No part of this document may be reproduced or transmitted in any form or by any means without prior written
consent of Huawei Technologies Co., Ltd.
Trademarks and Permissions
and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd.
All other trademarks and trade names mentioned in this document are the property of their respective holders.
Notice
The purchased products, services and features are stipulated by the contract made between Huawei and the
customer. All or part of the products, services and features described in this document may not be within the
purchase scope or the usage scope. Unless otherwise specified in the contract, all statements, information,
and recommendations in this document are provided "AS IS" without warranties, guarantees or representations
of any kind, either express or implied.
The information in this document is subject to change without notice. Every effort has been made in the
preparation of this document to ensure accuracy of the contents, but all statements, information, and
recommendations in this document do not constitute the warranty of any kind, express or implied.
Huawei Technologies Co., Ltd.
Address:Huawei Industrial Base
Bantian, Longgang
Shenzhen 518129
People's Republic of China
HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic ConfigurationsAbout This Document
About This Document
Purpose
This part describes the organization of this document, product version, intended audience,
conventions, and Change history.
NOTE
l This document takes interface numbers and link types of the NE40E-X8 as an example. In working
situations, the actual interface numbers and link types may be different from those used in this
document.
l On NE80E/40E series excluding NE40E-X1 and NE40E-X2, line processing boards are called Line
Processing Units (LPUs) and switching fabric boards are called Switching Fabric Units (SFUs). On
the NE40E-X1 and NE40E-X2, there are no LPUs and SFUs, and NPUs implement the same functions
of LPUs and SFUs to exchange and forward packets.
Related Versions
The following table lists the product versions related to this document.
Product Name
HUAWEI NetEngine80E/40E
Router
Intended Audience
This document is intended for:
lCommissioning Engineer
lData Configuration Engineer
lNetwork Monitoring Engineer
lSystem Maintenance Engineer
Version
V600R003C00
Symbol Conventions
The symbols that may be found in this document are defined as follows.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic ConfigurationsAbout This Document
SymbolDescription
Alerts you to a high risk hazard that could, if not avoided,
result in serious injury or death.
Alerts you to a medium or low risk hazard that could, if
not avoided, result in moderate or minor injury.
Alerts you to a potentially hazardous situation that could,
if not avoided, result in equipment damage, data loss,
performance deterioration, or unanticipated results.
Provides a tip that may help you solve a problem or save
time.
Provides additional information to emphasize or
supplement important points in the main text.
Command Conventions
The command conventions that may be found in this document are defined as follows.
Convention
BoldfaceThe keywords of a command line are in boldface.
ItalicCommand arguments are in italics.
[ ]Items (keywords or arguments) in brackets [ ] are optional.
{ x | y | ... }Optional items are grouped in braces and separated by
[ x | y | ... ]Optional items are grouped in brackets and separated by
{ x | y | ... }
[ x | y | ... ]
&<1-n>The parameter before the & sign can be repeated 1 to n times.
*
*
Description
vertical bars. One item is selected.
vertical bars. One item is selected or no item is selected.
Optional items are grouped in braces and separated by
vertical bars. A minimum of one item or a maximum of all
items can be selected.
Optional items are grouped in brackets and separated by
vertical bars. Several items or no item can be selected.
#A line starting with the # sign is comments.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
About This Document.....................................................................................................................ii
1 Logging In to the System for the First Time............................................................................1
1.1 Introduction to Log In to the Device for the First Time.....................................................................................2
1.2 Logging In to the Device Through the Console Port..........................................................................................2
1.2.1 Establishing the Configuration Task.........................................................................................................2
1.2.2 Establishing the Physical Connection........................................................................................................3
1.2.3 Logging in to the router.............................................................................................................................3
1.3 Logging In to the router That Supports the Plug-and-Play Function.................................................................5
2.1.1 Command Line Interface...........................................................................................................................8
2.1.3 Command Line Views.............................................................................................................................11
2.2.1 Full Help..................................................................................................................................................12
2.4.3 Use of Shortcut Keys...............................................................................................................................22
2.5.1 Example for Running Commands in Batches..........................................................................................23
2.5.2 Example for Using Tab............................................................................................................................24
2.5.3 Example for Using Shortcut Keys...........................................................................................................25
2.5.4 Example for Copying Commands Using Shortcut Keys.........................................................................25
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
3.1 Configuring the Basic System Environment....................................................................................................28
3.1.1 Establishing the Configuration Task.......................................................................................................28
3.1.2 Switching the Language Mode................................................................................................................28
3.1.3 Configuring the Equipment Name...........................................................................................................29
3.1.4 Setting the System Clock.........................................................................................................................29
3.1.5 Configuring a Header..............................................................................................................................30
3.1.7 Configuring the Undo Command to Match in the Previous View Automatically..................................32
3.2 Displaying System Status Messages.................................................................................................................33
3.2.1 Displaying System Configuration...........................................................................................................33
3.2.2 Displaying System Status........................................................................................................................34
3.2.3 Collecting System Diagnostic Information.............................................................................................34
4 Configuring User Interface........................................................................................................35
4.1 User Interface Overview...................................................................................................................................36
4.2 Configuring the Console User Interface...........................................................................................................38
4.2.1 Establishing the Configuration Task.......................................................................................................38
4.2.2 Setting Physical Attributes of Console User Interface............................................................................38
4.2.3 Setting Terminal Attributes of Console User Interface...........................................................................40
4.2.4 Configuring User Priority of Console User Interface..............................................................................41
4.2.5 Configuring the User Authentication Mode of the Console User Interface............................................41
4.2.6 Checking the Configuration.....................................................................................................................43
4.3 Configuring the AUX User Interface...............................................................................................................44
4.3.1 Establishing the Configuration Task.......................................................................................................44
4.3.2 Setting Physical Attributes of AUX User Interface.................................................................................44
4.3.3 Setting Terminal Attributes of AUX User Interface................................................................................46
4.3.4 Setting User Priority of AUX User Interface..........................................................................................47
4.3.5 Setting Modem Attributes of AUX User Interface..................................................................................47
4.3.6 (Optional) Configuring Auto-Execute Commands of AUX User Interface............................................48
4.3.7 Setting User Authentication Mode of AUX User Interface.....................................................................49
4.3.8 Checking the Configuration.....................................................................................................................50
4.4 Configuring VTY User Interface......................................................................................................................51
4.4.1 Establishing the Configuration Task.......................................................................................................51
4.4.2 Configuring Maximum VTY User Interfaces.........................................................................................52
4.4.3 (Optional)Setting Limit on Incoming and Outgoing Calls of VTY User Interfaces...............................53
4.4.4 Setting Terminal Attributes of the VTY User Interface..........................................................................53
4.4.5 Setting User Priority of VTY User Interface...........................................................................................54
4.4.6 Setting User Authentication Mode of the VTY User Interface...............................................................55
4.4.7 (Optional) Configuring NMS Users to Log In Through VTY User Interfaces.......................................56
4.4.8 Checking the Configuration.....................................................................................................................58
4.5.2 Example for Configuring AUX User Interface.......................................................................................61
4.5.3 Example for Configuring VTY User Interface........................................................................................63
5 Configuring User Login.............................................................................................................65
5.1 Overview of User Login...................................................................................................................................67
5.2 Logging in to the Devices Through the Console Port......................................................................................67
5.2.1 Establishing the Configuration Task.......................................................................................................68
5.2.2 Configuring Console User Interface........................................................................................................68
5.2.3 Logging in to the router Through a Console Port....................................................................................68
5.2.4 Checking the Configuration.....................................................................................................................69
5.3 Logging in to the Devices Through the AUX Port...........................................................................................70
5.3.1 Establishing the Configuration Task.......................................................................................................70
5.3.2 Configuring AUX User Interface............................................................................................................71
5.3.3 Logging in to the routerThrough an AUX Port.......................................................................................71
5.3.4 Checking the Configuration.....................................................................................................................74
5.4 Logging in to the Devices by Using Telnet......................................................................................................75
5.4.1 Establishing the Configuration Task.......................................................................................................75
5.4.2 Configuring VTY User Interface.............................................................................................................76
5.4.3 (Optional) Configuring Local Telnet Users.............................................................................................77
5.4.4 Enabling the Telnet Service.....................................................................................................................77
5.4.5 (Optional) Configuring Listening Port Number for Telnet Server..........................................................78
5.4.6 Logging in to the router by Using Telnet................................................................................................79
5.4.7 Checking the Configuration.....................................................................................................................80
5.5 Logging in to the Devices by Using STelnet....................................................................................................81
5.5.1 Establishing the Configuration Task.......................................................................................................81
5.5.2 Configuring VTY User Interface.............................................................................................................82
5.5.3 Configuring SSH for the VTY User Interface.........................................................................................82
5.5.4 Configuring an SSH User and Specifying STelnet as One of Service Types.........................................83
5.5.5 Enabling the STelnet Server Function.....................................................................................................86
5.5.6 (Optional) Configuring the STelnet Server Parameters...........................................................................86
5.5.7 Logging in to the router by Using STelnet..............................................................................................88
5.5.8 Checking the Configuration.....................................................................................................................89
5.6 Common Operations After Login.....................................................................................................................90
5.6.1 Establishing the Configuration Task.......................................................................................................90
5.6.2 Switching User Levels.............................................................................................................................90
5.6.3 Locking User Interfaces...........................................................................................................................91
5.6.4 Sending Messages to Other User Interfaces............................................................................................92
6.1 File System Overview....................................................................................................................................106
6.2.3 Managing the Directory.........................................................................................................................108
6.3 Performing File Operations by Means of FTP...............................................................................................111
6.3.1 Establishing the Configuration Task.....................................................................................................112
6.3.2 Configuring a Local FTP User..............................................................................................................112
6.3.3 (Optional) Specifying a Port Number for the FTP Server.....................................................................113
6.3.4 Enabling the FTP Server........................................................................................................................114
6.3.5 (Optional) Configuring the FTP Server Parameters..............................................................................114
6.3.6 (Optional) Configuring an FTP ACL....................................................................................................115
6.3.7 Accessing the System by Using FTP.....................................................................................................116
6.3.8 Performing File Operations by Using FTP Commands.........................................................................117
6.3.9 Checking the Configuration...................................................................................................................119
6.4 Performing File Operations by Means of SFTP.............................................................................................119
6.4.1 Establishing the Configuration Task.....................................................................................................119
6.4.2 Configuring VTY User Interface...........................................................................................................120
6.4.3 Configuring SSH for the VTY User Interface.......................................................................................120
6.4.4 Configuring an SSH User and Specifying SFTP as One of Service Types...........................................121
6.4.5 Enabling the SFTP Service....................................................................................................................124
6.4.6 (Optional) Configuring the STelnet Server Parameters.........................................................................125
6.4.7 Accessing the System by Using SFTP..................................................................................................126
6.4.8 Performing File Operations by Using SFTP..........................................................................................127
6.4.9 Checking the Configuration...................................................................................................................128
6.5 Performing File Operations by Means of Xmodem.......................................................................................129
6.5.1 Establishing the Configuration Task.....................................................................................................130
6.5.2 Getting a File Through Xmodem...........................................................................................................130
6.6.1 Example for Performing File Operations by Means of the File System...............................................131
6.6.2 Example for Performing File Operations by Means of FTP.................................................................132
6.6.3 Example for Performing File Operations by Means of SFTP...............................................................135
6.6.4 Example for Performing File Operations by Means of Xmodem..........................................................137
7 Configuring System Startup....................................................................................................140
7.1 System Startup Overview...............................................................................................................................141
7.1.1 System Software....................................................................................................................................141
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
7.2.5 Checking the Configuration...................................................................................................................146
7.3 Specifying a File for System Startup..............................................................................................................147
7.3.1 Establishing the Configuration Task.....................................................................................................147
7.3.2 Configuring System Software for a router to Load for the Next Startup..............................................147
7.3.3 Configuring the Configuration File for Router to Load for the Next Startup.......................................148
7.3.4 Checking the Configuration...................................................................................................................148
7.4.1 Example for Configuring System Startup.............................................................................................149
8 Accessing Another Device.......................................................................................................152
8.1 Accessing Another Device.............................................................................................................................153
8.2 Logging in to Other Devices by Using Telnet................................................................................................157
8.2.1 Establishing the Configuration Task.....................................................................................................157
8.2.2 (Optional) Configuring a Source IP Address for an Telnet Client........................................................158
8.2.3 Logging in to Another Device by Using Telnet....................................................................................158
8.2.4 Checking the Configuration...................................................................................................................159
8.3 Connecting to Another Device by Using the Telnet Redirection Function....................................................160
8.3.1 Establishing the Configuration Task.....................................................................................................160
8.3.2 Enabling the Telnet Redirection Function.............................................................................................161
8.3.3 Connecting Another Device by Using the Telnet Redirection Function...............................................162
8.3.4 Checking the Configuration...................................................................................................................162
8.4 Logging in to Another Device by Using STelnet...........................................................................................163
8.4.1 Establishing the Configuration Task.....................................................................................................163
8.4.2 Configuring the First Successful Login to Another Device (Enabling the First-Time Authentication on
the SSH Client)...............................................................................................................................................163
8.4.3 Configuring the First Successful Login to Another Device (Allocating an RSA Public Key to the SSH
8.6.6 Disconnecting from the FTP Server......................................................................................................176
8.6.7 Checking the Configuration...................................................................................................................176
8.7 Accessing Files on Another Device by Using SFTP......................................................................................177
8.7.1 Establishing the Configuration Task.....................................................................................................177
8.7.2 (Optional) Configuring a Source IP Address for an SFTP Client.........................................................178
8.7.3 Configuring the First Successful Login to Another Device (Enabling the First-Time Authentication on
the SSH Client)...............................................................................................................................................178
8.7.4 Configuring the First Successful Login to Another Device (Allocating an RSA Public Key to the SSH
8.8.1 Example for Logging in to Another Device by Using Telnet...............................................................183
8.8.2 Example for Logging in to Another Device by Using the Telnet Redirection Function.......................186
8.8.3 Example for Logging in to Another Device by Using Telnet on a VPN...............................................187
8.8.4 Example for Configuring the Device as the STelnet Client to Connect to the SSH Server..................189
8.8.5 Example for Accessing Files on Another Device by Using TFTP........................................................195
8.8.6 Example for Configuring the Access of the TFTP Server on the Public Network When the Management
VPN Instance Is Used.....................................................................................................................................197
8.8.7 Example for Accessing Files on Another Device by Using FTP..........................................................199
8.8.8 Example for Configuring the Access of the FTP Server on the Public Network When the Management
VPN Instance Is Used.....................................................................................................................................201
8.8.9 Example for Accessing Files on Another Device by Using SFTP........................................................202
8.8.10 Example for Configuring the Access of the SFTP Server on the Public Network When the Management
VPN Instance Is Used.....................................................................................................................................208
8.8.11 Example for Accessing the SSH Server Through Other Port Numbers..............................................213
8.8.12 Example for an SSH Client in the Public Network to Access an SSH Server in the Private Network
10.1 Introduction of Device Maintenance............................................................................................................256
10.1.1 Overview of Device Maintenance.......................................................................................................256
10.1.2 Maintenance Features Supported by the NE80E/40E.........................................................................256
10.2 Powering off the MPU..................................................................................................................................256
10.2.1 Establishing the Configuration Task...................................................................................................256
10.2.2 Powering off the Slave MPU...............................................................................................................257
10.2.3 Checking the Configuration.................................................................................................................258
10.3 Powering off the SFU...................................................................................................................................258
10.3.1 Establishing the Configuration Task...................................................................................................259
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
10.3.2 Powering off the SFU..........................................................................................................................259
10.3.3 Checking the Configuration.................................................................................................................260
10.4 Powering off the NPU..................................................................................................................................260
10.4.1 Establishing the Configuration Task...................................................................................................261
10.4.2 Powering off the NPU.........................................................................................................................261
10.4.3 Checking the Configuration.................................................................................................................262
10.5 Powering off the LPU...................................................................................................................................262
10.5.1 Establishing the Configuration Task...................................................................................................262
10.5.2 Powering off the LPU..........................................................................................................................263
10.5.3 Checking the Configuration.................................................................................................................263
10.6 Restoring the Bandwidth of 10GE LAN/WAN Interfaces on an NPU to 10 Gbit/s....................................264
10.6.1 Establishing the Configuration Task...................................................................................................264
10.6.2 Restoring the bandwidth of 10GE LAN/WAN interfaces on an NPU to 10 Gbit/s............................265
10.6.3 Checking the Configuration.................................................................................................................265
10.7 Switching Between the Operation Modes of the LPUF-10..........................................................................266
10.7.1 Establishing the Configuration Task...................................................................................................266
10.7.2 Switching Between the Operation Modes of the LPUF-10.................................................................267
10.7.3 Checking the Configuration.................................................................................................................267
10.8 Configuring a Working Mode for an LPUF-40 or LPUF-20/21..................................................................268
10.8.1 Establishing the Configuration Task...................................................................................................268
10.8.2 Configuring a Service Mode for an LPUF-20/21 or LPUF-40...........................................................269
10.8.3 Checking the Configuration.................................................................................................................270
10.9 Configuring the CMU...................................................................................................................................271
10.9.1 Establishing the Configuration Task...................................................................................................271
10.9.2 Configuring Monitor Items for a CMU...............................................................................................271
10.10 Configuring a Cleaning Cycle for the Air Filter.........................................................................................272
10.10.1 Establishing the Configuration Task.................................................................................................272
10.10.2 Configuring a Cleaning Cycle for the Air Filter................................................................................272
10.10.3 Remonitoring the Cleaning Cycle of the Air Filter...........................................................................273
10.10.4 Checking the Configuration...............................................................................................................273
10.11 Monitoring the Device Status.....................................................................................................................274
10.11.1 Displaying the System Version Information.....................................................................................274
10.11.2 Displaying Basic Information About the Router...............................................................................274
10.11.3 Displaying the Electronic Label........................................................................................................275
10.11.4 Displaying the Soft Boot Mode.........................................................................................................275
10.11.5 Displaying the Threshold of the Memory Usage...............................................................................276
10.11.6 Displaying the Threshold of CPU Usage..........................................................................................276
10.12.1 Resetting a Board...............................................................................................................................281
10.12.2 Clearing the Maximum CPU Usage..................................................................................................281
11.1 Overview of Device Upgrade.......................................................................................................................297
11.2 Upgrade Modes Supported by the NE80E/40E............................................................................................297
12.1 Introduction of Patch Management..............................................................................................................300
12.1.1 Overview of Patch Management.........................................................................................................300
12.1.2 Patches Supported by the NE80E/40E................................................................................................301
12.2 Checking the Running of Patch in the System.............................................................................................302
12.2.1 Establishing the Configuration Task...................................................................................................302
12.2.2 Checking the Running of Patch in the System....................................................................................303
12.2.3 (Optional) Deleting a Patch.................................................................................................................303
12.3 Loading a Patch............................................................................................................................................304
12.3.1 Establishing the Configuration Task...................................................................................................304
12.3.2 Loading a Patch...................................................................................................................................304
12.3.3 Checking the Configuration.................................................................................................................305
12.4 Installing a Patch..........................................................................................................................................306
12.4.1 Establishing the Configuration Task...................................................................................................306
12.4.2 Loading a Patch...................................................................................................................................307
12.4.3 Activating a Patch................................................................................................................................307
12.4.4 Running a Patch...................................................................................................................................308
12.4.6 Checking the Configuration.................................................................................................................309
12.5 (Optional) Unactivating the activating of Patch...........................................................................................313
12.5.1 Establishing the Configuration Task...................................................................................................313
12.5.2 Deactivating a Patch............................................................................................................................313
12.5.3 Checking the Configuration.................................................................................................................313
12.6 Configuration Examples of the Patch Management.....................................................................................314
12.6.1 Example for Installing a Patch.............................................................................................................314
A Glossary......................................................................................................................................317
B Acronyms and Abbreviations.................................................................................................323
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic Configurations1 Logging In to the System for the First Time
1 Logging In to the System for the First Time
About This Chapter
You can log in to a new router through the console port to configure the router.
1.1 Introduction to Log In to the Device for the First Time
A user can log in to the router that is powered on for the first time through the console port or
by the plug-and-play function to configure the router.
1.2 Logging In to the Device Through the Console Port
This section describes how to connect a terminal to a router through the console port to establish
the configuration environment.
1.3 Logging In to the router That Supports the Plug-and-Play Function
The plug-and-play function enables the router to automatically access the network and obtains
an IP address after the router is powered on. This allows engineers to remotely log in to the
router to perform basic configurations.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic Configurations1 Logging In to the System for the First Time
1.1 Introduction to Log In to the Device for the First Time
A user can log in to the router that is powered on for the first time through the console port or
by the plug-and-play function to configure the router.
Log in to the router through the console port
The console port is a linear port on the main control board.
Each main control board provides one console port that conforms to the EIA/TIA-232 standard
and whose type is DCE. The serial interface of a terminal can be directly connected to the console
port on the router. Users can then configure the router on the terminal.
NOTE
When a device is powered on for the first time, you must log in to the device through the console port. It
is a prerequisite for other login modes. For example, the IP address for Telnet login must be configured by
logging in to the device through the console port.
Log in to the router by the plug-and-play function
NOTE
The plug-and-play function only can be configured on the X1 , X2 and X3 models of the NE80E/40E.
During site deployment, the routers reside far away from the equipment room. Sending software
commissioning engineers to deploy the network at the site is quite costly. After the plug-andplay function is enabled, however, the router automatically obtains an IP address. Software
commissioning engineers are able to remotely deliver configurations to the router through the
NMS after installation personnel finishes hardware installation. This greatly simplifies
installation and reduces costs with minimized site visits.
The plug-and-play function is controlled by a PAF file and users do not need to configure it
manually. This function is automatically disabled after the router correctly obtains an IP address.
1.2 Logging In to the Device Through the Console Port
This section describes how to connect a terminal to a router through the console port to establish
the configuration environment.
1.2.1 Establishing the Configuration Task
Before logging in to the router through the console port, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
When the router is powered on for the first time, you need to use the console port to log in to
the router to configure and manage the router.
Pre-configuration Tasks
Before logging in to the router through the console port, complete the following tasks:
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic Configurations1 Logging In to the System for the First Time
lInstalling terminal emulation program on the PC (such as Windows XP HyperTerminal)
lPreparing the RS-232 cable
Data Preparation
To log in to the router through the console port, you need the following data.
No.Data
1Terminal communication parameters
l Baud rate
l Data bit
l Parity
l Stop bit
l Flow-control mode
NOTE
When the router is logged in for the first time, the system automatically uses default parameter values.
1.2.2 Establishing the Physical Connection
The console port on the router must be connected to the COM port on a terminal by using a
console cable.
Procedure
Step 1 Power on all devices to perform a self-check.
Step 2 Connect the COM port on the PC and the console port on the router by a cable.
----End
1.2.3 Logging in to the router
You can log in to the router through the console port to configure and manage the router that is
powered on for the first time.
Context
You need to configure terminal attributes for the PC according to the attributes configured for
the console port, including the transmission rate, data bit, parity bit, stop bit, and flow control
mode. As the router is logged in for the first time, every terminal attribute uses the default value
of the router.
Procedure
Step 1 Start a terminal emulator on the PC, and create a new connection, as shown in Figure 1-1.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic Configurations1 Logging In to the System for the First Time
Figure 1-3 Communication parameter setting
Step 4 Press Enter. A command line prompt such as <HUAWEI> appears, and the user view is
displayed for you to configure the router.
----End
1.3 Logging In to the router That Supports the Plug-and-Play
Function
The plug-and-play function enables the router to automatically access the network and obtains
an IP address after the router is powered on. This allows engineers to remotely log in to the
router to perform basic configurations.
Context
NOTE
The plug-and-play function only can be configured on the X1 , X2 and X3 models of the NE80E/40E.
During site deployment, the routers reside far away from the equipment room. Sending software
commissioning engineers to deploy the network at the site is quite costly. After the plug-andplay function is enabled, however, the router automatically obtains an IP address. Software
commissioning engineers are able to remotely deliver configurations to the router through the
NMS after installation personnel finishes hardware installation. This greatly simplifies
installation and reduces costs with minimized site visits. The plug-and-play function is controlled
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic Configurations1 Logging In to the System for the First Time
by a PAF file and users do not need to configure it manually. This function is automatically
disabled after the router correctly obtains an IP address. The process of logging in to the
router supporting the plug-and-play function is as follows:
Procedure
Step 1 After planning the network, network planning engineers provide a planning list for software
commissioning engineers.
Step 2 Based on the planning list, software commissioning engineers configure the mappings between
the router locations and IP addresses on the DHCP server, compile configuration scripts, and
configure the mappings between the router locations and scripts.
Step 3 Hardware installation personnel installs the router and power them on at the site.
Step 4 The router sends a DHCPREQUEST message to the DHCP server, and then the interface
connecting to the DHCP server obtains an IP address.
Step 5 The NMS delivers configurations to the router.
----End
Follow-up Procedure
If there is no DHCP server on the network or the router cannot obtain an IP address for some
reason, the router displays the following information:
PNP State!!!PLEASE UNDO PNP enable for manual Setup!
You can undo PNP in system view with "undo pnp enable"
At this time, do as follows to disable the plug-and-play function:
1.Run the system-view command to enter the system view.
2.Run the undo pnp enable command to disable the plug-and-play function.
3.Run the undo pnp default route command to delete the default route generated by the
plug-and-play function.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The command line interface (CLI) is used to configure and maintain devices.
2.1 CLI Introduction
After you log in to the router, a prompt is displayed, indicating that you enter the command line
interface (CLI). The CLI is used by users to interact with the router.
2.2 Online Help
When inputting command lines or configuring services, you can use the online help function to
obtain real-time help.
2.3 CLI Features
The CLI provides the following features to help users flexibly use it.
2.4 Shortcut Keys
Using the system or user-defined shortcut keys makes it easier to enter commands.
2.5 Configuration Examples
This section provides several examples for using command lines.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
After you log in to the router, a prompt is displayed, indicating that you enter the command line
interface (CLI). The CLI is used by users to interact with the router.
2.1.1 Command Line Interface
You can configure and manage the router by using the CLI commands.
The characteristics of CLI are as follows:
lLocal or remote configuration through the AUX port.
lLocal configuration through console port.
lLocal or remote configuration through Telnet or Secure Shell (SSH).
lRemote configuration by logging in to an asynchronous serial interface on the router
through Modem dialup.
lThe telnet command for directly logging in to and managing other routers.
lFTP service for file uploading and downloading.
lA user interface view for specific configuration management.
lHierarchical command protection for users of different levels, that is, running the
commands of the corresponding levels.
lThree authentication modes are supported, namely, none-authentication, password
authentication, and Authentication, Authorization, and Accounting (AAA) authentication.
Password and AAA authentication prohibit unauthorized users from logging in to the
router, guaranteeing system security.
lEntering "?" for online help at any time.
lA command line interpreter provides intelligent command resolution methods such as key
word fuzzy match and context conjunction. These methods make it easy for users to enter
their commands.
lNetwork testing commands such as tracert and ping for rapidly diagnosing a network.
lAbundant debugging information to help in diagnosing the network.
lRunning a command used previously on the device, like DosKey.
NOTE
l The system supports the command with up to 512 characters. The command can be incomplete. This
means that you can input initial characters (one or some) of the command to represent the whole
command. The incomplete command, however, must be unqiue in the system. For example, to use the
display current-configuration command, just input d cu, di cu, or dis cu. d c or dis c, however, cannot
be input, becuse they are not unique to represent the display current-configuration command.
l The system saves the incomplete command to the configuration files in the complete form; therefore,
the command may have more than 512 characters. When the system is restarted, however, the
incomplete command cannot be restored. Therefore, pay attention to the length of the incomplete
command.
2.1.2 Command Levels
The system manages commands in hierarchy for security. The administrator can set user levels
corresponding to command levels to implement user-specific access control.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
0Visit levelCommands of this level include commands of network
diagnosis tool (such as ping and tracert) and commands that
start from the local device and visit external device (such
as Telnet client side).
1Monitoring levelCommands of this level, including the display commands,
are used for system maintenance and fault diagnosis.
2Configuration
level
Commands of this level are service configuration
commands that provide direct network service to the user,
including routing and network layer commands.
3Management levelCommands of this level are commands that influence the
basic operation of the system and provide support to the
service. They include file system commands, FTP
commands, TFTP commands, XModem downloading
commands, configuration file switching commands, power
supply control commands, backup board control
commands, user management commands, level setting
commands, system internal parameter setting commands,
and debugging commands that are used for fault diagnosis.
To implement efficient management, you can increase the command levels to 0-15. For the
increase in the command levels, refer to Chapter 4 "Basic Configuration" Configuring
Command Levels in the HUAWEI NetEngine80E/40E Configuration Guide - Basic
Configurations.
NOTE
l The default command level may be higher than the command level defined according to the command
rules in application.
l The level of the command that a user can run is determined by the level of this user.
l Login users have the same 16 levels as the command levels. The login users can use only the command
of the levels that are equal to or lower than their own levels. The user privilegelevel level command
sets the user level.
Searching Commands Based on Command Levels
You can search for all commands of a specific level simultaneously. The procedure is as follows:
1.Open the command reference (.chm.) file.
2.Click the "Search" tab. The search window will be displayed as shown in Figure 2-1.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
3.Enter a desired command level in the "Type in the word(s) to search for" textbox and click
"List Topics". All commands of the specified level will be displayed as shown in Figure
2-2.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Figure 2-2 Searching commands based on a specific level
2.1.3 Command Line Views
The command line interface has different command views. All the commands are registered in
one or more command views. You can run a command only when you enter the corresponding
command view.
The following part uses the user, system, and BFD views as an example:
# Establish connection to the router. If the router adopts the default configuration, you can enter
the user view with the prompt of <HUAWEI>.
<HUAWEI>
# Run the system-view command to enter the system view.
<HUAWEI> system-view
[HUAWEI]
# Run the aaa command in the system view to enter the AAA view.
[HUAWEI] aaa
[HUAWEI-aaa]
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
lThe command prompt "HUAWEI" is the default host name.
lThe prompt indicates a specific view. For example, "<HUAWEI>" indicates the user view, and
"[HUAWEI-ui-console0]" indicates the console user interface view.
Some commands can be used in both system and other views, but have different effects. For
example, the mpls command can be run in the system view to enable MPLS globally or in the
interface view to enable MPLS only on this interface.
2.2 Online Help
When inputting command lines or configuring services, you can use the online help function to
obtain real-time help.
2.2.1 Full Help
When inputting a command, you can use the full help function to obtain all keywords or
parameters of this command.
Procedure
lYou can obtain the full help of a command line in the following manners.
– Enter a question mark (?) in any command line view to display all the commands and
their simple descriptions.
<HUAWEI> ?
User view commands:
arp-ping ARP-ping
backup Backup information
batch-cmd Batch commands
board-channel-check Board-Channel-Check enable/disable
capture-packet enable capturing packet
cd Change current directory
...
...
– Enter a command and a question mark (?) separated by a space. If the key word is at
this position, all key words and their simple descriptions are displayed. For example:
<HUAWEI> language-mode ?
Chinese Chinese environment
English English environment
Chinese and English are keywords; Chinese environment and English
environment describe the keywords respectively.
– Enter a command and a question mark (?) separated by a space, and if a parameter is at
this position, the related parameter names and parameter descriptions are displayed. For
example:
[HUAWEI] ftp timeout ?
INTEGER<1-35791> The value of FTP timeout (in minutes)
[HUAWEI] ftp timeout 35 ?
<cr> Please press ENTER to execute command
[HUAWEI] ftp timeout 35
In the preceding display, INTEGER<1-35791> describes the parameter value; The
value of FTP timeout (in minutes) is a simple description of the parameter usage;
<cr> indicates that no parameter is at this position. The command is repeated in the nextcommand line. You can press Enter to run the command.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
If you enter only the first one or a few characters of a command, you can use the partial help
function to obtain all keywords following the character or character string.
Procedure
lYou can obtain the partial help of a command line in the following manners.
– Enter a character string with a question mark (?) closely following it to display all
commands that begin with this character string.
<HUAWEI> d?
debugging delete
dir display
– Enter a command and a character string with a question mark (?) closely following it
to display all the key words that begin with this character string.
– Enter the first several letters of a key word in the command and then press Tab to display
the complete key word on the condition that the letters uniquely identify the key word.
Otherwise, if you continue to press Tab, different key words are displayed. You can
select the needed key word.
----End
2.2.3 Error Messages of the Command Line Interface
If an entered command passes the syntax check, the system executes it. Otherwise, the system
prompts an error message.
All the commands entered by the user are run correctly, if the grammar check has been passed.
Otherwise, error messages are reported to the user. See Table 2-2 for the common error
messages.
Table 2-2 Common error messages of the command line
Error messages
Unrecognized commandThe command cannot be found
Wrong parameterParameter type error
Incomplete commandIncomplete command entered
Too many parametersToo many parameters entered
Cause of the error
The key word cannot be found
The parameter value exceeds the limit
Ambiguous commandIndefinite parameters entered
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The CLI provides the following features to help users flexibly use it.
2.3.1 Editing
The editing function of command lines helps you edit command lines or obtain help by using
certain keys.
The command line supports multi-line edition. The maximum length of each command is 512
characters.
Keys for editing that are often used are shown in Table 2-3.
Table 2-3 Keys for editing
KeyFunction
Common keyInserts a character in the current position of the cursor if the editing
buffer is not full and the cursor moves to the right. Otherwise, an
alarm is generated.
BackspaceDeletes the character on the left of the cursor that moves to the
left. When the cursor reaches the head of the command, an alarm
is generated.
Left cursor key ← or
Ctrl_B
Right cursor key → or
Ctrl_F
TabPress Tab after typing the incomplete key word and the system
Moves the cursor to the left by the space of a character. When the
cursor reaches the head of the command, an alarm is generated.
Moves the cursor to the right by the space of a character. When
the cursor reaches the end of the command, an alarm is generated.
runs the partial help:
l If the matching key word is unique, the system replaces the
typed one with the complete key word and displays it in a new
line with the cursor a space behind.
l If there are several matches or no match at all, the system
displays the prefix first. Then you can press Tab to view the
matching key word one by one. In this case, the cursor closely
follows the end of the word and you can type a space to enter
the next word.
l If a wrong key word is entered, press Tab and the word is
displayed in a new line.
2.3.2 Displaying
All command lines have the same displaying feature. You can construct the displaying mode as
required.
You can control the display of information on the CLI as follows:
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
lPrompts and help information can be displayed in both Chinese and English. You can use
the language-modelanguage-name command to change the language mode.
lIf output information cannot be displayed on a full screen, you have three options to view
the information, as shown in Table 2-4.
Table 2-4 Keys for displaying
KeyFunction
Ctrl_CStops the display and running of the command.
NOTE
You can also press any of the keys except the spacebar and Enter key
to stop the display and running of the command.
SpaceAllows information to be displayed on the next screen.
EnterAllows information to be displayed on the next line.
2.3.3 Regular Expressions
The regular expression is an expression that describes a set of strings. It consists of common
characters (such as letters from "a" to "z") and particular characters (also named metacharacters).
The regular expression is a template according to which you can search for the required string.
Users can use regular expressions to filter output information to rapidly locate desired
information.
A regular expression can provide the following functions:
lSearching for and obtaining a sub-string that matches a rule in the string.
lSubstituting a string according to a certain matching rule.
Formal Language Theory of the Regular Expression
The regular expression consists of common characters and particular characters.
lCommon characters
Common characters are used to match themselves in a string, including all upper-case and
lower-case letters, digits, punctuation, and special symbols. For example, a matches the
letter "a" in "abc", 202 matches the digit "202" in "202.113.25.155", and @ matches the
symbol "@" in "[email protected]".
lParticular characters
Particular characters are used together with common characters to match the complex or
particular string combination. Table 2-5 describes particular characters and their syntax.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The HUAWEI NetEngine80E/40E uses a regular expression to implement the filtering function
of the pipe character. A display command supports the pipe character only when there is
excessive output information.
When the output information is queried according to the filtering conditions, the first line of the
command output starts with the information containing the regular expression.
The command can carry the parameter | count to display the number of matching entries. The
parameter | count can be used together with other parameters.
For the commands supporting regular expressions, the three filtering methods are as follows:
l| begin regular-expression: displays the information that begins with the line that matches
regular expression.
l| exclude regular-expression: displays the information that excludes the lines that match
regular expression.
l| include regular-expression: displays the information that includes the lines that match
regular expression.
NOTE
The value of regular-expression is a string of 1 to 255 characters.
Specify a Filtering Mode when Information is Displayed
When a lot of information is displayed, you can specify a filtering mode in the prompt "---- More
----".
l/regular-expression: displays the information that begins with the line that matches regular
expression.
l-regular-expression: displays the information that excludes lines that match regular
expression.
l+regular-expression: displays the information that includes lines that match regular
expression.
2.3.4 Previously-Used Commands
The CLI provides a function similar to DosKey to automatically save commands used previously
on the device. If you need to run a command that has been executed, you can call the command
from those have been used previously on the device. This facilitates user operation.
By default, the system saves a maximum of 10 previously-used commands for each user. You
can run the history-command max-sizesize-value command in the user view to set the number
of previously-used commands saved in the system. A maximum of 256 previously-used
commands can be saved in the system.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Setting the number of saved previously-used commands to a proper value is recommended. If a large
number of previously-used commands are saved, it will take a long time to locate a needed previouslyused command, affecting efficiency.
The operations are shown in Table 2-6
Table 2-6 Access the previously-used commands
ActionKey or CommandResult
Display
previously-
display historycommand
Display previously-used commands entered by
users.
used
commands.
Access the last
previouslyused
Up cursor key (↑) or
Ctrl_P
Display the last previously-used command if there
is an earlier previously-used command. Otherwise,
an alarm is generated.
command.
Access the next
previouslyused
Down cursor key
(↓) or Ctrl_N
Display the next previously-used command if there
is a later previously-used command. Otherwise, the
command is cleared and an alarm is generated.
command.
NOTE
On the HyperTerminal of Windows 9X, cursor key ↑ is invalid as the HyperTerminals of Windows 9X
define the keys differently. In this case, you can replace the cursor key ↑ with Ctrl_P.
When you use previously-used commands, note the following points:
lThe saved previously-used commands are the same as that those entered by users. For
example, if the user enters an incomplete command, the saved command also is incomplete.
lIf the user runs the same command several times, the earliest command is saved. If the
command is entered in different forms, they are considered as different commands.
For example, if the display ip routing-table command is run several times, only one
previously-used command is saved. If the disp ip routing command and the display ip
routing-table command are run, two previously-used commands are saved.
2.3.5 Batch Command Execution
If multiple commands are frequently used consecutively, you can edit these commands to be
executed in batches. This simplifies command input and improves efficiency.
Procedure
Step 1 In the user view, run:
batch-cmd edit
Commands are edited to be executed in batches.
The batch-cmd edit command can be used by only one user at a time.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The maximum length of a command (including the incomplete command) to be entered is 512
characters.
When editing commands, press Enter to complete the editing of each command.
NOTE
l After the batch-cmd edit command is run successfully to edit the commands to be executed in batches,
the system deletes the original commands to be run in batches.
l The commands that are already edited are saved in memory and are deleted for ever when the system
is restarted.
Step 2 After all commands are edited, you can press the shortcut buttons Ctrl_Z to exit the editing state
and return to the user view.
Step 3 In the user view, run:
batch-cmd execute
The commands are executed in batches.
The batch-cmd execute command can be used by only one user at a time.
The sequence of running commands is the same as the sequence of editing commands. You can
view the execution of these commands on the CLI. After the execution is complete, the user
view is displayed.
NOTE
If the batch-cmd edit or batch-cmd execute command is among the commands to be executed in batches,
the system displays an error when executing the batch-cmd edit or batch-cmd execute command and
continues to execute the following commands.
----End
2.4 Shortcut Keys
Using the system or user-defined shortcut keys makes it easier to enter commands.
2.4.1 Classifying Shortcut Keys
There are two types of shortcut keys, namely, system shortcut keys and user-defined shortcut
keys. Familiarize yourself with shortcut keys so as to use them accurately.
The shortcut keys in the system are classified into the following types:
lUser-defined shortcut keys: CTRL_G, CTRL_L, CTRL_O, and CTRL_U. The user can
correlate these shortcut keys with any commands. When the shortcut keys are pressed, the
system automatically runs the corresponding command. For details of defining the shortcut
keys, see 2.4.2 Defining Shortcut Keys.
lSystem-defined shortcut keys: These shortcut keys with fixed functions are defined by the
system. Table 2-7 lists the system-defined shortcut keys.
NOTE
Different terminal software defines these keys differently. Therefore, the shortcut keys on the terminal may
be different from those listed in this section.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
If one or multiple commands are frequently used, you can correlate these commands with
shortcut keys. This facilitates user operation and improves efficiency. Only management-level
users have the rights to define shortcut keys.
When defining the shortcut keys, use double quotation marks to define the command if this command
contains several commands words, that is, if spaces exist in the command.
By default, CTRL_G, CTRL_L and CTRL_O correspond to the following commands
respectively:
lCTRL_G: display current-configuration
lCTRL_L: display ip routing-table
lCTRL_O: undo debugging all
By default, CTRL_U is not correlated with any command.
2.4.3 Use of Shortcut Keys
You can use the shortcut key at any position that allows a command to be entered. The system
executes an entered shortcut key and displays the corresponding command on the screen in the
same way as you enter a complete command.
lIf you have typed part of a command and have not pressed Enter, you can press the shortcut
keys to clear the entered command and display the full corresponding command. This
operation has the same effect as that of deleting all commands and then re-entering the
complete command.
lThe shortcut keys are run as the commands, the syntax is recorded to the command buffer
and log for fault location and querying.
NOTE
The terminal in use may affect the functions of the shortcut keys. For example, if the customized shortcut
keys of the terminal conflict with those of the router, the input shortcut keys are captured by the terminal
program and hence the shortcut keys do not function.
Run the following command in any view to display the use of shortcut keys.
Action
Command
Check the usage of shortcut keys.display hotkey
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
This section provides several examples for using command lines.
2.5.1 Example for Running Commands in Batches
This part provides an example for running commands in batches. In this example, by editing the
commands to be run in batches, you can configure the system to automatically run the commands
in batches.
Context
If commands are frequently used consecutively, especially a large number of commands, you
can run the commands in batches to improve efficiency.
For example, during the preventive maintenance inspection (PMI), you can run commands in
batches. That is, enter all PMI commands once and then send all the command output information
to the PMI tool, which can improve the PMI efficiency.
Procedure
Step 1 Edit the display users, display startup, and display clock commands to be run in batches.
Step 2 Run the commands in batches.
Log in to the router and do as follows:
<HUAWEI> batch-cmd edit
Info: Begin editing batch commands. Press "Ctrl+Z" to abort this session.
This example shows how to use the Tab key. After inputting an incomplete keyword, you can
press Tab and obtain all related keywords or verify the correctness of the input keyword.
Context
Usually, you do not need to input complete keywords. Instead, you can just input one or a few
beginning characters of a keyword and press Tab to complete the keyword. The Tab key helps
search for and use commands.
Procedure
lTab can be used in three ways as shown in the following example.
– The matching key word is unique after the incomplete key word is input.
1.Input the incomplete key word.
[HUAWEI] info-
2.Press Tab.
The system replaces the input one with the complete key word and displays it in a
new line with the cursor leaving a space behind.
[HUAWEI] info-center
– There are several matches or no match after the incomplete key word is input.
The system displays information in a new line, but the keyword loglog remains
unchanged and there is no space between the cursor and the keyword, indicating
that this keyword is inexistent.
----End
2.5.3 Example for Using Shortcut Keys
This example shows how to use shortcut keys. In this example, frequently-used commands are
correlated with shortcut keys. You can press the shortcut keys instead of inputting the commands.
This facilitates user operation and improves efficiency.
Context
If the login router is defined with shortcut keys, the shortcut keys can be used by any user
regardless of the user level.
Procedure
Step 1 Correlate Ctrl_U with the display ip routing-table command and run the shortcut keys.
<HUAWEI> system-view
[HUAWEI] hotkey ctrl_u "display ip routing-table"
NOTE
When defining shortcut keys for a command, use double quotation marks to quote the command if the
command consisting of multiple words, which are separated by spaces. No double quotation marks are
required for single-word commands.
Step 2 Press Ctrl_U when the prompt [HUAWEI] appears.
[HUAWEI] display ip routing-table
Route Flags: R - relay, D - download to fib
-----------------------------------------------------------------------------Routing Tables: Public
Destinations : 8 Routes : 8
Destination/Mask Proto Pre Cost Flags NextHop Interface
51.51.51.9/32 Direct 0 0 D 127.0.0.1 InLoopBack0
100.2.0.0/16 Direct 0 0 D 100.2.150.51 GigabitEthernet0/
0/0
100.2.150.51/32 Direct 0 0 D 127.0.0.1 InLoopBack0
100.2.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.0/8 Direct 0 0 D 127.0.0.1 InLoopBack0
127.0.0.1/32 Direct 0 0 D 127.0.0.1 InLoopBack0
127.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
255.255.255.255/32 Direct 0 0 D 127.0.0.1 InLoopBack0
2.5.4 Example for Copying Commands Using Shortcut Keys
This example shows how to copy commands by using shortcut keys. In this example, after a
specified command is copied by using shortcut keys, you can use the shortcut keys
Ctrl_Shift_V to paste the command.
Context
If you need to repeatedly run a command, you can use shortcut keys to copy the command.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The copied command is saved on the clipboard and is available for only the current logged-in
user. After the user logs out of the router, the clipboard is cleared.
You can use shortcut keys to copy a command in any view.
Procedure
Step 1 Move the cursor to the beginning of the command and press Esc_Shift_<. Move the cursor to
the end and press Esc_Shift_>.
<HUAWEI> display ip routing-table
Step 2 Run the display clipboard command to view the contents on the clipboard.
<HUAWEI> display clipboard
---------------- CLIPBOARD----------------display ip routing-table
Step 3 Enter the command in any view, and press Ctrl_Shift_V to paste the contents of clipboard.
<HUAWEI> display ip routing-table
NOTE
If you press shortcut keys to copy a new command, you can paste only the new command by using shortcut
keys.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
This section describes how to configure the basic system environment.
3.1.1 Establishing the Configuration Task
Before configuring the basic system environment, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This can help
you complete the configuration task quickly and accurately.
Applicable Environment
Before configuring services, you need to configure the basic system environment (such as the
language mode, time, device name, login information, and command level) to meet the
environment requirement.
Pre-configuration Tasks
Before configuring the basic system environment, complete the following task:
lPowering on the router
Data Preparation
To configure the basic system environment, you need the following data.
No.
1Language mode
2System time
3Host name
4Login information
5Command level
Data
3.1.2 Switching the Language Mode
You can switch between the Chinese mode and the English mode as needed.
Context
After the language mode is switched, the system displays prompts and outputs of command lines
in the specified language.
Language information (Chinese and English) has been stored in the system software and does
not need to be loaded.
Do as follows in the user view:
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The help information on the router can be in English or in Chinese. The language mode is
stored in the system software and does not need to be loaded.
----End
3.1.3 Configuring the Equipment Name
When multiple devices on the network need to be managed, you can identify them by setting an
equipment name for each device.
Context
The new equipment name takes effect immediately.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
sysname host-name
The equipment name is set.
By default, the equipment name of the router is HUAWEI.
You can change the name of the router that appears in the command prompt.
----End
3.1.4 Setting the System Clock
You need to set the system time properly to ensure the cooperation between the NE80E/40E and
other devices.
Context
The system clock displays the current time and date of the system, time zone to which the system
belongs, and daylight saving time. The NE80E/40E supports the configurations of the time zone
and the daylight saving time.
Do as follows in the user view:
Procedure
Step 1 Run:
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
clock daylight-saving-time time-zone-name repeating start-time { { first | second
| third | fourth | last } weekday month | start-date } end-time { { first |
second | third | fourth | last } weekday month | end-date } offset [ start-year
[ end-year ] ]
The daylight saving time is set.
By default, the daylight saving time is not set.
During the configuration of the daylight saving time, you can configure the starting time and
ending time in one of the following modes: date+date, week+week, date+week, and week+date.
For details, see clock daylight-saving-time.
CAUTION
When the device is upgraded from an earlier version to the V600R003C00 version, the
configured daylight saving time does not take effect and needs to be reconfigured.
----End
3.1.5 Configuring a Header
If you need to provide information for users logging in, you can configure a header that the
system displays during or after login.
Context
A header text is a message displayed by the system when and after a user is logging in to the
router.
If you need to provide information for login users, you can configure a header that the system
displays during login or after login.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
header login { information text | file file-name }
The header displayed during login is set.
Step 3 Run:
header shell { information text | file file-name }
The header displayed after login is set.
To display the header when the terminal connection has been activated but the user is not being
authenticated, configure the parameter login.
To display the header after the user logs in successfully, configure the parameter shell.
If the user can log in to the router without authentication, the system directly displays the header
after the login.
CAUTION
l The header text starts and ends with the same character. After a character is input and
Enter is pressed, an interactive interface is displayed. You can input the required information
ended with the first character. The system then exits from the interactive interface.
l If a user logs in to the router by using SSH1.X, the login header is not displayed during login,
but the shell header is displayed after login.
l If a user logs in to the router by using SSH2.0, both login and shell headers are displayed.
----End
3.1.6 Configuring Command Levels
This section describes how to configure command levels to ensure device security or allow lowlevel users to run high-level commands. By default, commands are registered in the sequence
of Level 0 to Level 3. If refined rights management is required, you can divide commands in to
16 levels, that is, from Level 0 to Level 15.
Context
If the user does not adjust a command level separately, after the command level is updated, all
originally-registered command lines adjust automatically according to the following rules:
lThe commands of Level 0 and Level 1 remain unchanged.
lThe commands of Level 2 are updated to Level 10 and the commands of Level 3 are updated
to Level 15.
lNo command lines exist in Level 2 to Level 9 and Level 11 to Level 14. The user can adjust
the command lines to these levels separately to refine the management of privilege.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Changing the default level of a command is not recommended. If the default level of a command
is changed, some users may be unable to use the command any longer.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
command-privilege level rearrange
Update the command level in batches.
When no password is configured for a Level 15 user, the system prompts the user to set a superpassword for the level 15 user. At the same time, the system asks if the user wants to continue
with the update of command line level. Then, just select "N" to set a password. If you select "Y",
the command level can be updated in batches directly. This results in the user not logging in
through the Console port and failing to update the level.
The command level is configured. With the command, you can specify the level and view
multiple commands at one time (command-key).
All commands have default command views and levels. You do not need to reconfigure them.
----End
3.1.7 Configuring the Undo Command to Match in the Previous
View Automatically
You can run the undo command in the current view and thus the system automatically matches
the previous view.
Context
If the user allows the undo command to automatically match the previous view and the user
runs the undo command that is not registered in the current view, the system searches the
undo command in the previous view.
CAUTION
The undo command has disadvantages due to automatically matching. For example, when the
user runs the undo ospf command in the interface view where the command is not registered,
the system searches in system view automatically. This may lead to global deletion of the OSPF
feature.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The undo command is configured to match the upper level view.
By default, the undo command does not match the previous view automatically.
NOTE
l The matched upper-view command is valid for current login users who run this command.
l It is not recommended that you configure the undo command to automatically match the upper level
view, unless necessary.
----End
3.2 Displaying System Status Messages
This section describes how to use display commands to check basic configurations of the current
system.
Context
You can use the display commands to collect information about the system status. The display
commands are classified according to the following functions:
lDisplays system configurations.
lDisplays the running status of the system.
lDisplays the diagnostic information about a system.
lDisplays the restart information about the main control board.
See the related sections for display commands for protocols and interfaces. The following part
only shows the system-level display commands.
Run the following commands in any view.
3.2.1 Displaying System Configuration
This section describes how to check the system version, system time, original configuration, and
current configuration by using command lines.
Prerequisite
Basic configuration are complete.
Procedure
lRun the display version command to display the system version.
lRun the display clock [ utc ] command to display the system time.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
lRun the display calendar command to display system calendar.
lRun the display saved-configuration command to display the original configuration.
lRun the display current-configuration command to display the current configuration.
NOTE
l The display version command can be used to display the software version of the system, the
chassis type, and the information about the main control board and interface board.
l The original configuration refers to information about configuration files used by the device when
the device has been powered on and is being initialized. The current configuration refers to the
configuration files taking effect during the device operation. For details, see the chapter
"Configuring System Startup" in the NE80E/40E Basic-Configuration.
----End
3.2.2 Displaying System Status
This section describes how to check the system operating status (the configuration of the current
view) by using command lines.
Prerequisite
Basic configurations are complete.
Procedure
lRun the display this command to display the configuration of the current view.
----End
3.2.3 Collecting System Diagnostic Information
This section describes how to collect information about all modules in the system.
Context
When the system fails to perform routine maintenance, you need to collect a lot of information
to locate faults. Then, you have to run different display commands to collect all information. In
this case, you can use the display diagnostic-information command to collect all information
about the current running modules in the system.
Procedure
lRun:
display diagnostic-information [ file-name ]
The system diagnosis information is displayed.
The display diagnostic-information command collects all information collected by
running the following commands, including display clock, display version, display cpu-
usage, display interface, display current-configuration, display saved-configuration,
display history-command, and so on.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
A user can log in to the router by using a console port or an AUX port, or by means of Telnet
or SSH (STelnet). For users logging in to router in different modes, the system uses different
user interfaces to manage the sessions between the router and the users.
4.1 User Interface Overview
The system supports console, AUX, and VTY user interfaces.
4.2 Configuring the Console User Interface
When a user logs in to the router by using a console port for local maintenance, you can configure
attributes for the corresponding console user interface are needed.
4.3 Configuring the AUX User Interface
When a user logs in to the router for local or remote configuration by using an AUX port,
configuring attributes in the corresponding AUX user interface is needed.
4.4 Configuring VTY User Interface
If you need to log in to the router for local or remote maintenance by using Telnet or SSH, you
can configure the corresponding VTY user interface as needed.
4.5 Configuration Examples
This section provides examples for configuring console, AUX, and VTY user interfaces. These
configuration examples explain networking requirements, configuration roadmap, and
configuration notes.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The system supports console, AUX, and VTY user interfaces.
Each user interface has a corresponding user interface view. A user interface view is a command
line view provided by the system. It is used to configure and manage all the physical and logical
interfaces in asynchronous mode.
User Interfaces Supported by the System
lConsole port (CON)
The console port is a serial port provided by the main control board of the router.
The main control board provides one EIA/TIA-232 DCE console port for local
configuration by directly connecting a terminal to a router.
lAuxiliary port (AUX)
It is a linear port provided by the main control board of the router and supports the dialup
by using a modem.
Each main control board provides one AUX port with the type of EIA/TIA-232 DTE. A
terminal can remotely access the router through the modem on the AUX port.
lVirtual type terminal (VTY)
It is a logical terminal line. A VTY connection is set up when a router connects to a terminal
by means of Telnet. It is used for local or remote access to a router. A maximum of 16 users
can log in to the router by using the VTY user interface.
Numbering of a User Interface
After a user logs in to the router, the system assigns an idle user interface of the smallest number
to the user according to the user's login mode. You can number a user interface in the following
manners:
lRelative numbering
The relative numbering is in the format of user interface type + number.
The relative numbering is available for interfaces of a specific type. It is used only to specify
one or a group of user interfaces of a specified type. Relative numbering must comply with
the following rules:
– Number of the console port: CON 0
– Number of the auxiliary port: AUX 0
– Number of the VTY: VTY 0 for the first line, VTY 1 for the second line, and so on
lAbsolute numbering
The absolute numbering is used to uniquely specify a user interface or a group of user
interfaces.
The number starts with 0. The ports are numbered in the sequence of CON → AUX →
VTY. There is only one console port and one AUX port and 0-15 VTY interfaces. You can
use the user-interface maximum-vty command to set the maximum number of user
interfaces. The default number is five.
By default, the system supports three types of user interfaces: CON, AUX, and VTY.
Table 4-1 shows the absolute numbers of the user interfaces in this system.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
When a user logs in to the router by using a console port for local maintenance, you can configure
attributes for the corresponding console user interface are needed.
4.2.1 Establishing the Configuration Task
Before configuring the console user interface, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This can help
you complete the configuration task quickly and accurately.
Applicable Environment
If you need to log in to the router for local maintenance by using a console port, you can configure
the corresponding console user interface, including the physical attributes, terminal attributes,
user priority, and user authentication mode. The preceding parameters have default values on
the router and additional configuration is not needed. You can configure these parameters as
needed.
Pre-configuration Tasks
Before configuring a console user interface, complete the following tasks:
lLogging in to the router by using a terminal
Data Preparation
To configure a console user interface, you need the following data.
No.
1Baud rate, flow-control mode, parity, stop bit, and data bit
2Idle timeout period, number of lines displayed in a terminal screen, and the size of
3User priority
4User authentication method, user name, and password
Data
history command buffer
NOTE
All the default values (excluding the password and username) are stored on the router and do not need
additional configuration.
4.2.2 Setting Physical Attributes of Console User Interface
You can configure the rate, flow control mode, parity mode, stop bit, and data bit for the console
port.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Physical attributes of a console port have default values on the router and no additional
configuration is needed.
NOTE
When a user logs in to a router through a console port, the physical attributes set for the console port on
the HyperTerminal should be consistent with the attributes of the console user interface on the router.
Otherwise, the user cannot log in to the router.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface console interface-number
The console user interface view is displayed.
Step 3 Run:
speed speed-value
The baud rate is set.
By default, the baud rate is 9600 bit/s.
Step 4 Run:
flow-control { hardware | none | software }
The flow control mode is set. By default, the flow-control mode is none.
Step 5 Run:
parity { even | mark | none | odd | space }
The parity mode is set.
By default, the value is none.
Step 6 Run:
stopbits { 1.5 | 1 | 2 }
The stop bit is set.
By default, the value is 1 bit.
Step 7 Run:
databits { 5 | 6 | 7 | 8 }
The data bit is set.
By default, the data bit is 8.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
4.2.3 Setting Terminal Attributes of Console User Interface
This section describes how to set terminal attributes of the console user interface, including the
user timeout disconnection function, number of lines displayed in a terminal screen, and size of
the history command buffer.
Context
Terminal attributes of the console user interface have default values on the router and you can
set them as needed.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface console interface-number
The console user interface view is displayed.
Step 3 Run:
shell
The terminal service is started.
Step 4 Run:
idle-timeout minutes [ seconds ]
The idle timeout period is set.
If the connection keeps idle within the timeout period, the system automatically terminates the
connection.
By default, the idle timeout period on the user interface is 10 minutes.
Step 5 Run:
screen-length screen-length [temporary]
The length of a terminal screen is set.
The parameter temporary is used to display the number of lines to be temporarily displayed on
a terminal screen.
By default, the length of a terminal screen is 24 lines.
Step 6 Run:
history-command max-size size-value
The history command buffer is set.
By default, the size of history command buffer on a user interface is 10 entries.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
4.2.4 Configuring User Priority of Console User Interface
This section describes how to control users' authority of logging in to the router and improve
the security of managing the router by configuring the user priority.
Context
lSimilar to command levels, users are classified into 16 levels numbered 0 to 15. The greater
the number, the higher the user level.
lThis process is to set the priority for a user who logs in through the console port. A user
can only use the commands with the level corresponding to the user level.
For details about command levels, see "Command Level" in the chapter "CLI Overview" of
the Configuration Guide - Basic Configuration.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface console interface-number
The console user interface view is displayed.
Step 3 Run:
user privilege level level
The priority of the user is set.
NOTE
l By default, users logging in through the console user interface can use commands at level 3, and users
logging in through other user interfaces can use commands at level 0.
l If the command level is inconsistent with the user level, the user level takes precedence.
----End
4.2.5 Configuring the User Authentication Mode of the Console
User Interface
The system provides three authentication modes: AAA, password authentication, and nonauthentication. Configuring the user authentication mode can improve the security of the
router.
Context
By default, the user authentication mode of the console user interface is non-authentication.
Procedure
lConfiguring AAA Authentication
1.Run:
system-view
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
After configuring the console user interface, you can view information about the user interface,
physical attributes and configurations of the user interface, local user list, and online users.
Prerequisite
The configurations of the user management function are complete.
Procedure
lRun the display users [ all ] command to check information about the user interface.
lRun the display user-interfaceconsole ui-number1 [ summary ] command to check
physical attributes and configurations of the user interface.
lRun the display local-user command to check the local user list.
lRun the display access-user command to check the local user list.
----End
Example
Run the display users command, and you can view information about the current user interface.
<HUAWEI> display users
User-Intf Delay Type Network Address AuthenStatus AuthorcmdFlag
0 CON 0 00:00:44 pass no
Username : Unspecified
Run the display user-interface console ui-number1 [ summary ] command, and you can view
the physical attributes and configurations of the user interface.
<HUAWEI> display user-interface console 0
Idx Type Tx/Rx Modem Privi ActualPrivi Auth Int
0 CON 0 9600 - 3 - N -
+ : Current UI is active.
F : Current UI is active and work in async mode.
Idx : Absolute index of UIs.
Type : Type and relative index of UIs.
Privi: The privilege of UIs.
ActualPrivi: The actual privilege of user-interface.
Auth : The authentication mode of UIs.
A: Authenticate use AAA.
N: Current UI need not authentication.
P: Authenticate use current UI's password.
Int : The physical location of UIs.
Run the display local-user command, and you can view the local user list.
<HUAWEI> display local-user
--------------------------------------------------------------------------- Username State Type CAR Access-limit Online
--------------------------------------------------------------------------- user123 Active All Dft No 0
ll Active F Dft No 0
user1 Active F Dft No 0
--------------------------------------------------------------------------- Total 3,3 printed
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
When a user logs in to the router for local or remote configuration by using an AUX port,
configuring attributes in the corresponding AUX user interface is needed.
4.3.1 Establishing the Configuration Task
Before configuring the AUX user interface, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This can help
you complete the configuration task quickly and accurately.
Applicable Environment
If you need to log in to the router for remote maintenance by using an AUX port, you can
configure the corresponding AUX user interface as needed by setting the physical attributes,
terminal attributes, user priority, and user authentication mode. The preceding parameters have
default values on the router and additional configuration is not needed.
Pre-configuration Tasks
Before configuring an AUX user interface, complete the following tasks:
lLogging in to the router by using a terminal
Data Preparation
Before configuring an AUX user interface, you need the following data.
No.
1Baud rate, flow-control mode, parity, stop bit, and data bit
2Idle timeout period, number of lines displayed in a terminal screen, and the size of
3User priority
4Modem attributes
5(Optional) Auto-execute commands
6User authentication method, user name, and password
Data
history command buffer
NOTE
All the default values (excluding the auto-run commands, password, and username) are stored on the
router and do not need additional configuration.
4.3.2 Setting Physical Attributes of AUX User Interface
Physical attributes of the AUX user interface include the transmission rate, flow control mode,
parity mode, stop bit, and data bit of the AUX port.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Physical attributes of the AUX user interface have default values on the router and no additional
configuration is needed.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface aux interface-number
The AUX user interface view is displayed.
Step 3 Run:
speed speed-value
The transmission rate is set.
By default, the baud rate is 9600 bit/s.
Step 4 Run:
flow-control { hardware | none | software }
The flow control mode is set.
By default, the flow-control mode is none.
Step 5 Run:
parity { even | mark | none | odd | space }
The parity mode is set.
By default, the value is none.
Step 6 Run:
stopbits { 1.5 | 1 | 2 }
The stop bit is set.
By default, the value is 1 bit.
Step 7 Run:
databits { 5 | 6 | 7 | 8 }
The data bit is set.
By default, the value is 8.
NOTE
When the user logs in to a router through an AUX port, the configured attributes for the console port on
the HyperTerminal should be in accordance with the attributes of the AUX user interface on the router.
Otherwise, the user cannot log in to the router.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
4.3.3 Setting Terminal Attributes of AUX User Interface
This section describes how to configure terminal attributes of the AUX user interface, including
the user idle timeout, number of lines displayed in a terminal screen, and size of the history
command buffer.
Context
Terminal attributes of the AUX user interface have default values on the router and you can
configure them as needed.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface aux interface-number
The AUX user interface view is displayed.
Step 3 Run:
shell
AUX terminal service is enabled.
Step 4 Run:
idle-timeout minutes [ seconds ]
User idle timeout is enabled.
If the connection keeps idle within the timeout period, the system automatically terminates the
connection.
By default, idle timeout period on the interface is 10 minutes.
Step 5 Run:
screen-length screen-length [temporary]
The length of a terminal screen is set.
The parameter temporary is used to display the number of lines to be temporarily displayed on
a terminal screen.
By default, the length of a terminal screen is 24 lines.
Step 6 Run:
history-command max-size size-value
The size of the history command buffer is configured.
By default, the size of history command buffer on user interface is 10 entries.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
This section describes how to control users' authority of logging in to the router and improve
the security of managing the router by configuring the user priority.
Context
lSimilar to command levels, users are classified into 16 levels numbered 0 to 15. The greater
the number, the higher the user level.
lThis process is to set the priority for a user who logs in through the console port. A user
can only use the commands with the level corresponding to the user level.
For details about command levels, see "Command Level" in the chapter "CLI Overview" of
the Configuration Guide - Basic Configuration.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface aux interface-number
The AUX user interface view is displayed.
Step 3 Run:
user privilege level level
The user priority is set.
NOTE
l By default, users logging in by using the AUX user interface can use commands at level 0.
l If the authority to use commands is inconsistent with the user level, the user level takes precedence.
----End
4.3.5 Setting Modem Attributes of AUX User Interface
You can set the time period from picking up the signal to detecting the carrier when a call is
established, modem for only incoming calls or for both incoming and outgoing calls, and
automatic answer.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface aux interface-number
The AUX user interface view is displayed.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
The period between the system receiving the ring signal and the system waiting for the CD_UP
is set. That is the time that elapses between picking up the signal to detecting the carrier, since
the call is established.
By default, the waiting time is 30 seconds.
Step 4 Run:
modem [ both | call-in ]
The switch of incoming call or outgoing call is set.
By default, incoming and outgoing calls are prohibited.
Step 5 Run:
modem auto-answer
Automatic answer is enabled.
By default, manual answering is enabled.
----End
4.3.6 (Optional) Configuring Auto-Execute Commands of AUX User
Interface
You can set a command to be an auto-executed command.
Context
CAUTION
After the auto-execute command command is run, you cannot perform general configuration
in the system through a terminal.
Before configuring the auto-execute command command and the save command to save the
existing configurations, ensure that you can log in to the system using other methods to delete
the configurations.
Do as follows on the router that the user logs in to:
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface aux 0
The AUX user interface view is displayed.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
A command is specified as an auto-execute command.
Generally, the auto-execute command command is run to configure Telnet on a terminal. After
the configuration, the user can automatically connect to a designated host.
----End
4.3.7 Setting User Authentication Mode of AUX User Interface
The system provides three authentication modes: AAA, password authentication, and nonauthentication. Configuring the user authentication mode can improve the security of the
router.
Context
By default, the user authentication mode of the AUX user interface is non-authentication.
set authentication password { cipher | simple } password
A password is set.
lConfiguring Non-Authentication
1.Run:
system-view
The system view is displayed.
2.Run:
user-interface aux interface-number
The AUX user interface view is displayed.
3.Run:
authentication-mode none
The authentication mode is set to non-authentication.
----End
4.3.8 Checking the Configuration
After configuring the AUX user interface, you can view the usage information of the user
interface, physical attributes and configurations of the user interface, local user list, and online
users.
Prerequisite
Configurations of the AUX user interface are complete.
Procedure
lRun the display users [ all ] command to check usage information about the AUX user
interface.
lRun the display user-interfaceaux interface-number [ summary ] command to check
physical attributes and configurations of the user interface.
lRun the display local-user command to check the local user list.
lRun the display access-user command to check the local user list.
----End
Example
Run the display users command, and you can view information about the current user interface.
<HUAWEI> display users
User-Intf Delay Type Network Address AuthenStatus AuthorcmdFlag
33 AUX 0 00:00:44 pass no
Username : Unspecified
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Run the display user-interfaceaux ui-number1 [ summary ] command, and you can view the
physical attributes and configurations of the user interface.
<HUAWEI> display user-interface aux 0
Idx Type Tx/Rx Modem Privi ActualPrivi Auth Int
33 AUX 0 9600 - 0 - N -
+ : Current UI is active.
F : Current UI is active and work in async mode.
Idx : Absolute index of UIs.
Type : Type and relative index of UIs.
Privi: The privilege of UIs.
ActualPrivi: The actual privilege of user-interface.
Auth : The authentication mode of UIs.
A: Authenticate use AAA.
N: Current UI need not authentication.
P: Authenticate use current UI's password.
Int : The physical location of UIs.
Run the display local-user command, and you can view the local user list.
<HUAWEI> display local-user
--------------------------------------------------------------------------- Username State Type CAR Access-limit Online
--------------------------------------------------------------------------- user123 Active All Dft No 0
ll Active F Dft No 0
user1 Active F Dft No 0
--------------------------------------------------------------------------- Total 3,3 printed
4.4 Configuring VTY User Interface
If you need to log in to the router for local or remote maintenance by using Telnet or SSH, you
can configure the corresponding VTY user interface as needed.
4.4.1 Establishing the Configuration Task
Before configuring the VTY user interface, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the required data. This can help you complete
the configuration task quickly and accurately.
Applicable Environment
If you need to log in to the router for local or remote maintenance by using Telnet or SSH, you
can configure the corresponding VTY user interface, including the maximum number of VTY
user interfaces, limit of incoming and outgoing calls, user priority, and user authentication mode.
The preceding parameters have default values on the router. You can also set these parameters
as needed.
Pre-configuration Tasks
Before configuring VTY user interface, complete the following tasks:
lLogging in to the router by using a terminal
Data Preparation
To configure a VTY user interface, you need the following data.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
2(Optional) ACL code to limit VTY user interface to call in and out
3Idle timeout period, number of characters in each line displayed in a terminal screen
4User priority
5User authentication method, user name, and password
NOTE
All the preceding parameters (excluding the ACL for limiting incoming and outgoing calls in VTY user
interfaces, password, and user name) have default values on the router, and no additional configuration is
needed.
4.4.2 Configuring Maximum VTY User Interfaces
Context
Procedure
Step 1 Run:
Step 2 Run:
This section describes how to limit the number of users logging in to the router by configuring
the maximum number of VTY user interfaces.
The maximum number of VTY user interfaces is the total number of users logging in to the
router by using Telnet and SSH.
system-view
The system view is displayed.
user-interface maximum-vty number
The maximum VTY user interfaces that can log in to the router is set.
NOTE
When the maximum number of VTY user interfaces is set to zero, any user (including the NMS user) cannot
log in to the router by using a VTY user interface.
If the maximum number of VTY user interfaces to be configured is smaller than the maximum
number of current interfaces, current online users will not be affected and no addition
configuration is needed.
If the maximum number of VTY user interfaces to be configured is larger than the maximum
number of current interfaces, the authentication mode and password need to be configured for
newly added user interfaces.
For newly added user interfaces, the system defaults to password authentication.
For example, a maximum of five users are allowed online. To allow 15 VTY users online at the
same time, you need to run the authentication-mode command and the set authentication
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
4.4.3 (Optional)Setting Limit on Incoming and Outgoing Calls of
VTY User Interfaces
This section describes how to configure an ACL to limit incoming and outgoing calls of the
VTY user interface.
Context
Before setting the limit on incoming and outgoing calls of the VTY user interface, run the acl
command in the system view to create an ACL and enter the ACL view. Then, run the rule
command to add rules to the ACL.
Procedure
Step 1 Run:
Step 2 Run:
Step 3 Run:
NOTE
The user interface supports the basic ACL ranging from 2000 to 2999 and the advanced ACL ranging from
3000 to 3999.
The limits to calling in/out of VTY are configured.
l When you need to prevent a user of certain address or segment address from logging in to
the router, use the inbound command.
l When you need to prevent a user who logs in to a router from accessing other routers, use
the outbound command.
----End
4.4.4 Setting Terminal Attributes of the VTY User Interface
This section describes how to configure terminal attributes of the VTY user interface, including
user idle timeout, number of lines displayed in a terminal screen, and size of the history command
buffer.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Terminal attributes of the VTY user interface have default values on the router and you can set
them as needed.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface vty number1 [ number2 ]
The VTY user interface view is displayed.
Step 3 Run:
shell
VTY terminal service is enabled.
Step 4 Run:
idle-timeout minutes [ seconds ]
User idle timeout is enabled.
If the connection keeps idle within the timeout period, the system automatically terminates the
connection.
By default, the timeout period is 10 minutes.
Step 5 Run:
screen-length screen-length [temporary]
The length of a terminal screen is set.
The parameter temporary is used to display the number of lines to be temporarily displayed on
a terminal screen.
By default, the length of a terminal screen is 24 lines.
Step 6 Run:
history-command max-size size-value
Set the size of the history command buffer.
By default, a maximum number of 10 commands can be cached in the history command buffer.
----End
4.4.5 Setting User Priority of VTY User Interface
This section describes how to control users' authority of logging in to the router and improve
the security of managing the router by configuring the user priority.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
lSimilar to command levels, users are classified into 16 levels numbered 0 to 15. The greater
the number, the higher the user level.
lThis process is to set the priority for a user who logs in through the console port. A user
can only use the commands with the level corresponding to the user level.
For details about command levels, see "Command Level" in the chapter "CLI Overview" of
the Configuration Guide - Basic Configuration.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface vty interface-number
The VTY user interface view is displayed.
Step 3 Run:
user privilege level level
The user priority is set.
By default, users logging in through the VTY user interface can use commands at level 0.
NOTE
If the command level configured in the VTY user interface view is inconsistent with the user priority, the
user priority takes effect.
----End
4.4.6 Setting User Authentication Mode of the VTY User Interface
The system provides three authentication modes: AAA, password authentication, and nonauthentication. Configuring the user authentication mode can improve the security of the
router.
Context
By default, the user authentication mode of the VTY user interface is password authentication.
Procedure
lConfiguring AAA Authentication
1.Run:
system-view
The system view is displayed.
2.Run:
user-interface vty number1 [ number2 ]
The VTY user interface view is displayed.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
An authentication mode used to log in to the user interface is configured.
NOTE
The system reserves five VTYs (VTY 16-VTY 20) for an NMS user. The five VTYs are used as special
channels of the network management. The channels do not support the RSA authentication mode but
support the password authentication.
Step 8 Run:
quit
The system view is displayed.
Step 9 Run:
mmi-mode enable
The system is switched to the machine-to-machine mode.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
l This command is invisible to terminals and cannot be obtained by using the online help. In man-to-
machine mode, exercise caution when using this command.
l In the VTY machine-to-machine mode, the system reserves five user interfaces to which an NMS user
can log in through VTYs. A common user cannot log in through Telnet but can log in by using the five
reserved user interfaces.
l In the machine-to-machine mode, the system does not output logs, alarms, and debugging information
to the screen.
l In the machine-to-machine mode, the save and reboot commands can be used directly.
l In the machine-to-machine mode, a maximum of 512 lines are displayed by default. The value can be
adjusted by using the screen-length command. In addition, you can run the screen-length
temporary command to adjust the number of lines temporarily displayed on the screen.
----End
4.4.8 Checking the Configuration
After configuring the VTY user interface, you can view information about user interfaces, the
maximum number of VTY user interfaces, and physical attributes and configurations of user
interfaces.
Prerequisite
Procedure
Example
The configurations of the VTY user interface are complete.
lRun the display users [ all ] command to check information about user interfaces.
lRun the display user-interface maximum-vty command to check the maximum number
command to check the physical attributes and configurations of user interfaces.
lRun the display local-user command to check the local user list.
lRun the display vty mode command to check the VTY mode.
----End
Run the display users command, and you can view information about the current user interfaces.
<HUAWEI> display users
User-Intf Delay Type Network Address AuthenStatus AuthorcmdFlag
34 VTY 0 00:00:12 TEL 10.138.77.38 no
Username : Unspecified
+ 35 VTY 1 00:00:00 TEL 10.138.77.57 no
Username : Unspecified
Run the display user-interface maximum-vty command, and you can view the maximum
number of VTY user interfaces.
<HUAWEI> display user-interface maximum-vty
Maximum of VTY user:15
Run the display user-interface vty [ ui-number1 | ui-number ] [ summary ] command to check
the physical attributes and configurations of user interfaces.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
<HUAWEI> display user-interface vty 0
Idx Type Tx/Rx Modem Privi ActualPrivi Auth Int
+ 34 VTY 0 - 14 14 N + : Current UI is active.
F : Current UI is active and work in async mode.
Idx : Absolute index of UIs.
Type : Type and relative index of UIs.
Privi: The privilege of UIs.
ActualPrivi: The actual privilege of user-interface.
Auth : The authentication mode of UIs.
A: Authenticate use AAA.
N: Current UI need not authentication.
P: Authenticate use current UI's password.
Int : The physical location of UIs.
Run the display local-user command, and you can view the local user list.
<HUAWEI> display local-user
--------------------------------------------------------------------------- Username State Type CAR Access-limit Online
--------------------------------------------------------------------------- user123 Active All Dft No 0
ll Active F Dft No 0
user1 Active F Dft No 0
--------------------------------------------------------------------------- Total 3,3 printed
Run the display vty mode command, and you can view the prompt message indicating that the
machine-to-machine interface is enabled. For example:
<HUAWEI> display vty mode
current VTY mode is Machine-Machine interface
4.5 Configuration Examples
This section provides examples for configuring console, AUX, and VTY user interfaces. These
configuration examples explain networking requirements, configuration roadmap, and
configuration notes.
4.5.1 Example for Configuring Console User Interface
This part provides an example describing how to configure the console user interface. In this
configuration example, to allow a user in password authentication mode to log in to the router
by using a console user interface, multiple attributes of the console user interface are set,
including physical attributes, terminal attributes, user priority, user authentication mode, and
password.
Networking Requirements
To initialize configurations of the router or locally maintain the router, a user can log in to the
router through a console user interface. To allow the user to log in, you can set attributes of the
console user interface as needed (for security reasons, for example).
In the console user interface view, the user priority is set to 15, and the password authentication
mode is set (the password is huawei).
After a user logs in, if the user takes no action on the router for more than 30 minutes, the
connection between the user and the router is torn down.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
After the console user interface is configured, a user in password authentication mode can log
in to the router through a console port, implementing local maintenance of the router. For details
on how a user logs in to the router, see the 5 Configuring User Login.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
#
sysname HUAWEI
#
user-interface con 0
authentication-mode password
user privilege level 15
set authentication password simple huawei
history-command max-size 20
idle-timeout 30 0
screen-length 30
databits 6
parity even
stopbits 2
speed 4800
screen-length 30
#
return
4.5.2 Example for Configuring AUX User Interface
This part provides an example describing how to configure the AUX user interface. In the
configuration example, to allow a user in AAA authentication mode to log in to the router by
using an AUX user interface, multiple attributes of the console user interface are set, including
physical attributes, terminal attributes, user priority, user authentication mode, and password.
Networking Requirements
To maintain the router locally or remotely, a user can log in to the router through an AUX user
interface.
To allow the user login, an operator can set attributes of the AUX user interface as needed (for
security reasons, for example).
In the AUX user interface, the user priority is set to 15, and the authentication mode is set to
AAA, with the user name of user123 and the password of huawei.
After a user logs in, if the user takes no action on the router for more than 30 minutes, the
connection between the user and the router is torn down.
Configuration Roadmap
The configuration roadmap is as follows:
1.Enter the interface view and set physical attributes of the AUX user interface.
2.Set terminal attributes of the AUX user interface.
3.Set the user priority of the AUX user interface.
4.Set modem attributes of the AUX user interface.
5.Set the authentication mode and password in the AUX user interface.
Data Preparation
To complete the configuration, you need the following data:
lTransmission rate of the AUX user interface: 9600 bit/s
lFlow control mode of the AUX user interface: None
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
All the preceding physical attributes of the AUX user interface are set with default values. In
fact, if a user chooses to use the default values, the user does not need to set them. The preceding
settings only mean to provide the configuration method.
Step 2 Set terminal attributes of the AUX user interface.
After the AUX user interface is configured, a user in AAA authentication mode can log in to
the router through an AUX port, implementing maintenance of the router. For details on how a
user logs in to the router, refer to the 5 Configuring User Login.
----End
Configuration Files
#
sysname HUAWEI
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
This part provides an example describing how to configure the VTY user interface. In this
configuration example, to allow a user in password authentication mode to log in to the router
by using Telnet or SSH (Stelnet), multiple attributes of the VTY user interface are set, including
the maximum number of VTY user interfaces, call-in and call-out limit, terminal attributes,
authentication mode, and password.
Networking Requirements
A user logs in to the router through a VTY channel by using Telnet or SSH. To allow the user
login, an operator can set attributes of the VTY user interface as needed (for security reasons,
for example).
In the VTY user interface, the user priority is set to 15, the authentication mode is set to password,
with the password of "huawei", and the user with the IP address of 10.1.1.1 is prohibitted from
logging in to the router.
After logging in, if the user takes no action on the router for more than 30 minutes, the connection
between the user and the router is torn down.
Configuration Roadmap
The configuration roadmap is as follows:
1.Enter the interface view and set the maximum number of VTY user interfaces to 15.
2.Set the call-in and call-out limit of the VTY user interface, limiting the access of an IP
address or an IP address segment to the router.
3.Set terminal attributes of the VTY user interface.
4.Set the user priority in the VTY user interface.
5.Set the authentication mode and password in the VTY user interface.
Data Preparation
To complete the configuration, you need the following data:
lMaximum number of VTY user interfaces: 15
lACL applied to limit call-in in the VTY user interface: 2000
lTimeout period for disconnecting from the VTY user interface: 30 minutes
lNumber of lines that a terminal screen displays: 30
lSize of the history command buffer: 20
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
After the VTY user interface is configured, a user authenticated in password mode can log in to
the router by using Telnet or SSH (Stelnet), implementing local or remote maintenance of the
router. For details on how a user logs in to the router, see the 5 Configuring User Login.
A user can log in to the router through a console port, an AUX port, or by using Telnet or SSH
(STelnet). After the login, the user can maintain the router locally or remotely.
5.1 Overview of User Login
Users can manage and maintain the router only after logging in to the router. Users can log in
to the router by using the AUX port, console port, Telnet, or STelnet (SSH Telnet).
5.2 Logging in to the Devices Through the Console Port
When a user needs to configure the router that is powered on for the first time or locally maintain
the router, the user can log in to the router through a console port.
5.3 Logging in to the Devices Through the AUX Port
When a user terminal and the router have no reachable route between each other, the user can
remotely configure and manage or locally maintain the router by logging in to the router through
an AUX port.
5.4 Logging in to the Devices by Using Telnet
If multiple routers need to be configured and managed, you do not need to connect the routers
and maintain them locally one by one. Instead, you can log in to the routers from a terminal by
using Telnet. This implements remote maintenance of the router and greatly facilitates device
management.
5.5 Logging in to the Devices by Using STelnet
STelnet provides secured remote access over an insecure network. After the client/server
negotiation is complete and a secured connection is established, a user can log in to the router
in a similar way as Telnet.
5.6 Common Operations After Login
After logging in to the router, you can perform following operations as needed, such as user
priority switching and terminal window locking.
5.7 Configuration Examples
This section provides several examples describing how to configure user login by using a console
port, Telnet, or STelnet. You can understand the configuration procedures by referring to the
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
configuration flowchart. The configuration examples provide information about the networking
requirements, configuration notes, and configuration roadmap.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Users can manage and maintain the router only after logging in to the router. Users can log in
to the router by using the AUX port, console port, Telnet, or STelnet (SSH Telnet).
To configure, monitor, and maintain the local or remote network devices running NE80E/40E,
you need to configure the user interface, the user management, and the terminal service.
The user interface provides a login plane. The user management guarantees the login security
and the terminal service provides related processes of login protocol.
The NE80E/40E supports the following login methods:
lLogin through the console port
lLocal or remote login through the AUX port
lLocal or remote login through Telnet or STelnet
Table 5-1 User login modes
Login ModeApplication
Console portUsers log in to the router through the console port to configure the router
locally. Login through the console port is required when the router is
powered on for the first time.
TelnetUsers log in to the router by using Telnet for local and remote maintenance.
Telnet helps users maintain remote devices but brings security threats.
AUX portUsers log in to the router through the AUX port to maintain the router locally
when there is no available route and Telnet is unsuitable.
SSH (STelnet)SSH (STelnet) provides security protection for users logging in to the
router to maintain the router locally or remotely.
NOTE
Logins by using Telnet bring security risks because no secure authentication mechanism is available and
data is transmitted by using TCP in plain text mode. Unlike Telnet, SSH guarantees secure data transmission
on a conventional insecure network by authenticating the client and encrypting data in both directions. SSH
supports security Telnet (STelnet).
For detailed information about SSH, see the NE80E/40E Feature Description - Basic Configurations.
5.2 Logging in to the Devices Through the Console Port
When a user needs to configure the router that is powered on for the first time or locally maintain
the router, the user can log in to the router through a console port.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Before configuring user login through a console port, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
A user can log in to the router locally through a console port. If the router is powered on for the
first time, the user has to log in through a console port.
Pre-configuration Tasks
Before configuring user login through a console port, complete the following tasks:
lConfiguring the PC/terminal (including the serial port and RS-232 cable)
lInstalling the terminal emulator (such as HyperTerminal of Windows XP) to the PC
Data Preparation
To configure user login through a console port, you need the following data.
No.Data
1
l Transmission rate, flow control mode, parity mode, stop bit, data bit
l Number of lines displayed in a terminal screen, size of the history command buffer
l User priority
l User authentication mode, user name, and password
5.2.2 Configuring Console User Interface
To allow users to log in to the router through a console port, configure attributes of the console
user interface.
Context
Attributes of an console user interface have default values on the router, and generally need no
additional settings. To meet specific application requirements or ensure network security, you
can set attributes of the console user interface, such as terminal attributes and user authentication
mode.
For detailed settings, see Configuring Console User Interface.
5.2.3 Logging in to the router Through a Console Port
A user can log in to the router by connecting a terminal with the router through a console port.
Context
For details, see Login Through the Console Portrouter.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
l Communication parameters of the user terminal must be consistent with the physical attribute
parameters of the console user interface on the router.
l If a user authentication mode is specified in the console user interface, a user can log in to the router
only after passing the authentication. This enhances network security.
5.2.4 Checking the Configuration
After a user logs in through a console port, the user can view information on the console user
interface, such as use information, physical attributes and configurations, local user list, and
online users.
Prerequisite
Configurations of user login through a console port are complete.
Procedure
lRun the display users [ all ] command to check information about the user interface.
lRun the display user-interfaceconsole ui-number1 [ summary ] command to check
physical attributes and configurations of the user interface.
lRun the display local-user command to check the local user list.
lRun the display access-user command to check the local user list.
Example
----End
Run the display users command, and you can view information about the current user interface.
<HUAWEI> display users
User-Intf Delay Type Network Address AuthenStatus AuthorcmdFlag
0 CON 0 00:00:44 pass no
Username : Unspecified
Run the display user-interface console ui-number1 [ summary ] command, and you can view
the physical attributes and configurations of the user interface.
<HUAWEI> display user-interface console 0
Idx Type Tx/Rx Modem Privi ActualPrivi Auth Int
0 CON 0 9600 - 3 - N -
+ : Current UI is active.
F : Current UI is active and work in async mode.
Idx : Absolute index of UIs.
Type : Type and relative index of UIs.
Privi: The privilege of UIs.
ActualPrivi: The actual privilege of user-interface.
Auth : The authentication mode of UIs.
A: Authenticate use AAA.
N: Current UI need not authentication.
P: Authenticate use current UI's password.
Int : The physical location of UIs.
Run the display local-user command, and you can view the local user list.
5.3 Logging in to the Devices Through the AUX Port
When a user terminal and the router have no reachable route between each other, the user can
remotely configure and manage or locally maintain the router by logging in to the router through
an AUX port.
5.3.1 Establishing the Configuration Task
Before configuring user login through an AUX port, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
You can configure and maintain the router locally or remotely through an AUX port.
In local configuration of the router, the AUX login method is similar to the console login method.
The only difference between the two login methods lies in the default user priority: The default
user priority of the console user interface is 3, whereas that of the AUX user interface is 0.
Therefore, Logging in by using the console login method is recommended in the local
configuration. The following part mainly describes remote login of the router through an AUX
port.
NOTE
To manage and maintain the router through an AUX port, firstly modify the user priority of the AUX user
interface.
When there is no reachable route between a PC and the router, you can connect the serial port
of the PC to the AUX port of the router by using a modem. In this manner, you can use the PSTN
to configure and maintain the router remotely.
As shown in Figure 5-1, The COM interface of the PC is connected to the modem that is
connected to the PSTN. The AUX port of the router is connected to another modem that is
connected to the PSTN.
Figure 5-1 Networking diagram of remote login through an AUX port
Pre-configuration Tasks
Before configuring user login through an AUX port, complete the following tasks:
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
lInstalling a terminal emulator (such as HyperTerminal of Windows XP) in the PC
Data Preparation
To configure user login through an AUX port, you need the following data.
No.Data
1
2
l Transmission rate, flow control mode, parity, stop bit, data bit
l Number of lines displayed in a terminal screen, size of the history command buffer
l user priority
l modem attributes
l (Optional) Auto-run commands
l User authentication mode, user name, password
Telephone number of the modem at the remote router side.
5.3.2 Configuring AUX User Interface
To allow users to log in to the router through an AUX port, configure attributes of the AUX user
interface.
Context
Attributes of an AUX user interface have default values on the router, and generally need no
additional settings. To meet specific application requirements or ensure network security, you
can also set attributes of the AUX user interface, such as terminal attributes and user
authentication mode.
For detailed settings, see Configuring AUX User Interface.
5.3.3 Logging in to the routerThrough an AUX Port
You can establish a connection between a terminal and the router through an AUX port.
Procedure
Step 1 Start a terminal emulator (such as HyperTerminal of Windows XP) in the PC to establish a
connection with the router, as shown in Figure 5-2.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
If certain communication parameters need to be modified, press Modify in the Figure 5-4, as
shown in Figure 5-5, and then press Set, as shown in Figure 5-6.
Figure 5-5 Connection attribute modification
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
Step 4 Press Dialing. If user authentication is needed, input the corresponding authentication
information, and wait till the command line prompt of the user view appears, such as
<HUAWEI>. This indicates that the user view is entered and relevant configurations can be
input.
----End
5.3.4 Checking the Configuration
After a user log in through an AUX port, the user can view information on the console user
interface, such as use information, physical attributes and configurations, local user list, and
online users.
Prerequisite
Configurations of user login through the AUX port are complete.
Procedure
lRun the display users [ all ] command to check usage information about the AUX user
interface.
lRun the display user-interfaceaux interface-number [ summary ] command to check
physical attributes and configurations of the user interface.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
lRun the display local-user command to check the local user list.
lRun the display access-user command to check the local user list.
----End
Example
Run the display users command, and you can view information about the current user interface.
<HUAWEI> display users
User-Intf Delay Type Network Address AuthenStatus AuthorcmdFlag
33 AUX 0 00:00:44 pass no
Username : Unspecified
Run the display user-interfaceaux ui-number1 [ summary ] command, and you can view the
physical attributes and configurations of the user interface.
<HUAWEI> display user-interface aux 0
Idx Type Tx/Rx Modem Privi ActualPrivi Auth Int
33 AUX 0 9600 - 0 - N -
+ : Current UI is active.
F : Current UI is active and work in async mode.
Idx : Absolute index of UIs.
Type : Type and relative index of UIs.
Privi: The privilege of UIs.
ActualPrivi: The actual privilege of user-interface.
Auth : The authentication mode of UIs.
A: Authenticate use AAA.
N: Current UI need not authentication.
P: Authenticate use current UI's password.
Int : The physical location of UIs.
Run the display local-user command, and you can view the local user list.
If multiple routers need to be configured and managed, you do not need to connect the routers
and maintain them locally one by one. Instead, you can log in to the routers from a terminal by
using Telnet. This implements remote maintenance of the router and greatly facilitates device
management.
5.4.1 Establishing the Configuration Task
Before configuring user login by using Telnet, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This will help
you complete the configuration task quickly and accurately.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
If you have known the IP address of the router to be accessed, you can log in to the router from
a terminal by using Telnet, and remotely maintain the device. This allows you to maintain
multiple routers on the same terminal, greatly facilitating device management.
Note that IP addresses of the routers need to be preset through console ports.
Pre-configuration Tasks
Before configuring user login in Telnet mode, complete the following tasks:
lConfiguring reachable routes between the terminal and the device
Data Preparation
Before configuring user login in Telnet mode, you need the following data.
No.Data
1
2
3IPv4/IPv6 address or host name of the router
l Maximum number of VTY user interfaces
l (Optional) ACL for limiting call-in and call-out in VTY user interfaces
l Connection timeout period of terminal users, number of lines displayed in a
terminal screen, size of the history command buffer
l User priority
l User authentication mode, user name, password
TCP port number for the remote router to provide Telnet services, VPN instance name
5.4.2 Configuring VTY User Interface
To log in to the router by using Telnet, configure attributes of the VTY user interface.
Context
By default, the user authentication mode in the VTY user interface is password. Therefore, before
a user logs in to the router by using Telnet, the user authentication mode in the VTY user interface
must be set. Otherwise, the user cannot log in to the router.
You can log in to the router through a console port to set the user authentication mode in the
VTY user interface.
Other attributes of the VTY user interface in the router, such as terminal attributes and user
priorities, can also be set as needed. These attributes, however, generally do not need to be set
because they have default values.
For detailed settings, see Configuring VTY User Interface.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
If the user authentication mode is AAA in the VTY user interface, the access type of local users
needs to be specified. Local users with the access type of Telnet are Telnet users.
Context
If the user authentication mode of the VTY user interface is non-authentication or password
authentication, the following configurations are not needed.
By default, a local user can apply for any access type. You can specify an access type to allow
only users configured with the specified access type to log in to the router.
Do as follows on the router that functions as a Telnet server:
l If the undo telnet [ipv6]server enable command is run when a user logs in by using
Telnet, the command does not take effect.
l After the Telnet server function is disabled, you can log in to the device only using SSH
or an asynchronous serial port rather than using Telnet.
----End
5.4.5 (Optional) Configuring Listening Port Number for Telnet
Server
A user can configure or change the listening port number of a Telnet server. Changing the
listening port number ensures network security, because only the user that knows the current
listening port number can log in to the router.
Context
By default, the listening port number of a Telnet server is 23. Users can directly log in to the
router using the default listening port number. Attackers may access the default listening port,
consuming bandwidth, deteriorating server performance, and causing authorized users unable
to access the server. After the listening port number of the Telnet server is changed, attackers
do not know the new listening port number. This effectively prevents attackers from accessing
the listening port.
Do as follows on the router that functions as a Telnet server:
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
telnet server port port-number
The listening port number of the Telnet server is set.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
If a new listening port number is set, the Telnet server terminates all established Telnet
connections, and then uses the new port number to listen to new requests for Telnet connections.
----End
5.4.6 Logging in to the router by Using Telnet
After the router is configured, you can log in to the router from a terminal by using Telnet,
implementing remote maintenance of the router.
Context
If you need to log in to the router by using Telnet, you can use either windows command lines
or a third-party software in the terminal. In this part, the windows command line prompt is used.
Do as follows on the user terminal:
Procedure
Step 1 Use the windows command line.
Step 2 Run the telnet ip-address command to telnet the router.
1.Input the IP address of the Telnet server.
2.Press "Enter" to display the command line prompt of the system view, such as
<HUAWEI>. This indicates that you have accessed the Telnet server.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
After users log in to the system by using Telnet, you can view the connection status of the current
user interface, connection status of each user interface, and status of all established TCP
connections.
Prerequisite
Configurations of logins by using Telnet are complete.
Procedure
lRun the display users [ all ] command to check information about logged-in users on user
interfaces.
lRun the display tcp status command to check TCP connections.
Example
lRun the display telnet server status command to check the configuration and status of the
Telnet server.
----End
Run the display users command to view information about the currently-used user interface.
<HUAWEI> display users
User-Intf Delay Type Network Address AuthenStatus AuthorcmdFlag
34 VTY 0 00:00:12 TEL 10.138.77.38 no
Username : Unspecified
+ 35 VTY 1 00:00:00 TEL 10.138.77.57 no
Username : Unspecified
Run the display tcp status command to view TCP connections. In the command output,
Established indicates that a TCP connection has been established.
STelnet provides secured remote access over an insecure network. After the client/server
negotiation is complete and a secured connection is established, a user can log in to the router
in a similar way as Telnet.
5.5.1 Establishing the Configuration Task
Before configuring users to log in by using STelnet, familiarize yourself with the applicable
environment, complete the pre-configuration tasks, and obtain the required data. This will help
you complete the configuration task quickly and accurately.
Applicable Environment
Logins by using Telnet bring security risks because no secure authentication mechanism is
available and data is transmitted by using TCP in plain text mode. Unlike Telnet, SSH guarantees
secure data transmission on a conventional insecure network by authenticating the client and
encrypting data in both directions.
STelnet is a secure Telnet protocol. The SSH user can use the STelnet service in the same manner
as using the Telnet service.
Pre-configuration Tasks
Before configuring users to log in by using STelnet, complete the following task:
lConfiguring reachable routes between the terminal and the device
Data Preparation
To configure users to log in by using STelnet, you need the following data:
No.
1Maximum number of VTY user interfaces, (optional) ACL for limiting call-in and
2User name, password, authentication mode, and service type of an SSH user and
3(Optional) Name of an SSH server, number of the port monitored by the SSH server,
Data
call-out in VTY user interfaces, connection timeout period of terminal users, number
of rows displayed in a terminal screen, size of the history command buffer, user
authentication mode, user name, and password
remote public RSA key pair allocated to the SSH user
preferred encryption algorithm from the STelnet client to the SSH server, preferred
encrypted algorithm from the SSH server to the STelnet client, preferred HMAC
algorithm from the STelnet client to the SSH server, preferred HMAC algorithm from
the SSH server to the STelnet client, preferred algorithm of key exchange, name of
the outgoing interface, and source address
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
To allow a user to log in to the router by using STelnet, configure attributes of the VTY user
interface.
Context
By default, the user authentication mode in the VTY user interface is password. Therefore, before
a user logs in to the router by using STelnet, the user authentication mode in the VTY user
interface must be set. Otherwise, the user cannot log in to the router.
You can log in to the router through a console port to set the user authentication mode in the
VTY user interface.
Other attributes of the VTY user interface in the router, such as terminal attributes and user
priorities, can also be set as needed. These attributes, however, generally do not need to be set
because they have default values.
For detailed settings, see Configuring VTY User Interface.
5.5.3 Configuring SSH for the VTY User Interface
To allow users to log in to the router by using STelnet, you need to configure VTY user interfaces
to support SSH.
Context
By default, user interfaces support Telnet. If no user interface is configured to support SSH,
users cannot log in to the router by using STelnet.
Do as follows on the router that serves as an SSH server:
If a VTY user interface is configured to support SSH, the VTY user interface must be configured with
AAA authentication. Otherwise, the protocol inboundssh command cannot be configured.
----End
5.5.4 Configuring an SSH User and Specifying STelnet as One of
Service Types
To allow a user to log in to the router by using STelnet, you must configure an SSH user,
configure the router to generate a local RSA key pair, configure a user authentication mode, and
specify a service type for the SSH user.
Context
lSSH users can be authenticated in four modes: RSA, password, password-RSA, and all.
Password authentication depends on Authentication, Authorization and Accounting
(AAA). Before a user logs in to the router in password or password-RSA authentication
mode, you must create a local user with the specified user name in the AAA view.
Procedure
Step 1 Run:
Step 2 Run:
lConfiguring the router to generate a local RSA key pair is a key step for SSH login. If an
SSH user logs in to an SSH server in password authentication mode, configure the server
to generate a local RSA key pair. If an SSH user logs in to an SSH server in RSA
authentication mode, configure both the server and the client to generate local RSA key
pairs.
NOTE
Password-RSA authentication requires success of both password authentication and RSA authentication.
The all authentication mode requires success of either password authentication or RSA authentication.
Do as follows on the router that functions as an SSH server:
l Before performing the other SSH configurations, you must configure the rsa local-key-pair create
command to generate a local key pair.
l After generating the local key pair,you can perform the display rsa local-key-pair public command
to view the public key in the local key pair.
Step 4 Run:
ssh user user-name authentication-type { password | rsa | password-rsa | all }
The authentication mode for SSH users is configured.
Perform the following as required:
l Authenticate the SSH user through the password.
– Run:
ssh user user-name authentication-type password
The password authentication is configured for the SSH user.
– Run:
ssh authentication-type default password
The default password authentication is configured for the SSH user.
For the local authentication or HWTACACS authentication, if the number of SSH users
is small, you can adopt the former command; if the number of SSH users is large, adopt
the later command to simplify the configuration.
l Authenticate the SSH user through RSA.
1.Run:
ssh user user-name authentication-type rsa
The RSA authentication is configured for the SSH user.
2.Run:
rsa peer-public-key key-name
The public key view is displayed.
3.Run:
public-key-code begin
The public key editing view is displayed.
4.Run:
hex-data
The public key is edited.
NOTE
l In the public key view, only hexadecimal strings complying with the public key format can be
typed in. Each string is randomly generated on an SSH client. For detailed operations, see manuals
for SSH client software.
l After the public key editing view is displayed, the RSA public key generated on the client can
be sent to the server. Copy the RSA public key to the router that serves as the SSH server.
5.Run:
public-key-code end
Quit the public key editing view.
Issue 02 (2011-09-10)Huawei Proprietary and Confidential
l If the specified hex-data is invalid, the public key cannot be generated after the peer-
public-key end command is run.
l If the specified key-name is deleted in other views, the system prompts that the key does
not exist after the peer-public-key end command is run and the system view is
displayed.
6.Run:
peer-public-key end
Return to the system view from the public key view.
7.Run:
ssh user user-name assign rsa-key key-name
The public key is assigned to the SSH user.
Step 5 (Optional) Configuring the Basic Authentication Information for SSH Users
1.Run:
ssh server rekey-interval interval
The interval for updating the server key pair is configured.
By default, the interval for updating the key pair of the SSH server is 0 that indicates no
updating.
2.Run:
ssh server timeout seconds
The timeout period of the SSH authentication is set.
By default, the timeout period is 60 seconds.
3.Run:
ssh server authentication-retries times
The number of retry times of the SSH authentication is set.
By default, the retry times is 3.
Step 6 (Optional) Authorizing SSH Users Through the Command Line
SSH users can be authenticated in four modes: password, RSA, password-RSA, and all. In RSA
authentication mode, you can configure SSH users to be authorized based on command levels.
Run:
ssh user user-name authorization-cmd aaa
The command line authorization is configured for the specified SSH user.
After configuring the authorization through command lines for the SSH user to perform RSA
authentication, you have to configure the AAA authorization. Otherwise, the command line
authorization for the SSH user does not take effect.
Step 7 Run:
ssh user username service-type { stelnet | all }
The service type for the SSH user is configured.
By default, the service type of the SSH user is not configured.
----End
Issue 02 (2011-09-10)Huawei Proprietary and Confidential