CGN/BNG Performance Tests on Huawei NE8000 Platform

Learn from Luiz Puppin, a Huawei specialist, how to perform a technical analysis of the Forwarding Performance tests carried out in a laboratory environment with the Huawei NE8000 platform, validating the equipment’s ability to operate as an integrated BNG+CGN at high load. The tests sought to verify: Purpose of Performance Tests The aim was to prove that the Huawei solution can be sustained: These features are essential for ISPs and operators with a high concentration of subscribers behind CGNs. Architecture used The topology used connects: Methodology 5. Evidence and Results Below are the verifications taken directly from the test file. 5.1. Subscribers successfully authenticated The report confirms the simultaneous authentication of thousands of PPPoE subscribers: The total validated was: 5.2. Creation of 32 million NAT sessions The DUT has reached the scalability limit set by the manufacturer: In other words, the equipment was able to withstand 32 million simultaneous streams without any noticeable degradation. 5.3. Sustained Traffic at 50 Gbps – No Packet Loss In other words: 5.4. Bidirectional traffic 50 Gbps (25G + 25G) The laboratory validated simultaneous upstream and downstream operation: Again, with zero packet loss: 5.5. CPU stability The CPU remains at stable levels, without reaching critical limits. 5.6. Completion of Performance Tests Based on the evidence, it is possible to conclude that: Therefore, the platform demonstrates real capacity to operate CGN/BNG in large-scale environments, with a high volume of traffic and a high density of subscribers. This article was developed in collaboration with Huawei Brazil’s team of ISP IP Product Managers, with special thanks to Thiago Sério and Natan Fernandes. Need help setting up your Huawei devices? We can help you! I want to learn more

MC-LAG on Huawei routers

How to configure MC-LAG on Huawei: E-Trunk, Eth-Trunk, LACP and BFD step by step. Learn MC-LAG in Huawei, today we show you why E-Trunk (multi-chassis), when to use Eth-Trunk (aggregation), how to adjust LACP for active/backup ports and how BFD shortens MTTR. We include recommendations for hashing in MPLS scenarios and a test script to validate failure behavior. Link-aggregation (LAG), called Trunk at Huawei(Eth-Trunk when it’s Ethernet), is a technology that combines multiple physical interfaces into a single logical interface. With link-aggregation we win: Traditional LAG is always between two devices, point to point: Types of LAG for Huawei Quite simply, at Huawei we have three main ways of using Eth-Trunk: In the context of MC-LAG, what matters to us is basically: Let’s make it simple: Manual Static LACP How Trunk balances traffic Eth-Trunk doesn’t “add ports” like a giant door. The equipment decides which member to send each flow through using balancing algorithms. This defines two main behaviors: Hash-based load-balancing It’s standard on most routers/switches. It works like this: The hash can use various criteria, for example: With hash, the default mode is per-flow: Hash has an important consequence: It doesn’t always distribute bandwidth evenly.Depending on the distribution of flows (hash), one member may be at the bottleneck while another has almost no traffic. This is normal. Dynamic load-balance Some devices support dynamic mode, which monitors the instantaneous load of each member and reallocates flows between links that are underutilized or overloaded. One device that uses this type of balancing is Datacom’s switches. And what can the chips use for hashing? Hardly anyone talks about this point, but it’s crucial. Depending on the ASIC, the router may look: In the case of MPLS: This matters because: Practical examples: In a nutshell: The greater the MPLS depth that the ASIC sees, the better the distribution of MPLS flows in the LAG. What LACP does LACP (Link Aggregation Control Protocol, IEEE 802.3ad) is the guy who: At Huawei, when Eth-Trunk is in static LACP, the member interfaces: The side with the highest system priority (lowest numerical value) becomes the Actor. From there: What needs to be “OK” for LAG to rise properly For an Eth-Trunk with LACP to work as expected, certain points need to be aligned between the two sides: What LACP does is use system priority + system ID + interface priority + interface number to: Entering MC-LAG So far we’ve been talking about “normal” LAG, i.e. between two devices only. MC-LAG (Multi-Chassis LAG) comes in when you want it: The idea is simple: MC-LAG’s main objective: It’s basically taking the idea of redundancy from the port/link level to the device level. Active/active vs active/backup In many vendors you can find MC-LAG in two flavors: At Huawei, for this specific scenario with E-Trunk/mLACP, the behavior is active/backup: MC-LAG at Huawei: E-Trunk vs mLACP In Huawei, there are two main ways of implementing MC-LAG: The difference lies in the control mechanism between the PEs: In this article, we’ll focus on E-Trunk, which is the “classic” form of MC-LAG in many PE-CE scenarios. How E-Trunk works Don’t confuse E-Trunk (the sync technology between chassis) with Eth-Trunk (the link-aggregation itself). Consider the following scenario: The PEs then: With that: When a fault occurs: Optionally, you can: CE connectivity ↔ PEs with E-Trunk Some important design points: Use cases In the topology below, we’ll cover two use cases for MC-LAG (there are many others). 1) MC-LAG protecting VPLS (layer 2) At the top of the drawing, CE1 is multihomed to PE1 and PE2 using MC-LAG, all in the same VPLS-1 instance.On the network side, PE1/PE2 close the VPLS with PE3, which delivers the same service to CE2. This is end-to-end L2 protection for the VPLS, with equipment and POP redundancy. 2) MC-LAG protecting /30 L3 (layer 3) At the bottom of the drawing, CE3 receives a /30 L3 via MC-LAG, dual-homed in PE2 and PE3. Setting up the environment Now that you’re familiar with all the concepts behind MC-LAG, let’s head to the lab. We’ll be using the PNETLAB virtual environment with the Huawei NE40 V22 image. The physical ports and connections between devices are described in the topology below. The configuration of the CEs is simple: a mikrotik (ROS 7.6) using bonding interfaces, with LACP fast (in 1s). CE3 is simply a physical interface with a VLAN. CE1 CE2 CE3 The configuration of the PEs includes the point-to-point interfaces, active with OSPF, MPLS. On the access interfaces, the LAG and e-trunk synchronization configurations. And in the service layer, we have set up the VPLS (VSI) and also the L3 gateway (with the mac-address and the same IP). PE1 – Core Layer MLAG and E-trunk service This is where MLAG really comes into its own. We first create an ordinary Eth-Trunk, and then associate it with an e-trunk configuration, which makes the MLAG magic happen. Now that the LAG has been created, we need to configure the e-trunk. To configure it, we need to: In our lab, we’ll close the loopback between PE1 and PE2 – these are part of the MLAG from CE1’s perspective. The master priority will be PE2, with priority 5. The timers configured are 9 for hello and 30 for hold-timer. Finally, it’s time to associate the LAG interface with e-trunk, thus creating an MLAG from CE1’s perspective. VPLS services PE2 – Core Layer The CORE and VPLS configurations for PE2 are similar to those for PE1 MLAG and E-trunk service Redundant Gateway Services For the redundant gateway service for CE3, we will: PE3 – Core Layer The CORE settings for PE3 are similar to those for PE1. VPLS services Unlike PE1 and PE2, which have an MLAG with the CE, in this case PE3xCE2 communication takes place directly on the physical interface with vlan 10. The VPLS settings remain the same, the difference is in the peers, which close the VPLS with PE1 and PE2 at the same time. Redundant Gateway Services Validating configurations and redundancy MC-LAG

Comparing vendors

In this article we will compare some Ufispace devices with Huawei. We are going to talk about 4 pieces of equipment here: – Ufispace S9510-28DC Disaggregated Cell Site Gateway Router – Huawei S6730-H24X6C Switch – Ufispace 9600 Open Aggregation Router – Huawei NE8000 M4 Router We have chosen models that are similar in terms of number of ports, traffic capacity and features. Both Huawei and Ufispace have very good solutions for ISPs, with equipment that supports protocols such as OSPFv2/v3, IS-IS, BGP, MPLS, SR MPLS, SRv6, VXLAN, among others. Huawei is a Chinese brand well known among ISPs for its routing and switching solutions, with equipment such as the Huawei NE40 and NE8000 routers and the S5700 and S6700 switches, among others. It offers a robust product lineup to meet the needs of ISPs. Ufispace, from Taiwan, has a complete solution for switches and routers, and comes with an “Open Network” concept, meaning that the user can decide which management software to install on the hardware, such as IP Infusion‘s Ocnos, which is mature software with all the routing functionalities needed by ISPs. Let’s start by talking about the Huawei NE8000 M4 router. It’s a modular router that comes with the following features: – 16G of RAM – Six Core CPU – It comes with 4 combo 100G ports, which can be modified via configuration to use 10G ports; – Supports up to 4 expansion cards; – Supports up to 12 100G ports; – Switching capacity 2.4 Tbps This router is widely used by ISPs as a BGP router and supports 25 million routes in the RIB and 4 million in the FIB. It is also widely used as a BNG PPPoE or IPoE concentrator, supporting up to 64,000 subscribers. On the other hand, we have a Ufispace S9600-72XC router, which has the following features: – 32G of RAM; – Octa Core CPU; – Comes with 64 1/10/25G SFP28 ports; – 8 ports of 4/100G QSFP28; – Switching capacity 2.4 Tbps Ufispace is a very good brand that has made a name for itself in the ISP market. This particular model supports 20 million routes in the RIB and around 4 million in the FIB, so it can be used very well as an edge router. And because it’s a White box (you can choose an operating system), it can be used as a BNG. For more details about BNG in Ufispace, I suggest reading the article Using OpenBNG to build Resilient Broadband Networks – https://www.ufispace.com/company/blog/openbng-resilency-models Below is a table comparing some of the features of each router model: Now let’s talk about the switches. Let’s also make a brief comparison between the Huawei S6730-H24X6C and the Ufispace S5910-28DC. We started by checking out the Huawei S6730-H24X6C switch, which comes with a few features: – 4G of RAM – Quad Core CPU – Comes with 24 10G ports; – 6 ports of 40/100G; – Switching capacity 1.68 Tbps Huawei switches are well known and widely used in ISPs for access and aggregation functions in MPLS networks. It’s a switch that comes with good traffic capacity and is even used in some cases for BGP for CDN boxes such as Google, Netflix and FNA. On the other hand, we have the Ufispace S5910-28DC switch, which comes with similar features: – 8G (standard) or 16G (Premium) of RAM; – Quad Core (standard) or Octacore (premium) CPU; – Comes with 24 10G/25G ports; – 2 ports of 40/100G; – 2 ports of 100/400G; – Switching capacity 800 Gbps This is a switch that is gaining notoriety for having 400G ports, and it can very well be used in the MPLS backbone in the P/PE functions, and in the BGP function, as it supports 3.5 million routes in the RIB and 1.2 million in the FIB. Below is a comparison table between the switches: Conclusion: In this article we’ve seen a brief comparison between some Huawei and Ufispace models. We chose models that are similar in terms of traffic capacity, number of ports and functionalities. Both devices have protocol interoperability and can be deployed together, making them great options for ISP networks.

How to Configure Huawei WS5200 Routers Using TR069

Today I’m going to show you how to configure your CPE WS5200 using Made4Graph’s TR-069. I recommend that this be done at a workstation using a public IP address, since it will need to be approved. To do this, we’ll update some information in your CPE using the TR-069 form; we don’t want a customer to be left without internet service. Before beginning the configuration, it is essential that there be no “NAT” of any kind on the network between the CPE and the TR-069 server; if there is, it will compromise TR-069 functionality, as stated in the protocol documentation. Now that I’ve completed the prerequisites, let’s set up the CPE. When you access the CPE, go to the More Functionstab, then System Settings, and TR-069 When you reach the screen shown below, we will make the following settings CWMP Settings: The TR069 Management button must be enabledThe Information Interval button must be enabledACS server address = http://ip_do_server_de_tr:7547ACS username = adminACS password = adminConnection Request username = adminConnection Request password = adminInformation Interval = 300 Then click Save Shortly thereafter, the CPE should appear on made4graph, where it will be approved by our team Some information has been redacted to keep CPE data confidential. If you still have questions, send us a message, and we’ll help you with your CPE.

Interconnecting two Virtual Systems (VS) on Huawei NE platform (Interconnecting 2 virtual routers on Huawei NE)

The other way to link… Interconnecting two VS via VPN VPWS CCC # Admin-VS ! Side L2 Admin-VS Virtual-Ethernet0/2/100 interface ve-group 100 l2-terminate Virtual-Ethernet0/2/100,100 interface vlan-type dot1q 100 ! Side L2 VS1 Virtual-Ethernet0/2/200 interface ve-group 200 l2-terminate Virtual-Ethernet0/2/200.100 interface vlan-type dot1q 100 ! MPLS CCC VPWS interconnectionccc test interface Virtual-Ethernet0/2/100.100 tagged out-interface Virtual-Ethernet0/2/200.100 tagged # Admin-VS ! Side L3 Admin-VS Virtual-Ethernet0/2/101 interface mac-address c4b8-b434-ab45 ve-group 100 l3-access interface Virtual-Ethernet0/2/101.100 vlan-type dot1q 100 ip address 10.1.1.1 255.255.255.252 ! Side L3 VS1 interface Virtual-Ethernet0/2/201 ve-group 200 l3-access interface Virtual-Ethernet0/2/201.100 vlan-type dot1q 100 # Admin-VSadmin virtual-system vs1 pvmb slot 3 port-mode port assign interface Virtual-Ethernet0/2/201.100 # VS1 ! VS1 L3 Sideinterface Virtual-Ethernet0/2/201.100 vlan-type dot1q 100 ip address 10.1.1.2 255.255.255.252 Scenario Considerations Validations <HUAWEI>display vll ccctotal ccc vc : 1local ccc vc : 1, 1 upremote ccc vc : 0, 0 up name: teste, type: local, state: up,intf1: Virtual-Ethernet0/2/100.100 (up), access-port: false intf2: Virtual-Ethernet0/2/200.100 (up), access-port: false VC last up time: 2020/02/17 14:40:58VC total up time: 0 days, 0 hours, 16 minutes, 37 seconds Admin-VS:<HUAWEI>ping 10.1.1.2 PING 10.1.1.2: 56 data bytes, press CTRL_C to break Reply from 10.1.1.2: bytes=56 Sequence=1 ttl=255 time=1 ms Reply from 10.1.1.2: bytes=56 Sequence=2 ttl=255 time=1 ms Reply from 10.1.1.2: bytes=56 Sequence=3 ttl=255 time=1 msd Reply from 10.1.1.2: bytes=56 Sequence=4 ttl=255 time=1 ms Reply from 10.1.1.2: bytes=56 Sequence=5 ttl=255 time=1 ms — 10.1.1.2 ping statistics — 5 packet(s) transmitted 5 packet(s) received 0.00% packet loss round-trip min/avg/max = 1/1/1 ms VS1:<HUAWEI-vs1>ping 10.1.1.1 PING 10.1.1.1: 56 data bytes, press CTRL_C to break Reply from 10.1.1.1: bytes=56 Sequence=1 ttl=255 time=1 ms Reply from 10.1.1.1: bytes=56 Sequence=2 ttl=255 time=1 ms Reply from 10.1.1.1: bytes=56 Sequence=3 ttl=255 time=1 ms Reply from 10.1.1.1: bytes=56 Sequence=4 ttl=255 time=1 ms Reply from 10.1.1.1: bytes=56 Sequence=5 ttl=255 time=1 ms — 10.1.1.1 ping statistics — 5 packet(s) transmitted 5 packet(s) received 0.00% packet loss round-trip min/avg/max = 1/1/1 ms<HUAWEI>ping 10.1.1.2 PING 10.1.1.2: 56 data bytes, press CTRL_C to break Reply from 10.1.1.2: bytes=56 Sequence=1 ttl=255 time=1 ms Reply from 10.1.1.2: bytes=56 Sequence=2 ttl=255 time=1 ms Reply from 10.1.1.2: bytes=56 Sequence=3 ttl=255 time=1 msd Reply from 10.1.1.2: bytes=56 Sequence=4 ttl=255 time=1 ms Reply from 10.1.1.2: bytes=56 Sequence=5 ttl=255 time=1 ms — 10.1.1.2 ping statistics — 5 packet(s) transmitted 5 packet(s) received 0.00% packet loss round-trip min/avg/max = 1/1/1 ms <HUAWEI>display bgp peer BGP local router ID: 192.168.88.100 Local AS number: 11111 Total number of peers: 1 Peers in established state: 1 Peer V AS MsgRcvd MsgSent OutQ Up/Down State PrefRcv 10.1.1.2 4 22222 25 25 0 00:19:38 Established 0<HUAWEI>displ ospf peer brief (M) Indicates MADJ neighbor OSPF Process 1 with Router ID 10.0.0.1 Peer Statistics InformationTotal number of peers: 1 Peers in full state: 1—————————————————————————– Area Id Interface Neighbor id State 0.0.0.0 VE0/2/101.100 10.0.0.2 Full<HUAWEI> displ ospfv3 peer OSPFv3 Process (1) OSPFv3 Area (0.0.0.0) Neighbor ID Pri State Dead Time Interface Instance ID 10.0.0.1 1 Full/DR 00:00:38 VE0/2/201.100 0 Finally that’s it folks, we don’t know the performance or impact on the box, but the basic services worked normally. If you test it with traffic, let us know! Share your results with us. If you need assistance, please contact us! Hugs, Rafael Ganascim, Gabriel Henrique and Kevin Walters IT Consulting Team – Made4it

Netflow Configuration on Huawei Routers

Hello Today we’ll show you how to configure your Huawei router to export NetFlow (IP NetStream). Here we have the Network topology and the Netflow Server information These are the steps required to configure the Huawei Router to export Netflow v5/v9 via Netstream IP Let’s go to the step-by-step configuration 1.Configuring the NTP Server It is important to configure an NTP server because flow data uses a timestamp based on the router’s time. If the router’s time differs from the server’s, the data will not match the time, resulting in a discrepancy in the information. It is important that you configure at least 2 NTP servers and also your router’s timezone. ntp-service server disable ntp-service ipv6 server disable ntp-service unicast-peer 200.160.0.8ntp-service unicast-peer 200.189.40.8 2. Configure the slot to export information On Huawei routers, you need to configure the slot to export information. To do this, use the following commands: slot 3 ip netstream sampler to slot self ipv6 netstream sampler to slot self 3. Configuring Netstream IP with Netflow Server On Huawei routers you must configure the netstream IP to say which server will receive the Netflow data, which sampling (sampler), which Netflow version and Netflow source IP. For configuration use the following commands: ip netstream timeout active 1 ip netstream timeout inactive 15 ip netstream export version 9 ip netstream export index-switch 32 ip netstream export template timeout-rate 1 ip netstream sampler fix-packets 500 inbound ip netstream sampler fix-packets 500 outbound ip netstream export source 192.168.210.49 ip netstream export host 192.168.210.47 2055 ip netstream export template option sampler ip netstream export template option timeout-rate 1 ip netstream as-mode 32 ipv6 netstream as-mode 32 ipv6 netstream timeout active 1 ipv6 netstream timeout inactive 15 ipv6 netstream export version 9 ipv6 netstream export index-switch 32 ipv6 netstream export template timeout-rate 1 ipv6 netstream sampler fix-packets 500 inbound ipv6 netstream sampler fix-packets 500 outbound ipv6 netstream export source 192.168.210.49 ipv6 netstream export host 192.168.210.47 2055 ipv6 netstream export template option sampler ipv6 netstream export template option timeout-rate 1 ipv6 netstream as-mode 32 4. Configure the interface to enable Netflow on the interface Finally, we need to enable NetFlow on the interfaces that will export it. To do this, use the following commands on each interface: ip netstream inbound ipv6 netstream inbound Below is the complete configuration of the Router: ntp-service server disablentp-service ipv6 server disablentp-service unicast-peer 200.160.0.8ntp-service unicast-peer 200.189.40.8 slot 3 ip netstream sampler to slot self ipv6 netstream sampler to slot self ip netstream timeout active 1ip netstream timeout inactive 15ip netstream export version 9ip netstream export index-switch 32ip netstream export template timeout-rate 1ip netstream sampler fix-packets 500 inboundip netstream sampler fix-packets 500 outboundip netstream export source 192.168.210.49ip netstream export host 192.168.210.47 2055ip netstream export template option sampler ip netstream export template option timeout-rate 1 ip netstream as-mode 32 ipv6 netstream as-mode 32ipv6 netstream timeout active 1ipv6 netstream timeout inactive 15ipv6 netstream export version 9ipv6 netstream export index-switch 32ipv6 netstream export template timeout-rate 1ipv6 netstream sampler fix-packets 500 inboundipv6 netstream sampler fix-packets 500 outboundipv6 netstream export source 192.168.210.49ipv6 netstream export host 192.168.210.47 2055ipv6 netstream export template option sampleripv6 netstream export template option timeout-rate 1ipv6 netstream as-mode 32 interface eth-trunk0.100 (exemplo de interface)ip netstream inboundipv6 netstream inbound If you have an NE40, here is a sample configuration: ntp-service server disablentp-service ipv6 server disablentp-service unicast-peer 200.160.0.8ntp-service unicast-peer 200.189.40.8 slot 3 ip netstream sampler to slot self ipv6 netstream sampler to slot self ip netstream as-mode 32ip netstream timeout inactive 15ip netstream export version 9ip netstream export index-switch 32ip netstream export template timeout-rate 1ip netstream sampler fix-packets 500 inboundip netstream sampler fix-packets 500 outboundip netstream export source 192.168.210.49ip netstream export host 192.168.210.47 2055ip netstream export template option samplerip netstream export template option timeout-rate 1 #ipv6 netstream as-mode 32ipv6 netstream timeout inactive 15ipv6 netstream export version 9ipv6 netstream export index-switch 32ipv6 netstream export template timeout-rate 1ipv6 netstream sampler fix-packets 500 inboundipv6 netstream sampler fix-packets 500 outboundipv6 netstream export source 192.168.210.49ipv6 netstream export host 192.168.210.47 2055ipv6 netstream export template option sampleripv6 netstream export template option timeout-rate 1 On all interfaces add ip netstream inbound ipv6 netstream inbound If you have a router that isn’t listed here, send us a message on WhatsApp and we’ll send you the settings. I hope this helped, and see you next time.Big hug.

Made4it arises to meet the needs of the market, which has been demanding more and more personalized solutions.