Professional Documents
Culture Documents
Huawei SD-WAN Solution Technical Presentation
Huawei SD-WAN Solution Technical Presentation
1 SD-WAN Trends
3
2 Huawei SD-WAN Product Panorama
4
2 Success Stories
2 Huawei Confidential
SD-WAN Is the Best Way to Address Challenges Facing WANs
Development of new SD-WAN solutions driven by technological
Surge in enterprise WAN traffic
revolutions
Technological
revolutions
TDM IP/MPLS Cloud
80%
Private line
solutions
20% SD-WAN
SDH/PDH MPLS VPN
(Hybrid WAN, SDN
/ IPsec VPN / OTN … controller)
2016 2020
Proportion of WAN traffic to the total
3 Huawei Confidential
Industry Consensus: SD-WAN Is the Way Forward
• Meeting complex networking requirements of all • Providing 5G gigabit wireless uplinks, ensuring low • ZTP, facilitating site and service rollout
types of enterprises latency and requiring no cabling • Using the Internet to support the AI customer
• Extending to 10+ VASs, such as VoIP and LAN • Implementing application-based intelligent traffic service, reducing link costs
services, by making optimal use of CPEs steering, ensuring financial service experience • Ensuring high-quality experience of the AI
• Flexible and visualized O&M management, • Centralized network O&M and unified customer service and issuing insurance policies in
reducing OPEX management across LAN, WAN, and security minutes
4 Huawei Confidential
Key Considerations for Building SD-WAN Networks in the Digital Era
1. How to implement quick rollout of branches? ZTP, 5G High bandwidth and cabling-free
• ZTP, 5G ultra-broadband uplink, cabling-free, provisioning devices and
networks in minutes
5 Huawei Confidential
Contents
11 SD-WAN Trends
42 Success Stories
6 Huawei Confidential
Huawei SD-WAN, Facilitating Enterprise Digital Transformation
layer
Site deployment
orchestration
Application policy Visualized O&M
provisioning
Intelligent O&M
… … • Network visualization, service visualization, and
Customer
Counter VTM VR finance
service robot topology-based O&M
Large/Midsize branch Small branch • Proactive user and application experience
optimization
7 Huawei Confidential
Intelligent Network Construction, One-Stop Management
and O&M
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
8 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Manual onsite
Network planning Device selection Process approval Site survey
Hardware Hardware Software configuration and
transportation installation commissioning deployment,
(2 to 5 days) (1 to 3 days) (2 to 5 days) (1 to 3 days)
(2 to 5 days) (1 to 3 days) (1 to 3 weeks)
which is error-
prone and time-
consuming (1 to
As-Is 3 weeks)
MSP/Carrier Enterprise
Multiple ZTP
modes, deploying
devices and
provisioning
networks in minutes
email
Email
The CPE
registers with
iMaster NCE
The CPE Perform ZTP
registers with
iMaster NCE
at the site
Obtain an IP Import the initial
CPE
address configuration file in
batches
Perform deployment
on a mobile phone or
laptop DHCP server Obtain the IP address CPE
of iMaster NCE CPE
Scenario: send an email to a specific Scenario: Deploy a DHCP server and enable the Scenario: Centrally import the initial
address for deployment CPE to automatically obtain an IP address upon configuration through a USB flash drive.
Advantage: one-click deployment power-on. Advantage: batch device deployment
Advantage: zero skill requirements
10 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Site replication
11 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
13 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
14 Huawei Confidential
R21C00 New Features On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Requirements: fast and secure network Requirements: multi-cloud interconnection and Requirements: fast Internet access and
access for branches cloud-network synergy interworking
• Slow Internet access: Internet access traffic is • Lack of interoperability among multiple clouds: • Slow Internet access: Access to websites of other
diverted to the HQ, slowing down Internet access. Services deployed on different public clouds are regions or countries is slow or even fails.
• Expensive lines: Internet access traffic occupies isolated. • Slow mutual access: Internet-based connections are
valuable private line resources, resulting in high costs. • Low configuration efficiency: When branches access unstable, and user experience cannot be ensured.
• Insecure: Local breakout is performed without VPCs/VNETs on the cloud, IPsec tunnels need to be Traffic of intra-city mutual access via Internet of
security protection. separately established with the gateway, which are different carriers is not transmitted through the
• Unable to identity applications: Local breakout is complex to configure. optimal links.
faster for some applications, but breakout through • Difficult to manage policies: Only basic
the HQ is faster for some other applications, making interworking capabilities are available, and no route
it difficult to configure policies. selection capability is provided, making it hard to
control routes and policies on public clouds.
15 Huawei Confidential
R21C00 New Features On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Note: Unilateral TCP optimization is a test feature and will be put into commercial use in R21C10 (GA in March 2022).
16 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Requirements & First packet identification (FPI) Service awareness (SA) Customized application identification
Challenges
Traffic flow
…7 6 5 4 3 2 1 • Signature
identification
• Association
Mapping table identification
• Behavior
Destination Application identification Customized
• ... applications
IP Address Name based on 5-tuple
information
>> 1.1.1.1 W3
2.2.2.2 Salesforce
Unclassified
• Diversified enterprise 3.3.3.3 HR
services (production,
packets ……
4.4.4.4. Office 365 SA engine
office, and cloud
services) make it difficult ... ...
to ensure application
experience for key
services. • Lookup in the mapping table to quickly identify • Multiple identification methods: packet • Applications customized based on 5-tuple
• Network applications an application based on the destination IP signature identification, association information: matching based on the destination
emerge one after address of the first packet identification, and behavior identification, etc. IP address, destination port number, and
another but are difficult • Applicable to SaaS applications, with the correct • Application signature database containing up to protocol > matching based on the source IP
to identify. Non-key route selected at the first packet 6000+ records address, source port number, and protocol
applications preempt • Flexible SA application signature database • Applications customized based on DSCP, ACL.
bandwidth resources. upgrade through iMaster NCE
17 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
4 3 2 1 4 3 2 1 Flow P1
MPLS 2 1
4 3 2 1 Flow P2
Application
4 3 2 1 Flow P3 4 3 2 1
identification
Link switchover is triggered if 4 3 2 1
the quality is lower than the MPLS
SLA threshold.
HQ Application
Branch identification (100 Mbit/s)
Internet HQ
4 3
Branch
MPLS
4 3 2 1 (50 Mbit/s)
If the bandwidth utilization is greater than 70% (configurable), If the bandwidth utilization is less than 50% (configurable),
traffic of higher-priority applications is preferentially processed. traffic of lower-priority applications is switched back.
18 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Multi-Fed and Selective Receiving, Ensuring Zero Packet Loss of Key
Services
Quality deterioration or interruption of a wired Multi-fed and selective receiving @ hybrid links (wired and wireless, wired and
or wireless link, failing to guarantee the
wired, or wireless and wireless): Multi-path packet replication prevents packet
experience of key services
loss on links.
Weak signal
Packet loss
As-Is: Key service strength
P1 P2 X P4
P1 P2 P3 P4 P1 P2 X P4
5G
AR remote guidance
P1 X P3 P4
Multi-fed
Selective
Healthcare
receiving
P1 X P3 P4
Key services encounter packet loss or
5G/Wired
are interrupted.
19 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Check link quality in real time Packet loss Enable FEC on the receiving
and adjust the FEC protection during device and restore the
window as needed transmission original video packet
Note: FEC function only support in SD-WAN solution. After FEC is enabled, the forwarding performance of the
device is affected. FEC can be enabled based on service flows. To prevent the forwarding performance from Huawei: no frame freezing or artifact Vendors: frame freezing and
being affected, it is recommended that FEC be enabled for key services. even at 30% packet loss rate artifact at 3% packet loss rate
Requirements & Challenges Intelligent A-FEC: mitigating packet loss and offering optimal experience
Instant messaging services, such as voice • Redundant coding is performed based on historical packet information. After normal packets are sent, the
calls and video conferences, are sensitive to corresponding redundant packets are forwarded. The receive end recovers the lost packets based on the
packet loss. If the transmission link quality is redundant packets.
poor, frame freezing and artifacts may occur, • Huawei A-FEC: The intelligent data analysis engine adjusts the FEC protection window and protection mode
resulting in poor service experience.
based on the link quality, achieving fast recovery and low redundancy.
20 Huawei Confidential
On-Demand Application
R21C00 New Features ZTP Intelligent O&M
Interconnection Experience
System security:
Self-service Portal Orchestrator BSS/OSS
Rights- and domain-based management
HTTPS
System security Huawei & third-
SSH encryption for NETCONF, bidirectional security
party cloud security
authentication
Log analysis
Traffic analysis HTTPS encryption for third-party system
Document behavior
Rights- and domain-based management interconnection data
Zscaler
SSH encryption for NETCONF, E2E CPE-pipe-cloud data security:
bidirectional security authentication Forcepoint CPE security
Next-gen AR6000: built-in AV, IPS, URL filtering,
SA, and firewall protection capabilities
Secure boot, TPM (supported by AR8140)
21 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Numerous devices,
difficult deployment
Manual troubleshooting
Difficult O&M
Network fault -> Passive
response -> Check on the NMS -
> Manual locating...
22 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
WAN egress interconnection LAN campus configuration LAN & WAN port route WAN traffic policy, such as
intelligent traffic steering
One platform and integrated GUI, improving deployment and O&M efficiency and reducing customer investment
Note: CloudCampus solution supports integrated O&M of LAN/WAN networks.
23 Huawei Confidential
On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
Topology-based O&M
Topology-based graphical O&M
Network-wide inspection, detecting potential
problems
O&M demo Optimization of WAN investment
and configuration policies
Locating root causes in minutes
24 Huawei Confidential
Service Alarm Network
Log Tracing Agile Report
Visibility Management Diagnosis
Alarm
statistics
Application Network
statistics performance
statistics
25 Huawei Confidential
Service Alarm Network
Log Tracing Agile Report
Visibility Management Diagnosis
Rights-based: Who can perform what operations Domain-based: Who can view what resources
Different roles and operation rights are assigned to users based on their Different management objects are allocated to different management
responsibilities to implement rights-based management. domains to implement domain-based management.
Tenant administrator
Monitoring
√ √ ... √ Area 1
√ ... Area 3
Maintenance √ √
Policy √ √ ... ×
...
26 Huawei Confidential
Service Alarm Network
Log Tracing Agile Report
Visibility Management Diagnosis
27 Huawei Confidential
Service Alarm Network
Log Tracing Agile Report
Visibility Management Diagnosis
28 Huawei Confidential
Service Alarm Network
Log Tracing Agile Report
Visibility Management Diagnosis
29 Huawei Confidential
Service Alarm Network
Log Tracing Agile Report
Visibility Management Diagnosis
Step 1: Demarcate the fault. Step 2: Locate the fault. Step 3: Diagnose the fault.
• Check the VPN site view to determine the • Check the corresponding device or Use multiple diagnosis tools to drill
fault scope. link to determine the faulty object. down to the root cause.
• Add or remove sites to focus on key areas. • Check the health data to determine
the fault cause.
Interface down
Extensive
visualized KPIs
User-defined
key areas
30 Huawei Confidential
Service Alarm Network
Log Tracing Agile Report
Visibility Management Diagnosis
Self-service data
Simple operations Dashboard Periodic task
analysis
Drag and drop dimensions and • Multi-dimensional KPI data, gaining Quick filtering by time, field, top N, and • Creating periodic tasks
measurements to quickly generate insights into the overall service status comparison items, facilitating self- • Exporting Excel or PDF reports
reports • Abundant graphic components, which service data analysis
are intuitive and easy to understand
• Customized layout and flexible
adjustment
31 Huawei Confidential
R21C00 New Features On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
WAN health
Intelligent O&M of WANs:
AR device health evaluation
is added on the wired health
dashboard.
32 Huawei Confidential
R21C00 New Features On-Demand Application
ZTP Intelligent O&M
Interconnection Experience
1 SD-WAN Trends
3
2 Huawei SD-WAN Product Panorama
4
2 Success Stories
34 Huawei Confidential
NetEngine AR iMaster NCE
Full-Lineup of SD-WAN-Capable NetEngine ARs: High
Performance and Extensive Interfaces
HQ/Large branch NetEngine AR6300
NetEngine AR8140 NetEngine AR6280
NetEngine
AR6300/AR6200 5G SIC card
series (applicable to all
New SRU-400H/SRU-600H SRU-400H/SRU-600H AR6000 models)
SME branch
Small enterprise
NetEngine AR651 NetEngine AR651W NetEngine AR657W NetEngine AR651W-8P
NetEngine
AR650 series
NetEngine AR617VW-LTE4
SOHO
NetEngine AR611W/AR611 NetEngine AR617VW NetEngine AR617VW-LTE4EA
NetEngine
AR610 series
(Latin America only)
35 Huawei Confidential
NetEngine AR iMaster NCE
NetEngine AR: New SD-WAN Engine with 3x Industry Performance and 5G Ultra-Broadband
+
CPU + NP + hardware Multi-core ARM CPU (L4-L7 service processing)
acceleration engines CPU + NP heterogeneous forwarding
AI (In
... 3x industry performance
SA
IPsec acceleration acceleration
future)
36 Huawei Confidential
NetEngine AR iMaster NCE
Customer benefits:
Hub • High-performance SD-WAN hub gateway with a
New
maximum of 20 Gbps SD-WAN performance
• Large management capacity: up to 6000 CPEs
• High-density interfaces: highest density of
AR8000
NetEngine AR8140-12G10XG built-in 10GE interfaces in the industry
• Small size (1 U), saving rack space
Internet MPLS
Model AR8140-12G10XG/AR8140-T-12G10XG
Memory 16 GB
Terminal
38 Huawei Confidential
Contents
1 SD-WAN Trends
3
2 Huawei SD-WAN Product Panorama
4
2 Success Stories
39 Huawei Confidential
40 Huawei Confidential
Huawei NetEngine AR Routers and SD-WAN Solutions
Serve 50,000+ Global Customers
No.1
No. 2 No.1 Compound annual growth rate
Global enterprise router market Chinese enterprise router market (CAGR) in the last 5 years (among
mainstream vendors)
41 Huawei Confidential
Huawei NetEngine AR @ CCB: Building the First-of-Its-Kind
5G Smart Bank
42 Huawei Confidential
Huawei SD-WAN @ Ping An Technology: Optimizing AI Customer Service
Experience and Shortening the Insurance Policy Issuance Time from 2 Hours to 10 Minutes
Replacing 2–10 Mbit/s MPLS links with 10–30 Mbit/s Internet links to carry the AI customer service, reducing the
private line costs by 40%
Application-based intelligent traffic steering, ensuring the AI customer service experience
Branch network provisioning in minutes, device plug-and-play, requiring no professional personnel and no onsite
deployment
Status visualization from multiple dimensions, including the network, branch nodes, users, and applications, simplifying
O&M, automating the entire process, and reducing outsourcing service manpower
43
43 Huawei Confidential
Huawei Confidential
Thank you. 把数字世界带入每个人、每个家庭、
每个组织,构建万物互联的智能世界。
Bring digital to every person, home and
organization for a fully connected,
intelligent world.