and Cisco Routers. Assuming we connect via their physical interfaces and incoming and outgoing policies are basically allow all. Sample Configuration Huawei <Huawei>system-view Enter system view, return user view with return command. [~Huawei] interface GigabitEthernet1/0/0 description Connection to Cisco ip address 192.168.0.1 255.255.255.252 interface GigabitEthernet1/0/1 description Connection to Juniper ip address 192.168.1.1 255.255.255.252 xpl route-filter Cisco-Import approve end-filter xpl route-filter Cisco-Export approve end-filter xpl route-filter…
These are the some commands being used when performing network change or maintenance, depending on the features or services being run in the network. Typically, this is very useful in verification, troubleshooting and comparison between before and after the change. Commands Description Category screen-length 0 temporary display none split screen (useful in collecting info without pause) Basic Command display health display usage information of system resources Resources display cpu-usage display usage of CPU Resources display alarm all display all alarms…
Here are the sample VLAN configuration and commands comparing Cisco Nexus and Huawei switches. VLAN Creation: Cisco Huawei configure system-view vlan 88name VLAN 88 vlan 88name VLAN88 Access Interfaces: Cisco Huawei interface Ethernet1/1description Connection to Server1switchportswitchport access vlan 88no shutdown interface GigabitEthernet1/1/1description Connection to Server1port link-type accessport default vlan 88undo shutdown Trunk Interfaces: Cisco Huawei interface Ethernet2/1description Connect to Switch2switchportswitchport mode trunkswitchport trunk allowed vlan 10,20no shutdown interface GigabitEthernet2/1/1description Connect to Switch2port link-type trunkport trunk allow-pass vlan 10 20undo shutdown…
One Comment