Quidway S5600 Series Ethernet Switches
Operation Manual
Release 1510
Huawei Technologies Proprietary
Quidway S5600 Series Ethernet Switches
Operation Manual
Manual Version
Product Version
BOM
Huawei Technologies Co., Ltd. provides customers with comprehensive technical support
and service. If you purchase the products from the sales agent of Huawei Technologies Co.,
Ltd., please contact our sales agent. If you purchase the products from Huawei
Technologies Co., Ltd. directly, Please feel free to contact our local office, customer care
center or company headquarters.
Huawei Technologies Co., Ltd.
Address: Administration Building, Huawei Technologies Co., Ltd.,
Bantian, Longgang District, Shenzhen, P. R. China
OpenEye, Lansway, SmartAX, infoX, and TopEng are trademarks of Huawei
Technologies Co., Ltd.
All other trademarks and trade names mentioned in this manual a re the property of
their respective holders.
Notice
The information in this manual is subject to change without notice. Every effort has
been made in the preparation of this manual to ensure accuracy of the contents,
but all statements, information, and recommendations in this manual do not
constitute the warranty of any kind, express or implied.
Huawei Technologies Proprietary
About This Manual
Release Notes
The product version that corresponds to the manual is Release 1510.
Related Manuals
The related manuals are listed in the following table.
Manual Content
Organization
Quidway S5600 Series Ethernet Switches Operation Manual consists of the following
parts:
z 0 Product Overview
z 1 CLI
z 2 Login
Quidway S5600 Series Ethernet
Switches Installation Manual
Quidway S5600 Series Ethernet
Switches Command Manual
It provides information for the system installation.
It is used for assisting the users in using various
commands.
Introduces the characteristics and implementation s of the Ethernet switch.
Introduces the command hierarchy, command view and CLI features of the
Ethernet switch.
Introduces the ways to log into an Ethernet switch.
z3 Configuration File Management
Introduces the ways to manage configuration files.
z4 VLAN
Introduces VLAN fundamental and the related configuration.
z5 IP Address and Performance Configuration
Introduces IP address and IP performance fundamental and the related
configuration.
Huawei Technologies Proprietary
z6 Management VLAN
Introduces the management VLAN configuration and DHCP/BOOTP client
configuration.
z7 Voice VLAN
Introduces voice VLAN fundamental and the related configuration.
z8 GVRP
Introduces GVRP and the related configuration.
z9 Port Basic Configuration
Introduces basic port configuration.
z10 Link Aggregation
Introduces link aggregation and the related configuration.
z11 Port Isolation
Introduces port isolation and the related configuration.
z12 Port Security&Port Binding
Introduces port security, port binding, and the related configuration.
z13 DLDP
Introduces DLDP and the related configuration.
z14 MAC Address Table
Introduces MAC address forwarding table and the related configuration.
z15 Auto Detect
Introduces auto detect and the related configuration.
z16 MSTP
Introduces STP and the related configuration.
z17 Routing Protocol
Introduces the routing protocol-related configurations, including static route
configuration, RIP configuration, OSPF configuration, IS-IS configuration, BGP
configuration, and routing policy configuration.
z18 Multicast
Introduces the configuration of GMRP, IGMP Snooping, IGMP, PIM-DM, PIM-SM,
and MSDP.
z19 802.1x
Introduces 802.1x and the related configuration.
z20 AAA&RADIUS&HWTACACS&EAD
Introduces AAA, RADIUS, HWTACACS, EAD, and the related configurations.
z21 VRRP
Huawei Technologies Proprietary
Introduces VRRP and the related configuration.
z22 Centralized MAC Address Authentication
Introduces centralized MAC address authentication and the related configuration.
z23 ARP
Introduces ARP and the related configuration.
z24 DHCP
Introduces DHCP server, DHCP relay, DHCP-Snooping, and the related
configurations.
z25 ACL
Introduces ACL and the related configuration.
z26 QoS&QoS Profile
Introduces QoS, QoS profile and the related configuration.
z27 Mirroring
Introduces port mirroring and the related configuration.
z28 IRF Fabric
Introduces IRF fabric-related configuration.
z29 Cluster
Introduces the configuration to form clusters using HGMP V2.
z30 PoE&PoE Profile
Introduces PoE, PoE profile and the related configuration.
z31 UDP Helper
Introduces UDP Helper and the related configuration.
z32 SNMP&RMON
Introduces the configuration to manage network devices through SNMP and
RMON.
z33 NTP
Introduces NTP and the related configuration.
z34 SSH Terminal Service
Introduces SSH2.0 and the related configuration.
z35 File System Management
Introduces basic configuration for file system management.
z36 FTP and TFTP
Introduces basic configuration for FTP and TFTP, and the applications.
z37 Information Center
Huawei Technologies Proprietary
Introduces the configuration to analyze and diagnose networks using the
information center.
z38 System Maintenance and Debugging
Introduces daily system maintenance and debugging.
z39 VLAN VPN
Introduces VLAN VPN and the related configuration.
z40 HWPing
Introduces HWPing and the related configuration.
z41 DNS
Introduces DNS and the related configuration.
z42 Appendix A Acronyms
Lists the acronyms used in this manual.
Intended Audience
The manual is intended for the following readers:
z Network engineers
z Network administrators
z Customers who are familiar with network fundamentals
Conventions
The manual uses the following conventions:
I. General conventions
II. Command conventions
Convention Description
Arial Normal paragraphs are in Arial.
Boldface
Courier New
Headings are in Boldface.
Terminal Display is in Courier New.
Convention Description
Boldface
italic
The keywords of a command line are in Boldface.
Command arguments are in italic.
Huawei Technologies Proprietary
Convention Description
[ ]
{ x | y | ... }
[ x | y | ... ]
{ x | y | ... } *
[ x | y | ... ] *
# A line starting with the # sign is comments.
III. GUI conventions
Convention Description
Boldface
Items (keywords or arguments) in square brackets [ ] are
optional.
Alternative items are grouped in braces and separated by
vertical bars. One is selected.
Optional alternative items are grouped in square brackets
and separated by vertical bars. One or none is selected.
Alternative items are grouped in braces and separated by
vertical bars. A minimum of one or a maximum of all can be
selected.
Optional alternative items are grouped in square brackets
and separated by vertical bars. Many or none can be
selected.
Button names and menu items are in Boldface. For
example, click OK.
/
IV. Keyboard operation
Format Description
<Key>
<Key1+Key2>
<Key1, Key2>
V. Mouse operation
Action Description
Select
Multi-level menus are in bold and separated by forward
slashes. For example, select the File/Create/Folder menu.
Press the key with the key name inside angle brackets. For
example, <Enter>, <Tab>, <Backspace>, or <A >.
Press the keys concurrently. For example, <Ctrl+Alt+A>
means the three keys should be pressed concurrently.
Press the keys in turn. For example, <Alt, A> means the
two keys should be pressed in turn.
Press and hold the primary mouse button (left mouse
button by default).
Click
Select and release the primary mouse button without
moving the pointer.
Huawei Technologies Proprietary
Action Description
Double-Click
Drag
Press the primary mouse button twice continuously and
quickly without moving the pointer.
Press and hold the primary mouse button and move the
pointer to a certain position.
VI. Symbols
Eye-catching symbols are also used in the manual to highlight the points worthy of
special attention during the operation. They are defined as follows:
Caution, Warning, Danger: Means reader be extremely careful during the
operation.
Note, Comment, Tip, Knowhow, Thought: Means a complementary
description.
Huawei Technologies Proprietary
Operation Manual – Overview
Quidway S5600 Series Ethernet Switches-Release 1510 Table of Contents
Table of Contents
Chapter 1 Obtaining the Documentation .................................................................................... 1-1
4.1 Application in Small/Middle-Scaled Enterprise Networks.................................................. 4-1
4.2 Application in Large-Scaled/Campus Networks ................................................................4-1
Huawei Technologies Proprietary
i
Operation Manual – Overview
Quidway S5600 Series Ethernet Switches-Release 1510 Chapter 1 Obtaining the Documentation
Chapter 1 Obtaining the Documentation
Huawei-3Com Technologies Co., Ltd. provides various ways for you to obtain
documentation, through which you can obtain the product documentations and those
concerning newly added new features. The document ations are av ailable in one of the
following ways:
z CD-ROMs shipped with the devices
z Huawei-3Com website
z Software release notes
1.1 CD-ROM
Huawei-3Com delivers a CD-ROM together with each device. The CD-ROM contains a
complete product document set, including the operation manual, command manual,
installation manual, and compatibility manual. After installing the reader program
provided by the CD-ROM, you can search for the desired contents in a co nvenient way
through the reader interface.
The contents in the manual are subject to update on an irregular basis due to product
version upgrade or some other reasons. Therefore, the contents in the CD-ROM may
not be the latest version. This manual serves the purpose of user guide only. Unless
otherwise noted, all the information in the document set does not claim or imply any
warranty. For the latest software documentation, go to the Huawei-3Com website.
1.2 Huawei-3Com Website
Perform the following steps to query and download th e product documentation from the
Huawei-3Com website.
Table 1-1 Acquire product documentation from the Huawei-3Co m website
Log into http:// www.huawei-3com.com. Click
Registering
Acquire product
documentation
[Login/Register] in the home page. Enter your username
and password and click Register.
Click Documentation Center on the home page to query
the documentation by product category.
Select a product to display a detailed description of the
product.
Specify a device type and select a manual for that product.
Huawei Technologies Proprietary
1-1
Operation Manual – Overview
Quidway S5600 Series Ethernet Switches-Release 1510 Chapter 1 Obtaining the Documentation
1.3 Software Release Notes
With software upgrade, new software features may be added. You can acquire the
information about the newly added software features through software release notes.
Huawei Technologies Proprietary
1-2
Operation Manual – Overview
Quidway S5600 Series Ethernet Switches-Release 1510 Chapter 2 Documentation and Software Version
Chapter 2 Documentation and Software Version
2.1 Software Version for the Manual
Quidway S5600 Series Ethernet Switches Operation Manual Release1510 and
Quidway S5600 Series Ethernet Switches Command Manual Release1510
correspond to the following three software versions of the S5600 series switches:
Release0035, ESS1508, and Release1510. The three software versions have dif ferent
features:
zCompared with Release0035, Release1510 and ESS1508 have six new
features, as shown in
zCompared with ESS1508 and Release0035, Release1510 has seven new
features additionally, as shown in
Table 2-1 Newly added features in Release1510 and ESS1508
Table 2-1.
Table 2-2.
New features supported in both
Release1510 and ESS1508
Configuring the interval to generate port
statistics
Newly added port security mode: autolearn
Standard MSTP (STP Compliance)
Unknown Multicast Drop
HUAWEI Terminal Access Controller Access
Control System (HWTACACS)
Domain Name System (DNS)
Table 2-2 Features unique to Release1510
Giant packet statistics (you can
enable/disable the feature)
Active/standby switchover supported by
DLDP
New features unique to Release1510 Related part
09 Port Basic Configuration
12 Port Security&Port Binding
16 MSTP
18 Multicast
20
Quidway S5600 Series Ethernet Switches (hereinafter referred to as the S5600 se ries)
provide multi-layer switching capabilities, and support rich Layer 3 features and
enhanced growth capability. They are intelligent network-manageable switches
designed for network environments that require high performance, high port density
and easy-to-install characteristics.
3.2 Switch Models
Table 3-1 lists the available models in the S5600 series.
Table 3-1 Models in the S5600 series
Model
Quidway
S5624P
Quidway
S5624P-PWR
Quidway
S5624F
Quidway
S5648P
Power
supply
AC and DC
dual input
power supply
(PSL130-AD)
AC/DC input
external PoE
power supply
(PSL480-AD2
4P)
AC and DC
dual input
power supply
(PSL130-AD)
AC and DC
dual input
power supply
(PSL180-AD)
Available
24
24
24
48
service
port
Service
port
24 x
10/100/100
0Base-T
electrical
ports
24 x
10/100/100
0Base-T
electrical
ports
24 x 1000
Mbps SFP
optical
ports
48 x
10/100/100
0Base-T
electrical
ports
Combo
port
4 x 1000
Mbps SFP
Combo
ports
4 x 1000
Mbps SFP
Combo
ports
4 x 1000
Mbps
RJ45
Combo
ports
4 x 1000
Mbps SFP
Combo
ports
Console
port
1
1
1
1
Quidway
S5648P-PWR
AC/DC input
external PoE
power supply
(PSL480-AD4
8P)
An S5600 series switch provides one 2-port Fabric interface and one expansion
module slot on its rear panel. The available exp ansion module s you can select includ e:
8-port 1000 Mbps SFP module, 1-port 10G XENPAK module and 2-port 10G XFP
module.
3.3 Software Features
The S5600 series have abundant software features and can meet the requirements of
different applications.
Table 3-2 Service features of the S5600 series
Part Features
1 CLI
2 Login
Table 3-2 summarizes the features provided by each module.
z CLI
z Hierarchically grouped commands
z CLI online help
z Logging into a switch through the Console port
z Logging into a switch through an Ethernet port by using
Telnet or SSH
zLogging into a switch through the Console port by using
modem
zLogging into a switch through Web or NMS
3 Configuration
File Management
4 VLAN
5 IP Address and
Performance
Configuration
6 Management
VLAN
7 Voice VLAN
8 GVRP
9 Port Basic
Configuration
10 Link
Aggregation
11 Port Isolation
z Saving, restoring, and deleting the configuration file
z IEEE 802.1Q-compliant VLAN
z Port-based VLAN
z Protocol-based VLAN
z Configuring an IP address for a switch
z Configuring the TCP attributes for a switch
z Management VLAN configuration
z Management VLAN interface configuration
z Voice VLAN
z GARP VLAN registration protocol (GVRP)
z Three port states supported: Access, Trunk, and Hybrid
z Setting broadcast storm suppression globally
z Loopback detection supported
z Cable test
z Link aggregation control protocol (LACP)
z Port isolation group
12 Port
Security&Port
Binding
z Multiple security modes
z MAC address-to-port binding
z Device link detection protocol (DLDP)
z Manually configuring dynamic, static, and black hole
MAC addresses
z Configuring the aging time for MAC addresses
z MAC address learning limit
z Auto detect
z Auto detect applications in static routing, VRRP, and
VLAN interface backup
zSTP/RSTP/MSTP
16 MSTP
17 Routing
Protocols.
z QinQ BPDU tunnel
z Huawei-3Com-proprietary MSTP path cost standard
z Static route
z Routing information protocol (RIP) v1/v2
z Open shortest path first (OSPF)
z Border Gateway Protocol (BGP)
z Routing policy
z Internet group management protocol snooping (IGMP
Snooping)
18 Multicast
19 802.1x
20
AAA&RADIUS&H
WTACACS&EAD
z Internet group management protocol (IGMP)
z Protocol-independent multicast-dense mode (PIM-DM)
z Protocol-independent multicast-sparse mode (PIM-SM)
z 802.1X authentication
z Guest VLAN
z Huawei authentication bypass protocol (HABP)
z Authentication, authorization, and accounting (AAA)
z Remote authentication dial-In user service (RADIUS)
z Huawei terminal access controller access control system
(HWTACACS)
zEndpoint admission defense (EAD)
21 VRRP
zVirtual router redundancy protocol (VRRP)
22 Centralized
MAC Address
Authentication
23 ARP
24 DHCP
z Centralized MAC address authentication
z Gratuitous ARP
z Manually configuring ARP entries
z DHCP server
z DHCP relay
z DHCP Snooping
z DHCP accounting
z Using Option184 in DHCP server
z Using Option82 in DHCP relay
The S5600 series support flexible networking. They can be used as broadband access
devices, as well as networking devices in enterprise networks. The following describes
several typical networking methods for the S5600 series.
4.1 Application in Small/Middle-Scaled Enterprise Networks
The S5600 series can be used as backbone switches in the branches of
small/middle-scaled enterprises, where they can be connected (by routers) to the
networks of other branches or the headquarters. When the branches or enterprises
grow in scale, the S5600 series also provide seamless growth through IRF.
Core/Aggreg ation
Access
5600
3900
Figure 4-1 Application in small/middle-scaled enterprise branches
4.2 Application in Large-Scaled/Campus Networks
The S5600 series can also be used as aggregation devices in large-scaled enterprise
networks and campus networks, where each of them can be connect with multiple
Layer 2/3 downstream Ethernet switches (for example, S3900 series switches), and
connected to Layer 3 core upstream switches through the GE expansion module slot,
to provide a full solution for building enterprise networks in various size (from Gigabit
backbone network, 100 Mbps network to desktop netwo rk).
A Quidway series Ethernet switch provides a command line interface (CLI) and
commands for you to configure and manage the Ethernet switch. The CLI is featured by
the following:
zCommands are grouped by levels. This prevents unauthorized users from
operating the switch with relevant commands.
z Users can gain online help at any time by entering the question mark "?".
z Commonly used diagnosing utilities (such as Tracert and Ping) are available.
z Debugging information of various kinds is available.
z The command history is available. You can recall and execute a history command
easily.
zYou can execute a command by only entering part of the command in the CLI, as
long as the keywords you input uniquely identify the corresponding ones.
CLI Overview
1.2 Command Level/Command View
To prevent unauthorized accesses, commands are grouped by command levels.
Commands fall into four levels: visit, monitor , system, and manage:
zVisit level: Commands at this level are mainly used to diagnose network and
change the language mode of user interface, and cannot be saved i n configuration
files. For example, the ping, tracert, and language-mode commands are at this
level.
zMonitor level: Commands at this level are mainly used to maintain the system and
diagnose service problems, and cannot be saved to configuration files. For
example, the display and debugging commands are at this level.
zSystem level: Commands at this level are mainly used to configure services.
Commands concerning routing and network layers are at this level. Y ou can utilize
network services by using these commands.
zManage level: Commands at this level are associated with the basic operation of
the system, and the system supporting modules. These commands provide
supports to services. Commands concerning file system, FTP/TFTP/XModem
downloading, user management, and level setting are at this level.
Users logging into a switch also fall into four levels, each of which corresponding to one
of the above command levels. Users at a specific level can only use the commands of
the same level and those of the lower levels.
A user can switch the user level from one to another by executing a related command
after logging into a switch. The administrator can also set user level switching
passwords as required.
I. Setting a user level switching password
Table 1-1 lists the operations to set a user level switching password.
Table 1-1 Set a user level switching password
Operation Command Description
CLI Overview
Enter system view
Set a password for
switching from a lower
user level to the user level
identified by the level
argument
system-view
super password
[ level level ]
{ simple | cipher }
password
II. Switching to another user level
Table 1-2 lists operations to switch to another user level.
Table 1-2 Switch to another user level
Operation Command Description
Required
Execute this command in user view.
Switch to the user
level identified by
the level argument
super [ level ]
If a password for switching to the user
level identified by the level argument is
set and you want to switch to a lower
user level, you will remain at the lower
user level unless you provide the correct
password after executing this command.
Optional
A password is necessary only
when a user switch es from a
lower user level to a higher
user level.
Note:
z If the user level is not specified when user level switching and the switching
password are set, the user level is 3 by default.
zFor security purpose, the password a user enters when switching to a higher user
level is not displayed. A user will remain at the original user level if the user has tried
three times to enter the correct password but fails to do this.
1.2.2 Configuring the Level of a Specific Command in a Specific View
You can configure the level of a specific command in a specific view. Commands fall
into four command levels: visit, monitor , system, and manage, which are i dentified as 0,
1, 2, and 3 respectively. The administrator can change the command level a command
belongs to.
Table 1-3 lists the operations to configure the level of a specific command.
Table 1-3 Configure the level of a specific command in a specific view
Operation Command Description
Enter system view
Configure the level
of a specific
command in a
specific view
1.2.3 CLI Views
CLI views are designed for different configuration tasks. They are interrelated. You will
enter user view once you log into a switch successfully, where you can perform
operations such as displaying operation status and statistical information. And by
executing the system-view command, you can enter system view, where you can
enter other views by executing the corresponding commands.
The following CLI views are provided:
z User view
z System view
z Ethernet port view
z VLAN view
z VLAN interface view
z Loopback interface view
z Cascade interface view
z Local user view
z User interface view
z FTP client view
z SFTP client view
z MST region view
z Cluster view
z Public key view
z Public key editing view
z DHCP address pool view
z PIM view
system-view
command-privilege
level level view view
command
Required
Use this command with caution to
prevent inconvenience on
maintenance and operation.
z RIP view
z OSPF view
z OSPF area view
z Routing policy view
z Basic ACL view
z Advanced ACL view
z Layer 2 ACL view
z User-defined ACL view
z QoS profile view
z RADIUS scheme view
z ISP domain view
z HWPING view
z HWTACACS view
z MSDP view
z PoE profile view
Table 1-4 lists information about CLI views (including the operations you can performed
in these views, how to enter these views, and so on).
CLI Overview
Table 1-4 CLI views
View
Available
operation
Display
operation
User view
status and
statistical
information
System
view
Configure
system
parameters
Configure
Ethernet
port view
Ethernet
port
parameters
VLAN
view
Configure
VLAN
parameters
Prompt
example
<Quidway>
[Quidway]
[Quidway-Gi
gabitEtherne
t1/1/1]
[Quidway-vla
n1]
Enter methodQuit method
Enter user view
once logging
into the switch.
Execute the
system-view
command in
user view.
Execute the
interface
gigabitetherne
t 1/1/1
command in
system view.
Execute the quit
command in user
view to log out of the
switch.
Execute the quit or
return command to
return to user view.
Execute the quit
command to return
to system view.
Execute the return
command to return
to user view.
Execute the quit
Execute the
vlan 1
command in
system view.
command to return
to system view.
Execute the return
command to return
to user view.