No part of this document may be reproduced or transmitted in any form or by any means without prior written
consent of Huawei Technologies Co., Ltd.
Trademarks and Permissions
and other Huawei trademarks are trademarks of Huawei Technologies Co., Ltd.
All other trademarks and trade names mentioned in this document are the property of their respective
holders.
Notice
The purchased products, services and features are stipulated by the contract made between Huawei and the
customer. All or part of the products, services and features described in this document may not be within the
purchase scope or the usage scope. Unless otherwise specified in the contract, all statements, information,
and recommendations in this document are provided "AS IS" without warranties, guarantees or
representations of any kind, either express or implied.
The information in this document is subject to change without notice. Every effort has been made in the
preparation of this document to ensure accuracy of the contents, but all statements, information, and
recommendations in this document do not constitute a warranty of any kind, express or implied.
Huawei Technologies Co., Ltd.
Address:Huawei Industrial Base
Bantian, Longgang
Shenzhen 518129
People's Republic of China
Website:http://e.huawei.com
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
Intended Audience
This document describes the positioning, characteristics, architecture, link features, service
features, application scenarios, operation and maintenance functions, and technical
specifications of the switch.
This document helps you understand the characteristics and features of the switch.
This document is intended for:
About This Document
About This Document
Statement
lNetwork planning engineers
lHardware installation engineers
lCommissioning engineers
lData configuration engineers
lOn-site maintenance engineers
lNetwork monitoring engineers
lSystem maintenance engineers
The device provides the mirroring function for network monitoring and fault management,
during which communication data may be collected. Huawei alone is unable to collect or save
the content of users' communications. It is suggested that you activate the functions based on
the applicable laws and regulations in terms of purpose and scope of usage. You are obligated
to take considerable measures to ensure that the content of users' communications is fully
protected when the content is being used and saved.
The device provides the NetStream function for network traffic statistics collection and
advertisement, during which data of users may be used. You are obligated to take considerable
measures, in compliance with the laws of the countries concerned and the user privacy
policies of your company, to ensure that the data of users is fully protected.
Disclaimer
This document is designed as a reference for you to configure your devices. Its contents,
including web pages, command line input and output, are based on laboratory conditions. It
provides instructions for general scenarios, but does not cover all use cases of all product
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
models. The examples given may differ from your use case due to differences in software
versions, models, and configuration files. When configuring your device, alter the
configuration depending on your use case.
The specifications provided in this document are tested in lab environment (for example, the
tested device has been installed with a certain type of boards or only one protocol is run on
the device). Results may differ from the listed specifications when you attempt to obtain the
maximum values with multiple functions enabled on the device.
Symbol Conventions
The symbols that may be found in this document are defined as follows.
About This Document
Symbol
Description
Indicates an imminently hazardous situation
which, if not avoided, will result in death or
serious injury.
Indicates a potentially hazardous situation
which, if not avoided, could result in death
or serious injury.
Indicates a potentially hazardous situation
which, if not avoided, may result in minor
or moderate injury.
Indicates a potentially hazardous situation
which, if not avoided, could result in
equipment damage, data loss, performance
deterioration, or unanticipated results.
NOTICE is used to address practices not
related to personal injury.
Calls attention to important information,
best practices and tips.
NOTE is used to address information not
related to personal injury, equipment
damage, and environment deterioration.
Change History
Updates between document issues are cumulative. Therefore, the latest document version
contains all updates made to previous versions.
Changes in Issue 18 (2016-11-09)
The eighteenth commercial release has the following updates:
The documentation is modified according to updates in product features.
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
2.1 Application of the S5700 on a Large-scale Enterprise Campus Network......................................................................7
2.2 Application of the S5700 on a Small- or Medium-scale Enterprise Campus Network..................................................8
2.3 Application of the S5700 on a Small-scale Enterprise Campus Network......................................................................9
2.4 Application in Public Cloud........................................................................................................................................... 9
3.1 Product Features Supported by V200R010C00............................................................................................................12
3.2 Product Features Supported by V200R009C00............................................................................................................23
3.3 Product Features Supported by V200R008C00............................................................................................................33
3.4 Product Features Supported by V200R007C00............................................................................................................44
3.5 Product Features Supported by V200R006C00............................................................................................................54
3.6 Product Features Supported by V200R005C00............................................................................................................63
3.7 Product Features Supported by V200R003C00............................................................................................................74
S5700 Series Ethernet Switches
Product Description
1.1 Product Positioning
The S5700 series Ethernet switches (S5700 for short) are next-generation energy-saving
switches developed by Huawei to meet the demand for high-bandwidth access and Ethernet
multi-service aggregation. Based on cutting-edge hardware and Huawei Versatile Routing
Platform (VRP) software, the S5700 provides a large switching capacity, high reliability
(double power slots and hardware Ethernet OAM), and high-density GE ports to
accommodate 10 Gbit/s upstream transmissions. It also supports Energy Efficient Ethernet
(EEE) and iStack. The S5700 can be used in various enterprise network scenarios. For
example, it can function as an access or aggregation switch on a campus network, a gigabit
access switch in an Internet data center (IDC), or a desktop switch to provide 1000 Mbit/s
access for terminals.
The S5700 is available in a lite (LI) series, a standard (SI) series, an enhanced (EI) series, and
a hyper (HI) series.
1.2 Product Characteristics
1 Product Overview
Various Port Combinations
The S5700-EI, S5710-EI and S5720-EI support various extended subcards that provide highdensity GE/10GE uplink ports. The flexible port combinations meet bandwidth expansion
requirements, protecting customers' investment.
Intelligent Stack
The S5700 supports intelligent stack (iStack). This technology combines multiple switches
into a logical switch.
Member switches in a stack implement redundancy backup to improve device reliability and
use inter-device link aggregation to improve link reliability. iStack provides high network
scalability. You can increase ports, bandwidth, and processing capacity of a stack by simply
adding member switches to the stack. iStack also simplifies device configuration and
management. After a stack is set up, multiple physical switches are virtualized into one
logical device. You can log in to any member switch in the stack to manage all the member
switches in the stack.
The S5720-SI/S5720S-SI/S5720-EI/S5720-LI/S5720S-LI support stacking through electrical
ports.
Innovative AHM Energy Saving Technologies
The S5700-LI series (except S5700-52X-LI-48CS-AC, S5700-28P-LI-BAT and S5700-28PLI-24S-BAT) and S5720-LI/S5720S-LI series smart energy-saving switches reduce power
consumption without degrading system performance and user experience. The S5700-LI
series uses innovative energy-saving technologies including energy efficient Ethernet (EEE),
port power detection, dynamic CPU frequency adjustment, and device sleeping. These
technologies help reduce power consumption by adjusting power depending on the Up/Down
states of links, presence/absence of optical modules, shutdown and undo shutdown operations
on ports, and peak and off-peak hours. The S5700-LI series is the industry's first switch series
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
that supports entire device sleeping, and it provides three energy saving modes to adapt to
different usage scenarios: standard mode, basic mode, and deep mode.
Comprehensive VPN Technologies
The S5700 supports the multi-VPN-instance CE (MCE) function, which allows users in
different VPNs to connect to the same switch and isolates users through multi-instance
routing. Users in multiple VPNs connect to a PE device through the same physical uplink port
on the switch, which reduces the investment on network deployment. The S5710-EI and
S5700-HI support Multiprotocol Label Switching (MPLS) QoS, MPLS traffic engineering
(TE), virtual leased line (VLL), virtual private LAN service (VPLS), and Layer 3 virtual
private network (L3VPN). They can provide high-quality private line access services for
enterprises and are cost-effective case-shaped MPLS switches.
Easy Operation and Maintenance
The S5700 supports EasyDeploy, USB-based deployment, batch remote upgrade and is a
plug-and-play product. These functions facilitate device deployment, upgrade, service
provisioning, and other management and maintenance operations, and also greatly reduce
costs of operation and maintenance. The S5700 can be managed and maintained using Simple
Network Management Protocol (SNMP) V1, V2c, and V3, command line interface (CLI),
web-based network management system, Telnet, or Secure Shell (SSH) V2.0. Additionally, it
supports remote network monitoring (RMON), multiple log hosts, port traffic statistics
collection, and network quality analysis that help in network consolidation and reconstruction.
1 Product Overview
The S5700 can use the GARP VLAN Registration Protocol (GVRP) to implement dynamic
distribution, registration, and propagation of VLAN attributes. GVRP reduces manual
configuration workload and ensures correct configuration. Besides, the S5700 supports the
MUX VLAN function, which involves a principal VLAN and multiple subordinate VLANs.
Subordinate VLANs are classified into group VLANs and separate VLANs. Ports in the
principal VLAN can communicate with ports in subordinate VLANs. Ports in a subordinate
group VLAN can communicate with each other, whereas ports in a subordinate separate
VLAN can communicate only with ports in the principal VLAN.
Excellent Network Traffic Analysis
The S5700 provides the NetStream function and can function as a NetStream data exporter. It
periodically collects data traffic statistics, encapsulates the statistics in standard V5, V8, or V9
packets, and sends the packets to the NetStream data collector according to NetStream
configuration. The collected statistics are then processed to dynamically generate reports,
analyze traffic attributes, and generate alarms on abnormal traffic. The NetStream function
helps you optimize network structure and adjust resource deployment in a timely manner.
The S5700 supports the sFlow function. It uses a method defined in the sFlow standard to
sample traffic passing through it and sends sampled traffic to the collector in real time. The
collected traffic statistics are used to generate statistical reports, helping enterprises maintain
their networks.
Flexible Ethernet Networking
In addition to traditional Spanning Tree Protocol (STP), Rapid Spanning Tree Protocol
(RSTP), and Multiple Spanning Tree Protocol (MSTP), the S5700 supports Huaweideveloped Smart Ethernet Protection (SEP) technology and the latest Ethernet Ring
Protection Switching (ERPS) standard. SEP is a ring protection protocol specific to the
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
Ethernet link layer, and applies to various ring network topologies, such as open ring
topology, closed ring topology, and cascading ring topology. This protocol is reliable, easy to
maintain. ERPS is defined in ITU-T G.8032. It implements millisecond-level protection
switching based on traditional Ethernet MAC and bridging functions.
The S5700 supports Smart Link and Virtual Router Redundancy Protocol (VRRP), which
implement backup of uplinks. One S5700 switch can connect to multiple aggregation
switches through multiple links, significantly improving reliability of access devices. In
addition, the S5700 provides multiple connection fault detection mechanisms, including
Ethernet OAM (IEEE 802.3ah/802.1ag /ITU Y.1731) and Bidirectional Forwarding Detection
(BFD).
Diversified Security Control
The S5700 supports MAC address authentication and 802.1X authentication and implements
dynamic delivery of policies (VLAN, QoS, and ACL) to users.
The S5700 provides a series of mechanisms to defend against DoS attacks and user-targeted
attacks. DoS attacks are targeted at switches and include SYN flood, Land, Smurf, and ICMP
flood attacks. User-targeted attacks include bogus DHCP server attacks, IP/MAC address
spoofing, DHCP request flood, and change of the DHCP CHADDR value. The S5700 collects
and maintains information about access users, such as IP addresses, MAC addresses, IP
address leases, VLAN IDs, and access interfaces in a DHCP snooping binding table. In this
way, it can defend against DHCP attacks on the network. You can specify DHCP snooping
trusted and untrusted ports to ensure that users connect only to the authorized DHCP server.
1 Product Overview
The S5700 supports strict ARP learning. This feature prevents ARP spoofing attackers from
exhausting ARP entries so that users can connect to the Internet normally.
Mature IPv6 Technologies
The S5700 uses the mature, stable Versatile Routing Platform (VRP) and supports IPv4/IPv6
dual stacks, IPv6 routing protocols (RIPng, OSPFv3, BGP4+, and IS-IS for IPv6), and IPv6
over IPv4 tunnels including manual, 6-to-4, and Intra-Site Automatic Tunnel Addressing
Protocol (ISATAP) tunnels. With these IPv6 features, the S5700 can be deployed on a pure
IPv4 network, a pure IPv6 network, or a shared IPv4/IPv6 network, helping realize IPv4-toIPv6 transition.
Innovative Built-in Battery
The S5700-LI-BAT(S5700-28P-LI-BAT and S5700-28P-LI-24S-BAT) is the industry's first
switch model that supports internal lithium batteries as a backup power supply. It ensures
uninterrupted services in situations where power failures frequently occur at the access layer.
The S5700-LI-BAT has the following advantages:
lIn the event of a mains power failure the battery can power the switch, so services will
not be interrupted.
lCompared with switches using external power supply units, the S5700-LI-BAT occupies
less space and is easier to install.
lIntelligent power management, long standby time.
lBattery LAN switches on the entire network can be managed centrally using a web
system, facilitating network operation and maintenance. As the battery lifetime is
predictable, you do not need to replace batteries periodically, reducing hardware costs.
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
The non-PoE models of S5720-LI/S5720S-LI adopt the ground-free design. Only the 220 V
power module needs to be grounded. This design facilitates switch deployment in the places
where grounding is difficult, such as corridor.
CSFP Providing High-Density Access and Increased Bandwidth
CSFP switches support downlink CSFP ports. Each downlink CSFP port equipped with a
CSFP GE optical module and one pair of fibers can provide 2 Gbit/s bandwidth
bidirectionally, which is two times the bandwidth of standard SFP optical modules. The 24
downlink CSFP ports can provide 48 Gbit/s bandwidth bidirectionally, implementing highdensity access (equal to access of 48 standard SFP ports) and saving the cost of deploying
fibers and adding optical modules.
Cloud-based Management
1 Product Overview
Huawei provides the Agile Cloud Network solution based on public cloud. Since
V200R010C00, the S5720SI/S5720S-SI can be managed by a cloud management platform as
a cloud box. In the Agile Cloud Network solution, the cloud box is plug-and-play. It
automatically connects to the cloud management platform and uses bidirectional certificate
authentication to ensure management channel security. The cloud box provides the
Netconf&YANG interface for the cloud management platform to deliver configurations
remotely. In addition, remote maintenance and fault diagnosis can be performed on the cloud
box through the cloud management platform.
Related Content
Support Community
lIntroduction to Huawei Fixed Switches
Videos
lHuawei S5720HI Agile Switch Allows Services to Change On Demand
O ffice b uildingE le ctric ityM an ufactu rin gEn te rp rise
C SS link
A gg re ga tio n
switch
F ire w allC or e sw itch
A cc es s s w itc h
(S 57 00 )
R ou ter
W A NIn ter net
B ra n ch
M obile
S ta ff
P artne r
S5700 Series Ethernet Switches
Product Description
2 Application Scenarios
2.1 Application of the S5700 on a Large-scale Enterprise
Campus Network
This section describes the application of the S5700 on a large-scale enterprise campus
network.
As shown in Figure 2-1, the S5700 is deployed at the access layer of a campus network to
provide high performance, multi-service, and highly reliable enterprise network.
Figure 2-1 Position of the S5700 on a Large-scale enterprise campus network
The S5700 provides various terminal security management features, and supports functions
such as PoE, voice VLAN, and QoS. The S5700 can be used for desktop access and provides
GE access.
The S5700 provides various security features including ARP security, IP security, IP source
guard, and user access control policies such as NAC and ACLs, to control access of user
terminals.
The S5700 provides Easy-Operation and USB-based deployment, which facilitates
deployment and management.
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
2 Application Scenarios
2.2 Application of the S5700 on a Small- or Medium-scale
Enterprise Campus Network
This section describes the application of the S5700 on a small- or medium-scale enterprise
campus network.
As shown in Figure 2-2, the S5700 is deployed at the aggregation layer of a campus network
to provide high performance, multi-service, and highly reliable enterprise network.
Figure 2-2 Position of the S5700 on a small- or medium-scale enterprise campus network
On an enterprise network or campus network shown in Figure 2-2, the S5700s connect to
access switches through 100M/1000M interfaces, provide high performance and large
switching capacity, and connect to core switches through 10GE optical interfaces. The
network provides 10 Gbit/s rate for the backbone layer and 100 Mbit/s access rate for
terminals, meeting requirements for high bandwidth and multi-service.
The S5700 provides SEP and RRPP to implement millisecond-level protection switchover.
S5700s form a stack system by using iStack technology to implement the distributed
forwarding structure and fast fault recovery. The stack system increases the number of user
interfaces and improves packet processing capability. The iStack-enabled S5700s can be
managed in a uniform manner to facilitate network management and maintenance.
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
2 Application Scenarios
2.3 Application of the S5700 on a Small-scale Enterprise
Campus Network
This section describes the application of the S5700 on a small-scale enterprise campus
network.
As core switches of a small-scale enterprise network shown in Figure 2-3, the S5700s have
powerful aggregation and routing capabilities. S5700s use iStack to implement backup among
multiple devices and ensure high reliability. The S5700 provides various access control
policies to achieve centralized management and simplify configuration.
Figure 2-3 Position of the S5700 on a small-scale enterprise network
2.4 Application in Public Cloud
Agile Cloud Network is a suite of network solution based on Huawei public cloud. The
S5720SI/S5720S-SI can be located at the access layer of the agile cloud network as a cloud
box, as shown in Figure 2-4.
The cloud box is plug-and-play. It goes online after being powered on and connected with a
network cable, without complicated configurations. A cloud box can connect to the cloud
management platform and bidirectional certificate authentication is used to ensure
management channel security. The cloud box provides the Netconf&YANG interface for the
cloud management platform to deliver configurations remotely. In addition, remote
maintenance and fault diagnosis can be performed on the cloud box through the cloud
management platform.
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
FeatureDescriptionDifference
MPLS-MPLS QoSOnly the S5720HI and
3 Product Performance
VLLOnly the S5720HI and
S5720EI support this
PWE3
function.
VPLS
S5720EI support this
MPLS TE
function.
Device
reliability
BFDBasic BFD functionsOnly the S5700LI,
S5700S-LI, S5720LI,
BFD for static route/IS-IS/
OSPF/BGP
BFD for PIM
S5720S-LI, and S5710-XLI do not support this
function.
BFD for VRRP
StackingStack card supporting the stacking
function
Only some S5720EI
models (S5720-C-EI,
S5720-PC-EI,S5720-XEI, and S5720-P-EI)
support this function.
Service interface supporting the
stacking function
Only S5700LI, S5700SLI, S5720LI, S5720S-LI,
S5710-X-LI, some
S5720EI models (S5720C-EI,S5720-X-EI,S5720PC-EI) , S5720SI, and
S5720S-SI support this
function.
OthersVRRPOnly the S5700LI,
S5700S-LI, S5720LI,
S5720S-LI, and S5710-XLI do not support this
function.
Ethernet
OAM
EFM
OAM
(802.3ah)
Automatic discoveryNone
Link fault detection
Link fault troubleshooting
Remote loopback
CFM
Software-level CCMNone
OAM
(802.1ag)
MAC ping
MAC trace
OAM
association
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
FeatureDescriptionDifference
3 Product Performance
Portal authentication
Hybrid authenticationNone
ARP
security
ARP packet rate limiting based on
source MAC addresses
Only the S5720EI and
S5720HI support this
function.
ARP packet rate limiting based on
None
source IP addresses, interfaces, and
VLANs, and global ARP packet
rate limiting
ARP anti-spoofing
Association between ARP and STPOnly the S5700LI,
S5720LI, S5720S-LI,
ARP gateway anti-collision
S5710-X-LI and S5700S-
LI do not support this
function.
Dynamic ARP Inspection (DAI)
None
and Static ARP Inspection (SAI)
Egress ARP Inspection (EAI)
IP securityICMP attack defenseNone
IP source guard
Local
CPU attack defense
attack
defense
MFFMAC-Forced Forwarding (MFF)
DHCP
DHCP snooping
snooping
Option 82 function and dynamic
rate limiting for DHCP packets
Attack
defense
Defense against flood attacks
without IP payloads, attacks from
IGMP null payload packets, LAND
attacks, Smurf attacks, and attacks
from packets with invalid TCP flag
bits
Issue 18 (2016-11-09)Huawei Proprietary and Confidential
S5700 Series Ethernet Switches
Product Description
FeatureDescriptionDifference
3 Product Performance
Defense against attacks from many
fragments, attacks from many
packets with offsets, attacks from
repeated packet fragments, Tear
Drop attacks, Syndrop attacks,
NewTear attacks, Bonk attacks,
Nesta attacks Rose attacks, Fawx
attacks, Ping of Death attacks, and
Jolt attacks
Defense against TCP SYN flood
attacks, UDP flood attacks
(including Fraggle attacks and UDP
diagnosis port attacks), and ICMP
flood attacks
Network
managem
ent
-Ping and tracerouteNone
NQA
Network Time Protocol (NTP)
IPCAOnly the S5720HI support
this function.
sFlowThe S5720HI does not
support this function.
NetStreamOnly the S5720HI support
this function.
SNMP v1/v2c/v3None
Standard MIB
HTTP
Hypertext Transfer Protocol Secure
(HTTPS)
Remote network monitoring
(RMON)
RMON2Only theS5720EI and
WLAN-AP Management SpecificationsOnly the S5720HI support
Radio Management Specifications
WLAN Service Management
Specifications
QoS
Issue 18 (2016-11-09)Huawei Proprietary and Confidential