You are on page 1of 72

Huawei Campus Network Products and Solution Pre-sales

Training

Page 0 Copyright © 2020 Huawei Technologies Co., Ltd.


Contents
• Campus LAN Trend

• CloudEngine S-series Switch Introduction

• CloudEngine S-series Switch Highlight

• CloudEngine S-series Switch Evolution

Page 1 Copyright © 2020 Huawei Technologies Co., Ltd.


The new era of Wi-Fi 6 requires new campus bearer network

Office Asset management


Wi-Fi 6 AP

Video
HD conference AR/VR Access control
surveillance

How can we meet Wi-Fi 6 bandwidth How can we deploy different service networks How can we respond to concurrent user
needs? in a unified manner? traffic at peak hours?
Single AP = 10 Gbps Office, security protection, production... High burst -> packet loss

Page 2 Copyright © 2020 Huawei Technologies Co., Ltd.


Huawei CloudCampus Solution: Building a High-Quality Campus Network
Ideal for the Wi-Fi 6 Era
Wi-Fi 6 transforms enterprises

Customer Health Transform workplaces Transform production Transform public services


flow e-Schoolbag Managem Smart
analysis ent office

Open industry application development


platform SDK | API
iMaster NCE-Campus: autonomous driving platform that integrates management, control, and analysis,
Management and ideal for the Wi-Fi 6 era
control layer
Full automation, enabling Wi-Fi 6 services Intelligent O&M, ensuring Wi-Fi 6 experience
Planning automation · Network construction automation · Policy User experience visibility · Fault demarcation · Network
automation optimization & self-healing

Management, control,
and analysis High-quality bearer network ideal for Wi-Fi 6 era
NETCONF/YANG Telemetry
Full-10GE access, releasing Wi-Fi 6 speed
Network layer • Multi-GE switch + high-density 25GE fixed switch + 100GE core, building ultra-broadband channels for Wi-Fi 6
• Integrated wireless policy management (managing up to 10k APs and 50k concurrent users), meeting massive user concurrency
in the Wi-Fi 6 era
• Wireless campus with 10k users, thanks to 100GE capable CloudEngine S12700E (57.6 Tbps, 50k wireless users, 6x performance)
CloudEngine S series campus switches

AirEngine Wi-Fi 6 AirEngine Wi-Fi 6 powered by Huawei 5G, building a fully wireless campus network
Lightning speed More stable coverage More stable application More stable roaming
Industry's only dual-band 16 Dynamic Turbo: Lossless roaming:
Smart antenna: signals
smart antennas: 10.75 Gbps, application acceleration, zero packet loss
moving with users, 20%
2x the industry average < 10 ms latency during roaming
greater coverage distance

Page 3 Copyright © 2020 Huawei Technologies Co., Ltd.


Typical Architectures of Future Campus Networks, Best Suited for Different
Scenarios
As-Is To-Be: Typical Networking To-Be: Simplified Networking

N x 10GE N x 10GE N x 10GE N x 10GE 100GE 100GE

25/100GE 25/100GE
VXLAN

GE/10GE GE/10GE GE/10GE GE/10GE 25GE 25GE


OR
N x 10GE

Service Service
network 1 network 2

48 x GE 48 x FE/GE 48 x GE 48 x FE/GE 48 x multi-GE 48 x GE 48 x 10GE 48 x multi-GE 48 x 10GE

• FE/GE access • Layer-by-layer convergence +


• Two-level architecture
• Dedicated networks for dedicated virtualization
• Non-blocking forwarding at all links
purposes • Higher network resource utilization

Page 4 Copyright © 2020 Huawei Technologies Co., Ltd.


Contents
• Campus LAN Trend

• CloudEngine S-series Switch Introduction

• CloudEngine S-series Switch Highlight

• CloudEngine S-series Switch Evolution

Page 5 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S Series Switches: Building a High-Quality Campus Network for
the Wi-Fi 6 Era
CloudEngine
S12700E-12
CloudEngine
S12700E-8

CloudEngine
S12700E-4
CloudEngine
CloudEngine S7700 CloudEngine
CloudEngine S5735- S5730-H/S S6730-H/S
S/L

Wi-Fi 6 Ready IoT Ready Cloud Ready Quality Ready

• Core switches deliver 6x the industry • Integrated WAC (or native AC) provides • Cloud-based management and O&M, • HQoS ensures the application
switching performance ultra-large specifications when combined with iMaster NCE, experience for key users.
• Innovative hybrid optical-electrical • Intelligent terminal identification achieves automatic deployment and
• Fully programmable, open architecture
switches build ultra-high-speed Wi-Fi 6 facilitates refined access control of IoT intelligent O&M
facilitates smooth network evolution
networks terminals at scale

Page 6 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S12700E: The new core of the campus network in the era of
Wi-Fi 6

CloudEngine S12700E-4/8/12

• Control and switching separation architecture, enabling on-


demand configuration and flexible capacity expansion

• Redundancy design for key components, providing 99.999%


reliability

• Ultra-large buffer and HQoS scheduling, ensuring user


experience with key applications
Benchmarking Model
• 4.8 Tbps/slot super-strong forwarding, building a Wi-Fi 6 high-
HW:S12700E CISCO:C9600
speed channel

Next-Generation High-Performance Campus Core Switches Unleash Wi-Fi 6 High-Speed Potential

Page 7 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S12700E MPU/SFU

BITS CPU: Console port


(reserved) • Integrates hardware-based OAM/BFD
• Supports multi-core and multi-instance, as well as manages
USB port ETH management port 10K APs and 50K concurrent users
MPUE

• Bidirectional bandwidth per slot: 3.2 Tbps


• Used on CloudEngine S12700E-4/8.

SFUE

• Bidirectional bandwidth per slot: 4.8 Tbps


Subcard
(reserved) • SFUH is used on CloudEngine S12700E-4/8
• SFUM is used on CloudEngine S12700E-12
SFUH/SFUM
• One subcard slot is reserved for capacity expansion

Page 8 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S12700E Line Card

10GE GE GE
100GE 25GE Native Free
X Series Optical Optical Electrical VXLAN SVF iPCA MACsec
Ports Ports WAC Mobility
Ports Ports Ports

X6E 24 - - - √ √ √ √ √ √

X6E/X6S 6 - - - √ √ √ √ √ √

X6H - 40 - - - √ √ √ √ √ √

X6E/X6S - - 48 - - √ √ √ √ √ -

X6E/X6S* - - 24 24 - √ √ √ √ √ -

X6E/X6S* - - - 48 - √ √ √ √ √ -

X5E/X5S - - - - 48 √ √ √ √ √ -

Note: The 24-port 10GE (optical) and 24-port GE (optical) line card (X6E/X6S) and the 48-port GE (optical) line card (X6E/X6S) can be used on both S12700E
and S12700 chassis

Page 9 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S12700E Line Card – 25GE Line Card

40 x 25GE line card (X6H)

Type 1 (default): 32 x 25GE 8 x 25GE 8 x 10GE

Type 2: 32 x 25GE 16 x 10GE

Available for use Unavailable for use

• MACsec supported on all ports


• Ultra-large entries, far ahead of other vendors: 1M MAC, 1M FIB, and 384K ARP
• In-house chip inside, supporting key features such as native WAC, VXLAN, free mobility, SVF, and iPCA
• 4 GB ultra-large buffer and unique 4-level HQoS: experience assurance for key users and applications in bustry traffic scenarios

Page 10 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S12700E Power Supply

• S12700E-4:4 PS slots,N+1 Redundancy Mode


C
• S12700E-8:6 PS slots, N+1 or N+2 Redundancy Mode
MU
• S12700E-12:6 PS slots, N+1 or N+2 Redundancy Mode

• The CMU manages power modules and fan modules in a chassis. The CMU is hot swappable. Two CMU cards can be installed in a chassis to
work in active/standby mode.

3000W AC Power Supply(PAC3KS54-CE) 2200W DC Power Supply(W2PSD2200)

Input Voltage:
• AC: 90V AC~290V AC Input Voltage:
• DC: 190V DC~290V DC • -40V DC~-72V DC
Max Output Power: Max Output Power::
• 3000W@220V AC/240V DC • 2200W
• 1500W@110V AC

• Power supplies use a screw-free ejector latch for easy swapping. An indicator shows whether a power supply is securely installed in its slot.
• AC/DC power modules can be mixed in the same device.

Page 11 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S7700: Intelligent Routing Switches

CloudEngine S7703/06/12

• Leadership in native WAC, managing up to 4K APs

• Redundancy design for key components, providing


99.999% reliability

• PoE++ available on up to 288 ports

• Distributed forwarding architecture, high-speed


Benchmarking Model
HW:S7700 CISCO:C9400 upstream forwarding without bottlenecks

High-density, strong power supply capability, rich port forms, and flexible scenario adaptability

Page 12 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S7700 MCU
S7703/S7703 PoE MCU

• Bidirectional bandwidth per slot: 320 Gbps (S7703), 800 Gbps (S7703 PoE)
• Integrates the control and monitoring functions, excluding the SFU (full mesh).
• Better performance than MCUD: 1024 APs (via native WAC), 256 SVF ASs
MCUD • Improvements on ARP, ND, and RIB entry specifications

S7706/S7706 PoE/S7712 MCU

• Bidirectional bandwidth per slot: 720 Gbps (S7706), 720 Gbps/320 Gbps (S7712) *
• Integrates hardware-based OAM/BFD, achieving millisecond-level network quality detection
• Service port-based CSS ensures stable and reliable device running
• Used together with C-version line cards
• Cannot be used for capacity expansion or replacement of old MCUs on the live network
SRUHX1

Note: When SRUHX1 is used on S7712, slots 6 and 7 are golden slots that provide higher bandwidth

Page 13 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S7700 Line Card
GE
10GE GE
100GE GE Optical Electrical Native Free
X Series Optical Electrical VXLAN SVF iPCA Macsec
Ports Ports Ports WAC Mobility
Ports Ports
(PoE++)

X6E/X6S 6 - - - - √ √ √ √ √ √

X6E/X6S - 48 - - - √ √ √ √ √ -

X6E/X6S - 24 24 - - √ √ √ √ √ -

X6E/X6S - - 48 - - √ √ √ √ √ -

X5E/X5S - - - 48 - √ √ √ √ √ -

X5E - - - - 48 √ √ √ √ √ -

Page 14 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S7700 Line Card – GE Card

48 x GE PoE++

LSS7G48VX5E0

• PoE++
• In-house chip inside, supporting key features such as native WAC, VXLAN, free mobility, SVF, and iPCA
• Used on S7703 PoE and S7706 PoE chassis, with 60 W power supply on all ports
• Replaces X5E/X5S/EA series 48 x GE PoE cards, due to its higher specifications while similar or even lower prices than old cards

Page 15 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S7700 Power Supply

C
PS1-PS4 M PS5-PS8
U
PS1 PS2 PS3
S7703: PS3 is a PoE module. S7706/7712: PS5-PS8 is a PoE module.
S7703 PoE: All modules are PoE Module S7706 PoE: All modules are PoE Module
• The CMU manages power modules and fan modules in a chassis. The CMU is hot swappable. Two CMU cards can be installed in a chassis to work in active/standby
mode.

3000W AC Power Supply (PAC3KS54-CE) 2200W DC Power Supply (W2PSD2200)

Input Voltage:
• AC: 90V AC~290V AC Input Voltage:
• DC: 190V DC~290V DC • -40V DC~-72V DC
Max Output Power: Max Output Power::
• 3000W@220V AC/240V DC • 2200W
• 1500W@110V AC

• Power supplies use a screw-free ejector latch for easy swapping. An indicator shows whether a power supply is securely installed in its slot.
• AC/DC power modules can be mixed in the same device.

Page 16 Copyright © 2020 Huawei Technologies Co., Ltd.


Naming Rules for CloudEngine S Series Fixed Switches
Product series Port attributes Key Features

C l o u d E n g i n e S 5 7 0 0 E C - H 4 8 T 4 Y C - M A
A B C D E F G H I J K L M
Location Meaning Description
A Brand name (1 bit) Fixed as S
B Network positioning (1 bit) 8: core switch; 6: aggregation switch; 5: access switch
C Market positioning (1 bit) 7: enterprise network market; 3: carrier market
The leftmost one bit indicates the generation, for example, 10/20/50.
D Switch series (2 bits)
The rightmost one bit indicates the specification upgrade, for example, 01/02/03.
E Industry identifier (1 or 2 bits) Null by default; EC: e-commerce model; S: channel distribution model.
F Series model (1 bit) H: high-end model; S: standard model; L: lite model.
G Number of downlink ports (2 bits) Number of downlink ports
D: 400G; C: 100G; Q: 40G; Y: 25G; X: 10G optical; M: 10G electrical; N: 2.5G/5G electrical; S: GE optical; T: GE electrical; F: FE electrical; P:
H Downlink port type (2 bits)
GE electrical port, supporting PoE; U: GE electrical port, supporting PoE++; UM: multi-GE port, supporting PoE++.
I Number of uplink ports (1 bit) Number of uplink ports

J Uplink port type (2 bits) D: 400G; C: 100G; Q: 40G; Y: 25G; X: 10GE optical; S: GE optical; T: GE electrical; TP: combo port.

K Card slot (1 bit) Null: Cards are not supported; C: Uplink cards are supported.
Null by default; If there is a value (for example, M or I) for this bit, the switch is a dedicated one. M indicates a switch tailored for video
L Dedicated bit (1 bit)
surveillance scenarios, and I indicates an extended-temperature switch.
Type of power supply delivered by
M A: AC power supply; D: –48 V DC power supply; null: no power supply delivered by default.
default

Page 17 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S6730 At-A-Glance

Programmable Network Processor inside ,Native AC(1K AP), Free mobility, iPCA, VXLAN,
CloudEngine S6730-H NetStream, Telemetry, SVF, ECA, Threat deception, MPLS, IPv6,1588v2, service port
stacking
Downlink port: 10GE optical ports; uplink port: 40/100GE optical ports

Programmable Network Processor inside, Free mobility, iPCA, VXLAN, NetStream, Telemetry,
CloudEngine S6730-S SVF, ECA, Threat deception, IPv6, service port stacking
Downlink port: 10GE optical ports; uplink port: 40GE optical ports

Page 18 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S6730-H:Full-function 10GE routing switch

Programmable CPU: RAM:4GB


Console 6*40GE/100GE
chip 4 Core*1.4GHz Flash:2GB

Two slots for pluggable power modules


SSD card slot* USB 2.0 Four slots for pluggable
(1+1 redundancy)
fan modules
*Reserved SSD card slot

Page 19 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S6730-H

Stack bandwidth: 1.2Tbps MAC address: 384K


24/48 x 10GE optical ports, and 6 x 40GE/100GE optical ports

Cloud
√ SVF √ VXLAN √ iPCA √ ECA √ NetStream √ MPLS √ Telemetry √ √ iStack
mgmt.

• Native AC, managing a maximum of 1K APs • SVF parent/client mode, simplified deployment and management

• Supports IEEE 1588v2 protocol to achieve precise time • VXLAN-based automatic virtual network deployment, implementing
synchronization. multi-purpose network

Page 20 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S6730-S: Next-generation standard 10GE switch

CPU: RAM:4GB
Console Programmable chip 6*40GE
4 Core*1.4GHz Flash:2GB

Two slots for pluggable power modules


SSD card slot* USB 2.0 Four slots for pluggable
(1+1 redundancy)
fan modules
*Reserved SSD card slot

Page 21 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S6730-S

Stack bandwidth: 480Gbps MAC address: 64K


24 x 10GE optical ports, and 6 x 40GE optical ports

Cloud
√ SVF √ VXLAN √ iPCA √ ECA √ NetStream √ MPLS √ Telemetry √ √ iStack
mgmt.

• Native AC, managing a maximum of 1K APs • SVF parent/client mode, simplified deployment and management

• Supports 10GE optical port access, meeting fast • VXLAN-based automatic virtual network deployment,
connection requirements. implementing multi-purpose network

Page 22 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5730 At-A-Glance

Programmable chips inside, native AC, VXLAN, free mobility, iPCA, NetStream, Telemetry, SVF, ECA, threat
S5732-H
Enhanced GE/Multi-GE switch deception, MPLS, IPv6, service port stacking, GE/10GE models(with 40GE uplink), Multi-GE models(with
25GE/40GE/100GE uplink)
Programmable chips inside, native AC, VXLAN, free mobility, iPCA, NetStream, Telemetry, SVF, ECA, threat
S5731-H
intelligent GE switch deception, MPLS, IPv6, service port stacking, PoE+ (optional), extended cards,MACsec(8*10GE SFP+
subcard only)

S5731-S Programmable chips inside, VXLAN, free mobility, iPCA, NetStream, Telemetry, SVF, ECA, threat deception,
standard GE switch
IPv6, service port stacking, PoE+ (optional)

S5735-S Telemetry, sFlow, SVF (client), IPv6, RIP/RIPng, OSPF, BFD, BGP/BGP4+, IS-IS/IS-ISv6, intelligent upgrade, eMDI Pluggable
standard GE access switch
power modules (1+1 redundancy), airflow from the left, right, and front to the back, 10 kV surge protection, PoE (optional)

S5735-L Telemetry, sFlow, SVF (client), IPv6, RIP/RIPng, OSPF, intelligent upgrade, eMDI, terminal identification
simplified GE access switch
No fan or built-in fan (airflow from the left and front to the right), 10 kV surge protection, PoE (optional),,

Page 23 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5730 Series Switches

Free Cloud
Native AC MPLS VXLAN ECA iPCA NetStream BGP IS-IS BFD iStack RIP/OSPF
mobility mgmt.

S5732-H √ √ √ √ √ √ √ √ √ √ √ √ √

S5731-H √ √ √ √ √ √ √ √ √ √ √ √ √

S5731-S x x √ √ √ √ √ √ √ √ √ √ √

S5735-S x x x x x x x √ √ √ √ √ √

S5735-L x x x x x x x x x x √ √ √

Benchmarking Model

HW:S5732-H CISCO:C9300

HW:S5731-H CISCO:C9300

Page 24 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5732-H: GE/10GE Hybrid Switch

Programmable Memory: 4 GB
Console port 1.4 GHz quad-core CPU 6 x 40GE ports
chip Flash: 2 GB

ETH management port Four slots for pluggable fan Two slots for pluggable power modules (1+1
SSD card slot*
USB 2.0 port modules redundancy), supporting 600 W AC or 1000 W DC
power modules
*SSD card slot reserved

Page 25 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5732-H

Stack bandwidth: 480 Gbps 20/44 x GE optical ports, 4 x 10GE optical ports, and 6 x MAC address: 128K

40GE optical ports

Cloud
√ SVF √ VXLAN √ iPCA √ ECA √ NetStream √ MPLS √ Telemetry √ √ iStack
mgmt.

• SVF parent/client mode, simplifying deployment and


• Native AC, managing up to 1K APs
management

• Supports hybrid access of GE and 10GE optical ports, • Works with the CIS platform to implement ECA and threat
and provides abundant ports deception, achieving network-wide security collaboration

Page 26 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5732-H: Multi-GE Access Switch

Programmable 1.4 GHz quad-core Memory: 4 GB 2*100GE Ports


CPU
chip Flash: 2 GB 4*25GE + 2*40GE

Two slots for pluggable Two slots for pluggable power


USB 2.0 port One slot for an extended card
fan modules modules (1+1 redundancy)

Page 27 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5732-H(Multi-GE)

Stack bandwidth: 800 Gbps MAC address: 128K


24/48 x Multi-GE ports, 4 x 25GE optical ports + 2 x 40GE optical ports
or 2*100GE optical ports

Cloud
√ SVF √ VXLAN √ iPCA √ ECA √ NetStream √ MPLS √ Telemetry √ √ iStack
mgmt.

• SVF parent/client mode, simplifying deployment and


• Native AC, managing up to 1K APs
management

• Works with the CIS platform to implement ECA and threat


• PoE++,Supports a maximum of 48*10GE access
deception, achieving network-wide security collaboration

Page 28 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5732-H: Hybrid Optical-Electrical Switch
Hybrid optical-electrical cable + industry's first hybrid optical-electrical switch

Optical fiber + optical module

Cable + RJ45 Wi-Fi 6 AP


Hybrid optical-electrical switch
Data transmission rate Maximum transmission distance Network evolution

Category 5 cable
• 10GE optical fiber access, meeting Wi-Fi needs in the 1/2.5G 100 m (industry average) None
(CAT5E)
next 10 years
Category 6 cable
1/2.5/5G 100 m (industry average) None
(CAT6)

• Industry-unique 60 W power supply at a long Category 6 cable


1/2.5/5/10G 100 m (industry average) None
(CAT6A)
distance of 200 m*

Hybrid optical-
1G/10G 200 m Smooth upgrade
electrical cable

Application scenario: AP access distance is greater than 100 m, where power supply is difficult and cabling costs are high. Hybrid optical-electrical
cables are deployed once, while smoothly upgrading to 25G/40G/100G.

Page 29 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5731-H: Intelligent GE Switch

Programmable 1.4 GHz quad-core Memory: 4 GB 4 x 10GE Console port


CPU ETH management port
chip Flash: 1 GB ports

Two slots for pluggable Two slots for pluggable power


One slot for an extended card USB 2.0 port
fan modules modules (1+1 redundancy)

Page 30 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5731-H

Stack bandwidth: 240 Gbps 24/48 x GE electrical ports and 4 x 10GE optical ports MAC address: 288K

Extra uplink ports by using an extended card

Cloud
√ SVF √ VXLAN √ iPCA √ ECA √ NetStream √ MPLS √ Telemetry √ √ iStack
mgmt.

• SVF parent/client mode, simplifying deployment and


• Native AC, managing up to 1K APs
management

• Supports 512 MB buffer to meet services with bursty • Works with the CIS platform to implement ECA and threat
traffic deception, achieving network-wide security collaboration

Page 31 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5731-S: Standard GE Access Switch

Programmable 1.4 GHz quad-core Memory: 4 GB 4 x 10GE Console port


CPU ETH management port
chip Flash: 1 GB ports

Two slots for pluggable fan Two slots for pluggable power modules
USB 2.0 port
modules (1+1 redundancy)

Page 32 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5731-S

Stack bandwidth: 80 Gbps MAC address: 32K

24/48 x GE electrical ports and 4 x 10GE optical ports

Cloud
√ SVF √ VXLAN √ iPCA √ ECA √ NetStream √ BGP √ Telemetry √ √ iStack
mgmt.

• Supports 512 MB buffer to meet services with bursty


• Works as an SVF client, which is plug-and-play
traffic

• Comes with pluggable power modules and fan modules, • Works with the CIS platform to implement ECA and threat
supporting 1+1 redundancy deception, achieving network-wide security collaboration

Page 33 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5735-S: Standard GE Access Switch

Built-in ASIC 1.0 GHz quad-core Memory: 1 GB 4 x 10GE Console port


chip CPU Flash: 512 MB ports ETH management port

Two built-in fan modules, with airflow from the left,


right, and front to the back Two slots for pluggable power modules
USB 2.0 port
Note: For the switch model with 48 optical ports, (1+1 redundancy)
there are three built-in fan modules.

Page 34 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5735-S

Stack bandwidth: 80 Gbps MAC address: 16K


24/48 x GE optical or electrical ports and 4 x 10GE optical
ports
Note: The S5735-S32ST4X provides 24 x GE optical ports and 8 x GE electrical ports.

USB-based Cloud
√ SVF √ sFlow √ eMDI √ √ IS-IS/IS-ISv6 √ BGP √ Telemetry √ √ iStack
deployment mgmt

• Provides power module and fan module redundancy


• Works as an SVF client, which is plug-and-play
design, ensuring reliable device running

• Supports perpetual/Fast PoE, providing high-quality • Provides all-optical, all-electrical, and optical/electrical
power supply hybrid models to meet scenario-specific requirements

Page 35 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5735-S-I: Next-generation Extended-Temperature Switch

Built-in ASIC 1.0 GHz quad-core Memory: 1 GB 4 x 10GE Console port


Depth:420mm
chip CPU Flash: 512 MB ports ETH management port

Two built-in fan modules, with airflow from the left, Two slots for pluggable power modules
USB 2.0 port
right, and front to the back (1+1 redundancy)

Page 36 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5735-S-I(Extended-Temperature Switch)

Stack bandwidth: 80 Gbps MAC address: 16K


24 x GE electrical ports and 4 x 10GE optical ports

USB-based Cloud
√ SVF √ sFlow √ eMDI √ √ IS-IS/IS-ISv6 √ BGP √ Telemetry √ √ iStack
deployment mgmt

• Provides power module and fan module redundancy


• Works as an SVF client, which is plug-and-play
design, ensuring reliable device running

• 6 kV surge protection, -40°C to +70°C, applicable to harsh


• Exclusive eMDI for Intelligent Video Service Fault Diagnosis
environments

Page 37 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5735-S-IA: Next-generation Video Backhaul Switch

High reliability Easy deployment


• Operating temperature: –40°C to +55°C • Integrated design, requiring no internal
connections
• IP55, anti-salt spray, 6 kV surge protection
• Installation completed by a single person
• Natural heat dissipation without fans,
within 20 minutes, reducing onsite
maintenance-free for 5 years
Protective shell installation workload by 80%
Fiber splice
tray • 12 V DC, 24 V/220 V AC, and PoE

Surge AC/DC power


protector supply

High security Integrated Easy O&M


design
• Pan Tilt and Zoom (PTZ) dome camera linked Switch • IPC topology discovery and offline diagnosis*
PoE+
when an alarm is generated upon
• Industry-unique eMDI for intelligent diagnosis
unauthorized device opening SmartX of audio and video services
• IPC identification, preventing unauthorized
access or replacement

Page 38 Copyright © 2020 Huawei Technologies Co., Ltd.


Product Appearance of CloudEngine S5735-S-IA(Video Backhaul Switch)

2 x 10GE SFP+
CloudEngine S5735-S4T2X-IA150G1 4 x GE or 8 x GE (PoE) Console port
USB port
CloudEngine S5735-S8P2X-IA200G1 Ethernet management port

Access control sensor input/output

220 V AC input
12 V DC output

24 V AC output

Fiber
Circuit breaker management Access control sensor
(input/output) tray

Page 39 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5735-L: Simplified GE Access Switch

Built-in ASIC 1.0 GHz quad-core Memory: 1 GB 4 x GE or 10GE Console port


CPU ETH management port
chip Flash: 512 MB ports

Built-in AC power USB 2.0


module port

Note: The S5735-L48P4X-A has one built-in pluggable 1000 W AC power module.

Page 40 Copyright © 2020 Huawei Technologies Co., Ltd.


Main Features of CloudEngine S5735-L

12/24/48 x GE optical or electrical ports and 4 x GE or 10GE optical


Stack bandwidth: 80 Gbps MAC address: 16K
ports

Note: The S5735-L32ST4X provides 24 x GE optical ports and 8 x GE electrical ports.

USB-based Cloud
√ SVF √ sFlow √ eMDI √ √ RIP/RIPng √ OSPF √ Telemetry √ √ iStack
deployment mgmt.

• Supports intelligent port hibernation and intelligent


• Works as an SVF client, which is plug-and-play
fan speed adjustment, conserving energy

• Supports perpetual/Fast PoE, providing high-quality • Provides models with 12/24/48 x GE ports to meet
power supply scenario-specific requirements

Page 41 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine 5730 Series Switches – Extended Card(1/2)

Extended card slot

2 x 40GE QSFP+ card 8 x 10GE Base-T card

8 x 10GE SFP+ card 8 x 25GE SFP28 card

Note: supporting 2*25GE SFP28 mode

Page 42 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5730 Series Switches – Extended Card(2/2)

Model 2 x 40GE QSFP+ card 8*10GE Base-T card 8*10GE SFP+ card* 8*25GE SFP28 card**

S5732-H
√ √
Multi-GE Model

S5732-H
√ √
Hybrid Optical-Electrical Model

S5731-H √ √ √

*Note: The 8*10GE card supports 2*25GE SFP28 (ports 0 and 1) through mode switching, and all ports support MACsec.
**Note: The 8*25GE card supports 10GE/25GE auto-sensing, GE optical interfaces (CLI), and all ports support MACsec.

Page 43 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S6730/S5730 Series Switches – Power Module(1/2)

Power module slot 1 Power module slot 2

AC/DC power module PoE power module

60 W AC 150 W AC 600 W AC 1000 W DC 1000 W AC

AC input voltage 90 V AC to 264 V AC 90 V AC to 264 V AC 90 V AC to 290 V AC N/A 90 V AC to 290 V AC

AC input
47 Hz to 63 Hz 47 Hz to 63 Hz 45 Hz to 65 Hz N/A 45 Hz to 65 Hz
frequency
High-voltage DC
190 V DC to 290 V DC N/A 190 V DC to 290 V DC N/A 190 V DC to 290 V DC
voltage

DC input voltage N/A N/A N/A –38.4 V DC to –72 V DC N/A

Page 44 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S6730/S5730 Series Switches – Power Module(2/2)

Power S6730-H S6730-S S5732-H S5731-H S5731-S S5735-S S5735-S-I S5735-L


Module
Type 48 optical
All model All model Optical model Other PoE Model Other Model PoE Model Other Model PoE Model Other Model - 48 PoE Model
Model

60W AC √ √

150W AC √ √ √

600W AC √ √ √ √ √

1000W AC √ √ √ √ √

1000W DC √ √ √ √ √ √ √

Note: The table is for reference only. For the mapping between product models and power modules, see the latest brochure on the official website and the configurator SCT.

Page 45 Copyright © 2020 Huawei Technologies Co., Ltd.


Contents
• Campus LAN Trend

• CloudEngine S-series Switch Introduction

• CloudEngine S-series Switch Highlight

• CloudEngine S-series Switch Evolution

Page 46 Copyright © 2020 Huawei Technologies Co., Ltd.


Native AC: Implementing Wired and Wireless Network
Convergence
Traditional: standalone WAC, separate wired and wireless
Huawei: native AC, converged wired and wireless networks
networks

Unified control point for


Wired network Wired service flow Wired service flow
wired and Wi-Fi networks
control point
Wi-Fi network Wi-Fi service flow Wi-Fi service flow
control point

Forwarding
bottleneck
Core Core Native AC
WAC

• Independent service • Centralized service


forwarding forwarding
• Separated device • Converged device
management management
• Decentralized user policy • Unified user policy

Access Access

Wired Wi-Fi Wired Wi-Fi Wired Wi-Fi Wired Wi-Fi

Page 47 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S Series Switches Native AC Feature Description

S12700E S7703 S7706/7712 S6730-H S5732-H S5731-H


ITEM
MPUE MCUA MCUD SRUA SRUB SRUE SRUH* - - -

Native AC √ √ √ √ √ √ √ √ √ √

AP management
capacity 10K 512 1K 1K 1K 4K 4K 1K 1K 1K
(Total)
AP management
capacity 4K 512 1K 1K 1K 4K 4K - - -
(X-series LPU)

Note: The SRUH of the CloudEngine S7706/12 includes three models, SRUH, SRUHA1 and SRUHX1.

Page 48 Copyright © 2020 Huawei Technologies Co., Ltd.


VXLAN: 1-to-N Horizontal Virtualization, Achieving One Network for
Multiple Purposes

Physical topology Logical topology


• One network carries multiple services, instead of
dedicated networks for dedicated use.
• VXLAN tunnels are automatically established based on
BGP-EVPN.
• Collaboration with iMaster NCE achieves automatic
deployment of VNs.

Border

VN1 VN2 VN3


Office virtual Video conferencing virtual Security protection
VXLAN virtual network
network network

Edge Edge

Office Videoconfe Security Office Videoconfer Security Office Office Videoconferencing Videoconferencing Security Security protection
rencing protection encing protection protection

Page 49 Copyright © 2020 Huawei Technologies Co., Ltd.


VXLAN Centralized/Distributed Gateways: Flexible, On-Demand

Centralized gateway Distributed gateway

Border Border

VXLAN VXLAN

Edge A Edge B Edge A Edge B

Security protection Security Security protection Security


Office terminal Office Videoconfere Videoconfe Office terminal Office Videoconfere Videoconfe
terminal B protection terminal B ncing protection
A ncing rencing A rencing

The following uses office terminal A under Edge A as an example to describe the service forwarding mode during the communication with terminals or applications in the
VN, between VNs, and outside.

In Centralized VXLAN gateway mode, the Layer 3 gateway is deployed only on one device. All traffic sent across subnets is forwarded through the Layer 3 gateway,
implementing centralized traffic management.
In Distributed VXLAN gateway mode, Edge nodes function as VTEPs of VXLAN tunnels and can also function as Layer 3 VXLAN gateways. Border nodes are unaware of the
VXLAN tunnels and only forward VXLAN packets.

Page 50 Copyright © 2020 Huawei Technologies Co., Ltd.


VXLAN to the aggregation/access layer: meeting requirements in different
scenarios
VxLAN to the aggregation VxLAN to the access

Huawei Border Huawei Border

Huawei Huawei
or 3rd vendor or 3rd vendor

VxLAN
Edge A (BGP-EVPN) Edge B
VxLAN
(BGP-EVPN)

Access A Access B Edge A Edge B

Office PC IPC Conference TE Office PC Conference TE IPC Office PC IPC Conference TE Office PC Conference TE IPC

• Application scenario: network reconstruction and upgrade, supporting hybrid • Application scenario: applicable to new deployment or reconstruction scenarios and
deployment (access) of devices from different vendors; supports hybrid deployment of 3rd party devices
• Solution highlights: The existing access devices are reused to maximize the return • Solution Highlights: Reuse of Some Aggregation Devices, Protecting Investment on
on investment (ROI) of the live network the Live Network, and Network-wide Virtualization

Page 51 Copyright © 2020 Huawei Technologies Co., Ltd.


Free Mobility: User-Based Policy Control and Network-Wide Consistent
Experience
Define security groups Define network-wide policies based on users, applications, and experience

Group Group 5W1H (Who, When, Where, Network Service


Name ID Whose, How) Contextual Device To
Source Destination Application
Application Action Which Policies
Awareness Group Group Security
Are Delivered
Bandwidth Priority
VIP 30 Leader, wired and wireless,
anytime
Guest Internet BT X — 1M Pri: low Switch
Guest 10 Guest, wireless, working
hours…
Employee R&D — √ — 2M Pri: high Switch
Employee 20 Employees, wired/wireless...
Campus egress
VIP R&D All √ AV+URL+SPAM 4M Pri: high
NGFW
Server 57 Fixed IP address of the server
User Application Security Application Experience
identification management and security assurance
control
Jim

iMaster NCE
1. Define security groups and policies
8 Mbps
2. Automatically translate and
deliver policies Terry
Mark
3. Authenticate users 4. Match and enforce policies
2 Mbps
1 Mbps

Application Permission Bandwidth QoS


security Guest Employee VIP

Page 52 Copyright © 2020 Huawei Technologies Co., Ltd.


Scenario 1: Single Authentication Point and Centralized Policy
Control
Data center
Policy Execute Point

Authentication Point Security group Security group


Security group 5 definition policy matrix
(finance)
Security Group Group Policy (Permission)

Policy Group Name SG ID Extranet Finance Email R&D


Security group 6 Core delivery VIP 1 VIP √ √ √ √
(email)
R&D 2 R&D √ × √ √

Guest 3 Guest √ x x x

Security group 7 (R&D) Finance 5 Finance × √ √ ×

... ... ... ... ...

• Centralized authentication point and policy execute point are


Aggregation used on campus network.
• The authentication point and policy control point are the
same device.

Access R&D Data channel

VIP

Guest

Security group 2 Security group 1 Security group 3 Security group 2 Security group 3
(R&D) (VIP) (guest) (R&D) (guest)

Page 53 Copyright © 2020 Huawei Technologies Co., Ltd.


Scenario 2: Multiple Authentication Point and Centralized Policy
Control
Data center
Policy Execute Point Security group Security group
definition policy matrix
Authentication Point
Security group 5 Security Group Group Policy (Permission)
(finance) Group Name SG ID Extranet Finance Email R&D
Core Policy delivery VIP 1 VIP √ √ √ √

R&D 2 R&D √ × √ √
Security group 6
(email) Guest 3 Guest √ x x x
IP-Group Finance 5 Finance × √ √ ×
Synchronization ... ... ... ... ...
Security group 7 (R&D)

• The authentication points and policy execute point are


different devices.

Aggregation • The authentication points are responsible for user access


authentication. The policy execute point uses the IP-Group
synchronization function to obtain information about the
binding between users and security groups from iMaster NCE.

Access
R&D Data channel

VIP

Guest
Security group 2 Security group 1 Security group 3 Security group 2 Security group 3
(R&D) (VIP) (guest) (R&D) (guest)

Page 54 Copyright © 2020 Huawei Technologies Co., Ltd.


Scenario 3: Multiple VXLAN Gateways Implement Enhanced Free
Mobility
Data center
Policy Execute Point

Authentication Point Security group Security group


Security group 5 definition policy matrix
(finance)
Security Group Group Policy (Permission)

Group Name SG ID Extranet Finance Email R&D


Core Policy
Security group 6 VIP 1 VIP √ √ √ √
(email) delivery
R&D 2 R&D √ × √ √

Guest 3 Guest √ x x x

Security group 7 (R&D) Finance 5 Finance × √ √ ×

VXLAN ... ... ... ... ...

• Free mobility across authentication points.


Aggregation
• VXLAN is used in the campus network.
• The source security group information is carried in the
VXLAN packet header.

Access R&D Data channel

VIP
VXLAN tunnel
Sales

Security group 2 Security group 1 Security group 3 Security group 2 Security group 3
(R&D) (VIP) (guest) (R&D) (guest)

Page 55 Copyright © 2020 Huawei Technologies Co., Ltd.


Scenario 4: Traditional Campus Network Implement Enhanced Free Mobility

Data center
Policy Execute Point Security group Security group
definition policy matrix
Authentication Point
Security Group Group Policy (Permission)
Security group 5
(finance) Group Name SG ID Extranet Finance Email R&D
VIP 1 VIP √ √ √ √

R&D 2 R&D √ × √ √
Security group 6 Core
Guest 3 Guest √ x x x
(email)
Finance 5 Finance × √ √ ×

... ... ... ... ...


Security group 7 (R&D)
IP-Group
• Free mobility across authentication points.
Synchronization
• No VXLAN in the campus network.
Aggregation( • The policy execute point uses the IP-Group
Gateway) synchronization function to obtain information about the
binding between users and security groups from iMaster
NCE.

Access R&D Data channel

VIP

Sales

Security group 2 Security group 1 Security group 3 Security group 2 Security group 3
(R&D) (VIP) (guest) (R&D) (guest)

Page 56 Copyright © 2020 Huawei Technologies Co., Ltd.


iStack: N-to-1 Horizontal Virtualization Simplifies Device Configuration and
Management
Physical topology Logical topology
• Multiple devices are virtualized into one
device, greatly simplifying network
configuration and device management.

Eth-Trunk • Eth-Trunk uplink aggregation and load


Eth-Trunk
balancing improve uplink reliability.
iStack
iStack
• Service port stacking is supported,
removing the need to use dedicated
stack ports or stack cards. This allows for
flexible and convenient networking.

Page 57 Copyright © 2020 Huawei Technologies Co., Ltd.


With iStack, Nine Switches Become "One Switch"
The following figure shows the switch stack connections. CloudEngine S5700 series switches are widely used on aggregation or access
layers of large- and medium-sized campus networks. Enabling iStack can greatly
Logical stack port 1
simplify network configuration and management, and improve network
robustness.
Logical stack port 2
• A single iStack system supports a maximum of nine switches.

• Only switches of the same series can set up a stack.


Stack
• A single switch supports a maximum of two logical stack ports, and each

cable

logical stack port supports one or more physical ports of the same type.

• High-speed cables, AOC cables, optical fibers+optical modules, and dedicated


Logical stack port 1
stack cables can be used as stack cables. In particular, dedicated stack cables
support plug-and-play and do not require service configuration.
Logical stack port 2
For details about the stack cable type, see the CloudEngine S5730 Series
Switches Stack Cables.

Page 58 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S5730 Series Switches – Stack Cables

Type 1: high-speed cable Type 2: AOC cable


SFP/SFP+ high-speed cable QSFP+/QSFP28 high-speed cable SFP/SFP+ AOC cable QSFP+/QSFP28 AOC cable

• Used for GE or 10GE optical port stacking • Used for 40GE or 100GE optical port stacking • Used for GE or 10GE optical port stacking • Used for 40GE or 100GE optical port stacking

• Four types: 1 m, 3 m, 5 m, 10 m • Three types: 1 m, 3 m, 5 m • Two types: 3 m, 10 m • One type: 10 m

Type 3: fiber patch cord + optical module Type 4: dedicated stack cable
Fiber patch cord Optical module Dedicated stack cable
1. Used for GE or 10GE optical port stacking

+ 2. Device stacking without extra configuration, plug-and-play

3. Used on CloudEngine S5731-H/S series switches

SFP SFP+ QSFP+ QSFP28


0.5 m or 1.5 m

Note: For details about the stack cables used with specific product models, see the Switch Stack Specifications.xlsx.

Page 59 Copyright © 2020 Huawei Technologies Co., Ltd.


CSS, providing higher bandwidth and simplified O&M
Traditional: Huawei:
Route redundancy and link 1:1 protection Cluster Switch System,Link 1+1 aggregation

Physical Top Logical Top Physical Top Logical Top


Main advantages
• Two core devices are virtualized into

VRRP VRRP CSS


one device based on the CSS cluster,
reducing the number of managed
NEs by 50%.
STP STP Eth-Trunk Eth-Trunk
• Aggregation devices implement
uplink link aggregation based on
Eth-Trunks, increasing bandwidth by
100%

48*1GE 48*1GE 48*1GE 48*1GE

Note: The CloudEngine S12700E supports CSS based on service ports, and the S7706 and S77012 support CSS based on service ports or stack cards to ensure reliability of
core nodes and simplify device management.

Page 60 Copyright © 2020 Huawei Technologies Co., Ltd.


SVF: Vertical Virtualization Simplifies Deployment and Management of the
Entire Network
Traditional: Devices on the core, aggregation, and access layers are
Huawei: SVF manages the entire network as one network element (NE)
configured and managed separately.
• Access, aggregation, and core
devices are independently managed • One virtual NE on the entire
Managing Virtually
NEs. network
NEs managing NEs
• Each NE is independently configured
• Two layers of SVF clients (ASs)
and managed, which is complex and
• Plug-and-play of SVF clients,
involves heavy workload.
without extra configuration
Note: iStack on core nodes

iStack

Core Core SVF system Parent

Aggregation Client
Aggregation (AS1)

Client
Access Access
(AS2)

Note: The SVF system consists of the parent and clients. The parent manages all clients (ASs) connected to the SVF system. AS is the abbreviation of the access switch connected to the
parent. In an SVF system, AS is an SVF client.

Page 61 Copyright © 2020 Huawei Technologies Co., Ltd.


Device Roles in an SVF System and Related Specifications

Attribute S12700E S7700 S6730-H S6730-S S5732-H S5731-H S5731-S S5735-S S5735-L

SVF parent √ √ √ √ √ √ - - -

Number of layers of
ASs supported
2 2 2 2 2 2 - - -

Maximum number of
ASs supported
256 256 32 32 32 32 - - -

AS supporting stacking √ √ √ √ √ √ - - -

Number of stack
members in one AS
5 5 5 5 5 5 - - -

SVF client - - - √ √ √ √ √ √

Note: The S6730-S,S5732-H and S5731-H switches that use programmable chips can work as the SVF parent and client. You can flexibly configure them.

Page 62 Copyright © 2020 Huawei Technologies Co., Ltd.


Hardware-Based OAM/BFD: Rectifying Network-Level Faults in Milliseconds

Hardware-based OAM/BFD, implementing link fault detection and switchover in milliseconds

• OAM involves various link fault detection technologies, such as CFM


Normal link
(IEEE 802.1ag), EFM, and Y.1731 (ITU-T).
Link switchover (after a link fault occurs)
• BFD is a bidirectional link detection technology and can be associated

Interruption with static routes, RIP, OSPF, IS-IS, and BGP.

RIP/OSPF/IS-IS

Single-hop Multi-hop Single-hop Single-hop


detection detection detection detection

Multi-hop
detection

• Hardware-Based OAM/BFD provides 3.3 ms detection interval. • Upon a network-level fault, a switchover can be completed within 50
It helps quickly detect the link status. ms, with user services not affected.

Page 63 Copyright © 2020 Huawei Technologies Co., Ltd.


eMDI: Implementing Intelligent O&M of Audio/Video Services

Innovative eMDI detects and locates audio/video service faults in real time
CampusInsight
KPI collection flow

Video service flow Specifies the IPC to be detected

Packet loss rate: 11%


0% 0% 0%
9 8 7 6 5 3 2 1
IPC1 9 8 7 6 5 3 2 1
9 8 7 6 5 4 3 2 1 9 8 7 6 5 4 3 2 1

9 8 7 6 5 3 2 1
IPC2 VCN

KPI collection scope and KPI-assisted locating scope

Dimension RTP MDI eMDI


Protocol and standard RFC3350 RFC4445 Standards being extended, at the draft phase
Measures the application-layer Measures the packet loss rate, out-of-order packet rate, delay, and
Measures the packet loss rate at the TS layer of
Detection method packet loss rate of video jitter at the application layer of audio/video services. FEC/RET is
video services. FEC/RET is not supported.
services. supported.
Monitoring interval 1s 1s 1/10/30/60 seconds
Service flow Unicast/Multicast Multicast Unicast/Multicast
Medium, due to the need of high device
Deployment restrictions Low Low (supported by all industry models)
performance

Page 64 Copyright © 2020 Huawei Technologies Co., Ltd.


ECA: Encrypted Threat Awareness and Handling

Traditional: single-point defense through border security devices Huawei: network-wide defense by using security device + security probe

• Firewalls are used to isolate • Firewalls are used to isolate Basic principles of ECA
• The security probe extracts the features of
external network threats. external network threats. encrypted traffic and reports them to the CIS in
• The lateral movement of • Security probes inside access metadata.
internal threats is neither devices isolate terminal threats, • The CIS compares the features with the signature
database, identifies malicious traffic, and notifies
perceived nor addressed. preventing them from lateral iMaster-NCE of the result.
movement. • iMaster-NCE delivers the traffic policy to the
security probe to block or permit the traffic.
iStack iStack
iMaster-NCE CIS iMaster-NCE
platform

Security probe Security probe

Note: All models of fixed switches using programmable chips can collaborate with the CIS platform to implement security defense functions, such as ECA, threat deception,
and traffic anomaly detection.

Page 65 Copyright © 2020 Huawei Technologies Co., Ltd.


MACsec: Providing Secure Transmission of Layer 2 Data

Network-wide secure transmission of Layer 2 packets MACsec: Layer 2 data encryption technology

Media Access Control Security (MACsec) defines a method for secure data
communication over an IEEE 802 LAN. MACsec ensures data transmission

Routing/MPLS IPsec security by encrypting data transmitted between hop-by-hop devices. The
WAN protocol is 802.1AE.

Data source
Data frame
MACsec authenticity
integrity check
LAN verification
User data Replay
MACsec protection
encryption

Note: MACsec is enabled on the uplink ports (fixed ports or ports of cards) of access switches
Area A Area B Area C
and ports of aggregation devices, and on the uplink ports of aggregation devices and ports
of core devices to provide end-to-end secure transmission channels.

Page 66 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S Series Switches MACsec Feature Description

S12700E S7700 S5732-H(Multi-GE and Hybrid models) S5731-H


ITEM
6*100GE 24*100GE 40*25GE 6*100GE 4*25GE 2*40GE 2*100GE 8*10GE SFP+ 8*25GE SFP28 8*10GE SFP+

MACsec √ √ √ √ √ √ √ √ √ √

Encryption
Technology MACsec-256 MACsec-256 MACsec-256 MACsec-256 MACsec-256 MACsec-256 MACsec-256 MACsec-256 MACsec-256 MACsec-256

Interface card
Remark Interface card Interface card Interface card Uplink Port Extended card Extended card
(0~5 port)

Page 67 Copyright © 2020 Huawei Technologies Co., Ltd.


HQoS, Fine-grained User/Service Management

Flow queue User queue Class queue Port queue


HQoS scheduling
Voice, data, video… Common user, VIP… Voice, data, video… Physical port…
(single user) (all users)
Class
Service

Port
User

Traditional QoS HQoS


• Per port bandwidth control: service traffic is differentiated based on • Hierarchical per-user-per-service scheduling, quality guarantee
classes of service but not users for VIP users and high-priority services
• Unable to manage and schedule multiple services of multiple users • High performance, 64K queues

Page 68 Copyright © 2020 Huawei Technologies Co., Ltd.


Contents
• Campus LAN Trend

• CloudEngine S-series Switch Introduction

• CloudEngine S-series Switch Highlight

• CloudEngine S-series Switch Evolution

Page 69 Copyright © 2020 Huawei Technologies Co., Ltd.


CloudEngine S-series Switch Evolution Path

S12704/08/12 CloudEngine S12700E-4/8/12 X5/X6


Modular
S7703/06/12 S7700 MCU:MCUD/SRUHX1 X5/X6

S6720-HI/EI CloudEngine S6730-H

Fixed
S6720-SI CloudEngine S6730-S
(10GE)
S6720-LI CloudEngine S5732-H(Multi-GE)

S5730-HI CloudEngine S5732-H

S5720-HI/EI CloudEngine S5731-H

S5730-SI CloudEngine S5731-S


Fixed
(GE) S5720-SI CloudEngine S5735-S

S5720I-SI
CloudEngine S5735-S-IA
Video Backhaul Switch

S5720I-SI
CloudEngine S5735-S-I(24 Port)
Extended-Temperature Switch

S5720-LI CloudEngine S5735-L

Page 70 Copyright © 2020 Huawei Technologies Co., Ltd.


Thank You
www.huawei.com

Page 71 Copyright © 2020 Huawei Technologies Co., Ltd.

You might also like