Professional Documents
Culture Documents
Huawei Office Network Solution Overview
Huawei Office Network Solution Overview
Page 0 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1. Know More About Huawei
Page 1 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Know More About Huawei
Huawei: Leading Provider of ICT infrastructure and Smart Devices
Page 2 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Know More About Huawei
Focusing on ICT to provide products, solutions, and services to three customer groups
Page 3 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Know More About Huawei
Build connectivity for Indonesia: 13 region offices, 5 logistics centers
Page 4 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1. Know More About Huawei
Page 5 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Wireless, IoT, and Cloudification Drive Campus Network Transformation
employee terminals per 100 m2 increase from transformed to support 14,300 IoT terminals, 14 smart based, posing higher requirements on network
40 to 80, driving demand for higher wired applications, 306 smart classrooms, and more. quality and latency.
access bandwidth.
Building a high-quality campus network with higher bandwidth, better experience, and higher efficiency
Huawei CloudCampus 3.0 Solution: Building a High-Quality Campus Network for the
Digital Era
Digitalization transforms enterprises
Management, control,
NETCONF/YANG and analysis Telemetry High-quality network for the digital era
Network layer
Full-10GE access, unleashing digital productivity
• Multi-GE switch + high-density 10GE/25GE fixed switch + 100GE core, building a simplified, ultra-broadband network
• Wired and wireless convergence (managing up to 10K APs and supporting 50K concurrent users), preferential service assurance for VIPs
• Network-wide automated deployment, plug-and-play devices, and precise insight into network-wide link quality
CloudEngine S-series campus switches
AirEngine Wi-Fi 6/6E AirEngine Wi-Fi 6 powered by Huawei 5G, building a fully wireless campus network
Lightning-fast speed More stable coverage More stable application More stable roaming
Industry's only dual-band 16 Smart antenna: always-on signals Dynamic Turbo: Lossless roaming:
smart antennas: 10.75 Gbps, 2x for users, 20% greater coverage application acceleration, < zero packet loss
the industry average range 10 ms latency during roaming
7 Huawei Confidential
Innovative Simplified Architecture: Easier Campus Network Planning and Deployment,
Simpler Network Construction
As Is: traditional solution To Be: Huawei solution
Many configuration and management nodes, "planning first and then RUs are planning-free and configuration-free. They can be deployed or
deployment", high O&M costs replaced on demand and flexibly scaled.
Architecture
revolution
Core Core
Aggregation 3 layers → 2
layers
Central Central
switch Access switch
Access
8 Huawei Confidential
Innovative RTU, Building a "Pay-as-You-Grow" Campus Network
+ =
Elastic architecture Various RTU licenses On-demand target network
RTU is short for right-to-use. RTU licenses can be used to improve the port rates and switching capacity of switches.
9 Huawei Confidential
Free Mobility 3.0: Fine-Grained Policy Control, Automated Deployment, Consistent
Experience
Free mobility 3.0 Group Group ID Contextual Awareness (5W1H: Who, When, Where,
Name Whose, How)
Free Mobility 2.0 • IP-security group entry VIP 30 Leader, wired and wireless, anytime
synchronization
Guest 10 Guest, wireless, working hours…
Free Mobility 1.0 • VXLAN networking, with
packet header carrying user
Enhanced
10 Huawei Confidential
Intelligent O&M: Terminal Visibility, Fault Diagnosis and Analytics
Technical Solution
Initiate an NQA
ICMP test on
As-Is To-Be CampusInsight CampusInsight.
AAA DHCP
Step 2
Application quality analysis VoIP failure, poor quality, disconnection, and Layer 2
and path trace loop
AS-F15 AGS-F53 CS-F5 FW-F5
Port anomaly, optical module failure, PoE failure,
sudden traffic increase or decrease, packet loss during
Device fault analysis
forwarding, queue congestion, and threshold-cross
services
11 Huawei Confidential
CloudEngine S-Series Switch Portfolio (1/2)
Modular switches 25GE fixed switches
New S6730-H-V2
• 3.6 Tbps per slot • 2.4 Tbps per slot
(March 2023) 48 x 25GE, 6 x 100GE
• 50K users, 100K terminals • 10K APs, 50K users
VXLAN
• Clos orthogonal architecture • MACsec on 10GE, 25GE,
40GE, and 100GE ports
S16700-4/8
S12700E-4/8/12 S6730-H
24*100GE 6*100GE 48*10GE 24*10GE + 24*GE 2*100GE + 4*40GE
28 x 25GE, 4 x 100GE, 220 mm
36*100GE 18*100GE 24/36*40GE 48*10GE
VXLAN, MACsec
24*Multi-GE +
40*25GE 12*40GE 48*GE
24*GE
S5732-H-V2 S5732-H
24/48 x 2.5/5/10GE, 4 x 25GE + 2 x 100GE 24/48 x 1/ 2.5/5/10GE, 4 x 25GE + 2 x 100GE
90 W PoE++, supporting RTU licenses 60 W PoE++, supporting RTU licenses
Enhanced GE switches
13 Huawei Confidential
Contents
1. Know More About Huawei
Page 14 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
A Leader in the 2022 Gartner Magic Quadrant
Named a Leader
Steady rise in the past 11 years
The only non-North American vendor
Huawei strengths
• Comprehensive product portfolio: Huawei has a comprehensive
wired and wireless product portfolio. This allows it to address all
customer use cases and price competitively compared to most of its
competitors.
• AI- and ML-enabled network management platform: The iMaster
NCE-Campus network management platform provides AI-driven Wi-Fi,
wired, and WAN network assurance services, and user policy
orchestration, plus the ability to simulate, test and verify network
planning.
• Wireless-first support: Huawei is focused on supporting firms that are
adopting a "wireless-first" strategy. A focus on integrated features that
support ease of management and high levels of end-user experience.
• Simplified architecture: Innovative "central switch + remote unit (RU)"
architecture, as well as optical-electrical PoE at an ultra-long distance of
300 m greatly reduces cabling costs and energy consumption.
Magic Quadrant™ for Enterprise Wired and Wireless LAN Infrastructure Gartner MQ report
Common WLAN Issues Deteriorating User Experiences
network bandwidth.
Planning Construction O&M Optimization
AirEngine Wi-Fi 6
Leader AP Solution
GE/2.5GE/10GE
GE or 10GE uplink AC6508
Specification: 512 APs, 4K users
AC6805
Specification: 6K APs, 64K users
GE/2.5GE/10GE
uplink
GE or 10GE GE/2.5GE/10GE
Cloud Managed Solution
uplink Specification: 400K APs, 2000K users
Mesh Solution
Planning Construction O&M Optimization
Supported functions
• Crowd flow heatmap, walking
Network layer path, interference source
positioning, and location query
CampusInsight spectrum analysis monitors the status of all channels on APs and displays the usage of each
channel, which is simple and easy to understand.
Constant-frequency device
Frequency scanning device Frequency hopping device
(2.4G wireless video and audio,
(Microwave oven, Bluetooth, (Cordless phone and cordless
5G wireless video and audio, baby
and game controller) phone base)
monitor, and ZigBee device)
Flagship Indoor Wi-Fi AP: AirEngine 8760-X1-PRO
16 spatial streams + flexible
Industry's highest: two 10G uplink ports
radio mode switchover
16 spatial streams
Ultra-high capacity
AirEngine 8760-X1-PRO
Independent hardware +
dual-band scanning
Real-time network optimization Liquid cooling Bionic shark fin cooling
* Works with CampusInsight to perform big data optimization.
Switchable 5 GHz-2
Real-time network
AirEngine 6760-X1 AP rate: 8.35 Gbps AP rate: 10.75 Gbps Flexible switchover
status awareness
AirEngine 6760-X1E Built-in IoT ZigBee, RFID, asset Hardware encryption: IPsec and DTLS
Security
module management, and ESL WPA3
* Right To Use (RTU): The number of spatial streams and functions are added through licenses.
Indoor Triple Radios Wi-Fi 6 AP: AirEngine 6761-21T
Radio 1 Radio 2
Radio 3
Power
21.2 W (excluding USB) USB 1
consumption
Power DC: 12 V ± 10% IoT
AirEngine 6761-21T supply PoE+ power supply expansion
USB extended external IoT
Indoor Mid-Range Wi-Fi 6 AP: AirEngine 5761-21
Module CPE
Power
17.9 W (excluding USB) USB 1
consumption
AirEngine 5761-21 DC: 12 V ± 10%
Power supply IoT expansion USB extended external IoT
PoE+ power supply
WLAN Product Portfolio
Wi-Fi 6 (802.11ax) indoor AP Wi-Fi 6 (802.11ax) outdoor AP WAC
NEW AirEngine 8760R-X1 AirEngine 8760R-X1E
23/03 Wi-Fi 6E • Device rate: 10.75 Gbps • Device rate: 10.75 Gbps
• NSS: 8+8/4+12 • NSS: 8+8/4+4+4
• Built-in smart antennas • External antennas
• BLE 5.2, PoE out • BLE 5.2, PoE out
AirEngine 8760-X1-PRO AirEngine 8761-X1 AirEngine 6760-X1 AirEngine 6760-X1E AirEngine 6761-22T* • 1 x 10GE electrical + 1 x GE • 1 x 10GE electrical + 1 x GE
• Device rate: 10.75 Gbps • Device rate: 5.95 Gbps • Device rate: 10.75 Gbps • Device rate: 10.75 Gbps • Device rate: 6.575 Gbps electrical port + 1 x 10GE SFP+ electrical + 1 x 10GE SFP+
• NSS: 4+12/4+8+4 • NSS: 4+8 • NSS: 4+6/4+8/4+4+4 • NSS: 4+6/4+8/4+4+4 • NSS: 2+2+4 (6 GHz)
• Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • External antennas • Built-in smart antennas
• BLE 5.2, two built-in IoT slots • BLE 5.2, USB for IoT module • BLE 5.2, two built-in IoT slots • BLE 5.2, two built-in IoT slots • BLE 5.2 AC6805
• 2 x 10GE electrical + 1 x 10GE • 1 x 10GE electrical + 1 x GE • 1 x 10GE electrical + 1 x GE electrical • 1 x 10GE electrical + 1 x GE • 1 x 2.5GE electrical port, 1 x GE AirEngine 6760R-51 AirEngine 6760R-51E
• Device rate: 5.95 Gbps • Device rate: 5.95 Gbps
• Forwarding performance: 120 Gbps
SFP+ electrical + 1 x 10GE SFP+ electrical + 1 x 10GE SFP+ electrical port
Dynamic-Zoom • NSS: 4+4 • NSS: 4+4 • Maximum number of manageable APs: 6K
Smart Antennas • Built-in smart antennas • External antennas • Maximum number of access users: 64K
• BLE 5.2 • BLE 5.2
Hybrid Optical-
• 1 x 5GE electrical port + 1 x GE • 1 x 5GE electrical + 1 x GE
Electrical
electrical port + 1 x 10GE SFP+ electrical + 1 x 10GE SFP+
AirEngine 6761-21 AirEngine 6761-21E AirEngine 6761-21T AirEngine 5760-51
• Device rate: 3.55 Gbps • Device rate: 3.55 Gbps • Device rate: 6.575 Gbps • Device rate: 5.95 Gbps
Specification upgrade
• NSS: 4+4 • NSS: 4+4 • NSS: 2+2+4 • NSS: 2+4/4+4/2+2+4 AirEngine 5761R-11 AirEngine 5761R-11E
• Built-in Dynamic-Zoom • External antennas • Built-in smart antennas • Built-in smart antennas • Device rate: 1.775 Gbps • Device rate: 2.4 Gbps
Smart Antennas • BLE 5.2 • BLE 5.2 • BLE 5.2, two built-in IoT slots • NSS: 2+2 • NSS: 2+2
• BLE 5.2 • 1 x 2.5GE electrical port, 1 x • 1 x 2.5GE electrical port, 1 x • 1 x 5GE electrical port + 1 x GE • Built-in antennas • External antennas
• 1 x 2.5GE electrical port, 1 10GE SFP+ GE electrical port electrical • BLE 5.2 • BLE 5.2
x 10GE SFP+ NEW • 1 x GE electrical + 1 x SFP • 1 x GE electrical + 1 x SFP
23/03
AirEngine 9700-M1
• Forwarding performance: 120 Gbps
Wi-Fi 6 (802.11ax) scenario-specific AP • Maximum number of manageable APs: 3K
AirEngine 5761-21 AirEngine 5761-11 AirEngine 5762-12 AirEngine 5761-12 AirEngine 5762-10
• Device rate: 5.375 Gbps • Device rate: 1.775 Gbps • Device rate: 2.975 Gbps • Device rate: 1.775 Gbps • Device rate: 2.975 Gbps • Maximum number of access users: 32K
• NSS: 2+4 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2
• Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas
• BLE 5.2 • BLE 5.2 • BLE 5.2 • BLE 5.2, built-in dual IoT slots • 1 x GE electrical
• 1 x 2.5GE electrical port, 1 x • 1 x GE electrical • 1 x GE electrical • 2 x GE electrical AirEngine 6760-51EI
GE electrical port • Device rate: 4.8 Gbps
• NSS: 4
Wi-Fi 6 (802.11ax) wall plate AP • External antennas
NEW • 1 x 5GE electrical + 1 x GE electrical +
Port upgrade
23/03 1 x 10GE SFP+
Hybrid Optical-
Electrical AC6508
AirEngine 5761-11W AirEngine 5761-12W AirEngine 5762-12SW * AirEngine 5762-13W AirEngine 5762-15HW AirEngine 5762-17W • Forwarding performance: 10 Gbps
• Device rate: 1.775 Gbps • Device rate: 1.775 Gbps • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps • Maximum number of managed APs: 512
Wi-Fi 6 CPE UNR032H with vertical Wi-Fi 6 CPE UNR033H with
• NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 network ports horizontal network ports • Maximum number of access users: 4K
• Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps
• BLE 5.2 • BLE 5.2, PoE out • BLE 5.0 • BLE 5.0 • BLE 5.1 • BLE 5.1
• NSS: 2+2 • NSS: 2+2
• Uplink: 1 x GE electrical • Uplink: 1 x GE electrical • Uplink: 1 x GE electrical • Uplink: 1 x GE electrical • Uplink: 1 x 2.5G SFP • Uplink: 1 x GE electrical
• External antennas • External antennas
• Downlink: 4 x GE • Downlink: 4 x GE • Downlink: 1 x GE electrical • Downlink: 1 x GE electrical • Downlink: 4 x GE electrical • Downlink: 1 x GE electrical
electrical + 2 x RJ45 electrical + 2 x RJ45 (Optional colorful cover) • 4 x GE electrical • 4 x GE electrical
passthrough passthrough
Contents
1. Know More About Huawei
Page 26 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Huawei Is the Only Challenger in the Gartner® Magic QuadrantTM for SD-WAN
• Huawei SD-WAN has been listed as the only challenger in the Gartner® Magic QuadrantTM for five consecutive years
• The only Chinese vendor in the Gartner® Magic QuadrantTM.、
• Huawei continues to rank No. 1 in China in terms of the SD-WAN market share.
2022
Gartner® Magic Quadrant™
For SD-WAN
Gartner, Magic Quadrant for SD-WAN, Sept. 2022. This report was named Magic Quadrant for WAN Edge Infrastructure from 2018 to 2021.
Gartner Peer Insights, https://www.gartner.com/reviews/market/sd-wan/vendor/huawei/product/huawei-sd-wan
Gartner, Magic Quadrant, and Peer Insights are registered trademarks and service mark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users
based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise
technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all
warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
27 Huawei Confidential
Digital Transformation: Huawei SD-WAN Helps Improve Production Efficiency in Various Industries
Finance
Finance Large enterprise Retail store Energy
Financial services onto the cloud Remote office Retail 4.0 Digital gas station
28 Huawei Confidential
Challenges to Multi-Branch Services in the Cloud Era
29 Huawei Confidential
Simplified SD-WAN: Converged Deployment of LAN, WAN, and Security, Building Branch Networks
with Ultimate Experience
Integrated management, control, and analysis,
intelligent O&M
Network-wide automation | AI-
• LAN/WAN convergence, unified policy orchestration
powered intelligent O&M
• Batch site configuration, creating 1000 sites in a day
30 Huawei Confidential
Batch Flexible Application
Security O&M
Deployment Networking Optimization
Site replication
31 Huawei Confidential
Batch Flexible Application
Security O&M
Deployment Networking Optimization
(management channel)
Layer 2 switching, Layer 3 routing, and VPN isolation — to
achieve on-demand, flexible, and automatic connections RR
NETCONF
between enterprise branches, DCs, and the cloud, under the
management of iMaster NCE.
⚫ Huawei SD-WAN Solution uses the following channels to
MPLS
implement flexible networking:
Management channel
HQ/DC site GRE or GRE over IPsec (data channel) Branch site
Control channel
Edge Edge
Data channel Internet
32 Huawei Confidential
Batch Flexible Application
Security O&M
Deployment Networking Optimization
SLA non-
compliance
Internet
Selecting the optimal link for
Key applications, such as key applications
video and ERP
33 Huawei Confidential
Batch Flexible Application
Security O&M
Deployment Networking Optimization
34 Huawei Confidential
Batch Flexible Application
Security O&M
Deployment Networking Optimization
Traditional: Artifacts appear on the video when the packet loss rate is A-FEC: No frame freezing occurs in case of 30% packet loss.
higher than 2%.
Note: A-FEC is supported in Huawei SD-WAN Solution.
35 Huawei Confidential
Batch Flexible Application
Security O&M
Deployment Networking Optimization
Security Overview
⚫ The emergence of SD-WAN brings the
transformation of enterprise WAN architecture,
from a closed one to an open one, enlarging the
attack surface and bringing new security iMaster NCE
security
challenges, such as unauthorized access, data
(management channel)
hardening 1
breach, and network attacks. 1 Management RR
NETCONF
channel security
⚫ Huawei SD-WAN Solution provides high security
Control 1
from the following perspectives: channel
security
System security: component security and inter- 1 CPE security
component security hardening
MPLS
Service security: firewall, antivirus, intrusion
GRE or GRE over IPsec (data channel)
prevention system (IPS), and URL filtering HQ/DC site Branch site
1
2 Data
Edge Service traffic channel Edge
Internet
security security
36 Huawei Confidential
Batch Flexible Application
Security O&M
Deployment Networking Optimization
SD-WAN O&M
Quickly obtain abnormal Quickly locate faulty devices Optimize WAN investment and
traffic or sites configuration policies
37 Huawei Confidential
Portfolio of Huawei NetEngine AR Routers
HQ/Large branches NetEngine AR6300
NetEngine AR8140 NetEngine AR6280 5G-RU-101 5G-SIC
NetEngine
AR6300/AR6200
series
SRU-400H/SRU-600H SRU-400H/SRU-600H
Small- and medium-sized
enterprise branches
NetEngine AR6121E NetEngine AR6140E-9G-2AC NetEngine AR6710-L50T2X4 NetEngine AR6710-L26T2X4
NetEngine AR6100
series
Small enterprises
AR651 AR651W AR657W AR651W-8P
NetEngine AR650
series
Available only outside China
SOHO
NetEngine AR617VW-LTE4EA
AR611W AR617VW-LTE4
AR610 series
Available only Available only in Latin
outside China America
38 Huawei Confidential
Contents
1. Know More About Huawei
Page 39 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Entered the Gartner Magic Quadrant Ten Consecutive Times (2013-2022) and
Named a Challenger Six Consecutive Times (2017-2022)
40 Huawei Confidential
New Challenges Facing Firewalls
Difficult identification of
Service performance bottleneck Slow manual handling
unknown threats
Digital transformation drives interconnection Ever-changing unknown threats are highly It takes several hours to handle security
as well as the explosive growth of data, making difficult to identify, only 60% of which can be issues manually due to massive security
the service processing performance of accurately detected by traditional NGFWs. policies and logs.
firewalls become a bottleneck.
⚫ Growing popularity of all-optical networks and ⚫ Growing known threats ⚫ Analysis of massive security policies and logs
exponentially increased network traffic ⚫ Rapidly changed unknown threats ⚫ Time-consuming closed-loop threat handling
⚫ Higher demands on performance and latency ⚫ Ever-emerging encrypted attacks ⚫ Requirement for unified management
caused by the ever-increasing security service during interworking with other network
requirements products and security products
⚫ IPv6 network reconstruction
41 Huawei Confidential
ASE Dynamically Allocating Resources to Service Modules,
Maximizing Resource Utilization
As-Is To-Be
• Resources are dynamically allocated to service • The Adaptive Security Engine (ASE) is used to
modules in advance. The resources are occupied and dynamically allocate CPU resources to service
cannot be dynamically optimized. The functions of modules, maximizing resource utilization. In addition,
each module must be delivered as a whole. component-based function delivery is available.
• The traditional mechanism allocates CPU • Flexible resource scheduling: ASE can
Memory pre-allocation Dynamic memory
for IPS
resources to each function module in advance. allocation for IPS
dynamically schedule processes based on
Memory pre-allocation
Memory resources are still reserved for function Dynamic memory CPU resources and service traffic to
for AV modules even if the function is disabled. When allocation for AV decouple content security services and
Memory pre-allocation for the function requires more resources, the memory Dynamic memory maximize resource utilization.
anti-DDoS cannot be dynamically allocated. allocation for anti-DDoS • Component-based delivery (R22.0):
Memory pre-allocation for • Component-based delivery is not available. Memory pre-allocation independent compilation, release,
policy functions for policy functions
Compilation, release, and restart must be deployment, restart, and upgrade.
Idle resources performed as a whole. Idle resources
42 Huawei Confidential
NP-based Acceleration of Data Service Offloading and 10
μs-Level Low-Latency and Fast Forwarding
As Is To Be
Session1 Session1
30 µs–50 µs General- ARM core
purpose CPU Session2 Session2
Unloading
+ flow tables
Network
10-18 Network Forwarding Flow1
10 µs–18 µs forwarding chip microseconds (NP) acceleration Flow2
engine
(NP)
43 Huawei Confidential
Dynamic/Static Intelligent Uplink Selection Based on Multi-
Egress Links
Static intelligent uplink selection Dynamic intelligent uplink selection IPSec/Internet/MPLS-based
uplink selection
⚫ User-defined link weight ⚫ User-defined link SLA (latency, jitter, and ⚫ Intelligent IPSec uplink selection
⚫ Uplink selection by binding ISP address packet loss rate), selecting the optimal link
for traffic forwarding ⚫ Internet/MPLS-based uplink selection
sets to interfaces
⚫ Application-based intelligent uplink selection
44 Huawei Confidential
Extensive Security Database and Comprehensive
Security Detection Capability
⚫ Identification of 6000+ applications ⚫ Main web category database capacity > 160 million ⚫ Signatures: 20,000+
⚫ Full coverage of mainstream application protocols ⚫ Local high-performance self-learning hot database ⚫ Attack detection technology based on
⚫ Encrypted P2P protocols, Web 2.0, mobile ⚫ Effective data matching rate: 96%+ vulnerability and behavior analysis
applications, and micro applications ⚫ Enterprise-level web categories: 100+ ⚫ Anti-evasion technology based on context
⚫ Rapid response to customized requirements semantic restoration
⚫ Real-time analysis of 500 million URLs on the cloud
⚫ Default blocking rate > 85%
Unified management
• The SecoManager supports unified management
of multiple security products, such as the
iMaster NCE
firewall, IPS, and anti-DDoS, and centralized
control of security policies, improving O&M
efficiency
• The firewall supports plug-and-play and can
O&M Policy proactively register with the SecoManager after
connecting to the network
Automatic security service orchestration
Management Report • Policies can be automatically deployed to
SecoManager
corresponding firewalls based on protected
network segments, and network segment
changes will trigger policy changes of device
reselection and deployment
• Customers can configure and manage security
Configuration Policy Log sending policies in the logical partition view
delivering control
Flexible management in multiple
scenarios
...
• In data center(DC) scenarios, the SecoManager
AntiDDoS AIFW IPS and DC SDN controller are deployed together to
centrally manage firewalls
46 Huawei Confidential
Border Protection for Large and Midsize Enterprises
Border protection scenario for large and
midsize enterprises Scenario characteristics
File server Email server Web server • An enterprise has a large number of employees and
complex service traffic, making the enterprise network
vulnerable to various threats and attacks.
.COM
• High requirements are raised on defense performance and
border threat detection, requiring stable running in heavy
traffic environments.
DMZ
47 Huawei Confidential
Intranet Control and Security Isolation
Internet
• Deployment location: The USG6000F series is deployed at the
intranet border of a large or midsize enterprise.
R&D department 1 USG6000F • Fine-grained security policy control: provides fine-grained security
Untrust policy control based on 5-tuple traffic, service applications, user
information, and time ranges, effectively implementing intranet
management and control.
• Quota control: controls intranet users' online traffic and time to
prevent bandwidth abuse and decreased working efficiency due to
R&D department 2 long online time.
48 Huawei Confidential
Huawei HiSecEngine USG6500F Series AI Firewalls
2*10GE SFP+ +
Fixed 10*GE RJ45 + 2*GE 10*GE RJ45 + 4*GE SFP + 8*GE
Interfaces 2*GE SFP + 8*GE 2*GE RJ45 + 8*GE COMBO + 2*10GE SFP+
SFP 2*10GE SFP+ RJ45 + LTE
RJ45 + LTE
IPv4 Firewall
Throughput(1
518/512/64- 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 7/7/3.6 Gbps 9/8/4 Gbps
byte, UDP)
IPv6 Firewall
Throughput
2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 7/7/3.6 Gbps 9/8/4 Gbps
(1518/512/64-
Byte, UDP)
External
Optional, 64 GB microSD card available for purchase Optional, M.2 SSD (64 GB/240 GB), hot-swappable
Storage
Power
Single power supply Optional dual power modules for 1+1 redundancy
Supplies
49 Huawei Confidential
Huawei HiSecEngine USG6600F&USG6700F Series AI Firewalls
4*100GE(QSFP28) +
8*GE COMBO + 4*GE(RJ45) + 2*100GE(QSFP28) + 2*40G(QSFP+)+
8*GE COMBO + 4*GE(RJ45) + 10*10GE(SFP+) 16*25GE(ZSFP+) +
Fixed Interfaces 4*GE(SFP)+ 6*10GE(SFP+) 8*25(ZSFP+) + 20*10GE(SFP+)
8*10GE(SFP+)
IPv4 Firewall
Throughput(151 15/15/15 Gbit/s 25/25/25 Gbit/s 35/35/35 Gbit/s 50/50/40 Gbit/s 80/80/40 Gbit/s 100/100/60 Gbit/s 160/160/80 Gbit/s 240/240/120 Gbit/s
8/512/64-byte,
UDP)
IPv6 Firewall
Throughput 15/15/15 Gbit/s 25/25/25 Gbit/s 35/35/25 Gbit/s 50/50/25 Gbit/s 80/80/25 Gbit/s 100/100/45 Gbit/s 160/160/50 Gbit/s 240/240/75 Gbit/s
(1518/512/64-
Byte, UDP)
Form Factor 1U
External
Optional, SATA (1 x 2.5 inch) supported, 240 GB/960 GB/1000 GB
Storage
Power Single AC power supply; optional dual
Dual AC power supplies
Supplies AC power supplies
Note: Some 100GE interfaces and 25GE interfaces on the USG6710F/USG6715F/USG6725F are combo interfaces.
50 Huawei Confidential
Thank You
www.huawei.com
Page 51 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.