No part of this document may be reproduced or transmitted in any form or by any means without prior written
consent of Huawei Technologies Co., Ltd.
Trademarks and Permissions
and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd.
All other trademarks and trade names mentioned in this document are the property of their respective
holders.
Notice
The purchased products, services and features are stipulated by the contract made between Huawei and the
customer. All or part of the products, services and features described in this document may not be within the
purchase scope or the usage scope. Unless otherwise specified in the contract, all statements, information,
and recommendations in this document are provided "AS IS" without warranties, guarantees or
representations of any kind, either express or implied.
The information in this document is subject to change without notice. Every effort has been made in the
preparation of this document to ensure accuracy of the contents, but all statements, information, and
recommendations in this document do not constitute a warranty of any kind, express or implied.
Huawei Technologies Co., Ltd.
Address:Huawei Industrial Base
Bantian, Longgang
Shenzhen 518129
People's Republic of China
Website:http://e.huawei.com
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
Intended Audience
This document helps you understand the characteristics and features of the AR.
This document is intended for:
lNetwork planning engineers
About This Document
About This Document
lHardware installation engineers
lCommissioning engineer
lData configuration engineers
lOn-site maintenance engineers
lNetwork monitoring engineers
lSystem maintenance engineers
Symbol Conventions
The symbols that may be found in this document are defined as follows.
Symbol
Description
Indicates an imminently hazardous situation
which, if not avoided, will result in death or
serious injury.
Indicates a potentially hazardous situation
which, if not avoided, could result in death
or serious injury.
Indicates a potentially hazardous situation
which, if not avoided, may result in minor
or moderate injury.
Indicates a potentially hazardous situation
which, if not avoided, could result in
equipment damage, data loss, performance
deterioration, or unanticipated results.
NOTICE is used to address practices not
related to personal injury.
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
SymbolDescription
Security Conventions
lPassword setting
– When configuring a password, the cipher text is recommended. To ensure device
security, change the password periodically.
– When you configure a password in plain text that starts and ends with %@%@, @
%@%, %#%#, or %^%# (the password can be decrypted by the device), the
password is displayed in the same manner as the configured one in the
configuration file. Do not use this setting.
– When you configure a password in cipher text, different features cannot use the
same cipher-text password. For example, the cipher-text password set for the AAA
feature cannot be used for other features.
lEncryption algorithm
Currently, the device uses the following encryption algorithms: 3DES, AES, RSA,
SHA1, SHA2, and MD5. 3DES, RSA and AES are reversible, while SHA1, SHA2, and
MD5 are irreversible. The encryption algorithms DES/3DES/RSA (RSA-1024 or
lower)/MD5 (in digital signature scenarios and password encryption)/SHA1 (in digital
signature scenarios) have a low security, which may bring security risks. If protocols
allowed, using more secure encryption algorithms, such as AES/RSA (RSA-2048 or
higher)/SHA2/HMAC-SHA2, is recommended. The encryption algorithm depends on
actual networking. The irreversible encryption algorithm must be used for the
administrator password, SHA2 is recommended.
lPersonal data
Some personal data may be obtained or used during operation or fault location of your
purchased products, services, features, so you have an obligation to make privacy
policies and take measures according to the applicable law of the country to protect
personal data.
lThe terms mirrored port, port mirroring, traffic mirroring, and mirroring in this manual
are mentioned only to describe the product's function of communication error or failure
detection, and do not involve collection or processing of any personal information or
communication data of users.
About This Document
Calls attention to important information,
best practices and tips.
NOTE is used to address information not
related to personal injury, equipment
damage, and environment deterioration.
Mappings Between Product Software Versions and NMS
Versions
The mappings between product software versions and NMS versions are as follows.
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
1.2.3 Service Integration Capability..................................................................................................................................... 3
2.1 AR530 as a Industrial Router......................................................................................................................................... 5
2.2 AR500 or AR530 as the Industrial Switch..................................................................................................................... 5
2.3 AR2500 Used as the Industrial Switch...........................................................................................................................6
2.4 AR500&AR530 Used as Industrial Gateways............................................................................................................... 8
5 Maintenance and Management................................................................................................ 81
5.1 Various Maintenance Methods..................................................................................................................................... 82
5.1.1 Remote Deployment and Maintenance Using USB.................................................................................................. 82
5.2.2 Routing Service Fault Location.................................................................................................................................83
6 Industry Standards......................................................................................................................84
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
1.1 Product Positioning
The AR500&AR510&AR530&AR550&AR2500 Industrial Switch Routers, developed by
Huawei, is applied to the Internet of Things. It is a next-generation industrial routing gateway
that provides routing, switching, wireless, and security functions. In addition to gateway
functions, the AR500&AR510&AR530&AR550&AR2500 provides various extensions. For
example, it can function as the gateway on the Internet of Things to aggregate data. It applies
to various industries.
The AR500&AR510&AR530&AR550&AR2500 can work stably in challenging industry
environments for a long time, meeting local and remote networking requirements.
1.2 Product Characteristics
The AR500&AR510&AR530&AR550&AR2500 uses leading hardware platforms and
software architectures. The AR500&AR510&AR530&AR550&AR2500 provides integrated
network solutions for enterprises with minimum investment costs; therefore, they can meet
many facets of future business expansion and developments of the Internet of Things.
1 Product Positioning and Characteristics
1.2.1 Industrial Environment Adaptability
As the industrial routing and switching device, the
AR500&AR510&AR530&AR550&AR2500 adapts to various industry environments:
lComplies with IEC 61000-6-2.
lProtection level
– AR500 series: IP30
– AR530 series: IP51
– AR550 series: IP40
– AR2500 series: IP40
lUses fanless design and the operating temperatures are as follows:
– AR500 series operating at maximum LTE transmit power: -25°C to +65°C
– AR500 series operating at typical LTE transmit power:-25°C to +70°C
– AR531-2C-H and AR531-F2C-H: -40°C to +70°C
– AR531GPe-U-H, AR531G-U-D-H:-40°C to +60°C
– AR550 series: -40°C to +70°C
– AR2500 series: -40°C to 65°C
lComplies with transformer substation environment standard IEC61850-3/IEEE1613.
1.2.2 Industry-Class Reliability
lThe AR500&AR510&AR530&AR550&AR2500 complies with industry standards and
provides quality service.
lThe AR500&AR510&AR530&AR550&AR2500 defends against network attacks.
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
lThe AR500&AR510&AR530&AR550&AR2500 supports in-service patching so that the
system software can be upgraded during system operation.
lThe AR500&AR510&AR530&AR550&AR2500 supports fast switching on a data
channel and provides highly reliable networking.
1.2.3 Service Integration Capability
The AR500&AR510&AR530&AR550&AR2500 integrates various services:
lIntegrates routing, switching, and wireless services.
lUses open software architecture to support various industry services.
1.2.4 Hardware Extensibility
The AR500&AR510&AR530&AR550&AR2500 uses the modular design and daughter cards
for communication modules. The daughter cards can be flexibly replaced and extended,
meeting requirements for different services and installation environments.
1 Product Positioning and Characteristics
1.2.5 Remote Maintenance Capability
In addition to one-stop deployment, plug and play capability, and remote commissioning
functions, the AR500&AR510&AR530&AR550&AR2500 manages the customer premises
equipment (CPE) remotely. The remote maintenance function improves efficiency and greatly
reduces maintenance costs.
1.2.6 Strong Access Capability
The AR500&AR530 provide FE, GE, and RS485 interfaces, supports IEC62056 (DLMS/
COSEM), Modbus, DLT645, and PoweRline Intelligent Metering Evolution (PRIME), and
connects to various networks to transmit different industry services, which greatly reduces
investment and maintenance costs.
The AR2500 series supports GE interfaces and the AR2504E-H supports 10GE interfaces.
The AR2500 can connect to downstream terminals and access switches, greatly reducing
investment and maintenance costs.
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
2.1 AR530 as a Industrial Router
As the industrial router, the AR530 can connect a transformer substation to a dispatch center
(monitoring center) through the Internet, and establish a GRE/IPSec VPN or Dynamic Smart
Virtual Private Network (DSVPN) tunnel to secure data transmission. A transformer
substation can also use dedicated lines to connect to a dispatch center on a private network
through an AR530.
As shown in Figure 2-1, the dispatch center connects to the Internet, and transformer
substation A and transformer substation B connect to the Internet through the AR530. A GRE
VPN or IPSec VPN tunnel is established between the dispatch center and transformer
substation A/B so that the dispatch center can communicate with transformer substation A/B
and transformer substations A and B can communicate through the DSVPN tunnel.
You can also use an AR530 to directly connect the transformer substation (for example,
transformer substation C) to the dispatch center through dedicated lines to construct a private
network.
2 Applications
Figure 2-1 AR530 as the industrial router
Dispatch
center
AR530
GRE/IPSEC VPN
AR530
Transformer
substation A
DSVPN
GRE/IPSEC VPN
AR530
AR530
Transformer
substation C
Transformer
substation B
2.2 AR500 or AR530 as the Industrial Switch
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
An AR500 or AR530 can function as a switch in industry fields to implement fast switching
on a data channel, which improves reliability.
In Figure 2-2, highway device access is used as an example.
Router A, Router B, Router C, and Router D are AR500 or AR530s and connected through
GE optical interfaces, constitute an open-ring network, and connect to the aggregation layer
ring network composed of monitoring subcenters. SEP runs on the open-ring network and
ensures fast switching of data channels between the four AR500 or AR530s.
Figure 2-2 AR500 or AR530s as industrial switches
2 Applications
Router A
Monitoring
subcenter
Router B
SEP
Segment
STASTA
APAP
Monitoring
subcenter
Router C
Router D
6×
6×
Video
surveillance
device
Internet
2.3 AR2500 Used as the Industrial Switch
The AR2500 can function as a switch in industry fields. It provides multiple LAN interfaces
to connect to terminals and switches. In Figure 2-3, Router A, Router B, and Router C are all
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
AR2500s and play roles of switches. They connect to the MPLS/IP network through a CE,
and connect to terminals (for example, electrical meters and PCs) and switches.
Figure 2-3 AR2500 used as industrial switches to connect to terminals and access switches
2 Applications
Industrial field
PC
Electrical
meter
Electrical
meter
Electrical
meter
Electrical
meter
PC
Electrical
meter
Switch
PC
Switch
Switch
PC
Router A
Router B
Router C
MPLS/IP
network
CE
An AR2500 can function as a switch in an industry field to implement fast switching on a
data channel, which improves network reliability in the industry field. In Figure 2-4, Router
A through Router I are AR2500s and connected through GE interfaces. They constitute two
ring networks and connects to the substations, power distribution station, and power
distribution cabinet. SEP runs on the ring network and ensures fast switching of data channels
between the AR2500s.
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
Figure 2-4 AR2500s used as industrial switches to implement fast switching of data channels
2 Applications
Main
station
MPLS/IP
Router B
Electrical
meter
Substation
Router C
SEP
Segment
Router A
PCPC
Electrical
meter
Power
distribution
station
Router D
Substation
Router G
Router F
Electrical
meter
Substation
SEP
Segment
Router E
Electrical
2.4 AR500&AR530 Used as Industrial Gateways
As industrial gateways, AR500&AR530 integrate routing, switching, and data collection
functions, which facilitates installation and commissioning, and saves investments.
Router H
Power
distribution
cabinet
Router I
meter
As shown in Figure 2-5, RouterA, RouterB, RouterC, and RouterD, are AR500s or AR530s.
They are used as industrial gateways and provide the following functions:
lRouter: functions as the egress gateway and connects to the remote Head-End with data
collection functions through the Ethernet or 3G/GPRS.
lIoT gateway: RouterA, RouterB, RouterC, and RouterD function as concentrators and
connect to meters using RS485, ZigBee, RF, or PLC to implement remote management.
When the AR500 functions as the IoT gateway, electrical meters can connect to the
AR500 through RS485 only.
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
3 Product Characteristics
FeatureSub-
Feature
IP
routin
IPv4 Static
route
DescriptionDiffer
ence
Basic routing functionsNone
g
SecurityAAAAAA for administrators and access users, including
None
local, RADIUS, and HWTACACS AAA
SecurityLocal attack
Device protection measures, including CPCARNone
defense
SecurityACLTraffic classification based on physical ports, Layer 2
None
information, IP protocols, and TCP/UDP ports.
QoSMQCModular traffic classificationNone
QoSPriority
mapping
QoSTraffic
policing
Mapping between local priorities, 802.1p priorities,
DSCP priorities, and EXP priorities
Single-rate-two-bucket and two-rate-two bucket policy
based on traffic classifiers, permanent virtual circuits
None
None
(PVCs)/VLANs/data link connection identifiers
(DLCIs), and interfaces
QoSTraffic
shaping
Traffic shaping based on traffic classifiers, PVCs/
VLANs/DLCIs, and ports, traffic shaping adaptation,
and three-level traffic shaping
QoSCongestion
management
Congestion management based on traffic classifiers,
PVCs/VLANs/DLCIs, and ports; queue mechanisms
including PQ, WRR, DRR, WFQ, PQ+WRR/PQ
+DRR/PQ+WFQ, and CBQ
QoSCongestion
avoidance
Priority-based weighted random early detection
(WRED) and tail drop
QoSHQoSHierarchical Quality of Service (HQoS) implements
hierarchical scheduling based on queues and
differentiates services and users.
Devic
e
manag
Information
center
monitoring
Managing boards, power supply units, fans, and elabels
ement
Devic
e
Version
management
In-service upgrade, rollback, and patch installationNone
manag
ement
None
None
None
None
None
Devic
e
DeploymentAutomatic deployment using a universal serial bus
(USB) flash drive
manag
ement
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
3 Product Characteristics
FeatureSub-
Feature
Netwo
rk
Ping and
Tracert
manag
ement
Netwo
NTPTime synchronization for traditional IP networksNone
rk
manag
ement
Netwo
rk
Service
Diagnosis
manag
ement
Feature list of AR510 series
Table 3-2 Features supported by the AR510
DescriptionDiffer
ence
Network connectivity detectionNone
The service diagnosis function monitors user status
None
changes and protocol processing during user access and
exports the monitored information to a terminal or
server. Maintenance personnel can refer to and analyze
the monitored information to locate user access faults.
Feature
Sub-
DescriptionDifference
featur
e
Android
open
platform
Androi
d open
platfor
m
External USB interface, audio interface,
HDMI/YPbPr/CVBS interface, GPS
interface, and bluetooth interface
Support for integration of third-party
None
applications
LANVLANBasic VLANNone
LANMACDynamic MAC address learning and
None
static MAC address configuration; MAC
address learning limit, blackhole MAC
entries, sticky MAC entries, and antiMAC flapping
LANLink
aggreg
ation
Static link aggregation and Link
Aggregation Control Protocol (LACP)based aggregation
None
LANLLDPNeighboring device discoveryNone
LANWLANWireless access to LANs and AC
None
integration
Device as the STA to connect to the
WLAN
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
3 Product Characteristics
FeatureSub-
DescriptionDifference
featur
e
QoSConge
stion
manag
ement
Congestion management based on traffic
classifiers, PVCs/VLANs/DLCIs, and
ports; queue mechanisms including PQ,
WRR, DRR, WFQ, PQ+WRR/PQ
+DRR/PQ+WFQ, and CBQ
QoSConge
stion
Priority-based weighted random early
detection (WRED) and tail drop
avoida
nce
QoSHQoSHierarchical Quality of Service (HQoS)
implements hierarchical scheduling based
on queues and differentiates services and
users.
SecurityAAAAAA for administrators and access users,
stateful firewall, blacklist and whitelist,
and attack detection
None
None
None
None
None
SecurityAccess
securit
y
802.1x authentication, MAC address
authentication, MAC address bypass
authentication, and direct MAC address
authentication based on users and ports;
portal authentication for access users
SecurityLocal
attack
defens
Device protection measures, including
CPU attack defense and attack source
tracing.
e
SecurityARP
securit
y
SecurityIP
Suppression of ARP packets from the
user side and network side, and ARP
anti-spoofing
ICMP anti-attack, and URPFNone
securit
y
SecurityPKICertificate request, update, and
verification
SecurityHTTPSHTTPS server function, ensuring
transmission security between users and
devices using SSL features such as data
encryption and identity verification
None
None
None
None
None
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
3 Product Characteristics
FeatureSub-
DescriptionDifference
featur
e
SecurityACLTraffic classification based on physical
None
ports, Layer 2 information, IP protocols,
and TCP/UDP ports.
ReliabilityInterfa
ce
backup
Backup between WAN interfaces,
ensuring service reliability
Association between interface backup
None
and NQA/BFD/routing
ReliabilityInterfa
ce
monito
ring
group
In a dual-device backup scenario, when a
specific proportion of network-side
interfaces goes down, the user-side
interface status goes Down. Then traffic
is switched between the master and
None
backup links.
ReliabilityHSBBackup of firewall servicesNone
ReliabilityBFDSingle-hop and multi-hop BFD, BFD for
None
VRRP, BFD for a routing protocol
ReliabilityVRRPRedundancy backup mechanism for IP
services, IPv4 VRRP supported only.
Device
manage
ment
Inform
ation
center
Managing boards, power supply units,
fans, and e-labels
monito
ring
Device
manage
ment
Versio
n
manag
In-service upgrade, rollback, and patch
installation
ement
Device
manage
Mirror
ing
Port- and flow-based mirroringNone
ment
Device
manage
ment
Webbased
networ
Internal web management system,
providing GUI to manage and maintain
devices
k
manag
ement
system
None
None
None
None
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
3 Product Characteristics
FeatureSub-
featur
e
Device
manage
ment
Device
manage
OPS
Config
uration
Deplo
yment
ment
Network
SNMPSNMP agent, fault management (FM),
manage
ment
Network
manage
ment
Ping
and
Tracert
DescriptionDifference
The open programmability system (OPS)
None
is an open platform that provides
Application Programming Interfaces
(APIs) to achieve programmability,
allowing third-party applications to run
on the platform.
Automatic deployment using a universal
serial bus (USB) flash drive; AutoConfig function for the entire network
The AR511GW-L-B3,
AR511GW-LM7 has
only one Layer 3
interface, which is used
for factory settings and
does not support the
Auto-Config function.
None
and trap switch control (TSC)
Network connectivity detectionNone
Network
manage
ment
Network
manage
ment
Network
manage
ment
Network
manage
ment
Network
manage
ment
CWMPCWMP for remotely managing AR
devices
NQADetecting the performance of protocols
running on the network
NTPTime synchronization for traditional IP
networks
RMONMonitoring and traffic statistics for traffic
on a network segment
NetStr
eam
Fixed packet sampling and packet
statistics collection, with flow output in
V5, V8, V9, or V10 format
None
None
The AR510 series
(except AR515GW-
LM9-D) do not support
NTP.
The AR510 series do not
support RMON and
RMON2.
The AR510 series
(except AR515GW-
LM9-D) do not support
NetStream.
Issue 02 (2016-11-25)Huawei Proprietary and Confidential
Static link aggregation and Link Aggregation Control
Protocol (LACP)-based aggregation
None
21
Huawei AR500&AR510&AR530&AR550&AR2500
Series Industrial Switch Routers
Product Description
3 Product Characteristics
FeatureSub-
Feature
DescriptionDiffer
ence
LANLLDPNeighboring device discoveryNone
WANWAN
interface
Provides multiple uplink interfaces including 3G and
FE/GE interfaces.
Only
the
AR531
GPe-U-
H and
AR531
G-U-D-
H
support
3G
interfac
es.
WAN3GProvides 3G uplink and supports the 3G module.
Dual cards, single standby. The dual SIM cards connect
to different 3G networks in active/standby mode,
improving data transmission reliability of the 3G link.
Only
the
AR531
GPe-U-
H and
AR531
G-U-D-
H
support
3G
interfac
es.
IP
applic
ation
IP
applic
ation
IP
applic
ation
IP
applic
ation
IP
applic
ation
IP
applic
ation
ARPAddress resolution for EthernetNone
IPv4/IPv6
host
IPv4 and Ipv6 address management, TCP/UDP socket,
ICMP, ping and tracert, and UDP helper
None
IP FRRIP FRRNone
DNSDNS client, DNS proxy, and dynamic DNS (DDNS)
None
client
DHCPDHCP client(v4/v6), DHCP relay(v4/v6), and DHCP
None
server(v4/v6), and DHCP security
NetStreamFixed packet sampling and packet statistics collection,
None
with flow output in V5, V8 V9 or V10 format
Issue 02 (2016-11-25)Huawei Proprietary and Confidential