Huawei AR530 Series Configuration Manual

Industrial switch router
Hide thumbs Also See for AR530 Series:
Table of Contents

Advertisement

Huawei AR530&AR550 Series Industrial Switch
Routers
V200R005C70
Configuration Guide - Device
Management
Issue
01
Date
2014-11-30
HUAWEI TECHNOLOGIES CO., LTD.

Advertisement

Table of Contents
loading

Summary of Contents for Huawei AR530 Series

  • Page 1 Huawei AR530&AR550 Series Industrial Switch Routers V200R005C70 Configuration Guide - Device Management Issue Date 2014-11-30 HUAWEI TECHNOLOGIES CO., LTD.
  • Page 2 All other trademarks and trade names mentioned in this document are the property of their respective holders. Notice The purchased products, services and features are stipulated by the contract made between Huawei and the customer. All or part of the products, services and features described in this document may not be within the purchase scope or the usage scope.
  • Page 3: About This Document

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management About This Document About This Document Intended Audience This document provides the basic concepts, configuration procedures, and configuration examples in different application scenarios of the device management feature supported by the device.
  • Page 4: Command Conventions

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management About This Document Symbol Description Calls attention to important information, best NOTE practices and tips. NOTE is used to address information not related to personal injury, equipment damage, and environment deterioration.
  • Page 5 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management About This Document – When configuring a password, the cipher text is recommended. To ensure device security, change the password periodically. – When you configure a password in plain text that starts and ends with %@%@ (the password can be decrypted by the device), the password is displayed in the same manner as the configured one in the configuration file.
  • Page 6: Table Of Contents

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management Contents Contents About This Document........................ii 1 Displaying the Device Status......................1 1.1 Displaying Information About the device........................2 1.2 Displaying the ESN................................2 1.3 Displaying Versions...............................2 1.4 Displaying the Temperature............................3 1.5 Displaying CPU Usage..............................3 1.6 Displaying Memory Usage.............................4...
  • Page 7 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management Contents 3.5.1.1 Enabling the Information Center..........................24 3.5.1.2 (Optional) Naming an Information Channel......................25 3.5.1.3 (Optional) Configuring Log Filtering........................25 3.5.1.4 (Optional) Setting the Timestamp Format of Logs ....................26 3.5.1.5 Configuring the Device to Output Logs to the Log Buffer..................27 3.5.1.6 Configuring the Device to Output Logs to a Log File....................27...
  • Page 8 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management Contents 4.2.2 Network Architecture..............................60 4.2.3 Operating Mode.................................61 4.2.4 NTP Access Control..............................66 4.3 Application...................................67 4.4 Default Configuration..............................69 4.5 Configuring the NTP..............................69 4.5.1 Configuring Basic NTP Functions..........................69 4.5.1.1 Configuring an NTP primary clock........................70 4.5.1.2 Configuring NTP Operating Modes........................71...
  • Page 9 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management Contents 5.5 Maintenance................................107 5.5.1 Clearing Alarms and Events............................107 5.5.2 Monitoring Alarms and Events..........................108 5.6 References..................................108 Issue 01 (2014-11-30) Huawei Proprietary and Confidential viii Copyright © Huawei Technologies Co., Ltd.
  • Page 10: Displaying The Device Status

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 1 Displaying the Device Status Displaying the Device Status About This Chapter This chapter describes the functions of display commands and how to use the display commands to view the device running status.
  • Page 11: Displaying Information About The Device

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 1 Displaying the Device Status 1.1 Displaying Information About the device You can use the display commands to view component information about the device. Context When a fault occurs on the device, you can view device information to check whether the device is working properly.
  • Page 12: Displaying The Temperature

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 1 Displaying the Device Status The version information of the device is displayed. ----End 1.4 Displaying the Temperature You can use the display commands to view the temperature of the device.
  • Page 13: Displaying Memory Usage

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 1 Displaying the Device Status 1.6 Displaying Memory Usage You can use the display commands to view memory usage statistics and threshold. Context Memory usage is an important index to evaluate device performance. A high memory usage will cause service faults.
  • Page 14: Displaying Electronic Labels

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 1 Displaying the Device Status The interface view is displayed. Run: display this The configuration of the current interface is displayed. View the status of an interface using either of the following methods.
  • Page 15: Displaying Diagnostic Information

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 1 Displaying the Device Status Procedure Run: display current-configuration The information of the current configuration is displayed. ----End 1.10 Displaying Diagnostic Information You can use the display commands to view diagnostic information for fault location.
  • Page 16: Hardware Management

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 2 Hardware Management Hardware Management About This Chapter Scientific hardware management reduces the operations performed on hardware resources, including inserting, removing, installing and uninstalling the hardware, and improves hardware resource reliability.
  • Page 17: Hardware Management Overview

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 2 Hardware Management 2.1 Hardware Management Overview Scientific hardware management allows you to use commands to operate and manage hardware resources, for example, reset boards, back up electronic labels, and power on or off the hardware resources.
  • Page 18: Configuring The Cpu Usage Alarm Threshold

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 2 Hardware Management Run: set transceiver { transmit-power | receive-power } { upper-threshold | lower-threshold } threshold Upper and lower alarm thresholds are set for the transmit and receive power of optical modules.
  • Page 19: Configuring The Memory Usage Alarm Threshold

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 2 Hardware Management By default, the CPU usage alarm threshold is 80% and the CPU usage alarm recovery threshold is 75%. l When the CPU usage alarm threshold is lower than 60%, the default CPU usage alarm recovery threshold is 1% lower than the CPU usage alarm threshold.
  • Page 20: Backing Up Electronic Labels

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 2 Hardware Management 2.5 Backing Up Electronic Labels Backing up electronic labels helps improve efficiency in network maintenance. Context Information in electronic labels help locate network faults and replace hardware in batches.
  • Page 21: Information Center Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Information Center Configuration About This Chapter The information center works as the information hub. It records system running information in real time, which helps the network administrator and developers to monitor network operation and analyze network faults.
  • Page 22: Information Center Overview

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.1 Information Center Overview This section describes definition of Information Center and purpose of this feature. Definition The information center works as the information hub. Logs, traps, and debugging messages generated by the device are sent to the information center for unified management and flexible output.
  • Page 23: Information Hierarchy

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Information Type Description Trap Traps are notifications generated when the device detects faults. Traps record system status information. Different from logs, traps need to be notified to administrators in a timely manner.
  • Page 24: Information Output

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Value Severity Description Informational A normal operation is performed. For example, a display command is run. Debugging A normal operation is performed, which requires no attention.
  • Page 25: Information Filtering

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Table 3-3 Relationship between default channels and output directions Chan Default Output Description Channel Direction Numb Name Console Console Outputs logs, traps, and debugging messages to the local console.
  • Page 26: Information Output Format

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Trap output severity Debugging message output status Debugging message severity 3.2.5 Information Output Format Output format of logs Figure 3-2 shows the format of logs.
  • Page 27 Time Zone field of the display clock command output. HostName Host name. Huawei identifier. The log is output by Huawei products. Version number. Version number of the log. ModuleNam Module name. Name of the module that outputs information to the information center.
  • Page 28: Applications

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Field Description Remarks TimeStamp Timestamp, that is, Five timestamp formats are available: time to output log l boot: indicates that the timestamp is information. expressed in the format of relative time, a period of time since system start.
  • Page 29 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration a log file, and the log file needs to be transferred to the FTP server. The logs help an administrator learn the device running status or troubleshoot the device.
  • Page 30: Default Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Outputting Debugging Messages to the Console As shown in Figure 3-7, the information center is configured on the device. The information center sends debugging messages to the console, and the maintenance personnel debugs the device based on the debugging messages.
  • Page 31 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Table 3-7 Default output rules Output Module Trap Debugging Channe Enable Message d to Status Lowest Status Lowest Status Lowest Output Output Output Output Inform...
  • Page 32: Configuring Information Center

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Output Module Trap Debugging Channe Enable Message d to Status Lowest Status Lowest Status Lowest Output Output Output Output Inform Severit Severit Severit ation default...
  • Page 33: Enabling The Information Center

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Configuration Description Remarks Task 3.5.1.4 (Optional) To adjust the time format and time Setting the precision for information output, Timestamp configure the timestamp. Format of Logs 3.5.1.5...
  • Page 34: Optional) Naming An Information Channel

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.5.1.2 (Optional) Naming an Information Channel Context You can rename channels, which facilitates memorization and usage. NOTE Channel names must be unique. It is recommended that channel names represent channel functions.
  • Page 35: Optional) Setting The Timestamp Format Of Logs

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration filtering condition to any channel. As a result, all output directions cannot receive the specified logs. Procedure Step 1 Run: system-view The system view is displayed.
  • Page 36: Configuring The Device To Output Logs To The Log Buffer

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.5.1.5 Configuring the Device to Output Logs to the Log Buffer Context To view logs in the log buffer, configure the device to output logs to the log buffer.
  • Page 37 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: info-center logfile channel { channel-number | channel-name } A channel through which logs are output to a log file is specified.
  • Page 38: Configuring The Device To Output Logs To The Console

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.5.1.7 Configuring the Device to Output Logs to the Console Context After logs are output to the console, you can view logs on the console (host from which you can log in to the device through the console interface) to monitor device running.
  • Page 39: Configuring The Device To Output Logs To A Log Host

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: info-center monitor channel { channel-number | channel-name } A channel through which logs are output to a user terminal is specified.
  • Page 40: Checking The Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run the following command as required. l Run: info-center loghost ip-address [ channel { channel-number | channel-name } |...
  • Page 41: Configuring Trap Output

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Run the display logbuffer command to check logs recorded in the log buffer. Run the display logfile file-name [ offset | hex ] command to check the log file.
  • Page 42: Enabling The Information Center

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Name Description Remarks 3.5.2.6 Configuring the After traps are output to a Device to Output Traps log file, you can download to a Log File...
  • Page 43: Optional) Naming An Information Channel

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.5.2.2 (Optional) Naming an Information Channel Context You can rename channels, which facilitates memorization and usage. NOTE Channel names must be unique. It is recommended that channel names represent channel functions.
  • Page 44: Optional) Setting The Timestamp Format Of Traps

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration filtering condition to any channel. As a result, all output directions cannot receive the specified traps. Procedure Step 1 Run: system-view The system view is displayed.
  • Page 45: Configuring The Device To Output Traps To The Trap Buffer

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.5.2.5 Configuring the Device to Output Traps to the Trap Buffer Context To view traps in the trap buffer, configure the device to output traps to the trap buffer.
  • Page 46 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: info-center logfile channel { channel-number | channel-name } A channel through which traps are output to a log file is specified.
  • Page 47: Configuring The Device To Output Traps To The Console

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.5.2.7 Configuring the Device to Output Traps to the Console Context After traps are output to the console, you can view traps on the console (host from which you can log in to the device through the console interface) to monitor device running.
  • Page 48: Configuring The Device To Output Traps To A Log Host

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: info-center monitor channel { channel-number | channel-name } A channel through which traps are output to a user terminal is specified.
  • Page 49: Checking The Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration system-view The system view is displayed. Step 2 Run the following command as required. l Run: info-center loghost ip-address [ channel { channel-number | channel-name } |...
  • Page 50: Configuring Debugging Message Output

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Run the display trapbuffer [ size value ] command to check traps recorded in the trap buffer. ----End 3.5.3 Configuring Debugging Message Output Debugging messages of a specific module can be output to the log file, console, terminal, or log host.
  • Page 51: Enabling The Information Center

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Configuration Task Description Remarks 3.5.3.4 Configuring the After debugging Steps 4 to 7 can be Device to Output messages are output to a performed in any...
  • Page 52: Optional) Naming An Information Channel

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration By default, the information center is enabled. ----End 3.5.3.2 (Optional) Naming an Information Channel Context You can rename channels, which facilitates memorization and usage. NOTE Channel names must be unique.
  • Page 53: Optional) Setting The Timestamp Format Of Debugging Messages

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration 3.5.3.3 (Optional) Setting the Timestamp Format of Debugging Messages Context To adjust the time format and time precision for information output, configure the timestamp. Procedure...
  • Page 54: Configuring The Device To Output Debugging Messages To The Console

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Step 4 (Optional) Run: info-center logfile path path The path where log files are saved is specified. NOTE By default, log files are stored in the flash memory.
  • Page 55: Configuring The Device To Output Debugging Messages To The Terminal

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration A rule for outputting debugging messages to a channel is set. By default, channel 0 is enabled to output debugging messages and the lowest severity is debugging.
  • Page 56: Configuring The Device To Output Debugging Messages To The Log Host

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration quit Return to the user view. Step 5 Run: terminal monitor Display of logs, traps, and debugging message output is enabled on the user terminal.
  • Page 57: Checking The Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Step 3 Run: info-center source { module-name | default } channel { channel-number | channel- name } debug { state { off | on } | level severity } A rule for outputting debugging messages to a channel is set.
  • Page 58: Monitoring The Information Center

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Procedure To clear the statistics of the information center, run the reset info-center statistics command in the user view. To clear the statistics in the log buffer, run the reset logbuffer command in the user view.
  • Page 59 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Configuration Roadmap The configuration roadmap is as follows: Enable the information center. Configure a channel and a rule for outputting logs to a log file so that logs are saved in the log file.
  • Page 60: Example For Outputting Logs To A Log Host

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration channel number: 1, channel name: monitor SNMP Agent: channel number: 5, channel name: snmpagent Log buffer: enabled max buffer size: 1024, current buffer size: 512...
  • Page 61 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Figure 3-9 Networking diagram for outputting logs to a log host 10.1.1.2/24 10.1.1.1/24 Server1 Server 3 GE1/0/0 172.16.0.1/24 Router Server 4 Server 2 10.2.1.2/24 10.2.1.1/24...
  • Page 62 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration [Router] info-center loghost source gigabitethernet 1/0/0 Step 4 Configure the log host on the server. The Router can generate many logs, which may exceed the limited storage space of the Router.
  • Page 63: Example For Outputting Traps To The Console

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration info-center loghost 10.1.1.1 channel 6 info-center loghost 10.2.1.1 channel 7 info-center loghost 10.1.1.2 channel 6 info-center loghost 10.2.1.2 channel 7 interface GigabitEthernet1/0/0 undo portswitch ip address 172.16.0.1 255.255.255.0 ip route-static 10.1.1.0 255.255.255.0 172.16.0.2...
  • Page 64 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 3 Information Center Configuration Step 3 Enable terminal display. <Router> terminal monitor Info: Current terminal monitor is on. <Router> terminal debugging Info: Current terminal debugging is on. Step 4 Debug the ARP module.
  • Page 65: Ntp Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration NTP Configuration About This Chapter Network Time Protocol (NTP) synchronizes time among a set of distributed time servers and clients. 4.1 NTP Overview This section describes the definition, purpose, and version evolution of NTP.
  • Page 66: Ntp Overview

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration 4.1 NTP Overview This section describes the definition, purpose, and version evolution of NTP. Definition The Network Time Protocol (NTP) is an application layer protocol in the TCP/IP protocol suite.
  • Page 67: Principles

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Date Proto Description Septemb NTPv2 supports authentication and control messages. er 1989 1119 March NTPv3 uses correctness principles and improves clock selection 1992 1305 and filter algorithms, and it is widely used.
  • Page 68 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-1 Diagram of NTP implementation NTP packet 10:00:00am Step1: RouterA RouterB NTP packet 10:00:00am 11:00:01am Step2: RouterA RouterB 11:00:01am NTP packet 10:00:00am 11:00:02am Step3: RouterA...
  • Page 69: Network Architecture

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration 4.2.2 Network Architecture The NTP network architecture involves the following concepts: Synchronization subnet consists of the primary time server, secondary time servers, PC clients, and interconnecting transmission paths, as shown in Figure 4-2.
  • Page 70: Operating Mode

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration When faults occur in one or more primary/secondary time servers or network paths interconnecting them, the synchronization subnet will automatically be reconstructed into another hierarchical-master-slave structure to obtain the most precise and reliable time.
  • Page 71 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-3 Unicast Client/Server Mode Client Server C l o c k s y n c h r o n i z a t i o n p a c k e t s (mode3)...
  • Page 72 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-4 Peer mode Symmetric passive peer Symmetric active peer Interaction of clock synchronization packets (mode3 and mode4) Clock synchronization packets Automatically work in symmetric (mode1)
  • Page 73 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-5 Broadcast mode Broadcast Server Broadcast Client P e r i o d i c a l l y b r o a d c a s t c l o c k...
  • Page 74 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-6 Multicast mode Multicast server Multicast client P e r i o d i c m u l t i c a s t c l o c k...
  • Page 75: Ntp Access Control

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration NOTE In NTP implementation, a peer structure is established for each synchronization source, and these peer structures are stored in a chain in a Hash form. Each peer structure is corresponding to a connection.
  • Page 76: Application

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration When a server receives a large number of client access packets within a specified period of time and cannot bear the load, the KOD function can be enabled on the server to perform access control.
  • Page 77: Typical Application

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Typical Application On the network as shown in Figure 4-8, RouterA accessing a standard clock is used as the NTP master clock server to achieve synchronization of clocks on the entire network. RouterA is configured as the unicast server, and RouterB, RouterC and RouterD are configured as unicast clients.
  • Page 78: Default Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-9 NTP application in VPN networking CE A CE B VPN2 VPN2 NTP Client NTP Server CE C CE D VPN1 VPN1 4.4 Default Configuration This section describes the default system configuration and default parameters.
  • Page 79: Configuring An Ntp Primary Clock

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Configuration Procedure Basic NTP configuration contains the configuration of the NTP primary clock and operating mode. 4.5.1.1 Configuring an NTP primary clock Context A device on the network can synchronize its clock in the following manners.
  • Page 80: Configuring Ntp Operating Modes

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-10 NTP synchronization subnet RouterA Stratum1 RouterB Stratum2 RouterC Stratum3 Synchronization direction NOTE After the local clock is configured as the reference clock, the local device can be used as the clock source to synchronize other devices on the network.
  • Page 81 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Operating Usage Scenario Deployment Location Mode and Synchronization Direction Unicast The unicast client/server mode is used on a You need to configure only client/server higher stratum on a synchronization subnet.
  • Page 82 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration NOTE If a source address from which NTP packets are sent is specified on the server, the address must be the same as the server IP address configured on the client. Otherwise, the client cannot process the NTP packets sent by the server, resulting in failed clock synchronization.
  • Page 83 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Run: system-view The system view is displayed. Run: – ntp-service unicast-peer ip-address [ version number | authentication- keyid key-id | maxpoll max-number | minpoll min-number | source-...
  • Page 84 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration The interface for receiving NTP broadcast packets is specified, and the interface view is displayed. Run: ntp-service broadcast-client The local industrial switch router is configured as the NTP broadcast client.
  • Page 85: Checking The Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Configure the NTP manycast server. Run: system-view The system view is displayed. Run: interface interface-type interface-number The interface for receiving NTP manycast packets is specified, and the interface view is displayed.
  • Page 86: Configuring The Local Source Interface For Sending And Receiving Ntp Packets

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration 4.5.2 Configuring the Local Source Interface for Sending and Receiving NTP Packets You can configure a local source interface for sending and receiving NTP packets to prevent the IP addresses of other interfaces on the device becoming the destination address of a reply packet.
  • Page 87: Configuring Ntp Access Control

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Context In both unicast client/server mode and symmetric peer mode, command lines are used to establish a connection, which is a static session. Dynamic sessions are established in broadcast mode, manycast mode and multicast mode, so that the limit on the number of local dynamic sessions takes effect.
  • Page 88: Disabling The Ntp Service Function

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration An unreliable clock server exists on the interface. After the NTP function is enabled, all interfaces can receive NTP packets by default. However, an unreliable clock source makes NTP clock data inaccurate.
  • Page 89: Configuring Ntp Access Control Authority

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration 4.5.4.3 Configuring NTP Access Control Authority Context NTP access control is a simple security measure. When an access request reaches the local end, the access request is successively matched with the access authority from the highest one to the lowest one.
  • Page 90 The system view is displayed. Step 2 Configure the basic ACL. Before configuring the access control authority, you must create a basic ACL. For the creation procedure, see "ACL Configuration" in the Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide-Security. Step 3 Run:...
  • Page 91: Configuring Kod

    By default, the KOD function is disabled. Step 3 Configure the basic ACL. Before configuring the access control authority, you must create a basic ACL. For the creation procedure, see "ACL Configuration" in the Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide-Security. Step 4 Run: ntp-service access limited { acl-number | ipv6 acl6-number } Control on the rate of incoming NTP packets is enabled.
  • Page 92: Configuring Ntp Authentication

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration ntp-service discard { min-interval min-interval-val | avg-interval avg-interval- val } The minimum inter-packet interval and the average inter-packet interval of NTP are configured. By default, the minimum inter-packet interval of NTP is set to the first power of 2 in seconds, namely, 2 seconds, and the average inter-packet interval of NTP is set to the fifth power of 2 in seconds, namely, 32 seconds.
  • Page 93: Checking The Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration NOTE l Note that MD5 encryption algorithm cannot ensure security. HMAC-SHA256 encryption algorithm is recommended. l To improve password security, the password must be a combination of at least two of the following: digits, lowercase letters a to z, uppercase letters A to Z, and special characters, and the password length must be equal to or larger than 6.
  • Page 94: Configuration Examples

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Check the status information of NTP. Run: display ntp-service sessions [ verbose ] All session information maintained by the local NTP service is checked. Run: display ntp-service trace The path from the local device to the reference clock source is checked.
  • Page 95 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration The NTP unicast server/client mode is used to synchronize the clocks of RouterA and RouterB. RouterA functions as the server, and RouterB functions as the client.
  • Page 96 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration # Specify RouterA as the NTP server of RouterB, and use the configured authentication key. [RouterB] ntp-service unicast-server 10.2.2.2 authentication-keyid 42 Step 4 # Specify on RouterC that RouterB functions as the NTP server of RouterC.
  • Page 97 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration [RouterD] display ntp-service status clock status: synchronized clock stratum: 4 reference clock ID: 10.0.0.1 nominal frequency: 60.0002 Hz actual frequency: 60.0002 Hz clock precision: 2^18 clock offset: 3.8128 ms root delay: 31.26 ms...
  • Page 98: Example For Configuring Ntp Symmetric Peer Mode

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration network 10.0.0.0 0.0.0.255 network 10.0.1.0 0.0.0.255 ntp-service authentication enable ntp-service authentication-keyid 42 authentication-mode hmac-sha256 cipher %@% @,1_MBtq@`IsY6$XkI|J<"6P(%@%@ ntp-service reliable authentication-keyid 42 ntp-service unicast-server 10.2.2.2 authentication-keyid 42...
  • Page 99 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Figure 4-12 Networking diagram for configuring the symmetric peer mode RouterC GE1/0/0 10.0.0.1/24 GE1/0/0 GE1/0/0 10.0.0.2/24 10.0.0.3/24 RouterE RouterD Configuration Roadmap As is required by the user, the NTP protocol is used to synchronize clocks. The configuration roadmap is as follows: Configure the local clock of RouterC as the NTP primary clock.
  • Page 100 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration # Check the NTP status of RouterD, and you can find that the clock status is "synchronized", indicating that the synchronization is complete. The stratum of the clock is 3, which is one stratum lower than that of the clock of RouterC.
  • Page 101: Example For Configuring Authenticated Ntp Broadcast Mode

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Configuration file of RouterD sysname RouterD interface GigabitEthernet1/0/0 undo portswitch ip address 10.0.0.2 255.255.255.0 ntp-service unicast-server 10.0.0.1 return Configuration file of RouterE sysname RouterE interface GigabitEthernet1/0/0 undo portswitch ip address 10.0.0.3 255.255.255.0...
  • Page 102 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Configure RouterC as the NTP broadcast server that sends broadcast packets from interface GE1/0/0. Configure RouterA, RouterD and RouterF as NTP broadcast clients. RouterA uses interface GE1/0/0 to listen to the broadcast packets.
  • Page 103 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration [RouterD] interface gigabitethernet 1/0/0 [RouterD-GigabitEthernet1/0/0] ntp-service broadcast-client [RouterD-GigabitEthernet1/0/0] quit After the configuration is complete, RouterD synchronizes its clock to that of RouterC. For details about the configuration of RouterF, which is similar to that of RouterC, see the corresponding configuration file.
  • Page 104: Example For Configuring Ntp Multicast Mode

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration @,1_MBtq@`IsY6$XkI|J<"6P(%@%@ ntp-service reliable authentication-keyid 16 return Configuration file of RouterC sysname RouterC interface GigabitEthernet1/0/0 undo portswitch ip address 10.3.1.31 255.255.255.0 ntp-service broadcast-server authentication-keyid 16 ntp-service authentication enable ntp-service authentication-keyid 16 authentication-mode hmac-sha256 cipher %@% @,1_MBtq@`IsY6$XkI|J<"6P(%@%@...
  • Page 105 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration The clocks of all industrial switch routers on the network need to be synchronized to the standard clock. Figure 4-14 Networking diagram for configuring NTP multicast mode GE1/0/0 10.1.1.2/24...
  • Page 106 Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration Step 3 Configure the NTP multicast client RouterB on a network segment the same as that of the NTP server. # Configure RouterB as the NTP multicast client that listens to the NTP multicast packets from interface GE1/0/0.
  • Page 107: Reference

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 4 NTP Configuration interface GigabitEthernet1/0/0 undo portswitch ip address 10.1.1.2 255.255.255.0 ntp-service multicast-client return Configuration file of RouterC sysname RouterC interface GigabitEthernet1/0/0 undo portswitch ip address 10.1.1.3 255.255.255.0 ntp-service multicast-client return 4.8 Reference...
  • Page 108: Fault Management Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration Fault Management Configuration About This Chapter The fault management configuration allows users to collect fault information and locate faults quickly and efficiently at the NMS side.
  • Page 109: Introduction To Fault Management

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration 5.1 Introduction to Fault Management This section describes the definition and functions of fault management. Definition Fault management efficiently manages and reports alarms or events generated on a device in a centralized manner.
  • Page 110: Principles

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration Intermittent alarm: If the interval between the generation time and clearance time of an alarm is shorter than a specified value (called intermittent threshold that is specified based on the products and alarms), the alarm is called an intermittent alarm.
  • Page 111: Alarm Correlation

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration Value Severity Description Indeterminate Indicates that the severity of an alarm cannot be determined. Cleared Indicates that one or more previous alarms have been cleared.
  • Page 112: Default Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration If an alarm is considered as a root-cause alarm, it is suppressed for a period specified by the fault time window. If an alarm is considered as a non-root-cause alarm, it is suppressed for a period specified by the fault time window of its parent alarm.
  • Page 113: Setting The Alarm Severity

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration Pre-configuration Tasks Before configuring alarm management, complete the following task: Powering on the device and ensuring a successful self-check 5.4.1.1 Setting the Alarm Severity Context The system defines default alarm severity for each alarm.
  • Page 114: Configuring The Alarm Reporting Delay Function

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration The alarm severity is displayed. Step 4 Run: alarm-name alarm-name severity severity The alarm severity is changed. The system has defined default alarm severity for each alarm.
  • Page 115: Checking The Configuration

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration 5.4.1.3 Checking the Configuration Context Run the display alarm information [ name alarm-name ] command to view the specified alarm configuration. Run the display this command in the alarm view to view the alarm configuration.
  • Page 116: Maintenance

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration NOTE Run the undo suppression event-name and display event information commands in sequence to view the default period of reporting delay. ----End Checking the Configuration Run the display event information [ name event-name ] command to view the event configuration.
  • Page 117: Monitoring Alarms And Events

    Huawei AR530&AR550 Series Industrial Switch Routers Configuration Guide - Device Management 5 Fault Management Configuration The event view is displayed. Run: clear event all Events on the device are cleared. ----End 5.5.2 Monitoring Alarms and Events Procedure Monitoring alarms – Run: display alarm active Active alarms on the device are displayed.

This manual is also suitable for:

Ar550 series

Table of Contents