Huawei Network Solution Overview v2
Huawei Network Solution Overview v2
Page 0 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1. Know More About Huawei
Page 1 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Know More About Huawei
Huawei: Leading Provider of ICT infrastructure and Smart Devices
Page 2 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Know More About Huawei
Focusing on ICT to provide products, solutions, and services to three customer groups
Page 3 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Know More About Huawei
Build connectivity for Indonesia: 13 region offices, 5 logistics centers
Page 4 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Datacom: Building an intelligent cloud network to
help companies go digital
Page 5 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Contents
1. Know More About Huawei
Page 6 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Wireless, IoT, and Cloudification Drive Campus Network Transformation
employee terminals per 100 m2 increase from transformed to support 14,300 IoT terminals, 14 smart based, posing higher requirements on network
40 to 80, driving demand for higher wired applications, 306 smart classrooms, and more. quality and latency.
access bandwidth.
Building a high-quality campus network with higher bandwidth, better experience, and higher efficiency
Huawei CloudCampus 3.0 Solution: Building a High-Quality Campus Network for the
Digital Era
Digitalization transforms enterprises
Management, control,
NETCONF/YANG and analysis Telemetry High-quality network for the digital era
Network layer
Full-10GE access, unleashing digital productivity
• Multi-GE switch + high-density 10GE/25GE fixed switch + 100GE core, building a simplified, ultra-broadband network
• Wired and wireless convergence (managing up to 10K APs and supporting 50K concurrent users), preferential service assurance for VIPs
• Network-wide automated deployment, plug-and-play devices, and precise insight into network-wide link quality
CloudEngine S-series campus switches
AirEngine Wi-Fi 6/6E/7 AirEngine Wi-Fi 6/6E/7 powered by Huawei 5G, building a fully wireless campus network
Lightning-fast speed More stable coverage More stable application More stable roaming
Unique tri-band antennas enable Dynamic-zoom smart antennas Dynamic Turbo: Lossless roaming:
18.67 Gbps, twice the industry for high-density coverage modes, application acceleration, < zero packet loss
average. 10-20% higher performance. 10 ms latency during roaming
8 Huawei Confidential
Innovative RTU, Building a "Pay-as-You-Grow" Campus Network
+ =
Elastic architecture Various RTU licenses On-demand target network
RTU is short for right-to-use. RTU licenses can be used to improve the port rates and switching capacity of switches.
9 Huawei Confidential
Free Mobility: Policies Following Users, Ensuring Consistent Experience
Location: xx
Network
resources
Surabaya
Network Network
resources resources
1. Policy: permission
Bandung 2. Policy: security
Group Group ID Contextual Awareness (5W1H: Who, When, Where,
Name Whose, How) 3. Experience:
VIP 30 Leader, wired and wireless, anytime priority/bandwidth
Jakarta Guest 10 Guest, wireless, working hours…
10 Huawei Confidential
Intelligent O&M: Terminal Visibility, Fault Diagnosis and Analytics
Technical Solution
Initiate an NQA
ICMP test on
As-Is To-Be CampusInsight CampusInsight.
AAA DHCP
Step 2
Application quality analysis VoIP failure, poor quality, disconnection, and Layer 2
and path trace loop
AS-F15 AGS-F53 CS-F5 FW-F5
Port anomaly, optical module failure, PoE failure,
sudden traffic increase or decrease, packet loss during
Device fault analysis
forwarding, queue congestion, and threshold-cross
services
11 Huawei Confidential
CloudEngine S-Series Switch Portfolio (1/2)
Modular switches 25GE fixed switches
New S6730-H-V2
• 3.6 Tbps per slot • 2.4 Tbps per slot
(March 2023) 48 x 25GE, 6 x 100GE
• 50K users, 100K terminals • 10K APs, 50K users
VXLAN
• Clos orthogonal architecture • MACsec on 10GE, 25GE,
40GE, and 100GE ports
S16700-4/8
S12700E-4/8/12 S6730-H
24*100GE 6*100GE 48*10GE 24*10GE + 24*GE 2*100GE + 4*40GE
28 x 25GE, 4 x 100GE, 220 mm
36*100GE 18*100GE 24/36*40GE 48*10GE
VXLAN, MACsec
24*Multi-GE +
40*25GE 12*40GE 48*GE
24*GE
13 Huawei Confidential
Contents
1. Know More About Huawei
Page 14 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Wired and Wireless LAN Gartner Leader for 2022-2024
Common WLAN Issues Deteriorating User Experiences
network bandwidth.
iMaster NCE-CampusInsight, Ensuring Overall Experience of Networks, Users,
Applications, and Optimization
17 Huawei Confidential
3D Signal Simulation Resolves Coverage Holes or Weak Coverage
Problems from the Planning Perspective
Identify the obstacle height based on the AP deployment height and location, simulate signal coverage, and use 3D signal simulation to achieve more accurate effect.
CampusInsight spectrum analysis monitors the status of all channels on APs and displays the usage of each
channel, which is simple and easy to understand.
Constant-frequency device
Frequency scanning device Frequency hopping device
(2.4G wireless video and audio,
(Microwave oven, Bluetooth, (Cordless phone and cordless
5G wireless video and audio, baby
and game controller) phone base)
monitor, and ZigBee device)
With Many Innovations, We Build an Experience-Centric,
Highly Reliable Wireless Network
. . Ensuring wireless coverage and premium performance . .
Unique hardware design Beam training Codirectional matching of digital beams
Smart antenna:
try beam gain
try
Try-Best try
Traditional
antenna 20% wider coverage
• Patented design, this achieves all-round • Select the beam with the maximum gain, • Maximizes signal gains in the target STA
beamforming and more accurate beams. ensures optimal signal strength anytime. direction.
. . Ensuring wireless network-wide stable experience . .
25%
higher throughput in high-density multi-
user access scenarios
Or
256
STAs
1 Mbps/STA
MU-MIMO OFDMA OFDMA + MU-MIMO
Waste of spectrum resources Waste of spatial stream resources Both spatial streams and spectrum resources are well leveraged
21 Huawei Confidential
Intelligent Application Acceleration Technology, Ensuring Low-Latency
Experiences upon Multiple Services
Exclusive AI-based
AI-based application classification flow identification
VR gaming
IPTV
Unique intelligent application acceleration and HQoS
22 Huawei Confidential
Lossless Roaming + Dual Fed for Zero Packet Loss During Roaming
Competitive feature: lossless roaming, preventing packet loss Competitive feature: exclusive dual fed and selective receiving @
during roaming Wi-Fi 6 Advanced
Radio 1 AP AP Radio 2
P1 X P3 P4 P1 P2 X P4
CH1
P1 P2 P3 P4 P1 P2 P3 P4
AGV
Fed 1 CPE Fed 2
AGV Proactive packet loss mitigation, enhanced reliability, and reduced latency
AGV
Scenario: If a radio is roaming, the other radio is not, achieving zero packet loss, 99.999%
reliability, and 10 ms latency.
Pre-roaming Lossless resumable
• Pre-roaming traffic steering, transmission
1 improving efficiency by 100%
3 • Post-roaming data Smart warehousing: uninterrupted AGV services
• Roaming handover time: 50 playback without service
ms → 10 ms interruptions
Dual fed and selective receiving, high reliability, and zero packet loss
23 Huawei Confidential
Wi-Fi 7 with EHT320 and 4096 QAM, 2.4 times the maximum transmission rate than Wi-Fi 6
Wi-Fi 7 with Multi-RU allocation, greatly improves the utilization of radio resources
24 Huawei Confidential
Wi-Fi 7 MLO Enables Faster and More Reliable Wi-Fi Data Transmission
01010110
01010110
01010110
01010110
01010110
2.4 GHz or 5 GHz Wi-Fi 6 Wi-Fi 7 2.4 GHz 5 6 GHz
GHz
1 2 3 4 1 2 3 4
7
5 6 7 8 7
1 2 3 4
9 10 11 12 1 2 3 4
• Load balancing among multiple links, improving • Multi-fed and selective receiving, improving link
link bandwidth reliability
• Latency reduced by 80%
Upgrade to Wi-Fi 7, meeting wireless office needs over the next 5 years
80-channel 120-channel
Wi-Fi 6E Wi-Fi 7
26 Huawei Confidential
Huawei Wi-Fi 7: Zero Video Freezing in Video Conferences; Zero Packet Loss & Zero
Interruptions for Key Applications
27 Huawei Confidential
Huawei Wi-Fi 7 VIP Experience Upgrade: Dedicated Resources for VIP Users,
Zero Degradation on VIP Experience
Application scenario Huawei-only solution and benefits
Dedicated lane for VIP users,
preferential access anytime, anywhere
VIP
Dedicated lane for
VIP users
Preferential access
anytime, anywhere
• Unique VIP FastPass technology
• Dedicated slices for VIP users 50 ms (Huawei) vs >
200 ms (industry)
VIP-targeted
optimization
Enhanced signals Common user
for VIP users VIP user
Poor office experience for executives, difficult complaint handling
• Precise distance measurement, Huawei-only
per-packet power control
• Targeted signal enhancement for
VIP users
Proactive care for
VIP users
POS machine AGV PDA for medical Conference terminal Full-journey visibility on
image reading both wireless and wired
sides Real-time VIP user experience evaluation &
Hard to assure key services on terminals proactive care Fault warning (Huawei) vs.
none (industry)
28 Huawei Confidential
QoS Design — Wireless QoS (Wireless Queue Mapping)
On a WLAN, user traffic of different services is mapped to different queues based on the priority configured for each service.
This ensures that services that are sensitive to network parameters, such as audio and video services, can be preferentially
scheduled.
Modifying DSCP priorities based on application types Re-marking DSCP priorities of packets based on user groups
Internet Internet
VIP
29 Huawei Confidential
Flagship Wi-Fi 7 AP: AirEngine 8771-X1T
HE160 high-bandwidth
Triple radios Dynamic-zoom smart antennas
networking
Flexible switching between 5 GHz and 6 GHz Omnidirectional and high-density Continuous networking at HE160
on the local licensed spectrum coverage modes used on demand bandwidth, up to 320 MHz available
AirEngine 8760-X1-PRO
Independent hardware +
dual-band scanning
Real-time network optimization Liquid cooling Bionic shark fin cooling
* Works with CampusInsight to perform big data optimization.
Switchable 5 GHz-2
Real-time network
AirEngine 6760-X1 AP rate: 8.35 Gbps AP rate: 10.75 Gbps Flexible switchover
status awareness
AirEngine 6760-X1E Built-in IoT ZigBee, RFID, asset Hardware encryption: IPsec and DTLS
Security
module management, and ESL WPA3
* Right To Use (RTU): The number of spatial streams and functions are added through licenses.
Indoor Triple Radios Wi-Fi 6 AP: AirEngine 6761-21T
Radio 1 Radio 2
Radio 3
Power
21.2 W (excluding USB) USB 1
consumption
Power DC: 12 V ± 10% IoT
AirEngine 6761-21T supply PoE+ power supply expansion
USB extended external IoT
Indoor Mid-Range Wi-Fi 6 AP: AirEngine 5761-21
Module CPE
Power
17.9 W (excluding USB) USB 1
consumption
AirEngine 5761-21 DC: 12 V ± 10%
Power supply IoT expansion USB extended external IoT
PoE+ power supply
WLAN Product Portfolio (1/2)
Wi-Fi 6 (802.11ax) indoor AP Wi-Fi 6 (802.11ax) outdoor AP WAC
NEW AirEngine 8760R-X1 AirEngine 8760R-X1E
23/03 Wi-Fi 6E • Device rate: 10.75 Gbps • Device rate: 10.75 Gbps
• NSS: 8+8/4+12 • NSS: 8+8/4+4+4
• Built-in smart antennas • External antennas
• BLE 5.2, PoE out • BLE 5.2, PoE out
AirEngine 8760-X1-PRO AirEngine 8761-X1 AirEngine 6760-X1 AirEngine 6760-X1E AirEngine 6761-22T* • 1 x 10GE electrical + 1 x GE • 1 x 10GE electrical + 1 x GE
• Device rate: 10.75 Gbps • Device rate: 5.95 Gbps • Device rate: 10.75 Gbps • Device rate: 10.75 Gbps • Device rate: 6.575 Gbps electrical port + 1 x 10GE SFP+ electrical + 1 x 10GE SFP+
• NSS: 4+12/4+8+4 • NSS: 4+8 • NSS: 4+6/4+8/4+4+4 • NSS: 4+6/4+8/4+4+4 • NSS: 2+2+4 (6 GHz)
• Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • External antennas • Built-in smart antennas
• BLE 5.2, two built-in IoT slots • BLE 5.2, USB for IoT module • BLE 5.2, two built-in IoT slots • BLE 5.2, two built-in IoT slots • BLE 5.2 AC6805
• 2 x 10GE electrical + 1 x 10GE • 1 x 10GE electrical + 1 x GE • 1 x 10GE electrical + 1 x GE electrical • 1 x 10GE electrical + 1 x GE • 1 x 2.5GE electrical port, 1 x GE AirEngine 6760R-51 AirEngine 6760R-51E
• Device rate: 5.95 Gbps • Device rate: 5.95 Gbps
• Forwarding performance: 120 Gbps
SFP+ electrical + 1 x 10GE SFP+ electrical + 1 x 10GE SFP+ electrical port
Dynamic-Zoom • NSS: 4+4 • NSS: 4+4 • Maximum number of manageable APs: 6K
Smart Antennas • Built-in smart antennas • External antennas • Maximum number of access users: 64K
• BLE 5.2 • BLE 5.2
Hybrid Optical-
• 1 x 5GE electrical port + 1 x GE • 1 x 5GE electrical + 1 x GE
Electrical
electrical port + 1 x 10GE SFP+ electrical + 1 x 10GE SFP+
AirEngine 6761-21 AirEngine 6761-21E AirEngine 6761-21T AirEngine 5760-51
• Device rate: 3.55 Gbps • Device rate: 3.55 Gbps • Device rate: 6.575 Gbps • Device rate: 5.95 Gbps
Specification upgrade
• NSS: 4+4 • NSS: 4+4 • NSS: 2+2+4 • NSS: 2+4/4+4/2+2+4 AirEngine 5761R-11 AirEngine 5761R-11E
• Built-in Dynamic-Zoom • External antennas • Built-in smart antennas • Built-in smart antennas • Device rate: 1.775 Gbps • Device rate: 2.4 Gbps
Smart Antennas • BLE 5.2 • BLE 5.2 • BLE 5.2, two built-in IoT slots • NSS: 2+2 • NSS: 2+2
• BLE 5.2 • 1 x 2.5GE electrical port, 1 x • 1 x 2.5GE electrical port, 1 x • 1 x 5GE electrical port + 1 x GE • Built-in antennas • External antennas
• 1 x 2.5GE electrical port, 1 10GE SFP+ GE electrical port electrical • BLE 5.2 • BLE 5.2
x 10GE SFP+ NEW • 1 x GE electrical + 1 x SFP • 1 x GE electrical + 1 x SFP
23/03
AirEngine 9700-M1
• Forwarding performance: 120 Gbps
Wi-Fi 6 (802.11ax) scenario-specific AP • Maximum number of manageable APs: 3K
AirEngine 5761-21 AirEngine 5761-11 AirEngine 5762-12 AirEngine 5761-12 AirEngine 5762-10
• Device rate: 5.375 Gbps • Device rate: 1.775 Gbps • Device rate: 2.975 Gbps • Device rate: 1.775 Gbps • Device rate: 2.975 Gbps • Maximum number of access users: 32K
• NSS: 2+4 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2
• Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas
• BLE 5.2 • BLE 5.2 • BLE 5.2 • BLE 5.2, built-in dual IoT slots • 1 x GE electrical
• 1 x 2.5GE electrical port, 1 x • 1 x GE electrical • 1 x GE electrical • 2 x GE electrical AirEngine 6760-51EI
GE electrical port • Device rate: 4.8 Gbps
• NSS: 4
Wi-Fi 6 (802.11ax) wall plate AP • External antennas
NEW • 1 x 5GE electrical + 1 x GE electrical +
Port upgrade
23/03 1 x 10GE SFP+
Hybrid Optical-
Electrical AC6508
AirEngine 5761-11W AirEngine 5761-12W AirEngine 5762-12SW * AirEngine 5762-13W AirEngine 5762-15HW AirEngine 5762-17W • Forwarding performance: 10 Gbps
• Device rate: 1.775 Gbps • Device rate: 1.775 Gbps • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps • Maximum number of managed APs: 512
Wi-Fi 6 CPE UNR032H with vertical Wi-Fi 6 CPE UNR033H with
• NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 • NSS: 2+2 network ports horizontal network ports • Maximum number of access users: 4K
• Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Built-in smart antennas • Device rate: 2.975 Gbps • Device rate: 2.975 Gbps
• BLE 5.2 • BLE 5.2, PoE out • BLE 5.0 • BLE 5.0 • BLE 5.1 • BLE 5.1
• NSS: 2+2 • NSS: 2+2
• Uplink: 1 x GE electrical • Uplink: 1 x GE electrical • Uplink: 1 x GE electrical • Uplink: 1 x GE electrical • Uplink: 1 x 2.5G SFP • Uplink: 1 x GE electrical
• External antennas • External antennas
• Downlink: 4 x GE • Downlink: 4 x GE • Downlink: 1 x GE electrical • Downlink: 1 x GE electrical • Downlink: 4 x GE electrical • Downlink: 1 x GE electrical
electrical + 2 x RJ45 electrical + 2 x RJ45 (Optional colorful cover) • 4 x GE electrical • 4 x GE electrical
passthrough passthrough
WLAN Product Portfolio (2/2)
85%
Potential network faults
90%
User complaints
95%
Fault locating time
58%
Network-wide performance
38 Huawei Confidential
Cloud Campus 3.0 Solution for Indonesia Manufacturing Company New Plant
Challenges & Requirement
Analysis of Indonesia Manufacturing Company Challenges on their New Plants: Highly
Mobile AGV that have a large number of roaming times and Complex O&M.
• AGVs: are sensitive to packet loss and delay during roaming, required low latency to
running well
Network-wide automation | AI-powered • Difficult O&M: The problem occurs again and again, but cannot be located.
intelligent O&M
Huawei Solution
Huawei proposing Campus Network solution with the advanced WiFi 6 that supports AGVs
requirement and iMaster NCE Campus + CampusInsight to support Full Lifecycle Network
automation and AI-powered intelligent O&M
• WiFi6 Solution that support AGV Network Standards:
• Huawei's lossless roaming technology does Zero Packet Loss by ensuring zero
service interruptions for AGV scheduling, anytime, anywhere
• Intelligent O&M: Real-time link monitoring and intelligent O&M
Wired as a
supplement
Customer Benefits
The WiFi network performance is enhanced to meet the requirements of New Plant.
Existing • WiFi 6 Advanced solution helps lead the customer into the flexible production era,
New Plant Plants
ushering in lower costs, higher efficiency, and better quality.
• AI O&M → Visualized and accurate O&M, improving fault locating efficiency by 10 times
Huawei CloudCampus 3.0 Solution Enhanced Indonesia Top 3 Bank Smart Branch
Fully-Wireless Experience, Improve Business Performance
Network
layer Customer Benefits
With Huawei WIFI6 technology, wireless quality and stability improve 30% meet the
requirements of bank application experience.
• With fully-wireless banking hall no longer boring, more flexible and open space
Terminal • With Huawei WIFI6 improve wireless performance and reduce wireless interference issue
layer Smart ATM
• AI O&M Visualized and accurate O&M, improving fault locating efficiency by 10 times
Printer POS machine PC Security VR
terminal Machine
Contents
1. Know More About Huawei
Page 41 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Huawei is in the Gartner® Magic QuadrantTM for SD-WAN
• Huawei SD-WAN has been listed as the only challenger in the Gartner® Magic QuadrantTM for five consecutive years
• The only Chinese vendor in the Gartner® Magic QuadrantTM.、
• Huawei continues to rank No. 1 in China in terms of the SD-WAN market share.
2022
Gartner® Magic Quadrant™
For SD-WAN
Gartner, Magic Quadrant for SD-WAN, Sept. 2022. This report was named Magic Quadrant for WAN Edge Infrastructure from 2018 to 2021.
Gartner Peer Insights, https://www.gartner.com/reviews/market/sd-wan/vendor/huawei/product/huawei-sd-wan
Gartner, Magic Quadrant, and Peer Insights are registered trademarks and service mark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved. Gartner Peer Insights content consists of the opinions of individual end users
based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise
technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all
warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
42 Huawei Confidential
Digital Transformation: Huawei SD-WAN Helps Improve Production Efficiency
in Various Industries
Finance
Finance Large enterprise Retail store Energy
Financial services onto the cloud Remote office Retail 4.0 Digital gas station
43 Huawei Confidential
Challenges to Multi-Branch Services in the Cloud Era
44 Huawei Confidential
Simplified SD-WAN: Converged Deployment of LAN, WAN, and Security, Building Branch
Networks with Ultimate Experience
Integrated management, control, and analysis,
intelligent O&M
Network-wide automation | AI-
• LAN/WAN convergence, unified policy orchestration
powered intelligent O&M
• Batch site configuration, creating 1000 sites in a day
45 Huawei Confidential
Simplified/Batch Deployment, Higher Deployment Efficiency
Low efficiency, loose GUI relationships, and high Wizard-based template, batch deployment, higher
As-Is To-Be deployment efficiency
skill requirements
Site replication
46 Huawei Confidential
Application-based Intelligent Traffic Steering: Ensuring Experience of
Key Applications
Application-based intelligent traffic steering Customer benefits
Application controllability
and visibility
Application-based intelligent traffic steering,
• Traffic of key applications
Quick identification of key automatically switching traffic of key applications to
is automatically switched
applications the optimal link to the optimal link.
Intelligent traffic steering based on many factors,
FPI such as the application SLA, priority, and bandwidth
Feature
identification
• Hybrid links, such as MPLS,
Customized
applications
MPLS Internet, and LTE, are fully
SLA non- utilized.
compliance
SLA non-
compliance
Internet
Selecting the optimal link for
Key applications, such as key applications
video and ERP
47 Huawei Confidential
Per-Flow/Per-Packet Load Balancing: Ensuring a Bandwidth
Utilization of Over 90%
Uneven traffic distribution on links, resulting Per-flow and per-packet load balancing:
in low bandwidth utilization No congestion occurs on high-quality links, with a bandwidth utilization
Uneven traffic distribution on links of over 90%.
The primary link is congested while the secondary link
is idle.
P1 P2 P2 P3 P4 Packet
reassembly
Congested active link (MPLS) Key services MPLS (high-quality link) P1 P2 P3 P4
P1 P2 P3 P4
P1 P2 P3 P4
5G P1 P2 P3 P4 Receiving
secondary Sending end P1 P3 P4 end
Common services
link: (elephant flows)
idle 5G/Internet (lossy link)
• Per-flow/per-packet load balancing is configured for common services (elephant
flows) to share high-quality links.
• Packets on high-quality links are dynamically adjusted based on the bandwidth,
improving bandwidth utilization and preventing congestion.
Low comprehensive bandwidth • Only one retransmission is required upon packet loss on lossy links, preventing
packet loss and ensuring low latency.
utilization
48 Huawei Confidential
A-FEC: Ensuring Smooth Video Experience Even at 30% Packet Loss
Traditional: Artifacts appear on the video when the packet loss rate is A-FEC: No frame freezing occurs in case of 30% packet loss.
higher than 2%.
Note: A-FEC is supported in Huawei SD-WAN Solution.
49 Huawei Confidential
Built-in 6 Enterprise-level Security Capabilities, Ensuring Site Security
Flexible traffic steering for SaaS applications,
Branch HQ ensuring service quality
Centralized Internet access
• Local breakout, central breakout, and a combination of them, guaranteeing
services
Local breakout Internet
NetEngine AR for SaaS • Application-based flexible traffic steering
50 Huawei Confidential
Visible and Measurable SD-WAN Benefits, Facilitating Refined Operations
As-Is: lack of visibility into SD-WAN egress optimization To-Be: measurable and quantifiable SD-WAN
results optimization results
SPR traffic steering: How much experience Traffic steering: improved experience
Quality- Load Traffic steering: traceable
improvement? based
traffic
balancing
4 ? 3
Internet)
compression compression
Service packets
P1 P2 P1 P4 ? P1 P2 P4
P1 P2 P1 P4
Customer
Measurable Traceable
Intuitive comparison of traffic steering benefits, quantifiable Playback of the entire traffic steering, including intuitively displaying the
benefits
WAN data compression benefits selected link (good or not) and the resulting benefits
51 Huawei Confidential
Portfolio of Huawei NetEngine AR Routers
HQ/Large branches NetEngine AR6300
NetEngine AR8140 NetEngine AR6280 5G-RU-101 5G-SIC
NetEngine
AR6300/AR6200
series
SRU-400H/SRU-600H SRU-400H/SRU-600H
Small- and medium-sized
enterprise branches
NetEngine AR6121E NetEngine AR6140E-9G-2AC NetEngine AR6710-L50T2X4 NetEngine AR6710-L26T2X4
NetEngine AR6100
series
Small enterprises
AR651 AR651W AR657W AR651W-8P
NetEngine AR650
series
Available only outside China
SOHO
NetEngine AR617VW-LTE4EA
AR611W AR617VW-LTE4
AR610 series
Available only Available only in Latin
outside China America
52 Huawei Confidential
Huawei SD-WAN solution for integrated LAN and WAN management at
Indonesian Bank
Challenges & Requirement
Analysis of Pain Points on the Live Network: High MPLS Cost, Complex O&M, and High Labor
Investment.
• Single MPLS connection: MPLS is 5 to 10 times expensive of the Internet.
• High labor cost: Currently, Level 2 engineers are required to deliver a single site.
Network-wide automation | AI-powered • Difficult O&M: The problem occurs again and again, but cannot be located.
intelligent O&M • Long-term SLA: The expected time required for troubleshooting is 4.38 hours per year.
Wired as a …
Customer Benefits
supplement
The network quality is doubled to meet the requirements of bank application experience.
• Intelligent traffic diversion:Link usage up to 90%
• App & Link Quality Visibility:Timely optimization to guaranty experience
HQ Branch Improve the efficiency by three times and ensure the project SLA
• ZTP→ The deployment efficiency of branch banks is improved to 1 person-day per store.
53 Huawei Confidential • AI O&M → Visualized and accurate O&M, improving fault locating efficiency by 10 times
Contents
1. Know More About Huawei
Page 54 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Three Challenges Facing Data Center Networks on the Way of Evolution
Apps
DC
IT team: Network team:
service view network view Controller A Controller B
.
Risk control Bills
. X: breakpoint
Leaf Leaf
.. ..
Multiple rounds of network solution review Separated services and networks, siloed data 100+ breakpoints for complex services
40% faults caused by configuration errors Multiple departments take hours for joint No unified management: many distinct
standards and devices from different
troubleshooting vendors across clouds
55 Huawei Confidential
Easy CloudFabric: Intelligent + Simplified, Delivering Easy Network Experience
Easy deployment
• Fast deployment: automatic orchestration of
cross-cloud services and minute-level application
rollout
Easy Easy • Accurate configuration: simulation + verification,
deployment Easy O&M evolution 100% change correctness
Easy O&M
• Lossless upgrade: no packet loss during the
CloudFabric 3.0 upgrade, zero service interruptions
• Automatic troubleshooting: intelligent full-flow
analysis and fault locating in minutes
CloudEngine 16800/16800-X
CloudEngine 9800/8800/6800
Easy evolution
• Unified heterogeneous management:
supports heterogeneous co-management and
General-purpose flexible service migration
Storage network HPC network
computing network
• Unified protocol: hyper-converged Ethernet,
36%↓ TCO
56 Huawei Confidential
iMaster NCE Integrates Management, Control, and
Analysis
Past Now
iMaster NCE
EMS/NMS SDN controller Network analyzer Open API
Intent engine
eSight/U2000 iMaster NCE- iMaster NCE- Design
Fabric FabricInsight Studio
Management Control Analysis
NETCONF/YANG Telemetry
CLI/SNMP/Qx NETCONF/YANG
OpenFlow/OVSDB Telemetry
CLI/SNMP/Qx OpenFlow/OVSDB
Traditional Traditional
SDN device SDN device
device device
• Multiple independent products, including the NMS, • Manager, controller, and analyzer convergence
controller, and analyzer • Closed-loop automation
Page 57 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Microsegmentation
Microsegmentation, also called EPG-based secure isolation, groups servers on
a DCN based on rules. It applies traffic control policies based on End Point
Groups (EPGs) to simplify O&M and implement secure management and
control.
• Efficient forwarding
Microsegmentation is effective in scenarios that require high forwarding and
weak security because it does not introduct traffic detour or cause the
bottleneck of forwarding performance.
Delivers source and destination
EPGs to source and destination
TOR switches, and EPG policies
• Distributed security
to the destination TOR switch
Traffic of VMs is isolated on access switches. East-west isolation can be
DIP: NVE2_IP
③
DIP: NVE2_IP
implemented without relying on firewalls.
SIP: NVE1_IP SIP: NVE1_IP
VNI ② ④
VNI • Unified isolation
S_EPG NVE1 NVE2 S_EPG
Payload Payload Microsegmentation implements the zero-trust security model. It implements
fine-grained isolation based on discrete IP addresses and VM names. In
DIP: 10.10.20.3 ① ⑤ DIP: 10.10.20.3
SIP: 10.10.10.1 SIP: 10.10.10.1 addition, it provides unified isolation for VMs, PMs, and BMs.
Payload VM1 VM2 Payload
10.10.10.1 10.10.20.3
DC
Page 58 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
CloudFabric Service Automation Scenarios
The CloudFabric solution supports four service automation scenarios, including network virtualization, computing, cloud-network integration -
OpenStack, and Kubernets container network.
Network virtualization Computing Cloud-network integration Container network
VMware vCenter
System Center
OpenShift
VM VM VM VM C C
VM VM Hypervisor VM Hypervisor Hypervisor C
VM VM VM C
VM VM VM VM C
VM VM C
VM VM
Page 59 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Main Functions of iMaster NCE-FabricInsight
Intelligent O&M
Telemetry-Powered
Network Health Evaluation "1-3-5" Troubleshooting
Monitoring
Common indicators: Proactive Health check report: Multi- Abnormal root causes: Quick
monitoring in multiple modes dimensional heath details diagnosis and rectification
• Real-time monitoring and proactive • Comprehensive network health check • Root cause diagnosis for a detected
subscription to all-scenario data based on the five-layer model typical fault in 3 minutes
• Data collection using multiple modes, • Real-time or periodic push of • Troubleshooting together with iMaster
such as gRPC or syslog professional health check reports NCE-Fabric
Page 60 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
CloudEngine 16800 Series
Parameter CE8850-64CQ-EI
64 x 100GE QSFP28/40GE QSFP+
Port type
ports
Parameter CloudEngine
48 x 25GE/50GE 8 x 100GE/200GE
48 x 25GE + 8 x 100GE: 4 Tbps
Switching capacity 48 x 50GE + 8 x 200GE: 8 Tbps
CloudEngine 6866-48S6CQ-P 48 x 25GE + 8 x 100GE: 1450 Mpps
Forwarding performance 48 x 50GE + 8 x 200GE: 2175 Mpps
Buffer 64 MB
Forwarding
954 Mpps
performance
Page 66 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.
Entered the Gartner Magic Quadrant Eleven Consecutive Times (2013-2023) and
Named a Challenger Seven Consecutive Times (2017-2023)
67 Huawei Confidential
New Challenges Facing Firewalls
Difficult identification of
Service performance bottleneck Slow manual handling
unknown threats
Digital transformation drives interconnection Ever-changing unknown threats are highly It takes several hours to handle security
as well as the explosive growth of data, making difficult to identify, only 60% of which can be issues manually due to massive security
the service processing performance of accurately detected by traditional NGFWs. policies and logs.
firewalls become a bottleneck.
⚫ Growing popularity of all-optical networks and ⚫ Growing known threats ⚫ Analysis of massive security policies and logs
exponentially increased network traffic ⚫ Rapidly changed unknown threats ⚫ Time-consuming closed-loop threat handling
⚫ Higher demands on performance and latency ⚫ Ever-emerging encrypted attacks ⚫ Requirement for unified management
caused by the ever-increasing security service during interworking with other network
requirements products and security products
⚫ IPv6 network reconstruction
68 Huawei Confidential
NP-based Acceleration of Data Service Offloading and 10
μs-Level Low-Latency and Fast Forwarding
As Is To Be
Session1 Session1
30 µs–50 µs General- ARM core
purpose CPU Session2 Session2
Unloading
+ flow tables
Network
10-18 Network Forwarding Flow1
10 µs–18 µs forwarding chip microseconds (NP) acceleration Flow2
engine
(NP)
69 Huawei Confidential
Dynamic/Static Intelligent Uplink Selection Based on Multi-
Egress Links
Static intelligent uplink selection Dynamic intelligent uplink selection IPSec/Internet/MPLS-based
uplink selection
⚫ User-defined link weight ⚫ User-defined link SLA (latency, jitter, and ⚫ Intelligent IPSec uplink selection
⚫ Uplink selection by binding ISP address packet loss rate), selecting the optimal link
for traffic forwarding ⚫ Internet/MPLS-based uplink selection
sets to interfaces
⚫ Application-based intelligent uplink selection
70 Huawei Confidential
Extensive Security Database and Comprehensive
Security Detection Capability
⚫ Identification of 6000+ applications ⚫ Main web category database capacity > 160 million ⚫ Signatures: 20,000+
⚫ Full coverage of mainstream application protocols ⚫ Local high-performance self-learning hot database ⚫ Attack detection technology based on
⚫ Encrypted P2P protocols, Web 2.0, mobile ⚫ Effective data matching rate: 96%+ vulnerability and behavior analysis
applications, and micro applications ⚫ Enterprise-level web categories: 100+ ⚫ Anti-evasion technology based on context
⚫ Rapid response to customized requirements semantic restoration
⚫ Real-time analysis of 500 million URLs on the cloud
⚫ Default blocking rate > 85%
Unified management
• The SecoManager supports unified management
of multiple security products, such as the
iMaster NCE
firewall, IPS, and anti-DDoS, and centralized
control of security policies, improving O&M
efficiency
• The firewall supports plug-and-play and can
O&M Policy proactively register with the SecoManager after
connecting to the network
Automatic security service orchestration
Management Report • Policies can be automatically deployed to
SecoManager
corresponding firewalls based on protected
network segments, and network segment
changes will trigger policy changes of device
reselection and deployment
• Customers can configure and manage security
Configuration Policy Log sending policies in the logical partition view
delivering control
Flexible management in multiple
scenarios
...
• In data center(DC) scenarios, the SecoManager
AntiDDoS AIFW IPS and DC SDN controller are deployed together to
centrally manage firewalls
72 Huawei Confidential
Intranet Control and Security Isolation
Internet
• Deployment location: The USG6000F series is deployed at the
intranet border of a large or midsize enterprise.
R&D department 1 USG6000F • Fine-grained security policy control: provides fine-grained security
Untrust policy control based on 5-tuple traffic, service applications, user
information, and time ranges, effectively implementing intranet
management and control.
• Quota control: controls intranet users' online traffic and time to
prevent bandwidth abuse and decreased working efficiency due to
R&D department 2 long online time.
73 Huawei Confidential
Huawei HiSecEngine USG6500F Series AI Firewalls
2*10GE SFP+ +
Fixed 10*GE RJ45 + 2*GE 10*GE RJ45 + 4*GE SFP + 8*GE
Interfaces 2*GE SFP + 8*GE 2*GE RJ45 + 8*GE COMBO + 2*10GE SFP+
SFP 2*10GE SFP+ RJ45 + LTE
RJ45 + LTE
IPv4 Firewall
Throughput(1
518/512/64- 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 7/7/3.6 Gbps 9/8/4 Gbps
byte, UDP)
IPv6 Firewall
Throughput
2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 2.5/2.5/2.5 Gbps 5/5/3.6 Gbps 7/7/3.6 Gbps 9/8/4 Gbps
(1518/512/64-
Byte, UDP)
External
Optional, 64 GB microSD card available for purchase Optional, M.2 SSD (64 GB/240 GB), hot-swappable
Storage
Power
Single power supply Optional dual power modules for 1+1 redundancy
Supplies
74 Huawei Confidential
Huawei HiSecEngine USG6600F&USG6700F Series AI Firewalls
4*100GE(QSFP28) +
8*GE COMBO + 4*GE(RJ45) + 2*100GE(QSFP28) + 2*40G(QSFP+)+
8*GE COMBO + 4*GE(RJ45) + 10*10GE(SFP+) 16*25GE(ZSFP+) +
Fixed Interfaces 4*GE(SFP)+ 6*10GE(SFP+) 8*25(ZSFP+) + 20*10GE(SFP+)
8*10GE(SFP+)
IPv4 Firewall
Throughput(151 15/15/15 Gbit/s 25/25/25 Gbit/s 35/35/35 Gbit/s 50/50/40 Gbit/s 80/80/40 Gbit/s 100/100/60 Gbit/s 160/160/80 Gbit/s 240/240/120 Gbit/s
8/512/64-byte,
UDP)
IPv6 Firewall
Throughput 15/15/15 Gbit/s 25/25/25 Gbit/s 35/35/25 Gbit/s 50/50/25 Gbit/s 80/80/25 Gbit/s 100/100/45 Gbit/s 160/160/50 Gbit/s 240/240/75 Gbit/s
(1518/512/64-
Byte, UDP)
Form Factor 1U
External
Optional, SATA (1 x 2.5 inch) supported, 240 GB/960 GB/1000 GB
Storage
Power Single AC power supply; optional dual
Dual AC power supplies
Supplies AC power supplies
Note: Some 100GE interfaces and 25GE interfaces on the USG6710F/USG6715F/USG6725F are combo interfaces.
75 Huawei Confidential
Thank You
www.huawei.com
Page 76 Copyright © 2020 Huawei Technologies Co., Ltd. All rights reserved.