Huawei quidway s3526 Getting Started

1. Getting Started
4. Network Protocol
5. Routing Protocol
6. Multicast
7. QoS/ACL
8. Integrated Management
9. STP
10. Security
11. Reliability
12. System Management
13. Auto Detecting
14. Appendix
Quidway S3500 Series Ethernet Switches Command Manual
Quidway S3500 Series Ethernet Switches Command Manual
Manual Version
About This Manual
Release Notes
This manual applies to S3526-0025/S3526EF-S3526C-0035/S3528-S3552-0017.
Related Manuals
The related manuals are listed in the following table.
Manual Content
Quidway S3528 Series Ethernet Switches Installation Manual
It provides information for the system installation.
Quidway S3552F Ethernet Switch Installation Manual
It provides information for the system installation.
Quidway S3526 Ethernet Switch Installation Manual
It provides information for the system installation.
Quidway S3526E Ethernet Switch Installation Manual
It provides information for the system installation.
Quidway S3526 FM/FS Ethernet Switches Installation Manual
It provides information for the system installation.
Quidway S3552 Ethernet Switch Installation Manual
It provides information for the system installation.
Quidway S3526C/S3526E FM/S3526E FS Ethernet Switches Installation Manual
It provides information for the system installation.
Quidway S3500 Series Ethernet Switches Operation Manual
It is used for assisting the users in data configurations and typical applications.
There are 14 modules in the manual.
z Getting Started
This module introduces the commands used for accessing the Ethernet Switch.
z Port
This module introduces the commands used for configuring Ethernet port and link aggregation.
This module introduces the commands used for configuring VLAN.
z Network Protocol
This module introduces the commands used for configuring network protocols.
z Routing Protocol
This module introduces the commands used for configuring routing proto col s.
z Multicast
This module introduces the commands used for configuring multicast protocol s.
This module introduces the commands used for configuring QoS/ACL.
z Integrated Management
This module introduces the commands used for integrated management.
This module introduces the commands used for configuring STP.
z Security
This module introduces the commands used for configuring 802.1X, AAA & RADIUS, HABP and system-guard.
z Reliability
This module introduces the commands used for configuring VRRP.
z System Management
This module introduces the commands used for system management and maintenance.
z Auto Detecting
This module introduces the commands used for auto-detecting configuration.
z Appendix
This module includes all the commands in this command manual, which are arranged alphabetically.
Intended Audience
The manual is intended for the following readers:
z Network engineers z Network administrators z Customers who are familiar with network fundamentals
Quidway S3500 Series Ethernet Switches Command Manual
Getting Started
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Table of Contents
Table of Contents
Chapter 1 Logging in Switch Commands................................................................................... 1-1
1.1 Logging in Switch Commands........................................................................................... 1-1
1.1.1 authentication-mode................................................................................................ 1-1
1.1.2 auto-execute command........................................................................................... 1-1
1.1.3 command-privilege level ......................................................................................... 1-2
1.1.4 databits....................................................................................................................1-3
1.1.5 display history-command ........................................................................................ 1-4
1.1.6 display user-interface.............................................................................................. 1-5
1.1.7 display users ........................................................................................................... 1-6
1.1.8 flow-control..............................................................................................................1-7
1.1.9 free user-interface................................................................................................... 1-7
1.1.10 header...................................................................................................................1-8
1.1.11 history-command max-size................................................................................. 1-10
1.1.12 idle-timeout.......................................................................................................... 1-10
1.1.13 language-mode................................................................................................... 1-11
1.1.14 lock......................................................................................................................1-11
1.1.15 parity....................................................................................................................1-12
1.1.16 protocol inbound.................................................................................................. 1-13
1.1.17 quit.......................................................................................................................1-13
1.1.18 return...................................................................................................................1-14
1.1.19 screen-length.......................................................................................................1-14
1.1.20 send.....................................................................................................................1-15
1.1.21 service-type.........................................................................................................1-15
1.1.22 set authentication password................................................................................1-17
1.1.23 shell.....................................................................................................................1-18
1.1.24 speed...................................................................................................................1-19
1.1.25 stopbits................................................................................................................1-19
1.1.26 super ...................................................................................................................1-20
1.1.27 super password...................................................................................................1-21
1.1.28 sysname..............................................................................................................1-22
1.1.29 system-view.........................................................................................................1-22
1.1.30 telnet....................................................................................................................1-23
1.1.31 user-interface ......................................................................................................1-23
1.1.32 user privilege level .............................................................................................. 1-24
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Chapter 1 Logging in Switch Commands
1.1 Logging in Switch Commands
1.1.1 authentication-mode
authentication-mode { password | scheme | none }
User interface view
password: Perform local password authentication. scheme: Perform local or remote authentication of username and password. none: Perform no authentication.
Using authentication-mode command, you can configure the authentication method for login user.
This command with the password parameter indicates to perform local password authentication, that is, you need to configure a login password using the set authentication pass word { cipher | simple } password command.
This command with the scheme parameter indicates to perform authentication of local or remote username and password. The type of the authentication depends on your configuration. For detailed information, see “Security” section.
By default, users logging in via the Console port do not need to pass any terminal authentication, whereas the password is required for authenticating the Modem and Telnet users when they log in.
# Configure local password authentication.
[Quidway-ui-aux0] authentication-mode password
1.1.2 auto-execute command
auto-execute command text
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
undo auto-execute command
User interface view
text: Specifies the command to be run automatically.
Using auto-execute command command, you can configure to automatically run a specified command. When a user logs in, the command configured will be executed automatically. Using undo auto-execute command command, you can configure not to run the command automatically.
This command is usually used to configure the telnet command on the terminal, which will connect the user to a designated device automatically .
By default, auto run is disabled.
z If you execute this command, the user-interface can no longer be used to perform
routine configurations on the local system. Therefore use caution when using this command.
z Ensure that you will be able to log into the system in some other way to cancel the
configuration, before you configure the auto-execute command command and save the configuration.
# Configure to automatically telnet after the user logs in via VTY 0.
[Quidway-ui-vty0] auto-execute command telnet
1.1.3 command-privilege level
command-privilege level level view view command undo command-privilege view view command
System view
Huawei Technologies Proprietary
level: Specifies the command level, ran ging from 0 to 3. view: Specifies the command view, which can be any of the views supported by the
switch. command: Specifie s the command to be configured.
Using command-privilege level command, you can configure the priority of the specifically command of the specifically view. Using undo command-privilege view command, you can restore the default command priority.
The command levels include visit, monitoring, system, and management, which are identified as 0 through 3 respectively. The network administrator can customize the command levels as needed.
When users log into the switch, the commands they can use depend jointly on the user level settings and the command level settings on the user interface. If the two types of settings differ,
z For the users using AAA/RADIUS authentication, the commands they can use are
determined by the user level settings. For example, if a use is set to level 3 and the command level on the VTY 0 user interface is level 1, he or she can only use the commands of level 3 or lower when logging into the switch from the VTY 0 user interface.
z For the users using RSA public key authentication, the commands they can use
are determined by the command level settings on the user interface.
By default, ping, tracert, and telnet are at visit level (0); display and debugging are at monitoring level (1); all configuration commands are at system level (2); and FTP, XMODEM, TFTP and commands for file system operations are at management level (3).
# Configure the precedence of the command "interface" as 0.
[Quidway] command-privilege level 0 view system interface
1.1.4 databits
databits { 7 | 8 } undo databits
User interface view
Huawei Technologies Proprietary
7: The data bits are 7. 8: The data bits are 8.
Using databits command, you can configure the data bits for AUX (Console) port. Using undo databits command, you can restore the default bit s of the AUX (Console).
This command can only be performed in AUX user interface view. By default, the value is 8.
# Configure the data bits of AUX (Console) port to 7 bits.
[Quidway-ui-aux0] databits 7
1.1.5 display history-command
display history-command
Any view
Using display history-command command, you can view the saved history commands.
For the related command, see history-command max-size.
# Display history commands.
<Quidway> display history-command sys quit display his
Huawei Technologies Proprietary
1.1.6 display user-interface
display user-interface [ type number ] [ number ]
Any view
type: Specifies the type of a user interface. number: Specifies the number of a u ser interfa ce.
Using display user-interface command, you can vie w the relational inform ation of the user interface. The displayed information includes user interface type, absolute/relative index, transmission speed, priority, and authentication methods.
# Display the relational information of user interface 0.
<Quidway> display user-interface 0 Idx Type Tx/Rx Modem Privi Auth F 0 AUX 0 9600 3 N
+ : Current user-interface is active. F : Current user-interface is active and work in async mode. Idx : Absolute index of user-interface. Type : Type and relative index of user-interface. Privi: The privilege of user-interface. Auth : The authentication mode of user-interface. A: Authenticate use AAA. N: Current user-interface need not authentication. P: Authenticate use current UI's password.
Table 1-1 Output description of the display user-interface command
Field Description
+ Current user interface is in use F Current user interface is in use and work in asynchronous mode Idx Absolute index of user interface Type Type and relative index of user interface Tx/Rx User interface speed
Huawei Technologies Proprietary
Field Description
Modem Modem operation mode
Which levels of commands can be used after logging in from the user interface
Auth User interface authentication method
1.1.7 display users
display users [ all ]
Any view
all: Display the information of all user interfaces.
Using display users command, you can view the information of the user interface.
# Display the information of the current user interface.
[Quidway] display users UI Delay Type Ipaddress Username F 0 AUX 0 00:00:00
Table 1-2 Output description of the display users command
Field Description
F Current user interface is in use and work in asynchronous mode.
Number of the first list is the absolute number of user interface.
Number of the second list is the relative number of user interface. Delay Indicates the interval from the latest input till now in seconds. Type User type
Displays initial connection location, namely the host IP address of
the incoming connection.
Display the name of the user using this user interface, namely the
login username of the user.
Huawei Technologies Proprietary
1.1.8 flow-control
flow-control { hardware | none | software } undo flow-control
User interface view
hardware: Configures to perform hardware flow control. none: Configures no flow control. software: Configures to perform software flow control .
Using flow-control command, you can configure the flow control mode on AUX (Console) port. Using undo flow-control command, you can restore the default flow control mode.
By default, the value is none. That is, no flow control will be performed. This command can only be performed in AUX user interface view.
# Configure software flow control on AUX (Console) port.
[Quidway-ui-aux0] flow-control software
1.1.9 free user-interface
free user-interface [ type ] number
User view
type: Specifies the user interface type. number: Specifies the absolute/relative number of the user interface. Configured
together with the type, it will specify the user interface number of the corresponding type. If the type is not specified, number will specify an absolute user interface number.
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Huawei Technologies Proprietary
Using free user-interface command, you can clear a user of a specified user inte rface. The user interface will be disconnected after the command is executed.
Note that the user of the current user interface cannot be cleared.
# Clear the user of the user interface 1 after logging in to the switch via user interface 0.
<Quidway> free user-interface 1
After the command is executed, user interface 1 will be disconnected. It will not be connected to the switch until you log in via the user interface 1 for the next time.
1.1.10 header
header [ shell | incoming | login ] text undo header [ shell | incoming | login ]
System view
login: Login information in case of authentication. It is displayed before the user is
prompted to enter user name and password. shell: User conversation established header, the information output after user
conversation has been established. If authentication is required, it is prompted after the user passes authentication.
incoming: Login header, the information output after a Modem user logs in. If authentication is required, it is prompted after the user passes authentication. In this case, no shell information is output.
text: Specifies the title text. If you do not choose any keyword in the command, the system displays the login information by default. The system supports two types of input modes: one is to input all the text in one line, and altogether 256 characters can be input; the other is to input all the text in several lines using the <Enter> key, and altogether 1024 characters, excluding command key word, can be input. The text starts and ends with the first character. After inputting the end character, press the <Enter> key to exit the interact process.
Using header command, you can configure to display header when user login. Using undo header command, you can configure not to display the header.
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Huawei Technologies Proprietary
When the users log in the switch, if a connection is activated, the login header will be displayed. After the user successfully logs in the switch, the shell header will be displayed.
Note that if you press <Enter> after typing any of the three keywords shell, login and incoming in the command, then what you type after the word header is the contents of the login information, instead of identifying header type.
You can judge whether the initial character can be used as the header contents this way:
1) If there is only one character in the first line and it is used as the identifier, this initial character pairs with the ending character and is not the header contents.
2) If there are many characters in the first line but the initial and ending characters are different, this initial character pairs with the ending character and is the header contents.
3) There are many characters in the first line and the initial character is identical with the ending character, this initial character is not the header contents.
# Configure the header of setting up a session. Mode 1: Input in one line
[Quidway] header shell %SHELL: Hello! Welcome% (The starting and ending characters must be the same, and press the <Enter> key to finish a line)
When you log on the switch again, the terminal displays the configured session establishment title.
[Quidway] quit <Quidway> quit Please press ENTER SHELL: Hello! Welcome (The initial character “%” is not the header contents) <Quidway>
Mode 2: Input in several lines
[Quidway] header shell % SHELL: (After you pressing the <Enter> key, the system prompts the following message:) Input banner text, and quit with the character '%'.
Go on inputting the rest text and end your input with the first letter:
Hello! Welcome % (Press the <Enter> key) [Quidway]
When you log on the switch again, the terminal displays the configured session establishment title.
[Quidway] quit <Quidway> quit
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Please press ENTER %SHELL: (The initial character “%” is the header contents) Hello! Welcome <Quidway>
1.1.11 history-command max-size
history-command max-size value undo history-command max-size
User interface view
value: Defines the size of the history buffer , ranging from 0 to 256. By default, the size is 10, that is, 10 history commands can be saved.
Using history -command max-size command, you can configure the size of the history command buffer . Using undo history-command max-si ze command, you can re store default size of the history command buffer.
# Set the history buffer to 20, namely saving 20 history commands.
[Quidway-ui-aux0] history-command max-size 20
1.1.12 idle-timeout
idle-timeout minutes [ seconds ] undo idle-timeout
User interface view
minutes: Specifies the minute, rangi ng from 0 to 35791. seconds: Spe cifies the second, ranging from 0 to 59.
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Using idle-timeout command, you can configure the timeout function. If there is no user operation performed before idle-timeout expires, the user interface will be disconnected. Using undo idle-timeout command, you can restore the default idle-timeout.
idle-timeout 0 means disabling idle-timeout. By default, idle-timeout is set to 10 minutes.
# Configure the timeout value to 1 minute on the AUX user interface.
[Quidway-ui-aux0] idle-timeout 1 0
1.1.13 language-mode
language-mode { chinese | english }
User view
chinese: Configures the language environment of command line interface as Chinese. english: Configures the language environment of command line interface as English.
Using language-mode command, you can switch between different language environments of command line interface for convenience of dif f erent users.
By default, the value is English.
# Switch from English mode to Chinese mode.
<Quidway> language-mode chinese
1.1.14 lock
User view
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Using lock command, you can lock the user interface to prevent unauthorized user from operating it.
# Lock the current user interface.
<Quidway> lock Password: xxxx Again: xxxx
1.1.15 parity
parity { even | mark | none | odd | space } undo parity
User interface view
even: Configures to perform even parity. mark: Configures to perform mark parity. none: Configures not to perform parity. odd: Configures to perform odd parity. space: Configures to perform space parity.
Using parity command, you can configure the parity mode on AUX (Console) port. Using undo parity command, you can restore the def ault parity mode.
This command can only be performed in AUX user interface view. By default, the mode is set to none.
# Set mark parity on the AUX (Console) port.
[Quidway-ui-aux0] parity mark
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
1.1.16 protocol inbound
protocol inbound { all | ssh | telnet }
VTY user interface view
all: Supports both Telnet and SSH protocols. ssh: Supports only SSH protocol (S3526, S3526 FS and S3526 FM not support the
telnet: Supports only Telnet protocol.
Using the protocol inbound command, you can configure the protocols supported by a designated user interface.
By default, the user interface supports Telnet and SSH protocols. For the related commands, see user-interface vty.
# Configure SSH protocol supported by VTY0 user interface.
[Quidway-ui-vty0] protocol inbound ssh
1.1.17 quit
Any view
Using quit command, yo u can return to the lower level view from the current view . If the current view is user view, you ca n quit the system.
There are three levels of views, which are listed from low to high as follows:
z User view
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
z System view z VLAN view, Ethernet port view, and so on.
For the related commands, see return, system-view.
# Return to user view from system view.
[Quidway] quit <Quidway>
1.1.18 return
System view or above
Using return command, you can return to user view from a view other than user view. Combination key <Ctrl+Z> performs the same function with the return command. For the related command, see quit.
# Return to user view from system view.
[Quidway] return <Quidway>
1.1.19 screen-length
screen-length screen-length undo screen-length
User interface view
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
screen-length: Specifies ho w many lines can be di spl ayed on a scre en, ranging f r om 0 to 512. The default value is 24.
Using screen-length command, you can configure how many lines that can be displayed on a screen of the terminal. Using undo screen-length command, you can restore the default number of terminal information lines displayed on the terminal screen.
The screen-length 0 command is used to disable this function.
# Configure the lines that can be displayed on a screen as 20 lines.
[Quidway-ui-aux0] screen-length 20
1.1.20 send
send { all | number | type number }
User view
all: Configures to send message to all user interfaces.
type: Specifies the user interface type, which can be aux or vty. number: Specifies the absolute/relative numb er of the user interface.
Using send command, you can send messages between different user interfaces.
# Send message to all the user interfaces.
<Quidway> send all
1.1.21 service-type
For S3552 series, S3528 series, S3526E series and S3526C:
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
service-type { ftp [ ftp-directory directory ] | lan-access | { ssh | telnet }* [ level level ] }
undo service-type { ftp [ ftp-directory ] | lan-access | { ssh | telnet }* [ level level ] } For S3526, S3526 FM and S3526 FS:
service-type { ftp [ ftp-directory directory ] | lan-access | telnet [ level level ] } undo service-type { ftp [ ftp-directory ] | lan-access | telnet [ lev el level ] }
Local-user view
telnet: Specifies user type as Telnet. ssh: Specifies user type as SSH. level level: Specifies the level of Telnet or SSH users. The argument level is an integer
in the range of 0 to 3 and defaults to 1.
ftp: Specifies user type as ftp. ftp-directory directory: Specifies the directory of ftp users, directory is a character
string of up to 64 characters. lan-access: Specifies user type to lan-access, which mainly refers to Ethernet
accessing users, 802.1x supplicants for example.
Using service-type command, you can configure which level of command a user can use after logon. Using undo service-type command, you can restore the d efault level of command a user can use after logon.
Commands are classified into four levels, namely visit level, monitoring level, system level and management level. They are introduced as follows:
z Visit level: Commands of this level involve command of network diagnosis tool
(such as ping and tracert), command of switch between different language environments of user interface (language-mode), and telnet command etc. The operation of saving configuration file is not allowed on this level of commands.
z Monitoring level: Commands of this level, including the display command and the
debugging command, are used for system maintenance, service fault diagnosis,
etc. The operation of saving the configuration file is not allowed on this level of commands.
z System level: Service configuration commands, including routing command and
commands on each network layer, are used to provide direct network service to the user.
z Management level: These are commands that influence the basic operation of the
system and system support module, which plays a supporting role on service.
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Commands of this level involve file system commands, FTP commands, TFTP commands, XModem downloading commands, user management commands, and level setting commands.
# Configure the user zbr to use commands at level 0 after logon.
[Quidway] local-user zbr [Quidway-luser-zbr] service-type telnet level 0
# Quit the system and logs on with username “zbr” again. Now only the commands at level 0 are listed on the terminal.
[Quidway] quit <Quidway> ? User view commands: cluster Run cluster command language-mode Specify the language environment ping Ping function quit Exit from current command view super Privilege specified user priority level telnet Establish one TELNET connection tracert Trace route function
1.1.22 set authentication password
set authentication password { cipher | simple } password undo set authentication password
User interface view
cipher: Configure encrypted text password. simple: Configure plain text password.
password: If the authentication is in the simple mode, the password must be in plain text. If the authentication is in the cipher mode, the password can be either in encrypted text or in plain text. The result is determined by the input. A plain text password is a sequential character string of no more than 16 digits, for example, huawei918. The length of an encrypted password must be 24 digits and in encrypted text, for example, _(TT8F]Y\5SQ=^Q`MAF4<1!!.
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
Using set authentication password command, you can configure the password for local authentication. Using undo set authentication passw ord command, you can cancel local authentication password.
The password in plain text is required when performing authentication, regardless whether the configuration is plain text or encrypted text.
By default, password is required to be set for authenticating the users connecting via Modem or Telnet. If no password has been set, the following prompt will be displayed “Login password has not been set !”
# Configure the local authentication password on VTY 0 to huawei.
[Quidway-ui-vty0] set authentication password simple huawei
1.1.23 shell
shell undo shell
User interface view
Using shell command, you can enable terminal se rvice of a user interface. Using undo shell command, you can disable the terminal service of a user interface.
By default, terminal service is enabled. When using the undo shell command, note the following points.
z For the sake of security, the undo shell command can only be used on the user
interfaces other than the AUX user interface.
z You cannot use this command on the user interface via which you log in.
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
z You will be asked to confirm before executing this command on any legal user
# Disable terminal service on the vty user interface 0 to 4 after logging in to the switch via user interface 0.
[Quidway] user-interface vty 0 4 [Quidway-ui-vty0-4] undo shell
# The following message will be displayed on the Telnet terminal after logon.
Connection to host lost.
1.1.24 speed
speed speed-value undo speed
User interface view
speed-value: Specifies the transmission rate on the AUX (Console) port in bit/s, which can be 300, 600, 1200, 4800, 9600, 19200, 38400, 57600, or 115200. The default rate is 9600bit/s.
Using speed command, you can configure the tran smission rate on the AUX (Console) port. Using undo speed command, you can restore the default rate.
This command can only be performed in AUX user interface view.
# Configure the transmission speed on the AUX (Console) port as 9600bit/s.
[Quidway-ui-aux0] speed 9600
1.1.25 stopbits
stopbits { 1 | 1.5 | 2 } undo stopbits
Command Manual - Getting Started Quidway S3500 Series Ethernet Switches Chapter 1 Logging in Switch Commands
User interface view
1: Sets 1 stop bit.
1.5: Sets 1.5 stop bits.
2: Sets 2 stop bits.
Using stopbits command, you can configure the stop bits on the AUX (Console) port. Using undo stopbits command, you can restore the default stop bits.
This command can only be performed in AUX user interface view. By default, the value is 1.
# Configure 2 stop bits on the AUX (Console) port.
[Quidway-ui-aux0] stopbits 2
1.1.26 super
super [ level ]
User view
level: User level, ranging 0 to 3. The default value is 3.
Using super command, you can enable the user to change to user level from the current user level. If the user has set the super passw ord [ level level ] { simple | cipher } password, then user password of the higher level is needed, or the former user level will not change.
Login users are classified into four levels that correspond to the four command levels respectively. After users of different levels log in, they can only use commands at the levels that are equal to or lower than its own level.
For the related commands, see super password, quit.
