Huawei AR150 Series Configuration Manual
Hide thumbs Also See for AR150 Series:
Table of Contents

Advertisement

Huawei AR150&200&1200&2200&3200 Series
Enterprise Routers
V200R003C01
Configuration Guide - Device
Management
Issue
05
Date
2014-01-16
HUAWEI TECHNOLOGIES CO., LTD.

Advertisement

Table of Contents
loading

Summary of Contents for Huawei AR150 Series

  • Page 1 Huawei AR150&200&1200&2200&3200 Series Enterprise Routers V200R003C01 Configuration Guide - Device Management Issue Date 2014-01-16 HUAWEI TECHNOLOGIES CO., LTD.
  • Page 2 All other trademarks and trade names mentioned in this document are the property of their respective holders. Notice The purchased products, services and features are stipulated by the contract made between Huawei and the customer. All or part of the products, services and features described in this document may not be within the purchase scope or the usage scope.
  • Page 3: About This Document

    NOTICE is used to address practices not related to personal injury. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 4: Command Conventions

    Interface numbers used in this manual are examples. In device configuration, use the existing interface numbers on devices. Change History Changes between document issues are cumulative. Therefore, the latest document version contains all updates made to previous versions. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 5 Example for Configuring Auto-Config on the Same Network Segment Example for Configuring Auto-Config on Different Network Segments 4.5.1 Example for Configuring Alarm Management Changes in Issue 01 (2013-01-31) Initial commercial release. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 6: Table Of Contents

    2.8 Backing Up Electronic Labels............................17 2.9 Forcing the RPS to Supply Power for the Device......................17 3 Information Center Configuration...................19 3.1 Information Center Overview............................20 3.2 Principles..................................20 3.2.1 Information Classification............................20 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 7 3.6.3.6 Configuring the Device to Output Debugging Messages to the Terminal.............58 3.6.3.7 Configuring the Device to Output Debugging Messages to the Log Host.............59 3.6.3.8 Checking the Configuration............................60 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 8 4.5.1 Example for Configuring Alarm Management......................81 4.6 References..................................83 5 NTP Configuration........................85 5.1 NTP Overview................................86 5.2 Principles..................................87 5.2.1 Operating Principle..............................87 5.2.2 Network Architecture..............................89 5.2.3 Operating Mode.................................90 5.2.4 NTP Access Control..............................95 5.3 Application...................................97 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 9 6.6.4 Configuring PoE Power-on and Power-off Management..................139 6.6.5 Checking the Configuration.............................141 6.7 Configuration Examples.............................141 6.7.1 Example for Configuring PoE..........................141 6.8 FAQ....................................143 6.8.1 What Is the PoE Output Voltage of AR1200 Series?....................144 Issue 05 (2014-01-16) Huawei Proprietary and Confidential viii Copyright © Huawei Technologies Co., Ltd.
  • Page 10: Displaying The Device Status

    You can use the display commands to view the configuration and status of a specified interface. 1.11 Displaying Electronic Labels You can use the display commands to view electronic labels. 1.12 Displaying the Current Configuration Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 11 You can use the display commands to view the health status of the device. 1.15 Displaying the Board Working Mode You can use the display commands to view the board working mode. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 12: Displaying Information About The Device

    You can view version information about the device to determine whether the device needs to be upgraded or whether the upgrade succeeds. Procedure Run: display version [ slot slot-id ] Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 13: Displaying Power Supply Information

    The information about the power of the device is displayed. ----End 1.6 Displaying the Temperature You can use the display commands to view the temperature of the device. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 14: Displaying Fan Status

    BGP route flapping, frequent VRRP active/standby switchover, and even failed device login. You can use the display commands to view CPU usage statistics and configurations to check whether devices are working properly. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 15: Displaying Memory Usage

    [ slot slot-id ] The memory usage statistics is displayed. Run: display memory-usage threshold [ all | slot slot-id ] The memory usage threshold is displayed. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 16: Displaying Interface Status

    The status of the specified interface is displayed. Method 2: Run: system-view The system view is displayed. Run: interface interface-type interface-number The interface view is displayed. Run: display this interface Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 17: Displaying Electronic Labels

    The information of the current configuration is displayed. ----End 1.13 Displaying Diagnostic Information You can use the display commands to view diagnostic information for fault location. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 18: Displaying Health Status

    Only the work mode of the boards with configurable work modes can be displayed. The working mode of the following interface cards can be changed: 1E1T1-M/2E1T1-M/4E1T1- M/8E1T1-M, 1E1T1-F/2E1T1-F/4E1T1-F/8E1T1-F, 4G.SHDSL, VDSL2, 1CPOS-155M and 2BST. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 19 The display command does not display the board working mode of the AR150&200 series. Procedure Step 1 Run the display workmode { slot slot-id | all } command to view the board working mode. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 20: Hardware Management

    2.9 Forcing the RPS to Supply Power for the Device You can force the redundant power system (RPS) to supply power for the device to ensure normal device running. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 21: Hardware Management Overview

    Boards are hot swappable. Therefore, you do not need to power on or off boards before hot swapping them. The AR150&200 series does not support this function. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 22: Configuring The Alarm Function For Optical Modules

    { enable | disable The optical module alarm function is enabled or disabled. By default, the optical module alarm function is enabled. Configure alarm thresholds for optical modules. Run: system-view Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 23: Configuring The Cpu Usage Alarm Threshold

    When CPU usage falls within this threshold, the system generates a clear alarm. Procedure Step 1 (Optional) Run: display cpu-usage configuration [ slot slot-id ] The CPU usage configurations are displayed. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 24: Configuring The Memory Usage Alarm Threshold

    Step 2 Run: system-view The system view is displayed. Step 3 Run: set memory-usage threshold threshold-value [ slot slot-id ] The memory usage alarm threshold is set. By default: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 25: Configuring The Fan Speed

    By default, the system automatically adjusts the fan speed. NOTE If multiple fans are installed on a fan tray, all the fans run at the speed configured by this command. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 26: Backing Up Electronic Labels

    RPS can supply power for the device in a timely manner to ensure normal device running. When the fault is rectified, the RPS stops supplying power for the device. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 27 The RPS is forced to supply power for the device. By default, the system does not force the RPS to supply power for the device. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 28: Information Center Configuration

    This section provides several configuration examples of the information center, covering networking requirements, configuration notes, and configuration roadmap. 3.9 FAQ This section provides the questions you may encounter during configuration and their answers. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 29: Information Center Overview

    Logs include user logs, and diagnostic logs. l User logs: record user operations and system operating information. l Diagnostic logs: record information used for fault location. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 30: Information Hierarchy

    Notification A key operation is performed to keep the device running normally. For example, the shutdown command is run; a neighbor is discovered; protocol status changes. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 31: Information Output

    The information sent to the log host is output from channel 6 but not channel 2. Table 3-3 lists relationships between default channels and output directions. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 32: Information Filtering

    The content of the information filtering table is as follows: Number of the module that generates information Log output status Log output severity Trap output status Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 33: Information Output Format

    YYYY-MM-DD hh:mm:ss format. l none: indicates that no timestamp is contained in information. Logs use the date format. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 34 Time Zone field of the display clock command output. HostName Host name. Huawei identifier. The log is output by Huawei products. Version number. Version number of the log. ModuleNam Module name. Name of the module that outputs information to the information center.
  • Page 35: Applications

    3-4, the information center is configured on the device, and the device is connected to an FTP server. The information center stores the logs of the specified severity in Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 36 (NMS). The information center sends traps to the NMS, and the NMS monitors the device running status based on the traps. Figure 3-6 Outputting traps to the NMS Internet Router Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 37: Default Configuration

    Default Output Rules of Information Channels Default output rules define information modules to which different types of information can be output, lowest information severity, and information channels. See Table 3-7. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 38 Enabled debuggi Disabled debuggi (channel (all modules default Enabled debuggi Enabled debuggi Disabled debuggi (channel (all modules default Enabled debuggi Enabled debuggi Disabled debuggi (channel (all modules Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 39: Default Configuration

    Default Output Rules of Information Channels Default output rules define information modules to which different types of information can be output, lowest information severity, and information channels. See Table 3-9. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 40 Enabled debuggi Disabled debuggi (channel (all modules default Enabled debuggi Enabled debuggi Disabled debuggi (channel (all modules default Enabled debuggi Enabled debuggi Disabled debuggi (channel (all modules Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 41: Configuring Information Center

    Naming an channels to facilitate information Information center usage. Channel 3.6.1.3 (Optional) If some logs are unnecessary, configure Configuring Log the Router not to output these logs. Filtering Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 42: Enabling The Information Center

    Logs to a Log Host running. 3.6.1.1 Enabling the Information Center Procedure Step 1 Run: system-view The system view is displayed. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 43: Optional) Naming An Information Channel

    Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: info-center channel channel-number name channel-name Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 44: Optional) Configuring Log Filtering

    3.6.1.4 (Optional) Setting the Timestamp Format of Logs Context To adjust the time format and time precision for information output, configure the timestamp. Procedure Step 1 Run: system-view The system view is displayed. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 45: Optional) Disabling The Log Counter Function

    Channel number: 4, Channel name: logbuffer Dropped messages: 0 Overwritten messages: 167 Current messages: 512 May 10 2012 13:42:59+00:00 Huawei %%01DEFD/4/CPCAR_DROP_MPU(l)[0]:Some packets are dropped by cpcar on the MPU. (Packet-type=arp-request, Drop- Count=912) May 10 2012 13:32:59+00:00 Huawei %%01DEFD/4/CPCAR_DROP_MPU(l)[1]:Some packets are dropped by cpcar on the MPU.
  • Page 46: Configuring The Device To Output Logs To The Log Buffer

    { module-name | default } channel { channel-number | channel- name } log { state { off | on } | level severity } A rule for outputting logs to a channel is set. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 47: Configuring The Device To Output Logs To A Log File

    By default, channel 9 is enabled to output logs and the lowest log severity is debugging. Step 4 (Optional) Run: info-center logfile path path The path where log files are saved is specified. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 48: Configuring The Device To Output Logs To The Console

    { channel-number | channel-name } A channel through which logs are output to the console is specified. By default, the device uses channel 0 to output logs to the console. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 49: Configuring The Device To Output Logs To A Terminal

    } log { state { off | on } | level severity } A rule for outputting logs to a channel is set. By default, channel 1 is enabled to output logs and the lowest log severity is warning. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 50: Configuring The Device To Output Logs To A Log Host

    By default, the device does not output logs to a log host. The device supports a maximum of eight log hosts to implement backup among log hosts. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 51: Checking The Configuration

    SNMP agent. Pre-configuration Tasks Before enabling trap output, complete the following task: Starting the Router Configuration Process Table 3-12 lists the configuration process for enabling trap output. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 52 Terminal view traps on the user terminal (host from which you log in to the Router through STelnet) to monitor device running. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 53: Enabling The Information Center

    The information center is enabled. By default, the information center is enabled. ----End 3.6.2.2 (Optional) Naming an Information Channel Context You can rename channels, which facilitates memorization and usage. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 54: Optional) Configuring Trap Filtering

    As a result, all output directions cannot receive the specified traps. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 55: Optional) Setting The Timestamp Format Of Traps

    3.6.2.5 Configuring the Device to Output Traps to the Trap Buffer Context To view traps in the trap buffer, configure the device to output traps to the trap buffer. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 56: Configuring The Device To Output Traps To A Log File

    Information can be saved in file format only when the device has storage media such as the USB disk or SD card. Procedure Step 1 Run: system-view The system view is displayed. Step 2 Run: info-center logfile channel { channel-number | channel-name } Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 57 By default, a maximum of 200 log files can be saved. If the number of log files generated on the Router exceeds the limit, the system deletes the oldest log file. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 58: Configuring The Device To Output Traps To The Console

    After traps are output to a user terminal, you can view traps on the user terminal (host from which you log in to the device through Telnet) to monitor device running. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 59: Configuring The Device To Output Traps To A Log Host

    After configuring the device to output traps to a log host, you can view traps saved on the log host to monitor device running. Pre-configuration Tasks There is a reachable route between the device and the log host. Procedure Step 1 Run: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 60: Configuring The Device To Output Traps To An Snmp Agent

    NMS server, configure the device to output traps to an SNMP agent. Then the SNMP agent sends traps to the NMS server. Procedure Step 1 Run: system-view Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 61: Checking The Configuration

    The SNMP agent can work properly and receive traps only when the SNMP agent function is enabled. NOTE For details on how to configure the SNMP agent, see SNMP Configuration in the Huawei AR150&200&1200&2200&3200 Series Enterprise Routers Configuration Guide - Network Management.
  • Page 62: Configuration Process

    You can view the Log File download the log file debugging messages in anytime to monitor device the console or terminal. running based on debugging messages. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 63: Enabling The Information Center

    Step 1 Run: system-view The system view is displayed. Step 2 Run: info-center enable The information center is enabled. By default, the information center is enabled. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 64: Optional) Naming An Information Channel

    A name is configured for the information channel with the specified number. ----End 3.6.3.3 (Optional) Setting the Timestamp Format of Debugging Messages Context To adjust the time format and time precision for information output, configure the timestamp. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 65: Configuring The Device To Output Debugging Messages To The Log File

    By default, channel 9 is disabled to output debugging messages and the lowest severity is debugging. Step 4 (Optional) Run: info-center logfile path path The path where log files are saved is specified. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 66: Configuring The Device To Output Debugging Messages To The Console

    A channel used by the device to output debugging messages to the console is specified. By default, the device uses channel 0 to output debugging messages to the console. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 67: Configuring The Device To Output Debugging Messages To The Terminal

    { module-name | default } channel { channel-number | channel- name } debug { state { off | on } | level severity } A rule for outputting debugging messages to a channel is set. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 68: Configuring The Device To Output Debugging Messages To The Log Host

    } | facility local-number | { language language-name | binary [ port ] } ] The device is configured to output debugging messages to the IPv6 log host. By default, the device does not output debugging messages to a log host. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 69: Checking The Configuration

    This section describes how to maintain the information center. 3.7.1 Clearing Statistics Context NOTICE Statistics of the information center cannot be restored after you clear them. Exercise caution when running the commands. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 70: Monitoring The Information Center

    FTP cannot secure secure file transfer. SFTP is recommended on networks that require high security. Figure 3-8 Networking diagram for outputting logs to the log file 10.2.1.1/16 GE1/0/0 Network RouterA FTP Server 10.1.1.1/16 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 71 FTP: 2761463 byte(s) sent in 26.062 second(s) 105.95Kbyte(s)/sec. [RouterA-ftp] quit Step 4 Verify the configuration. # View information recorded by the channel. <RouterA> display info-center Information Center: enabled Log host: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 72: Example For Outputting Logs To A Log Host

    3-9, the Router connects to four log hosts. Log hosts are required to have reliability and receive logs of different types so that the network administrator can monitor logs generated by different modules on the Router. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 73 [Router] info-center source ppp channel loghost2 log level warning [Router] info-center source aaa channel loghost2 log level warning Step 3 Specify the source interface for sending logs. # Specify the source interface for sending logs. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 74 IP channel 6 log level notification info-center source PPP channel 7 log level warning info-center source AAA channel 7 log level warning info-center loghost source GigabitEthernet1/0/0 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 75: Example For Outputting Traps To The Snmp Agent

    [Router] info-center snmp channel channel7 # Configure a rule for outputting traps to the SNMP agent. [Router] info-center source ip channel channel7 trap level informational state on Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 76 ENABLE TRAP_LEVEL ENABLE DEBUG_LEVEL ffff0000 default debugging debugging debugging c16a0000 IP debugging informational N debugging # View traps output to the NMS station by the SNMP agent. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 77: Example For Outputting Traps To The Console

    %$%$sqZd.Z5;=9}%}USLx>3D,!HA%$%$ snmp-agent sys-info version v2c snmp-agent target-host trap-hostname nms address 10.1.1.1 udp-port 162 trap- paramsname trapnms snmp-agent target-host trap-paramsname trapnms v2c securityname huawei@123 snmp-agent trap enable snmp-agent info-center source IP channel 7 trap level informational info-center snmp channel 7 interface GigabitEthernet1/0/0 ip address 10.1.1.2 255.255.255.0...
  • Page 78: Faq

    Configuration file of the Router sysname Router info-center source ARP channel 0 return 3.9 FAQ This section provides the questions you may encounter during configuration and their answers. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 79: Why Cannot Command Line Operation Logs Be Displayed In The Log Buffer And How Can These Logs Be Displayed In The Log Buffer

    The default destination UDP port number is 162. To ensure secure communication between the NMS and managed devices, run the udp-port command to change the UDP port number to a non-well- known port number. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 80: Fault Management Configuration

    This section describes fault management configurations based on the configuration flowchart, including networking requirements, configuration roadmap, and configuration procedure. 4.6 References This topic lists the references of fault management. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 81: Introduction To Fault Management

    Non-root-cause alarms are caused by the root-cause alarm. For example, an unreachable route is caused by the interface fault. The alarm generating due to the unreachable route is a non-root-cause alarm. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 82: Principles

    Warning Indicates that a potential or impending service-affecting fault is detected before any significant effects have been felt. Take corrective actions to diagnose and rectify the fault. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 83: Alarm Correlation

    – Persistent Event: An alarm enters the active alarm queue. – Filtered Out: An alarm and its clear alarm are both deleted from the active alarm queue. The process of alarm correlation analysis is as follows: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 84: Default Configuration

    4.4 Configuring Fault Management This section describes how to configure fault management. 4.4.1 Configuring Alarm Management Alarm management includes setting alarm severities, alarm correlation suppression, and enabling alarm reporting delay. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 85: Setting The Alarm Severity

    Step 1 Run: system-view The system view is displayed. Step 2 Run: alarm The alarm view is displayed. Step 3 (Optional) Run: display alarm information [ name alarm-name ] Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 86: Configuring The Alarm Reporting Delay Function

    The delay in reporting alarms is displayed. Step 5 (Optional) Run: suppression alarm-name alarm-name cause-period cause-seconds The delay in reporting alarms is configured. The system defines a default delay in reporting alarms. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 87: Configuring Alarm Correlation Suppression

    Alarm correlation suppression based on the NMS IPv6 address is enabled. By default, NMS-based alarm correlation suppression is enabled. l Configuring interface-based alarm correlation suppression Run: mask interface interface-type interface-number Interface-based alarm correlation suppression is enabled. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 88: Checking The Configuration

    By default, the event reporting delay function is enabled. Step 4 (Optional) Run: display event information [ name event-name ] The period of delay in reporting events is displayed. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 89: Maintenance

    The system view is displayed. Run: alarm The alarm view is displayed. Run: clear alarm active { all | sequence-number sequence-number Active alarms on the device are cleared. Clearing events Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 90: Monitoring Alarms And Events

    4-2, the route between the device and the NMS is reachable. Users want to view alarms generated by the device on the NMS in real time. Users must monitor the LinkDown alarm to ensure the normal interconnection of the device. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 91 NOTE In actual applications, you can select a version of the SNMP protocol based on the network requirements. For details, see SNMP Configuration in the Huawei AR150&200&1200&2200&3200 Series Enterprise Routers Configuration Guide-Network Management. Step 2 Set the severity for the linkDown alarm to major.
  • Page 92: References

    10.1.1.1 udp-port 162 trap- paramsname params snmp-agent target-host trap-paramsname params v3 securityname huawei privacy snmp-agent mib-view linnkdown include linkDown snmp-agent usm-user v3 user huawei authentication-mode md5 9807A25AE2748D1E4112F703C8B2333B privacy-mode aes128 9807A25AE2748D1E411...
  • Page 93 Document Description Remarks X.733 CCITT standards for – information technology– Open system interconnection–System management: alarm reporting function G.7710 ITU-T standards for common – equipment management function requirements Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 94: Ntp Configuration

    This topic provides configuration examples of NTP together with the configuration flowchart. The configuration examples explain networking requirements, configuration notes, and configuration roadmap. 5.8 Reference This section lists references of NTP. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 95: Ntp Overview

    Date Proto Description June NTPv1 puts forward complete NTP rules and algorithms for the 1988 1059 first time, but it does not support authentication and control messages. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 96: Principles

    RouterB. It takes one second to unidirectionally transmit an NTP message between RouterA and RouterB. Both RouterA and RouterB take one second to process an NTP message. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 97 The preceding example is only a brief description of the operating principle of NTP. In fact, NTP uses the standard algorithms in RFC 1305 to ensure the precision of clock synchronization. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 98: Network Architecture

    NOTE When the synchronization subnet has multiple primary time servers, the optimal server can be selected using an algorithm. Such a design ensures that: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 99: Operating Mode

    Usually, the host running in server mode is a clock server on a network. It provides synchronization information for clients but does not change its own clock. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 100 The passive peer can provide time information about the local clock for its peer, or synchronize the time information about the local clock based on that of the peer clock. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 101 This allows the client to obtain the network delay between the client and the server. Then, the client returns the broadcast mode, and continues to sense the incoming clock synchronization packets to synchronize the local clock. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 102 Then, the client returns the multicast mode, and continues to sense the incoming multicast packets to synchronize the local clock. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 103 Then the client repeats the preceding process. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 104: Ntp Access Control

    Only a control query can be performed on the local clock. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 105 ID and a decryption algorithm. If the authentication fails, the system directly discards the packet. If the authentication succeeds, the system processes the received packet. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 106: Application

    VPN 2. CE B is used as an NTP unicast server, CE A is used as an NTP unicast client, and NTP time synchronization can be implemented between CE B and CE A. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 107: Default Configuration

    Before the basic NTP functions are configured, complete the following task: Configuring the network layer address and routing protocol of an interface to ensure that NTP packets can reach the destination. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 108: Configuring An Ntp Primary Clock

    RouterB is synchronized with RouterA, RouterC can synchronize its clock with the clock of RouterB. After all the devices on the synchronization subnet are synchronized, RouterB and RouterC are respectively stratum2 and stratum3. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 109: Configuring Ntp Operating Modes

    The local clock is configured as the NTP primary clock. By default, no NTP primary clock is specified. ----End 5.5.1.2 Configuring NTP Operating Modes Context The following NTP operating modes are supported by a device: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 110 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 111 Configure the symmetric active peer. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 112 The local router is configured as the NTP broadcast server. To specify the parameter authentication-keyid, see 5.5.4.5 Configuring Authentication. Configure the NTP broadcast client. Run: system-view The system view is displayed. Run: interface interface-type interface-number Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 113 Run: ntp-service multicast-client [ ip-address | ipv6 [ ipv6-address The local router is configured as the NTP multicast client. Manycast Mode Configure the NTP manycast server. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 114: Checking The Configuration

    Run the display ntp-service sessions [ verbose ] command to check the NTP session status. Run the display ntp-service trace command to check the path of reference clock source from the local device. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 115: Configuring The Local Source Interface For Sending And Receiving Ntp Packets

    Excess dynamic sessions limit the number of static sessions. To address this problem, you can limit the number of dynamic sessions on the device. Prerequisites All configurations of basic NTP functions have been completed. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 116: Configuring Ntp Access Control

    5.5.4.1 Disabling a Specified Interface from Receiving NTP Packets Context You can disable the interface connected to external devices from receiving NTP packets in the following scenarios: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 117: Disabling The Ntp Service Function

    The system view is displayed. Step 2 Run: undo ntp-service enable The NTP service function on the device is disabled. By default, the NTP service function is enabled. ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 118: Configuring Ntp Access Control Authority

    NTP multicast mode The client is restricted from NTP multicast client synchronizing to the server. NTP broadcast The client is restricted from NTP broadcast client mode synchronizing to the server. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 119: Configuring Kod

    The system view is displayed. Step 2 Configure the basic ACL. Before configuring the access control rights, you must create a basic ACL. For the creation procedure, see "ACL Configuration" in the Huawei AR150&200&1200&2200&3200 Series Enterprise Routers Configuration Guide-Security. Step 3 Run:...
  • Page 120 By default, the KOD function is disabled. Step 3 Configure the basic ACL. Before configuring the access control rights, you must create a basic ACL. For the creation procedure, see "ACL Configuration" in the Huawei AR150&200&1200&2200&3200 Series Enterprise Routers Configuration Guide-Security. Step 4 Run: ntp-service access limited { acl-number | ipv6 acl6-number } Control on the rate of incoming NTP packets is enabled.
  • Page 121: Configuring Ntp Authentication

    Follow-up Procedure After the configuration of the NTP authentication is completed, apply the NTP authentication key in Configuring NTP Operating Modes. That is, specify the parameter authentication-keyid. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 122: Checking The Configuration

    ----End 5.7 Configuration Examples This topic provides configuration examples of NTP together with the configuration flowchart. The configuration examples explain networking requirements, configuration notes, and configuration roadmap. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 123: Example For Configuring Authenticated Ntp Unicast Server/Client Mode

    To ensure successful authentication, configure the NTP client and server properly. Procedure Step 1 According to Figure 5-11, configure IP addresses, and configure reachable routes between any two of RouterA, RouterB, RouterC, and RouterD. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 124 The stratum of the clock is 3, which is one stratum lower than that of the clock of the server RouterA. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 125 2^18 clock offset: 0.0000 ms root delay: 0.00 ms root dispersion: 26.50 ms peer dispersion: 10.00 ms reference time: 12:01:48.377 UTC Mar 2 2012(C7B15D2C.60A15981) ----End Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 126 42 authentication-mode md5 %@%@vYE*2sz:,+4/u! Pbe,_#&@`7%@%@ ntp-service reliable authentication-keyid 42 ntp-service unicast-server 10.0.0.1 authentication-keyid 42 return Configuration file of RouterD sysname RouterD interface GigabitEthernet1/0/0 ip address 10.0.0.3 255.255.255.0 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 127: Example For Configuring Ntp Symmetric Peer Mode

    # Configure an IP address on RouterC. For details about the configurations of RouterD and RouterE, see "Configuration Files". Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 128 ID: 10.0.0.2 nominal frequency: 64.0029 Hz actual frequency: 64.0029 Hz clock precision: 2^7 clock offset: 0.0000 ms root delay: 124.98 ms root dispersion: 0.15 ms Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 129: Example For Configuring Authenticated Ntp Broadcast Mode

    RouterA directly connects to RouterF. RouterC directly synchronize its clock to a standard clock by radio. All routers except RouterA on the LAN are required to synchronize their clocks to the standard clock. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 130 # Configure the local clock of RouterC as the NTP primary clock, and set the clock stratum to <RouterC> system-view [RouterC] ntp-service refclock-master 3 # Enable NTP authentication. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 131 RouterC. [RouterD] display ntp-service status clock status: synchronized clock stratum: 4 reference clock ID: 3.0.1.31 nominal frequency: 60.0002 Hz actual frequency: 60.0002 Hz clock precision: 2^18 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 132 16 authentication-mode md5 %$%$Q1Ub0~;Ga! 9IasE'@Db-,5,#%$%$ ntp-service reliable authentication-keyid 16 return Configuration file of RouterF sysname RouterF interface GigabitEthernet1/0/0 ip address 1.0.1.2 255.255.255.0 interface GigabitEthernet2/0/0 ip address 3.0.1.2 255.255.255.0 ntp-service broadcast-client Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 133: Example For Configuring Ntp Multicast Mode

    <Huawei> system-view [Huawei] sysname RouterA [RouterA] interface gigabitethernet 1/0/0 [RouterA-GigabitEthernet1/0/0] ip address 10.1.1.1 24 [RouterA-GigabitEthernet1/0/0] quit For details about the configurations of RouterB and RouterC, see "Configuration Files". Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 134 24.47 ms root dispersion: 208.39 ms peer dispers ion: 9.63 ms reference time: 12:17:21.773 UTC Mar 7 2012(C7B7F851.C5EAF25B) ----End Configuration Files Configuration file of RouterA sysname RouterA Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 135: Reference

    Network Time Protocol (Version 3) Specification, Implementation and Analysis RFC 5905 Network Time Protocol Version 4: Protocol and Algorithms Specification RFC 5906 Network Time Protocol Version 4: Autokey Specification Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 136: Poe Configuration

    After configuring PoE functions, the device provides power for PDs. 6.7 Configuration Examples This section provides examples for configuring PoE. 6.8 FAQ This section provides the questions you may encounter during configuration and their answers. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 137: Poe Overview

    Works with the Uninterruptible Power Supply (UPS) to provide backup power supply for IP cameras, video servers, and IP phones, and prevents power-off. 6.2 Principles Introduction to PoE PoE involves the following devices: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 138 The PD is removed. l The power consumption of the PD is overloaded or short-circuited. l The power consumption of the PD exceeds the power supply load. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 139 PoE module is installed out of the device) and Endpoint (the PoE module is integrated to device) PSEs. Huawei' PoE modules are Endpoint PSEs. The Endpoint PSE is compatible with 10Base- T, 100Base-TX, and 1000Base-T interfaces. The Endpoint PSE is more widely used than the Midspan PSE.
  • Page 140 3 and 6 for power supply. – 2: Alternative A: The Endpoint PSE use line pairs connected to pins 4 and 5 and pins 7 and 8 for power supply. power class Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 141: Functions Description

    01: indicates the PSE. PSE: l 11: indicates to be reserved. l 10: indicates the backup power supply. l 01: indicates the primary power supply. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 142: Applications

    IP phones and cameras. The PoE function reduces power cables, saves network construction costs, and facilitates access device management because external power supplies are not required. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 143: Configuration Notes

    The device can be configured with the power-off time range to facilitate PD management. PoE Power Supplies Supported by the Device The device supports only one external PoE power supply, and the default power is 100 W. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 144: Default Configuration

    6.6.1 Enabling the PoE Function Context Ensure that the PoE function on the interface is enabled before powering on a PD connected to the interface. Procedure Step 1 Run: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 145: Optional) Configuring The Lldp Power Capacity Negotiation

    If LLDP is enabled globally, by default, LLDP is enabled on each interface. Step 5 Run: lldp tlv-enable dot3-tlv power LLDP is configured to advertise Power Via MDI TLV. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 146: Configuring Poe Power Management

    You can configure the maximum output power of the device to ensure power stability for a PD. Run: system-view The system view is displayed. Run: Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 147 However, if the power consumption exceeds the range, some PDs are powered off. To solve this problem, configure the alarm threshold for the power Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 148: Configuring Poe Power-On And Power-Off Management

    – In automatic mode, configure the power supply priority of the interface. The device powers on or powers off PDs connected to an interface based on the power supply priority of the interface. Run: interface interface-type interface-number Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 149 PD that does not comply with the 802.3af or 802.3at standard. Run: system-view The system view is displayed. Run: interface interface-type interface-number Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 150: Checking The Configuration

    The location makes it difficult to connect power supplies to these devices. The user wants Router to provide power for these devices and save the deployment costs. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 151 Step 3 If IP Phone1 and AP1 respectively requires power of 10 W and 15 W, configure the maximum output power on Ethernet0/0/4 and Ethernet0/0/6. [Router] interface ethernet 0/0/4 [Router-Ethernet0/0/4] poe enable [Router-Ethernet0/0/4] poe power 10000 Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 152: Faq

    10000 interface Ethernet0/0/6 poe priority critical poe power 15000 return 6.8 FAQ This section provides the questions you may encounter during configuration and their answers. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.
  • Page 153: What Is The Poe Output Voltage Of Ar1200 Series

    The PoE output voltage is 48 V. The standard PD converts 48 V voltage into its voltage, and a non-standard PD must connect to a PoE splitter to convert 48 V voltage into its voltage. Issue 05 (2014-01-16) Huawei Proprietary and Confidential Copyright © Huawei Technologies Co., Ltd.

This manual is also suitable for:

Ar1200 seriesAr200 seriesAr2200 seriesAr3200 series

Table of Contents