Professional Documents
Culture Documents
Table of Contents
i
System Description
Quidway S5600 Series Ethernet Switches Table of Contents
ii
System Description Chapter 1 Product OverviewError! Reference source
Quidway S5600 Series Ethernet Switches not found.
1.1 Preface
Huawei Quidway S5600 Series Ethernet Switches (the S5600 series) are wire speed
L2/L3 Ethernet switches. The S5600 series supply the Ethernet interfaces of 10 Mbps,
100 Mbps, 1000Mbps and 10GE. They can downlink with S3026, S3526, S3050 or
S3900 switches and so on, and uplink with IP device or high-capacity L3 switches
through GE, 10GE or aggregation links. The S5600 series support 1000Mbps to
desktop access in the enterprise network, or can serve as convergence layer devices,
as well as core devices for small or midsize enterprises, to offer highly dense 1000
Mbps ports and 10GE uplink ports. They are intelligent network management switches
intended for the use in a network environment where high performance, dense port
distribution, and ease of installation are required.
1-1
System Description Chapter 1 Product OverviewError! Reference source
Quidway S5600 Series Ethernet Switches not found.
S5648P: Adopts AC/DC dual input power module (PSL180-AD). Its rear panel
provides two fixed fabric ports and one expansion module slot that is compatible
with 8-port 1000 Mbps SFP, 1-port 10 Gbps XENPAK, and 2-port 10 Gbps XFP
modules. Its front panel provides 48 x 10/100/1000Base-T auto-negotiation
Ethernet ports with RJ-45 connectors and four SFP Combo ports. Each Combo
port corresponds to an Ethernet port, so there are four port pairs; only one port in a
pair can be used at the same time. For the relationship between the Combo ports
and the Ethernet ports, refer to Table 1-1.
S5648P-PWR: Adopts PoE power module (PSL480-AD48P, with external AC/DC
input). Its rear panel provides two fixed fabric ports and one expansion module slot
that is compatible with 8-port 1000 Mbps SFP, 1-port 10 Gbps XENPAK, and
2-port 10 Gbps XFP modules. Its front panel provides 48 x 10/100/1000Base-T
auto-negotiation Ethernet ports with RJ-45 connectors and four SFP Combo ports.
Each Combo port corresponds to an Ethernet port, so there are four port pairs;
only one port in a pair can be used at the same time. For the relationship between
the Combo ports and the Ethernet ports, refer to Table 1-1.
25 22
26 24
S5624P/S5624P-PWR/S5624F
27 21
28 23
49 46
50 48
S5648P/S5648P-PWR
51 45
52 47
Note:
The electrical ports of S5624P-PWR/S5648P-PWR are capable of supplying -48
VDC power to remote PDs (powered devices, such as S2016C, S2008B, S2016B,
S2016-EI, and so on).
The S5624P-PWR/S5648P-PWR adopts PoE power module, which provides
AC/DC power to PD devices. When delivering the AC input, the module can supply
up to 300 W power. If more power is needed, use the DC input or both AC and DC
inputs to ensure the operation of all the connected devices.
1-2
System Description Chapter 1 Product OverviewError! Reference source
Quidway S5600 Series Ethernet Switches not found.
The S5600 series support the Intelligent Resilient Framework (IRF) feature. The
IRF-supported switches of the same type (called units) are connected to form a “device
union” or a fabric (4 switches recommended). With the IRF feature, you can
Manage multiple devices but with one connection and one IP address, thus
decreasing the overheads,
Expand the network by adding devices as desired, thus protecting the existing
investment, and
Have high reliability of N + 1 redundancy, thus avoiding single point failures which
can result in service interruption.
S5624P/S5624P-PWR: 24 x
10/100/1000 Mbps electrical ports
and four SFP combo ports 48 x 10/100/1000 Mbps electrical
Fixed port
S5624F: 24 x 1000 Mbps SFP ports and four SFP combo ports
ports and four electrical combo
Service port ports
1000Base-SX-SFP
1000Base-LX-SFP
1000Base-LH-SFP
1000Base-T-SFP
Port type
10GBase-LR-XENPAK
10GBase-ER-XENPAK
10GBase-CX4-XENPAK
10GBase-LR-XFP
10GBase-ER-XFP
1-3
System Description Chapter 1 Product OverviewError! Reference source
Quidway S5600 Series Ethernet Switches not found.
AC:
Rated voltage: 100V to 240V, 50 Hz to 60Hz
S5624P: 170 W
S5648P: 230 W
S5624F: 170 W
S5624P-PWR: 540 W
Power consumption (full load)
S5648P-PWR: 600 W
When with PoE power supply:
S5624P-PWR: 540 W (DC input), 540 W (AC input)
S5648P-PWR: 970 W (DC input), 600 W (AC input)
Operating humidity
10% to 90%
(non-condensing)
1-4
System Description Chapter 1 Product OverviewError! Reference source
Quidway S5600 Series Ethernet Switches not found.
The software of the S5600 series is designed on Huawei versatile routing platform
(VRP). Table 1-3 summaries the available software features.
The port forwarding IP telephony traffic added to voice VLAN according to the MAC
Voice VLAN
address
Broadcast storm
Port rate ratio and PPS based suppression
suppression
HTTPD Supported
1-5
System Description Chapter 1 Product OverviewError! Reference source
Quidway S5600 Series Ethernet Switches not found.
Address self-learning
IEEE 802.1D standard
MAC address
table Up to 16K MAC address entries
Up to 1088 static MAC address entries, in which 1k entries is authenticated entries,
64 entries is manually configured ones.
1-6
System Description Chapter 1 Product OverviewError! Reference source
Quidway S5600 Series Ethernet Switches not found.
Access control Three scheduling algorithms on per port and queue basis: strict priority (SP),
list (ACL) weighted round robin (WRR), SP + WRR
Replacing the of 802.1p or DSCP preference values of packets
Packet filter at the layers 2 through 4, providing filtering based on source/destination
MAC address, source/destination IP address, port, protocol, VLAN, VLAN range,
MAC address range, or invalid frame
Time range setting
QoS profile management, allowing QoS service scheme customization
DHCP(dynamic
host
Supported
configuration
protocol) Relay
NTP (network
Supported (client/server/master)
time protocol)
1-7
System Description
Quidway S5600 Series Ethernet Switches
2.1.1 Appearance
The S5624F provides 24 x 1000 Mbps SFP optical ports, one Console port, and four
1000 Mbps RJ-45 Combo ports on its front panel, as shown in Figure 2-2.
(8) (7)
2-1
System Description
Quidway S5600 Series Ethernet Switches
Note:
The combo SFP ports support multiplexing with the corresponding 10/100/1000Base-T Ethernet electrical
ports, that is, you can use either these optical ports or the electrical ports, but not concurrently.
I. Console port
Attribute Description
Connector RJ-45
II. LEDs
You can learn the operating state of the S5624P/S5624P-PWR by reading the LEDs on
its front panel. Note that at a time a port LED can indicate only the state of speed,
duplex, or data transmission. You can toggle between them by pressing the Mode
button.
2-2
System Description
Quidway S5600 Series Ethernet Switches
The power is
OFF
disconnected.
Both the internal AC input
Solid green and the DC input are
normal.
The internal AC power
DC-input LED DC
Solid yellow supply fails or the DC input
is disconnected.
2-3
System Description
Quidway S5600 Series Ethernet Switches
No voltage is delivered on
OFF
the port.
Flashing
The POST on the port
yellow (3
fails..
Hz)
PoE
OFF ––
2-4
System Description
Quidway S5600 Series Ethernet Switches
Duplex
and
data OFF ––
transmi
ssion
PoE OFF ––
POST Flashing
Failed POST test ID
failed red
Softwar
Flashing A bar rotates clockwise
e
green around the LED.
loading
Tempe
“t”, meaning the switch is
rature Solid red
over-temperature.
7-number LED Unit alarm
Speed,
duplex
Unit ID in the Fabric; and
and Solid
for a standalone unit, it is
data green
1.
transmi
ssion
The total number of ports
in PoE status. All bars are
flashing when the
Solid
PoE threshold of PoE ports is
green
exceeded. The LEDs for
the problem ports are in
flashing green.
2-5
System Description
Quidway S5600 Series Ethernet Switches
2-6
System Description
Quidway S5600 Series Ethernet Switches
A “t” is displayed.
Over
temperature Solid red
alarm
41 - 60%
21 - 40%
0 - 20%
Blinking
yellow (at The port fails the POST.
3 Hz)
RJ-45 OFF The port is not connected.
Combo port
mode LED The port is operating in full duplex
Green mode. The LED blinks quickly when the
port is receiving or sending data.
The port is operating in half duplex
Yellow mode. The LED blinks quickly when the
Duplex mode port is receiving or sending data.
Blinking
Yellow (3 The port fails the POST.
Hz)
2-7
System Description
Quidway S5600 Series Ethernet Switches
Attribute Description
Connector RJ-45
Number of ports 24
Transmission segment over the 100 m (328.08 ft) over the category-5 unshielded twisted pair
selected medium (UTP) cable
The S5624P/S5624P-PWR provides four SFP combo ports (optical or electrical) on its
front panel.
SFP modules allow you great flexibility in networking because they are hot-swappable
and user-configurable.
Central Transmission
SFP module Connector Fiber specifications
wavelength segment
1000BASE-LX-SF
Single mode fiber 10 km (6.21 mi)
P
1310 nm
1000BASE-LH-SF 30 km (18.64
P mi)
1000BASE-ZX-LR 40 km (24.86
1550 nm
-SFP mi)
2-8
System Description
Quidway S5600 Series Ethernet Switches
1000BASE-ZX-VR 70 km (43.50
-SFP mi)
100 m (328.08
1000BASE-TX –– RJ-45 ––
ft.)
Note:
The available 1000 Mbps SFP module types are subject to changes without notice. For information on the
latest module options, contact Huawei marketing or technical support personnel.
You can choose AC-DC dual input mode (mutual backup) and only AC or DC input
mode.
AC input
Rated voltage: 100VAC to 240VAC, 50 Hz to 60 Hz
2-9
System Description
Quidway S5600 Series Ethernet Switches
The S5624P/S5624P-PWR is cooled by two ∅40mm fans. They are located in right of
the switch.
The S5624F is cooled by four ∅40mm fans. They are located in right of the switch.
The fan in the power module can cool the power module, as well as the mainboard and
expansion module of the switch.
2.2.1 Appearance
I. Console port
II. LEDs
You can learn the operating state of the S5648P/S5648P-PWR by reading the LEDs on
its front panel (see Table 2-2). Note that at a time a port LED can indicate only the state
of speed, duplex, or data transmission. You can toggle between them by pressing the
Mode button.
2-10
System Description
Quidway S5600 Series Ethernet Switches
Attribute Description
Connector RJ-45
Number of ports 48
Transmission segment over the 100 m (328.08 ft) over the category-5 unshielded twisted pair
selected medium (UTP) cable
You can choose AC-DC dual input mode (mutual backup) and only AC or DC input
mode.
AC input
Rated voltage: 100VAC to 240 VAC, 50 Hz to 60 Hz
2-11
System Description
Quidway S5600 Series Ethernet Switches
DC input
The S5624P-PWR/S5648P-PWR must use the external PoE PSU recommended by
Huawei-3Com as its DC input, but not the -48VDC power supply generally available in
the equipment room. Otherwise, the device may be damaged.
The S5648P/S5648P-PWR is cooled by three ∅40mm fans. They are located in right of
the switch.
The fan in the power module can cool the power module, as well as the mainboard and
expansion module of the switch.
2-12
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
The link aggregation function is used for the connection between Ethernet switches or
between the switches and high-speed servers. It is a simple and cheap way to expand
the bandwidth of a switch port and balance the traffic among all the ports in a link
aggregation. Moreover, it enhances the connection reliability.
With link aggregation, several Ethernet ports on a switch are bundled together and are
considered one logical port inside the switch. The switch automatically balances the
traffic among the ports and increases the bandwidth in this aggregation, while ensuring
the right order of packets for the sake of service compatibility. If the link on a port in the
aggregation fails, the traffic on it is distributed among other ports without interrupting
the normal service. After the port recovers, the traffic is automatically distributed again
so that the port can share the load together with others. The S5600 series support
manual link aggregation and dynamic link aggregation through the link aggregation
control protocol (LACP).
For the S5600 series, the broadcast storm suppression is configured on port. After
configuring a broadcast suppression ratio on a port, you can monitor the broadcast
traffic of unknown unicast, multicast and broadcast packets on it. When the traffic
exceeds the specified bandwidth limit, the switch drops the excessive traffic and
3-1
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
reduces the traffic ratio to a rational amount to guarantee the normal operation of
network services. The S5600 series can implement broadcast storm suppression not
only based on port rate ratio but also on pps.
3.1.3 VLAN
Virtual local area network (VLAN) is a technology that implements virtual workgroups
by assigning devices of the same category (such as PC) on a LAN into network
segments logically rather than physically. IEEE 802.1Q is the standard protocol for the
VLAN technology.
As devices are divided logically rather than physically, they do not necessarily reside on
the same physical network segment. After the division, the broadcast and unicast traffic
is confined inside the VLAN to which it belongs.
The VLAN technology helps network flow control, network management, and network
security.
3.1.4 STP/RSTP/MSTP
I. STP/RSTP
The spanning tree protocol (STP)/rapid spanning tree protocol (RSTP) prunes a loop
L2 switching network into a loop-free tree (all data on the L2 switching network must
travel along the spanning tree), thereby avoiding network broadcast storms caused by
network loops and providing redundant links for data forwarding.
Basically, STP/RSTP is to generate a “tree” whose root is a switch called root bridge.
Which switch is to be selected as the root bridge is based on their settings (such as
switch priority and MAC address), but there should be only one root bridge at any time.
Setting out from the root, a tree stretches through the switches. A non-root switch
forwards data to the root from its root port and to the connected network segment from
its designated port. A root periodically transmits configuration BPDUs, while a non-root
switch receives and forwards them. If a switch receives configuration BPDUs from two
or more ports, it assumes that there is a loop in the network. To eliminate the loop, the
switch selects one of the ports as the root port and blocks others. When a port receives
no configuration BPDUs for a long time, the switch considers that the configuration of
this port has timed out and the network topology may have changed. Then it
recalculates the network topology and generates a new tree.
RSTP is an STP enhancement that significantly shortens the time for the network
topology to stabilize.
RSTP is a single spanning tree protocol, that is, only one tree is generated within a
switching network. To ensure the interior communications of VLANs, each VLAN of a
3-2
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
network must be consecutively distributed along the spanning tree; otherwise, some
VLANs are parted because of the blocking of interior link, and the inside VLAN
communications fail. In the event of special requirements or failure to distribute VLANs
along the path of the spanning tree, you can configure the STP-ignore attribute of
VLAN on the specific switch to solve this problem.
II. MSTP
MSTP stands for Multiple Spanning Tree Protocol, which is compatible with STP and
RSTP.
STP cannot transit fast. Even on the point-to-point link or the edge port, it has to take an
interval as long as twice forward delay before the network converges.
RSTP can converge fast, but still has the drawback, that is, all the network bridges in a
VLAN share a spanning tree and the redundant links cannot be blocked by VLAN.
MSTP makes up for the drawback of STP and RSTP. It makes the network converge
fast and the traffic of different VLAN distributed along their respective paths, which
provides a better load-balance mechanism for the redundant links.
MSTP associates VLAN and the spanning tree and divides a switching network into
several regions, each of which has a spanning tree independent of one another. MSTP
prunes the network into a loopfree tree to avoid proliferation, it also provides multiple
redundant paths for data forwarding to implement the VLAN data forwarding
load-balance.
An Ethernet switch with DHCP Relay enabled relays the messages between a DHCP
server and a client. It can have a DHCP server in a subnet serves another subnet that
has no DHCP server. With DHCP Relay, a network administrator needs not to deploy a
DHCP server for every subnet, thereby reducing the investment cost. The DHCP
security function checks the validity of user addresses under VLAN interfaces.
3-3
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
Note:
When a switch runs a routing protocol, it can perform router functions. In this chapter, a router represents
a physical router or a L3 routing switch that runs routing protocols.
I. Static Routing
The proper configuration and use of static routes can effectively guarantee network
security and guarantee bandwidth resources to crucial applications as well. However, if
the network topology changes, as the result of a network device failure for example, the
static routes cannot change automatically to accommodate to the change without the
help of an administrator.
A default route is used only when no route match is found. In default routing, the mask
and destination addresses are both 0.0.0.0 in the routing table. When there are a large
number of users in communications, default routing is useful because it uses less time
and fewer bandwidth resources to route and forward packets, in comparison to other
routing methods.
3.3.2 RIP
Routing information protocol (RIP) is a widely used interior gateway protocol (IGP) and
is D-V distance-vector (D-V) algorithm-based. It is suitable for small-sized and simple
networks.
RIP switches routing information with user datagram protocol (UDP) datagrams and
sends updates regularly. It uses hop count as the routing metric and allows up to 15
hops. RIP has two versions: RIPv1 and RIPv2. RIPv2 supports plain text authentication
and MD5 authentication and variable-length subnet masks as well. Both of them can
work with the S5600 series.
3.3.3 OSPF
Open shortest path first (OSPF) is an IGP protocol based on link-state (L-S), which is
suitable for large-sized and complex networks.
3-4
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
A router uses OSPF to maintain the routing table information in an autonomous system
(AS). In an AS, every OSPF router collects and broadcasts its link state information
throughout the AS with the flooding algorithm to synchronize the link state databases
(LSDBs) of other OSPF routers. With its LSDB, the router calculates a shortest-path
tree with itself as the root and other network nodes as leaves, thus getting its optimal
reachable routes inside the system.
Note:
When a switch runs a routing protocol, it can perform router functions. In this chapter, a router represents
a physical router or a L3 routing switch that runs routing protocols.
The IGMP snooping runs at the link layer. When a L2 Ethernet switch receives an IGMP
message that is sent from a host to a router, it uses the IGMP snooping to analyze the
information carried by the IGMP message. When the switch hears an IGMP Host
Report message from the host, it adds the host to the appropriate multicast table. When
hearing an IGMP Leave message, it removes the host from the multicast table. By
continuously listening to IGMP packets, the switch creates and maintains a L2 MAC
multicast address table and based on which forwards the multicast packets sent from
the upstream router.
Caution:
IGMP Snooping and IGMP cannot run on the same VLAN at the same time.
3-5
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
3.4.2 IGMP
The Internet group management protocol (IGMP) runs between hosts and multicast
routers for tracing and learning the membership of the hosts. A multicast router learns
whether there is a multicast member on a subnet connected to it by periodically
sending IGMP Host-Query messages. A host sends IGMP Report messages for joining
a multicast group. The S5600 series support both IGMPv1 and IGMPv2.
3.4.3 PIM-DM
The protocol-independent multicast (PIM) runs between multicast routers. Using PIM, a
multicast router traces and learns which multicast packets are to be forwarded to other
routers, and then transmits them to the LANs connected to the multicast routers.
3.4.4 PIM-SM
3.5 IRF
3.5.1 IRF
3-6
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
Expand the number of ports and switching capacity by adding devices as desired,
thus protecting the existing investment when scaling up the network.
Achieve high reliability of N + 1 redundancy, thus avoiding single point failures
which can result in service interruption.
3.6 QoS
In traffic classification, a rule is specified for discriminating packets compliant with some
characteristics. Classification rules can be very simple; for example, packets can be
sorted by the priority defined in the type of service (ToS) field in the IP header. They can
also be very complex; for example, packets can be sorted by any combination of MAC
address, IP protocol type, source (host or network) address, destination (host or
network) address, and even application port number, which involve the layers of data
link, network, and transport.
Traffic policing polices the traffic matching a traffic classification rule on the port where
the packets are received, so that the traffic can effectively use the assigned network
resources such as bandwidth.
Traffic policing mainly functions to limit the speed of an input port and thereby monitor
the traffic that enters its connected network. When packets arrive at the port at a speed
exceeds the assigned bandwidth, they are either dropped or assigned a new
preference.
Bandwidth guarantee refers to assuring the minimum bandwidth for a special traffic so
that it can satisfy such QoS requirements as packet loss rate, delay, jitter even when
network congestion occurs.
Port flow control is used for congestion management. Congestion occurs when the
network cannot reach the committed or negotiated performance specifications (such as
speed).
3-7
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
When congestion occurs, the switch transmits a pause frame to the corresponding
connection and notifies the peer to pause for a period of time before transmitting data
again, so as to reduce the incoming traffic on the network. The port control takes effect
on all traffic.
When this function is applied, data packets on a mirroring port are copied to its monitor
port for network test and troubleshooting.
Traffic mirroring monitors the traffic that matches the traffic classification rule.
This function is to copy the data packets that match the traffic classification rule to the
monitor port for network detection and trouble shooting.
Queues
High
Outgoing packets
Medium
Classifiy
Incoming Normal Queue
packets scheduling
Low
The SP mechanism applies to key services that are delay-sensitive and must have
priority when congestion occurs. In SP, packets are assigned to four queues, namely,
high-priority queue, medium-priority queue, normal-priority queue, and low-priority
queue (numbered as 3, 2, 1, and 0 respectively) with priority in descending order.
SP schedules the packets in a strict priority order. It sends the packets in a queue only
when the queue with a higher priority is empty. By putting the key service packets in the
high priority queues, you can ensure that they can always be served first. At the same
3-8
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
time the common service packets can be put in the low priority queues and transmitted
when there are no key service packets waiting for transmission.
If congestion occurs and the high priority queues are occupied for a long time, however,
the packets in the lower-priority queues are “starved” before obtaining services.
2) WRR
In WRR, there are four or eight outgoing queues on each port. The packets in different
queues are processed in turn, so that every queue is assigned some time of service. If
there are four queues on a port, they are each assigned a weight for obtaining
resources: w3, w2, w1, and w0 respectively. On a 100 Mbps port, for example, you can
assign the weights 50, 30, 10, 10 to the four queues with w3, w2, w1 and w0. Thus the
lowest-priority queue can be guaranteed of a minimum bandwidth of 10 Mbps. This
avoids the case that the packets in the low priority queues cannot be served, as in SP.
More than that, WRR assigns service time slices flexibly to every queue. When a queue
is empty, the next one is processed immediately. Thus it makes a full use of the
bandwidth resources.
3) SP+WRR
SP+WRR schedules some of the queues on the port with SP mechanism, and some
with WRR mechanism. Thus can make rather full use of the bandwidth.
The S5600 series offer 8 queues on each port, and support SP, WRR and SP+WRR
mechanisms.
Traffic shaping is to control traffic output rate as such that packets can be output at an
even rate. Normally, traffic shaping is applied on a device to adapt its output rate to the
input rate of its connected downstream device so as to avoid unnecessary packet drop
and congestion. It is different from traffic policing in the sense that it buffers the packets
that exceed the specified rate limit so that packets are sent out at an even speed,
whereas traffic policing is to discard the packets. Besides, traffic shaping can result in
the additional delay that can be avoided in traffic policing.
The priority tag feature is used for setting packet a new priority.
The S5600 series provide some specific packets with a new priority service. The
contents include ToS priority, differentiated services codepoint priority (DSCP), and
802.1p priority.
3-9
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
3.7 NTP
Clock synchronization among devices is important for a complex network. The network
time protocol (NTP) is a TCP/IP protocol that releases accurate time on a network.
3.8 Security
The S5600 series protect command lines in a hierarchical way by dividing the
command lines into four levels: visitor, monitor, operator, and administrator.
Commensurate with the command division, login users are classified into four levels. A
login user can use only the commands equal to or lower than its level.
3-10
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
3.8.2 SSH
When users log onto the Ethernet switch from an insecure network, secure shell (SSH)
offers security information protection and powerful authentication function to safeguard
the Ethernet switch from attacks such as IP address spoofing and plain text cipher
interception. The Ethernet switch can accept multiple SSH customer connections at the
same time. The SSH client allows users to connect to the Ethernet switches and UNIX
mainframes that support SSH servers.
Port isolation means layer 2 isolation of the ports in the same VLAN so that layer 2 relay
cannot be done between a port and another port (or another group of ports), but it can
communicate with the port in the upper layer. It prevents visiting between the ports,
effectively controls unnecessary broadcasting and increases the network throughput.
Packet filtering filters invalid or non-interesting data packets. The switch filters each
packet based on the defined rules, by comparing the source or destination address for
example. With packet filter, session state is ignored and data is not analyzed. You can
define which packets are permitted and which are denied.
IEEE 802.1x is actually a port based network access control protocol. As the name
implies, the NAS on a LAN authenticates and controls the connected customer
premises equipment (CPE) at the port level. If the CPE connected to a port passes
authentication, it is allowed to access the LAN resources. Otherwise, it is rejected just
like its physical link is disconnected.
In implementing 802.1x, the Ethernet switches not only support the port-based access
authentication, but also extends and optimizes it by:
Allowing a physical port to be connected to several terminals.
Supporting access control (that is user authentication) based on MAC address in
addition to port.
The system thus becomes securer and more operational and manageable.
Note that, although 802.1x provides an implementation scheme for user authentication,
the protocol itself is not enough to implement the scheme. The NAS administrators,
however, can use RADIUS or local authentication to complete the user authentication
with 802.1x.
3-11
System Description
Quidway S5600 Series Ethernet Switches Chapter 3 Software Features
MAC address authentication: the server or the Ethernet switch stores the information
on user MAC addresses. Once a new user is detected, the switch authenticates the
user by taking its MAC address as its user name and password. It searches the MAC
addresses table in the server or the switch for the user’s MAC address. If found, the
user is authenticated and the MAC address will be automatically added to the
corresponding port; if not, the authentication fails and the packet will be discarded. This
authentication method does not involve the client, the client’s own MAC address is
taken as its user name and password.
With the disconnect unauthorized device (DUD) function enabled, the switch filters out
all the traffic of a connected device once it detects that the device is unauthorized. It is
implemented through limiting the number of learned MAC addresses and binding MAC
addresses with ports.
3-12
System Description
Quidway S5600 Series Ethernet Switches Chapter 4 System Maintenance and Management
The S5600 series can be configured through the command line interface (CLI), NMS,
HGMP, or Web.
In the CLI approach, you can configure the switch locally through the console port,
or configure it remotely through modem dialup or Telnet. The S5600 series
support both Telnet server and Telnet client.
In the NMS approach, you can configure the switch through an SNMP-based
NMS.
In the Web approach, you can configure the switch that supports the Web-based
network management.
The S5600 series provide means for system software and hardware fault detection and
diagnosis. The ping and tracert commands are available for you to test network
connectivity and trace packet transmission paths online and therefore your later fault
locating.
4-1
System Description
Quidway S5600 Series Ethernet Switches Chapter 4 System Maintenance and Management
The S5600 series provide multiple approaches to software upgrade, and support
remote grade and rollback to the previous version after upgrade.
The S5600 series support Huawei Quidview NMS for centralized management, which
is usually implemented in bingual graphic interfaces. The NMS provides management
in topology, configuration, fault, security, and performance.
The Quidview helps you learn your network in direct and convenient way by providing a
network-wide device topology view. The Quidview delivers powerful topology
management. It provides the physical topology view, logical topology view, and
customized views, offering a unified network-wide equipment view. It also provides the
user-friendly interface for network/equipment operation and maintenance. The system
supports automatic topology discovery, reflecting the real-time changes in network
topology and equipment status.
With the Quidview, you can configure and manage the S5600 series, speccfically,
query/enable/disable ports, query/reset/load boards, and query port parameters/VLAN
configurations.
Fault management is the most important and common management approach during
the network operation and maintenance. In the graphic interfaces, you can implement
equipment running/fault status query, real-time monitoring, fault
filtering/locating/check/analysis. The system provides audio prompt and graphical
displays on the alarm card. Additionally, it can be connected to the alarm box and
therefore facilitates routine maintenance.
4-2
System Description
Quidway S5600 Series Ethernet Switches Chapter 4 System Maintenance and Management
The S5600 series can collect and analyze performance data, monitor performance,
and provide graphical performance reports in different forms. You can thus learn the
information on equipment load and access traffic, track network service quality, and
allocate network resources based on your network evaluation.
The S5600 series provide several security measures to strictly authenticate the user’s
operations and ensure the system security. It offers detailed operation log for later
query and analysis.
Web-based network management allows you to manage and maintain a switch through
Web. It is implemented as follows:
The switch provides a built-in Web server and runs a Web-based network management
program on the homepage at the IP address of the management VLAN. The PC users
connected to the Ethernet ports on the switch can access and use, through a browser,
the program on the homepage to manage the switch. Figure 4-1 shows the Web-based
NM operating environment.
Switch
HTTP connection
PC
4-3
System Description Chapter 5 Networking ApplicationsError! Reference s
Quidway S5600 Series Ethernet Switches ource not found.
You can deploy S5600 series on many types of networks, such as enterprise networks
and broadband access networks. Following are several typical networking applications.
S5600 series can serve as backbone switches in small and midsize enterprise
networks. They are uplinked to the headquarters or other branches through routers.
They can smoothly enlarge capacity with the IRF technique.
Core/Aggregation
Access
5600
3900
In a large enterprise or campus network, the S5600 series are located at the
convergence layer. They are downlinked to layer 2 switches (S3900 Series for
example), and uplinked to a layer 3 switch through the GE expansion module. These
switches together provide a network-wide intranet solution that covers
gigabit-to-backbone and 100 Mbps-to-desktop.
5-1
System Description Chapter 5 Networking ApplicationsError! Reference s
Quidway S5600 Series Ethernet Switches ource not found.
C ore
A ggregation
A ccess
G aribaldi
5600
3900
Figure 5-2 S5600 series application in large enterprise and campus network
5-2
System Description Chapter 6 Guide to PurchaseError! Reference sourc
Quidway S3900 Series Ethernet Switches e not found.
To meet varied customer needs, S5600 series can be delivered to your order. You can
purchase the switch and optional expansion modules as needed.
I. Networking requirements
Make sure you want a dual input power module or PoE power module.
6-1