Professional Documents
Culture Documents
01 Huawei High-Quality 10 Gbps CloudCampus Solution
01 Huawei High-Quality 10 Gbps CloudCampus Solution
Foreword
⚫ Campus networks are the cornerstone for digital transformation of enterprises and
organizations and also a bridge between the physical and digital worlds. Facing rapidly
emerging technologies and applications, enterprises and organizations urgently need to
deploy intelligent and reliable campus networks in a simplified and fast manner.
⚫ Huawei CloudCampus Solution is designed for enterprises of all sizes to build ultra-
broadband, intelligent, simplified, secure, and open intent-driven campus networks, enabling
enterprises to gain real-time insights into and quickly respond to network and service needs.
⚫ This course systematically introduces Huawei CloudCampus Solution, including the solution
architecture, key components, key functions and features.
1 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
2 Huawei Confidential
A trusted partner for global customers in diverse industries
---Helping to accelerate digital transformation and unleash digital productivity
Beijing
IP Router, WAN Network
Nanjing
Ethernet Switch, Campus
Suzhou
Wi-Fi AP and WLAN
Hangzhou
Firewall and
13
Solutions Network Solutions Network Solutions Network Security research centers worldwide
Solutions
11,000+
R&D staff
>20%
of annual revenue reinvested into R&D
100+
scientists and top experts
Germany France Ireland Canada
TSN, Cyber Security, Network Calculus, Network Open Programmable, Graph DB, Network
Short Distance Optical Measurement Intent Assurance AI & Digital map
Continuous contribution to industry standards including IETF
and IEEE
Wu Qin
IETF IAB member
12+
Industry standards bodies and open
600+
Huawei's
11,000+
Total patents
50+ (China)
Leading contributions to the IPv6 Enhanced, Wi-Fi 6/7 and 400G/800G fields
Benoit Claise
Chief expert of ADN
automation engine
(Ireland)
Top ranking in the data communication network industry
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
1987 1994 2003 2009 2010 2011 2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023
Best Practices of Huawei's Office Campus Network
Huawei IT service: 20,000+ employees, 1000+ branch offices, 700,000 video conferences per month
3 key requirements
NetEngine
SD-WAN
Audio & video and VIP user
Application experience assurance
0
CloudEngine experience upgrade • 1 solution for experience assurance of video
30,000 users conference
AirEngine • 0 degradation on VIP experience freezing
LAN
5 min-wait for Frequent interruptions @ 30-user @ 4K XR: dizziness & Borderless signals, One network for office and guest
500 MB file transferred
reading 1 GB CT 30-user video conference unclear images due to packet loss customer concerns services, unassured security
in over 2 min
images
2x higher performance than Wi-Fi 6E 2x higher user concurrency than Wi-Fi 6E (hard to eavesdrop → impossible to eavesdrop)
MLO Dynamic-zoom smart antennas MU-MIMO OFDMA MRU Converged Industry's only Wi-Fi Guard
scheduling
2.4G 1 2 Rogue
5G terminal MACsec
3 4 + + =
Authorized
6G terminal
5 6
High-density mode
Overpass Multi-lane Multi-user Rogue
Omnidirectional mode road carpooling terminal
Wireless Experience Upgrade: All-Scenario IoT, Creating One Smart
Network for the Entire Campus
Enterprise office & education Healthcare Retail Hotel
Frequent loss of valuable assets, Manual clinical data collection, Untimely information update for diversified Complex management, due to too many
low utilization difficult archiving products intelligent environment control protocols
Free from IoT cards and site visits Wi-Fi-based human/environment sensing, no need of sensors Unified protocol for unified management and O&M,
€ 1200 → € 0, 90% TCO 30% conference room utilization 80% O&M efficiency
PCIe/USB Built-in IoT chip + container AP + sensor AP + Wi-Fi sensing BLE/RFID/ZigBee NearLink
Backhaul Upgrade: Digital and Intelligent Transformation Drive Campus
Network Upgrade to 10 Gbps
Wi-Fi upgrade Fully-wireless trend vs siloed network construction Surging wireless terminals, high security risks
AP uplink rate: > 1 Gbps Conflicts between multiple wireless networks, difficult service deployment 85% of cyber security risks come from terminals.
As Is To Be As Is To Be
GE 10GE
2.5GE IoT
Security
Wi-Fi 5/6 Wi-Fi 7 OA
Security
AirEngine 8771 CloudEngine S5732/S5755
Security
100% detected
OA
IoT
IoT
OA
One-off deployment, on-demand upgrade CloudEngine S5755-H
10GE 2 x 25GE 25GE
CloudEngine S8700
In-flow
detection
Poor experience, due to bandwidth Network freeze (by dozens of IT Application identification
Suppressing greedy Hop-by-hop visibility and
with AI, experience
occupation by file download, cloud engineers) two weeks before the applications; flexible measurement across
assurance for 30,000
disk synchronization, system update, event, while still uncontrollable slicing terminals, LAN, and WAN
terminals
etc. network performance CloudEngine S5755-H/S5732-H
Private line
Common
0 0
line packet incident
More private lines Deployment of static Network freeze for loss
used → only partial QoS → not effective performance assurance
optimization on SaaS applications → high costs
Wi-Fi 7 AP One person managing a
Key applications
10,000-user campus
VIP Experience Upgrade: Dedicated Resources for VIP Users, Zero Impact
on VIP Experience Even Upon Network Congestion
As Is: To Be:
Resource sharing by both VIP and common users Dedicated lanes for VIP users, preferential access anytime, anywhere
Proactive care
for VIP users
POS AGV PDA for Conference
machine image terminal Full-journey visibility
reading on both wireless and Real-time VIP user experience
Hard to assure key Common wired sides evaluation & proactive care
user Fault warning (Huawei) vs.
services on terminals none (industry)
VIP user
O&M Experience Upgrade: Experience-centric digital map, 10x O&M
efficiency, "Bits drive watts", 30% ↓ power
> 1000 devices managed 4,380,000 kWh/year
per person , > 2h for fault rectification
Normal KPIs yet video freezing 20,000 APs consume EUR 1M/Y (EUR 0.24/kWh)
Experience-centric digital map, 10x ↑ efficiency "Bits drive watts", 30% ↓ power
Connection-centric O&M Experience-centric O&M Reliance on manual labor Traffic tidal prediction
Di s c o v e ry Visibility
Us er e xp er ien c e Network/Site/Building/Floor
alarm
Digital Map
Digital Map
AI-based root cause analysis + minute-level fault locating and Traffic tidal prediction reducing energy costs by 30%/year
rectification (EUR300,000)
AI
A hyper-converged platform
(management + control + analysis)
Full lineup of Wi-Fi 6 & Wi-Fi 7 APs S5735I S6700 S8700 S12700E S16700 S7700 S5700 AR5700 AR6700 AR8700 AR631I
tailored to all scenarios
Huawei Wi-Fi 7 Product Portfolio in 2024
Available
Outdoor Outdoor
2024.Q3 2024.Q3 2024.Q3
2024.Q2 2024.Q2
2024.Q3 2024.Q3
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
Device Alarm
Campus interconnection WAN interconnection
Wired network LAN-WAN convergence, device WAN
SD-WAN
plug-and-play
2
Wired network planning
Policy provisioning Routine maintenance
Access authentication Service assurance Cloud-based
Resource planning Device upgrade
Intelligent VIP experience inspection
Intelligent terminal Authentication &
Network resource planning HQoS assurance Report statistics System O&M
management authorization
Intent-driven deployment Intelligent verification
Guest management Free
5G terminal access mobility Multi-service campus
3
IP address management IoT sensing Intelligent O&M
Multi-service logical isolation
network
1. Through WLAN Planner Experience visualization
Multi-branch interconnection WAN interconnection
2. Manually or using eDesigner
Intelligent traffic Network path Fault Intelligent
3. Through iMaster NCE-CampusInsight A-FEC IFIT
steering navigation identification optimization
21 Huawei Confidential
Planning Construction Maintenance Optimization
1. Environment setting
3
2. Region setting
With WLAN Planner, users
can complete WLAN • Use the network planning
3. Device deployment planning in five steps. 4
report to provide guidance for
onsite construction.
4. Signal simulation • The network planning result can
be imported to iMaster NCE.
5. Report export
22 Huawei Confidential
Planning Construction Maintenance Optimization
23 Huawei Confidential
Planning Construction Maintenance Optimization
capabilities
• A network deployment solution is automatically generated upon the
Scenario
Key
• The solution provides preset deployment scenarios, such as retail, office,
only have limited network O&M capabilities, and they want their networks
to be planned and deployed quickly.
and primary/secondary education, and allows users to customize
deployment scenarios as well.
24 Huawei Confidential
Planning Construction Maintenance Optimization
Large enterprises need to reduce the proportion of the time required for initial
device installation, configuration, and upgrade to the entire network
management and O&M period.
R&D VN
Requirements
Auto
Interconnection VLAN routing • Automatically generates IP addresses and routing protocol
Underlay Interconnection IP address configur- configurations based on the topology plan.
ation • Uses configuration simulation and verification technology.
25 Huawei Confidential
Planning Construction Maintenance Optimization
Multi-
• VXLAN-based multi-purpose network
purpose
• Automatic tunnel establishment through BGP-EVPN
network
26 Huawei Confidential
Planning Construction Maintenance Optimization
Security
group- • User- and resource-based policy/experience
based configuration
Policy migration,
consistent experience Natural • GUI
User A User A language • Natural language-based configuration
Security group (R&D) Security group (R&D)
27 Huawei Confidential
Planning Construction Maintenance Optimization
MPLS
CPE CPE
Identification of 6000+ well-known and user- Application- and traffic classifier-based Application- and VPN-based multi-level queues
defined applications IP FPM in-line service quality detection Bandwidth allocation for different VPNs
28 Huawei Confidential
Planning Construction Maintenance Optimization
Overview Alarms
• LAN overview, WAN overview • Current alarms, historical alarms, masked
• Site and inter-site overview alarms
• 360-degree terminal, application, and • Alarm notification mode setting
device overview (notification by email)
• WLAN resource overview, region • ...
monitoring
• ...
29 Huawei Confidential
Planning Construction Maintenance Optimization
Information reporting
>
30 Huawei Confidential
Planning Construction Maintenance Optimization
31 Huawei Confidential
Planning Construction Maintenance Optimization
32 Huawei Confidential
Planning Construction Maintenance Optimization
33 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
34 Huawei Confidential
E2E Bandwidth Upgrade, Meeting the Needs of Digital Terminals
and Service Growth
Scenarios and Requirements
Core layer
35 Huawei Confidential
CloudEngine S12700E: New Campus Network Switching Core with Superior
Performance
Full
Wired and wireless
Massive throughput programmability
convergence
Service agility
MPUE GE electrical interface cards X5E/X5S Functioning as the border node of a VXLAN-based virtual campus network,
Campus
CloudEngine S12700E works with the controller to achieve a multi-purpose
virtualization campus network, thereby improving network resource utilization.
36 Huawei Confidential
All-Scenario WLAN: High-Density Access in Indoor and Outdoor Scenarios
Densely populated outdoor scenario: stadiums (AP Densely populated indoor scenario: small summit venues and
installation height: > 15 m) auditoriums (AP installation height: 3 m to 15 m)
Outdoor AP +
directional antennas Traditional Built-in small-angle Indoor AP +
omnidirectional directional antennas directional antennas
antennas
Traffic burst scenario: e-classrooms and conference rooms Indoor multi-partition scenario: multi-partition office area (AP
(AP installation height: < 3 m; bandwidth per capita: > 4 Mbps) installation height: < 3 m)
37 Huawei Confidential
With Many Innovations, Huawei Wi-Fi 6 Builds an Experience-
Centric, Highly Reliable Wireless Network
Exclusive technologies providing network-wide wireless coverage and premium performance
Frequency
User 1
User 2
User 3
User 4
Time
Smart antennas, providing searchlight-like signals Dynamic-zoom smart antennas, MU-MIMO and OFDMA joint scheduling,
Always-on signal for users, stronger signal, higher providing spotlight-like signals providing overpass-like outcomes
speed, Targeted coverage, with less interference 40% higher capacity of the entire network
and 20% longer distance and less packet loss
Intelligent roaming technology, offering Intelligent multimedia scheduling technology, delivering Intelligent continuous networking technologies,
"satellite navigation-like" experience biological fingerprint-like assurance building neural-like networks
Terminal roaming always on track Identifies and accelerates applications, and suppresses greedy Network-wide quality detection, fault prediction, and
services to prevent frame freezing in audio and video services automatic optimization
38 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
39 Huawei Confidential
CSS and iStack
CSS: two-to-one virtualization with 1+1 link protection iStack: many-to-one virtualization, simplifying device configuration and
management
• Multiple devices are virtualized into one device, greatly simplifying network
configuration and device management.
• Two core devices are virtualized into one device, reducing the number of • iStack works with Eth-Trunk to provide uplink aggregation and load
managed NEs by 50%. balancing, improving uplink reliability.
• Uplink aggregation is implemented on aggregation devices using Eth- • Service port stacking is supported, eliminating the need for dedicated stack
Trunk, increasing the bandwidth by 100%. ports or stack cards, making networking convenient and flexible.
40 Huawei Confidential
Native WAC Implements Wired and Wireless Network Convergence
Problems: separate wired and wireless authentication points, distributed policy control, separate traffic forwarding, complex troubleshooting,
difficult to manage
Solution: wired and wireless convergence (native WAC)
The switch integrates the WAC function to eliminate bottlenecks in wireless traffic forwarding,
Native WAC reduce failure points, and manage wired and wireless traffic in a centralized manner:
• Uniformly manages and forwards wired and wireless services.
• Functions as the gateway of both wired and wireless users and manages both types of users.
• Used as the authentication point for both wired and wireless access.
• Enforces policies for both wired and wireless services.
41 Huawei Confidential
Converged Forwarding, Converged Authentication, and Converged
Policy Enforcement
NM Area
Native AC
42 Huawei Confidential
Wi-Fi & IoT Convergence Enables Unified Network Deployment
and O&M, Lowering TCO by 50%
ESL Healthcare Health Asset
management IoT management management
Scenarios and Challenges
• Scenarios: retail, healthcare, education, enterprise, and other campuses where
IoT service
innovative digital services need to be provided based on IoT
management platform
• Challenges: Wi-Fi and IoT (such as Bluetooth and RFID) networks are deployed
separately. Numerous wireless networks are deployed, resulting in high costs
Internet and inflexible service expansion. There is also radio interference between these
wireless networks, affecting service experience.
Store
Huawei IoT AP
Bluetooth
• Wi-Fi & IoT converged architecture
RFID
IoT AP • Converged site for the AP and IoT base station, reducing auxiliary resources
ZigBee (for access and power supply management) by 50%
• Cloud-based management and plug-and-play, facilitating service configuration
• Wi-Fi and IoT configuration association, allowing automatic Wi-Fi channel
switching when a conflict is detected
Wi-Fi Wi-Fi Bluetooth RFID IoT Wristband 2.4 GHz (Wi-Fi) 2.4 GHz (RFID)
terminal tag tag tag sensor Channel-6 Channel-11
43 Huawei Confidential
Simplified Architecture: Planning-Free, Configuration-Free, Plug-and-Play RUs
As-Is: traditional solution To-Be: Huawei solution
A large number of nodes configured and managed, Planning-free and configuration-free RUs, on-demand
deployment after planning, high O&M costs deployment/replacement, flexible expansion
RU AP RU AP
44 Huawei Confidential
Optical-Electrical PoE: Network Continuity Even Without Local Power
45 Huawei Confidential
New Transmission Media — Hybrid Cable
Electrical signal
Optical signal
Hybrid module
Cable Cable PoE Distance PoE+ Distance PoE++ Distance PoE++ Distance
Remarks
Specification Diameter (15.4 W) (30 W) (60 W) (90 W)
Hybrid cable-1.5
9.0 mm 1900 650 330 220
mm2
Hybrid cable-
6.2 mm 1280 500 250 195
17AWG
Hybrid cable-
5.7 mm 500 200 97
21AWG
46 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
47 Huawei Confidential
One-to-Many Virtualization Implements Multi-Purpose Network
48 Huawei Confidential
Diversified Networking Models
Border
VXLAN
Transparent Edge Edge
• Two-layer physical network. • Three-layer physical network. • Three-layer physical network. • Aggregation switches function
• Access switches function as • Access switches function as edge • Aggregation switches function as edge as edge nodes and provide
edge nodes. nodes. nodes. the native WAC function.
• Aggregation switches do not • Access switches do not need to support • APs are managed by
need to support VXLAN. VXLAN and can work with aggregation aggregation switches. APs do
switches to implement policy association. not need to support VXLAN
and can be reused.
• Legacy access switches can be reused.
49 Huawei Confidential
Multi-Border Network
Internet Internet Data Center Internet Internet
Campus 1
Campus 2
Border1 Border2 Border1 Border2 Border1 Border2
VXLAN VXLAN
VXLAN
Networking description: On a single campus Networking description: On a single campus Networking description: There are multiple
network, multiple border nodes are connected to the network, multiple border nodes are connected campuses, and each campus is connected to its
same egress device, implementing egress to different egress devices, and different services external network through an independent border
redundancy. are transmitted through different border nodes. node.
Application scenario: A single campus network has Application scenario: A single campus network Application scenario: Multiple campus networks
multiple border nodes that are connected to the is connected to different external networks belong to the same fabric, and each campus
same external network, implementing reliability in through different border nodes. network has an independent border node and
non-stacking scenarios. egress network.
50 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
51 Huawei Confidential
User Access Authentication
Authentication • Able to associate with social media, including QQ, Sina Weibo,
devices Facebook, Twitter, and Google
User terminals
52 Huawei Confidential
Intelligent Policy Engine Achieves Refined Policy Control
Condition: 5W1H-based policy Result: fine-grained rights control
User identity
User/User group/Role Permission VLAN/ACL/Security group, VIP user...
Who
Access time
Day/Hour
When
High/Medium/Low
QoS
Traffic and duration control
Terminal type
PC/iOS/Android...
What
Intelligent
policy Application Application group/Application
Company-issued/BYOD Device attribute
terminal Whose engine
53 Huawei Confidential
Portal Authentication: Allows Portal Page Customization
With this function, enterprises can conveniently customize their own Portal pages so as to launch VASs such as brand
promotion and advertisement push.
54 Huawei Confidential
Terminal Identification: Supports Proactive and Passive Detection
Proactive detection Passive detection
Deliver configurations
and policies Deliver configurations
and policies
4 5
3 4
Display Display
Administrator Administrator
identification identification
Scan- results results
1 and-
3 Report fingerprint
detect Collect
finger 2
print
2 Feedback
• Terminal visibility: collects terminal type statistics (by vendor and OS), displays the relationship between terminals and access ports, queries access
policies (VLAN, QoS, and authentication mode), and exports reports
• Terminal policy automation:
▫ Supports automatic terminal access based on terminal types, thereby achieving automatic MAC address authentication of dumb terminals.
▫ Authorizes policies (VLAN, security group, access permission, and QoS) on a per-terminal-group basis; supports IPv4/IPv6 dual-stack terminals.
55 Huawei Confidential
Terminal Identification: Numerous Identification Methods
Identification
Category Description Application Scenario
Method
LLDP LLDPDUs carry device model information. IP phones, IP cameras, network devices, etc.
56 Huawei Confidential
Terminal Identification: Automatic Policy Delivery Based on Terminal Types
The administrator enables
1 terminal identification and
configures terminal policies.
1. On the iMaster NCE web UI, an administrator enables
iMaster NCE matches the the terminal identification function, selects terminal
terminals' fingerprint information
against the fingerprint database types, and specifies the corresponding policies.
and identifies the terminal types.
2. iMaster NCE delivers terminal identification
4
configurations to the network device.
57 Huawei Confidential
Bogus Dumb Terminal Detection: Accurate Identification of Bogus
Terminals Based on Traffic Behaviors
Dumb terminals are prone to
spoofing, and manual Bogus dumb terminal detection
troubleshooting is difficult.
Campus Campus
Network Network
Report an alarm.
58 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
59 Huawei Confidential
Free Mobility: Achieves Security Group-based Policy Management
Free mobility: grants a user consistent network permissions and enforces the corresponding policies, regardless of the user's location
and the IP address used to access the network.
60 Huawei Confidential
Free Mobility: Typical Solution
Scenario description
Security group Security group–based policy control matrix
• Centralized authentication point + Centralized policy enforcement
Group Name Group ID Sales R&D Marketing ... point
Sales 1 Sales √ × √ ... • The authentication point and policy enforcement point are deployed
R&D 2 R&D × √ √ ... on the same device.
Marketing 3 Marketing √ √ √ ... • The devices do not support VXLAN.
... ... ... ... ... ... ...
Scenario characteristics
• The Core device functions as the centralized authentication point for
Core
network-wide wired and wireless users.
• The Core device functions as the policy enforcement point for free
mobility.
• The Core device has authentication information about all users on the
network. After traffic is forwarded to the device, it enforces policies
AGG1 AGG2 based on the policy control matrix defined by the administrator.
• The network does not need to support VXLAN or has VXLAN deployed
on it.
Access1 Access2
PC1 1.1.1.1 PC2 2.2.2.2 PC3 3.3.3.3 Authentication Policy Security group and policy
Sales R&D Marketing point enforcement point control matrix delivery
61 Huawei Confidential
IP-Security Group Entry Synchronization
Scenarios and pain points IP-security group entry synchronization
iMaster NCE synchronizes the mappings between user IP addresses and security groups to the switches
functioning as policy enforcement points. In this way, authentication points and policy enforcement points
can be separated, implementing flexible networking. In addition, hybrid networking with third-party
devices can be easily achieved.
IP Group
1.1.1.1 Group1 3
2.2.2.2 Group2
4
Synchronize the mappings
User authentication between IP addresses and
2
1. Switches that do not support free mobility groups.
2. WAC 5
3. Routers Enforce the
Third-party device
4. Third-party devices (non-Huawei) inter-group
policy when
These devices do not support free mobility, so the traffic
how to realize free mobility if a solution User access 1
arrives.
includes these devices?
62 Huawei Confidential
Preferential Access of VIP Users
Access denied for non-VIP users Access permitted for VIP users
AP AC AP AC
STA STA
Online user Online user 3 An online user is forced to go offline.
If a non-VIP user attempts to connect to an AP when the number of If a VIP user attempts to connect to an AP when the number of users
users connected to the AP reaches the threshold, the connection connected to the AP reaches the threshold, the AP forcibly disconnects
attempt will fail. a non-VIP user and connects the VIP user to the network.
63 Huawei Confidential
Bandwidth Reservation for VIP Users: Guaranteeing Sufficient
Bandwidth for VIP Users
Requirements
Spectrums and Identify VIP users and guarantee sufficient bandwidth
Frequency bandwidth
64 Huawei Confidential
Intelligent HQoS: User- and Application-based QoS Policies
Challenges
Manager + Controller + • Define who are VIP
Analyzer users.
1
• Define application • Traditional QoS schedules traffic based on port bandwidth,
priorities. allowing differentiation of traffic based on service levels.
However, it is difficult to differentiate services based on users.
• Traditional QoS cannot manage and schedule traffic of
multiple services from multiple users simultaneously.
2
Two-level
Network device scheduling: user Solutions
queue and
application queue
• Hierarchical QoS (HQoS) can not only differentiate traffic of
VIP Common different users but also schedule traffic based on service
user user priorities.
• HQoS differentiates service traffic using multi-level queues,
and manages and schedules transport objects such as
multiple users and services in a unified manner.
User terminal
65 Huawei Confidential
Multi-Campus Interconnection: IPsec VPN and SD-WAN Support
RR
Branch 1
BGP EVPN+
HQ Branch 2
Branch 1
Internet
HQ MPLS
MPLS/Internet
Branch 1
Internet
Branch 2
HQ MPLS
MPLS/Internet
Branch 2
In static IPsec VPN, IPsec tunnels are established between devices at different EVPN can be used to establish tunnels between sites and dynamically advertise
sites to create VPN channels. Traffic is diverted to the VPN tunnels based on the routes. The forwarding plane supports GRE or GRE over IPsec. In addition, high-
configured network segments to implement mutual access between the sites. quality links can be chosen based on applications and policies for data
transmission, implementing application- and policy-based intelligent traffic
steering.
66 Huawei Confidential
Functions and Features of the SD-WAN Interconnection
Solution (1/3)
Centralized
Flexible overlay network based on the hybrid Intelligent traffic steering, ensuring
management/control and
WAN application experience
visualization
GUI
MPLS
2
MPLS Internet
Dynamic
Internet adjustment Centralized
Latency management
1
Performance and control
data
When an enterprise has multiple types of WAN egress Measures the quality of different WAN links, defines
links (hybrid WAN), WAN links can be flexibly used to network quality requirements of applications, and
implement interconnection and interworking. performs intelligent traffic steering based on specific
policies.
67 Huawei Confidential
Application Experience Optimization Policy: Intelligent Traffic Steering
Link quality-based traffic steering Load balancing-based traffic steering
CPE2 CPE2
Voice and video services are sensitive to delay and packet loss rate. You When an enterprise has multiple links, you can configure load balancing-
can configure the high-quality MPLS link as the primary link and the based traffic steering to make full use of the link bandwidth.
Internet link as the secondary link for this type of service. In addition, you
need to configure SLA requirements for the services so that intelligent
traffic steering can be performed based on link SLA.
68 Huawei Confidential
Application Experience Optimization Policy: Intelligent Traffic Steering
Application priority-based traffic steering Bandwidth-based traffic steering
CPE2 CPE2
Low priority
If multiple types of service packets are transmitted on the same link, traffic When the bandwidth usage of a link reaches the threshold, this link is not
of high-priority applications is preferentially processed in case of selected for new traffic of some applications, and other links that meet the
congestion, ensuring user experience of high-priority applications. requirements are preferred. This method ensures the bandwidth usage of
high-priority services and prevents application quality and link quality from
deteriorating due to network congestion.
69 Huawei Confidential
Functions and Features of the SD-WAN Interconnection Solution
(2/3)
Cloud on-ramp for IaaS, one hop to six clouds,
Cloud on-ramp for SaaS, flexible path selection
cloud-network interconnection
Cloud
SaaS services Cloud
IaaS services
70 Huawei Confidential
Functions and Features of the SD-WAN Interconnection Solution
(3/3)
Cloud on-ramp through PoP gateway, delivering private line-like quality with an Internet-like price
A PoP uses the private line for cross-area fast cloud access.
Cloud
SaaS
PoP PoP
Internet MPLS
71 Huawei Confidential
Application Experience Optimization Policy: Multi-Fed and Selective
Receiving and A-FEC
Multi-fed and selective receiving A-FEC
When key services are transmitted in SD-WAN interconnection scenarios, The FEC technology uses Reed-Solomon (RS) coding to generate
the sending AR router can replicate traffic and send the traffic over redundant packets based on the original packets at the transmit end, and
different links. The receiving AR selects the packets and preserves the sends the original and redundant packets to the receive end, which then
packet order to ensure service experience. Because signals are sent over decodes the received packets to recover lost packets (if any). FEC can
two channels simultaneously, packet loss on either channel does not dynamically adjust the proportion of redundant packets to minimize
affect service experience. In this way, 0 ms switchover can be achieved.. bandwidth waste. This ensures smooth video services even at 30% packet
loss.
72 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
73 Huawei Confidential
Panorama of Intelligent O&M
Service • Wireless positioning
Intelligent assurance
Optimization
& Service Intelligent
Assurance • Intelligent radio calibration • AI roaming
optimization
Fault Group fault • Wireless group fault analysis • Wired group fault analysis
WAC analysis
Identification
& Root Cause
Individual
Analysis • Protocol trace
• Mainstream application analysis
fault • Poor-QoE client analysis
Big Data & ML
analysis
74 Huawei Confidential
Contents
1. Huawei Campus Network Updates
4. Ultra-Broadband Connectivity
5. Simplified Network
6. Multi-Purpose Network
7. Access Authentication
8. Intelligent Policy
9. Intelligent O&M
75 Huawei Confidential
Cloud Management of Security Services for Small Campus Networks
and Multi-Branch Networks
Integrates Huawei
iMaster NCE security service management
Firewall service security controller
management SecoManager • Intrusion protection system (IPS)
• Security policy
• File filtering
• URL filtering
• IPS • Content filtering
• Antivirus • Antivirus (AV)
configuration Internet • URL filtering
• APT defense • Application behavior control
• ...
Solution advantages
• Plug-and-play, rapid provisioning
FW FW Hosting for small- and medium-sized enterprises,
interconnection between mass branches of large
enterprises
FW LSW Proactive firewall registration for rapid management by
the cloud management platform
AP Rapid and unattended deployment
AP AP • Policy delivery, unified management
Remote security service configuration and management
Remote device monitoring and fault management
Branch 1 Branch 2 Branch N
Cloud-based management of massive numbers of devices,
simplifying O&M
76 Huawei Confidential
Quiz
77 Huawei Confidential
Summary
⚫ To build an end-to-end intelligent cloud campus solution, Huawei provides a variety of
products covering the access, aggregation and management layers, including four engines
(CloudEngine, AirEngine, NetEngine, and HiSecEngine), iMaster NCE-Campus, and iMaster
NCE-CampusInsight.
⚫ The Intent-Driven Campus Network Solution builds ultra-broadband, simplified, intelligent,
secure, and open campus networks for customers, so they can easily cope with challenges in
connectivity, experience, O&M, security, and ecosystem during their digital transformation.
78 Huawei Confidential
Thank you. 把数字世界带入每个人、每个家庭、
每个组织,构建万物互联的智能世界。
Bring digital to every person, home, and
organization for a fully connected,
intelligent world.