------------- ✅ Perfect Thumbnail Prompt (Copy This Every Time) ------------- “Generate a 1280×720 YouTube thumbnail. Make sure NOTHING touches or crosses the left or right edges. Keep all text centered inside safe margins. Do NOT crop, do NOT zoom, keep full frame visible.” ------------- ✅ Optional Add-Ons (if you want to include logos or diagrams) ------------- “Place logos inside the frame, not touching any edges. Keep all elements fully visible with padding around them.” -------------✅ Full Prompt Example (Best for Your Use Case) ------------- “Generate a clean 1280×720 YouTube thumbnail, all elements centered, nothing touching or crossing edges, text inside safe margins, no overflow, no cropping, logos fully inside with padding.” Deleted Permanently: mmadilkhan1@outlook.com mmadilkhan@outlook.com 1310159789789 Corvit@12345 +966597227131 Asadhaf786 NA Email------------------|ID-------------|Pass-------------------|Phone----------|Browser----------------|myccount1 Ph. Bond-----|Remarks mmadilawan@gmail.com Zh4148781 Geopak@Huawei.mmadil123 +966597227131 mmadilawan@gmail.com 966597227131 KSA Official mmadil.comm@gmail.com Geopak@Huawei123 NESPk Telnet NA malikadil@mmadil.com Geopak@Huawei.mmadil123 03165507778 malikadil@mmadil.com NA ============================================================= Key Points for eNSP to Work Proper and avoid error 40 etc.: 1. Use VirtualBox version 5.2.44 2. use eNSP version eNSP V100R003C00SPC100 with Vbox version 5.2.44 3. Use WinPcap_4_1_3 Optional: The "Oracle_VM_VirtualBox_Extension_Pack-5.2.44.vbox-extpack" is here if you want to use VirtualBox for running proper VMs. ============================================================= ============================================================ Huawei EVE-NG images download: https://forum.huawei.com/enterprise/intl/en/thread/run-ce12800-ne40e-in-eve-ng/667237045992570881?blogId=667237045992570881 Huawei eNSP images download: https://forum.huawei.com/enterprise/intl/en/thread/resources-downloading-for-ensp/667245683301826561?blogId=667245683301826561 ============================================================ ------------------- Huawei Exam & Certifications ------------------- HCNA Training (HCIA Training) Huawei H12-811 Exam Certifications/ Couses: https://e.huawei.com/en/talent/cert/#/careerCert Huawei Certificate Verification: https://e.huawei.com/en/talent/#/cert/certificate-verification ------------------- Huawei useful Web Addresses ------------------- https://e.huawei.com/en/talent/#/pearson-VUE-appointment Exam Booking https://www.pearsonvue.com/us/en/huawei.html https://e.huawei.com/en/talent/usercenter/#/home/ e-Huawei Account info https://uniportal.huawei.com/myaccount1/ Uniportal Account info https://id1.cloud.huawei.com/AMW/portal/userCenter/index.html Huawei ID User Detailed Info https://e.huawei.com/en/myspace/accountinformation MyHuawei My Learning: https://e.huawei.com/en/talent/portal/#/ Certiifcates & Learning Profile: https://talent.shixizhi.huawei.com/center/privateCenter.htm?schoolId=1365189427395223554&type=personalCenter_MyCertificates&sxz-lang=en_US Talent Pakistan: https://talent.shixizhi.huawei.com/center/privateCenter.htm?schoolId=1365189427395223554&type=studyCenter_LearningTask&sxz-lang=en_US&mapDetail=3&mapDetailId=1856513213288005633 ------------------- HCNA Course Content ------------------- Mainly, we will focus on the below lessons on this Huawei Course (HCIA Course): Network Basics Basic Protocols (ICMP, ARP, FTP, TELNET) IPv4 Addressing IPv6 Addressing TCP and UDP VLANs Spanning Tree (STP,RSTP) Link Aggregation Routing Basics RIP Overview OSPF Overview WAN GRE and IPSec VPN DHCP NAT SNMP Access Lists Basic Router Security AAA Huawei CLI Huawei Cisco Operation ------------------------------------------------------------------------------------------------------------------------------ system-view enable Enter global configuration mode [nespk]sysname nespk hostname Set device hostname save all / set save-configuration / commit write memory / copy run start Save running configuration display changed-configuration time Show last configuration change time display current-configuration show running-config Show current running configuration display saved-configuration show startup-config show saved/startup configs display interface brief show ip interface brief Display interface status and IP info display interfaces show interfaces show all interfaces status display interface GigabitEthernet0/0/1 show interfaces Gig0/0/1 Show detailed interface info display clock show clock / show time Show system time display users show users Show logged-in users display ip interface brief show ip interface brief Show IP addresses on interfaces display vlan / display vlan 10 / display vlan summary show vlan Show VLAN information [nespk]vlan 10 vlan 10 Create VLAN quit exit Exit current mode to just previous mode return (Ctrl + Z) end Exit from system-view all the way back to user view display startup-config show startup-config Show startup configuration reboot reload Restart the device [nespk]display mac-address show mac address-table Display MAC address table [nespk]display arp show arp Display ARP table [nespk]display version show version Show device OS version and uptime [nespk]display logbuffer show logging Display system logs [nespk]display ip route show ip route Show IPv4 routing table [nespk]display ipv6 route show ipv6 route Show IPv6 routing table [nespk]display startup show startup-config Show saved configuration [nespk]shutdown / undo shutdown shutdown / no shutdown Disable or enable interface [nespk]display cpu-usage show processes cpu Display CPU utilization [nespk]display memory-usage show processes memory Display memory utilization [nespk]display version / display device show version Show device version & hardware info [nespk]display ntp status show ntp status Show NTP synchronization status [nespk]ping ping Basic connectivity test [nespk]tracert traceroute Trace route to destination <<<<<<<<<<<<<< Routing software Operating systems & network operating systems >>>>>>>>>>>>> -------------------1. Linux-based ------------------- ````````` Entirely free ````````` Endian Floppyfw IPFire LEDE libreCMC OpenWrt VyOS Zeroshell ````````` Partly proprietary ````````` AirOS & EdgeOS Alliedware Plus DD-WRT ExtremeXOS FRITZ!Box RouterOS SmoothWall Tomato Vyatta ------------------- 2. FreeBSD-based ------------------- ````````` Entirely free ````````` m0n0wall OPNsense pfSense ````````` Partly proprietary ````````` Junos OS Juniper -------------------3. Proprietary ------------------- Cisco IOS cisco NX-OS cisco Cisco IOS XE cisco Cisco IOS XR cisco ExtremeWare TiMOS Alcatel-Lucent VRP Huawei ******************* Huawei Hardware ******************* ------------------- Switches ------------------- S2700 //Entry-level L2/L3 switch S3700 //Gigabit L2/L3 switch S5700 //Enterprise Gigabit L2/L3 switch S5720 //Enhanced Enterprise Gigabit L2/L3 switch S6700 //High-end L3 Gigabit switch S7700 //Core switch, high-performance L3 S9700 //Data center/core switch, high-density 10G/40G ------------------- Routers ------------------- AR100 //Branch office router AR1200 //Enterprise VPN router AR2200 //High-performance enterprise router AR3200 //Multi-service router for enterprise AR3600 //Carrier-grade router NE40E //Core router, large-scale ISP/enterprise networks NetEngine 5000E //High-end backbone router ------------------- Firewalls ------------------- USG200 //Entry-level next-gen firewall USG6000V //Virtual NGFW USG6300 //High-performance next-gen firewall F100 //Industrial firewall F500 //Enterprise-grade firewall ******************* Cisco CLI Modes ******************* Modes: Representation Command to go to mode 1. User Exec mode Switch> PRESS ENTER on startup 2. Privilage Exec/enable mode Switch# Switch> enable 2. Global Configuration mode /Priv. Config. Switch(config)# Switch# configure terminal 3. interface Configuration mode/Priv. Int. Switch(config-if)# Switch(config)# interface INTERFACE_NAME 4. VLAN Configuration mode switch(vlan)# switch# vlan database ******************* Huawei CLI or VRP (Versatiile Routing Platform) BASIC Details ******************* UNIX base OS Default User: NULL Default Pass: NULL Modes: Representation Command to go to mode 1. User View NA (Default) 2. System View [Switch] Switch# system-view 3. Interface View [Switch-] [Switch] interface 4. Protocol View [Switch-ospf1] [Switch] vlan batch *********************** Shortcut Keys or Hotkeys *********************** [Huawei]Hotkey Ctrl_G "display interfaces" configures manual short keys Key Combination Function / Description | --------------------------- | ---------------------------------------------------------- | Ctrl + A | Moves the cursor to the beginning of the current line | | Ctrl + B | Moves the cursor one character to the left | | Ctrl + C | Stops the currently executing function | | Ctrl + D | Deletes the character at the current cursor position | | Ctrl + E | Moves the cursor to the end of the last line | | Ctrl + F | Moves the cursor one character to the right | | Ctrl + H | Deletes one character to the left of the cursor | | Ctrl + K | Terminates outgoing connections during connection establishment phase | | Ctrl + N or Cursor Down | Displays the next command in the history command buffer | | Ctrl + P or Cursor Up | Displays the previous command in the history command buffer | | Ctrl + T | Enters the question mark “?” | | Ctrl + W | Deletes a string (word) to the left of the cursor | | Ctrl + X | Deletes all characters to the left of the cursor | | Ctrl + Y | Deletes the cursor position and all characters to its right | | Ctrl + Z | Returns to User View | | Ctrl + ] | Terminates an incoming connection or redirect connection | | Esc + B | Moves the cursor one string (word) to the left | *********************** System/Software/ VRP OS Management Commands *********************** --------------- Reset the switch or Router --------------- dir show directory delete flash:/vrpcfg.zip delete a file form flash: directory display version display startup *********************** File Management Commands *********************** dir show directory dir /all View all files including hidden/system pwd print working directory mkdir ABCD create folder in root directory more view content of text file cd change directory rmdir remove directory copy file.zip file.txt copy and rename in same directory copy file.zip file1.zip copy and rename in same directory move file.txt flash:/folder/ moce the file to some directory delete goes to Recycle Bin delet unreserved backup delete permanently undelete restore form recycle bin reset recycle-bin reset recycle-bin file 3 Delete Only One File from Recycle-bin 3 is index# not file name rename xyz.zip nms.txt rename folder ✅ 1. Create an empty file system-view [Huawei] cd flash:/ [Huawei] touch myfile.txt ✅ 2. Create a file with text (using the built-in editor) system-view [Huawei] cd flash:/ [Huawei] edit myfile.txt startup saved-configuration configure any cofigs file for next startup ------------------ USB Drive Configs ------------------ mount usb: // Makes the router recognize the USB drive. unmount usb: // Safely disconnects the USB drive. ✅1️⃣ Insert USB Use a FAT32-formatted USB drive. Insert into the USB port on the router. ✅2️⃣ Check USB contents dir usb0: // Lists all files on USB. ✅3️⃣ Copy file from USB to flash copy usb0:/myfile.txt flash:/myfile.txt // usb0:/myfile.txt → file on USB ✅4️⃣ Copy file from flash to USB copy flash:/myfile.txt usb0:/myfile.txt ------------------ copy file from or to TFTP Server ------------------ tftp 10.1.1.1 get vrpcfg.txt flash:/vrpcfg.bak copy file from TFTP server to Flash tftp 10.1.1.1 put flash:/vrpcfg.txt vrpcfg.bak copy file from flash to TFTP Server *********************** Reset Router Configs *********************** reset saved-configuration clear saved configurations display startup show saved or startup configs reboot display current-configuration ✅ 2️⃣ Factory Reset When You Forgot the Password Console cable required Connect console Power ON router During boot, press Ctrl + B Boot menu appears Enter password: Huawei@123 (default boot-menu password) Choose ("7. Clear configuration") Confirm Reboot router ✔ Router boots completely fresh. ✅ 3️⃣ Hard Reset Button (only on some AR models) If your AR router has a RESET pinhole: Hold RESET button for 10–15 seconds while powered ON Release when SYS or RUN LED flashes fast ✔ Router resets to factory defaults. (Not all AR models have this button.) ✅ 4️⃣ Restore Only the Admin Username/AAA (Not full reset) If you only want to remove users: system-view undo local-user admin undo aaa ✅ 1️⃣ Reload router WITHOUT saving (quick reset of running config) This clears all current config and reloads the router with the old startup-config. reboot Save the configuration? [y/n]: n //Choose n. ✔ Router will reboot ✔ All current (unsaved) changes are wiped ✔ Device loads the last saved configuration ****************************** NTP / Time / Date Management ****************************** // ------------------- Time Zone Configuration ------------------- clock timezone PST ? //Show options to add or subtract offset add Add time zone offset minus Minus time zone offset clock timezone PST add 05:00 //Set PST time zone with +5 hours offset // ------------------- Manual Date & Time ------------------- clock datetime 22:06:00 2024-04-11 //Set system time manually (HH:MM:SS YYYY-MM-DD) clock daylight-saving-time // ------------------- NTP Server Configuration ------------------- interface Ethernet0/0/0 ip address 192.168.10.1 255.255.255.0 //Assign IP to server interface [nespk]ntp refclock-master 1 //Set device as NTP master with stratum 1 [nespk]ntp authentication enable //Enable NTP authentication [nespk]ntp authentication-keyid 45 authentication-mode md5 nespk@123 //Set NTP authentication key (MD5) [nespk]ntp trusted authentication-keyid 45 //Trust this authentication key [nespk]ntp server source-interface Vlanif 100 //Use specific interface as NTP source [nespk]undo ntp server disable //Enable NTP server if previously disabled // ------------------- NTP Client Configuration ------------------- ntp server disable //Disable default NTP server ntp ipv6 server disable //Disable IPv6 NTP server [nespk2]ntp authentication enable //Enable NTP authentication on client [nespk2]ntp authentication-keyid 45 authentication-mode md5 nespk@123 //Set client authentication key [nespk2]ntp unicast-server 192.168.10.1 authentication-keyid 45 //Set NTP server IP and associate key // ------------------- Verification / Troubleshooting ------------------- display clock //Show current system date and time display ntp status //Show NTP status and synchronization info display ntp sessions //Display current NTP sessions [nespk]display ntp trace //Trace NTP packet activity for troubleshooting display ntp-service status //Shows detailed NTP service running state display ntp-service session //Displays session info between NTP peers *************************************** Header / Login Banner *************************************** ------------------- Shell Header Banner ------------------- [Huawei]header shell information &Hello! Welcome to system!& //Short message displayed at shell session start [Huawei]header shell information % PRESS ENTER //Start multi-line long banner Hello! Welcome to system Hello! Welcome to system Hello! Welcome to system Hello! Welcome to system % //End multi-line banner // ------------------- Login Header Banner ------------------- [Huawei]header login information &Hello! Welcome to system!& //Short message displayed at user login [Huawei]header login information % PRESS ENTER //Start multi-line login banner Hello! Welcome to system Authorized users only. Access monitored. By logging in, you agree to terms. % //End multi-line login banner // ------------------- Verification Commands ------------------- display header shell information //Show configured shell banner display header login information //Show configured login banner // ------------------- Undo / Remove Configurations ------------------- undo header shell information //Remove shell banner undo header login information //Remove login banner ************************************ Display or Show Commands ************************************ ------------------ VLAN & Interface ------------------- [nespk] display vlan // Show all VLANs [nespk] display vlan 10 // Show specific VLAN 10 [nespk] display vlan summary // Show VLAN summary [nespk] display interface brief // Show brief info of all interfaces display interfaces // Show detailed interface info [nespk] display interface description // Show interface descriptions display ip interface brief // Show interface IP addresses and status display mac-address // Show all learned MAC addresses display mac-address static // Show static MAC addresses display mac-address sticky // Show sticky MAC addresses display arp // Show ARP table display ip routing-table // Show routing table display current-configuration // Show running configs [nespk] display changed-configuration time // Show last configuration change time display startup ------------------ System & Users ------------------- display version // Show software version display clock // Show system time display users // Show currently logged-in users display history-command // Show command history at current config level ------------------ System Hardware ------------------- display power-supply // Show power supply status reboot //Restart the switch or router shutdown //Shutdown the device startup //Start the device after shutdown display device //Show device hardware information display version //Show device software and version details display cpu-usage //Show current CPU usage display memory-usage //Show memory utilization display temperature //Show device temperature status display fan //Show fan status display power //Show power supply status display environment //Show all environmental parameters (temperature, voltage, fan, power) display health //Shows overall device health summary display patch-information //Displays loaded or active patches display logbuffer //Show system log messages stored in buffer display alarm //Show current active alarms display alarm all //Show all alarms including cleared display interface brief //Show interface status (up/down, protocol) display voltage //Show voltage readings of power supply modules display board //Show line cards and chassis board status display cpu-usage history //Show CPU usage history over time display memory-usage history //Show memory usage history over time display temperature-history //Show temperature history display fan all //Show status of all fans including redundant fans display power all //Show status of all power modules including redundant units display startup //Show startup configuration display log //Show system logs stored in flash display version detail //Show detailed version info, including patch and build display cpu-usage peak //Show peak CPU usage ------------------ Routing Protocols ------------------- display rip // Show RIP routing info display ospf peer // Show OSPF neighbors and states display ospf routing // Show OSPF routes display ospf interface // Show OSPF interface info display bgp peer // Show BGP neighbors display bgp routing-table // Show BGP routing table display ip routing-table display ip routing-table protocol rip display ip routing-table protocol ospf display ip routing-table protocol isis display ip routing-table protocol bgp ------------------ LLDP & CDP ------------------- display lldp local // Show local LLDP info display lldp neighbor // Show LLDP neighbors display lldp statistics // Show LLDP statistics ------------------ Ether-Trunk / LACP ------------------- display eth-trunk // Show all Ether-Trunks display eth-trunk 1 // Show specific Ether-Trunk 1 display lacp counters // Show LACP counters/statistics ------------------ Spanning Tree Protocol ------------------- display stp // Show STP info for all VLANs display stp brief // Show STP summary display stp interface // Show STP per interface display stp topology-change // Show recent STP topology changes ------------------ DHCP ------------------- display dhcp server statistics // Show DHCP server statistics display dhcp client // Show DHCP client info display dhcp lease // Show DHCP lease table display dhcp snooping binding // Show DHCP snooping binding table ------------------ Security / Port Security ------------------- display port-security // Show port security status display mac-address sticky // Show learned sticky MAC addresses display acl all // Show all access control lists ------------------ Undo / Clear / Reset ------------------- reset counters // Reset interface counters undo shutdown // Enable interface shutdown // Disable interface clear arp // Clear ARP table clear ip route * // Clear routing table entries ************************************** User Management & AAA ************************************** [nespk]aaa //Enter AAA mode to create/manage users ---------------- Local AAA Users ----------------- [nespk-aaa]local-user ADMIN password cipher Admin@123 //Create local user with encrypted password [nespk-aaa]local-user ADMIN password irreversible-cipher Admin@123 //Create local user with irreversible encrypted password [nespk-aaa]local-user GUEST password simple Guest123 //Create local user with plain text password [nespk-aaa]local-user ADMIN service-type http telnet terminal ssh ftp ppp //Assign allowed services to user [nespk-aaa]local-user ADMIN privilege level 15 //Assign superuser privilege level 15 [nespk-aaa]local-user GUEST privilege level 1 //Assign low privilege level ---------------- Remote AAA Server Integration (RADIUS/TACACS+) ----------------- [nespk]aaa [nespk-aaa]radius-server shared-key cipher radiusKey123 //Set RADIUS shared key [nespk-aaa]radius-server authentication 192.168.1.100 1812 //Add RADIUS authentication server [nespk-aaa]radius-server accounting 192.168.1.100 1813 //Add RADIUS accounting server [nespk-aaa]domain RADIUS-AAA [nespk-aaa-domain-radius-a] authentication-scheme default //Apply AAA scheme for RADIUS [nespk-aaa-domain-radius-a] accounting-scheme default //Apply accounting scheme [nespk-aaa]tacacs-server shared-key cipher tacacsKey123 //Set TACACS+ shared key [nespk-aaa]tacacs-server 192.168.1.200 49 //Add TACACS+ server [Huawei-ui-vty0-4]authentication-mode aaa //Enable authentication from AAA server (local + remote) [Huawei-ui-console0]authentication-mode aaa //Enable authentication from AAA server ---------------- RSA Key for SSH ----------------- [nespk]rsa local-key-pair create //Generate RSA key pair for SSH (press ENTER, 1024-bit) ---------------- Console, Telnet & SSH Configurations ----------------- ------------------- SSH ------------------- [nespk]user-interface vty 0 4 //Configure VTY 0-4 sessions [nespk-ui-vty0-4]protocol inbound telnet //Allow Telnet [nespk-ui-vty0-4]protocol inbound ssh //Allow SSH [nespk-ui-vty0-4]protocol inbound all //Allow all protocols [nespk]stelnet server enable //Enable SSH server [nespk]ssh client first-time enable //Enable first-time SSH client connections --------OPTIONAL-------- [Huawei]ssh user USERNAME authentication-type password //Set SSH user authentication type [Huawei]ssh user USERNAME service-type stelnet //Assign SSH service to user [Huawei]ssh server enable //Enable SSH server globally [Huawei]ssh client enable //Enable outgoing SSH client ------------------- Console Password & Timeout ----------------- [Huawei]user-interface console 0 4 //Configure console sessions 0-4 [Huawei-ui-console0]authentication-mode password //Authenticate via password [Huawei-ui-console0]set authentication password cipher abcd123 //Set console password OR [Huawei-ui-console0]authentication-mode aaa //Authenticate via AAA server [Huawei-ui-console0]protocol inbound all //Allow all protocol sessions [Huawei-ui-console0]idle-timeout mm ss //Set console idle timeout [Huawei-ui-console0]undo idle-timeout //Remove console idle timeout ------------------- Telnet Password & Timeout ----------------- [Huawei]telnet server enable //Enable Telnet server [Huawei]user-interface vty 0 4 //Configure VTY session 0-4 [Huawei-ui-vty0-4]authentication-mode password //Authenticate via password [Huawei-ui-vty0-4]set authentication password cipher abcd123 //Set VTY password OR [Huawei-ui-vty0-4]authentication-mode aaa //Authenticate via AAA server [Huawei-ui-vty0-4]protocol inbound telnet //Allow only Telnet or all [Huawei-ui-vty0-4]idle-timeout mm ss //Set VTY idle timeout [Huawei-ui-vty0-4]undo idle-timeout //Remove VTY idle timeout ------------------- Verification Commands ------------------- display local-user //Show all local users display local-user USERNAME //Show a specific user display aaa //Show AAA configuration display ssh server status //Show SSH server status display ssh client //Show SSH client sessions display telnet-client //Show Telnet/SSH client sessions display user-interface vty 0 4 //Check VTY session configs display user-interface console 0 //Check console session configs display current-configuration section aaa //Show AAA configuration section display current-configuration section ssh //Show SSH configuration section ------------------- Undo / Delete Commands ------------------- [Huawei-aaa]undo local-user USERNAME //Delete AAA/local user [Huawei-ui-vty0-4]undo authentication-mode aaa //Disable AAA authentication on VTY [Huawei-ui-console0]undo authentication-mode aaa //Disable AAA authentication on console [Huawei-ui-console0]undo set authentication password //Remove console password [Huawei-ui-vty0-4]undo set authentication password //Remove VTY password [nespk]undo stelnet server enable //Disable SSH server [Huawei]undo telnet server enable //Disable Telnet server [Huawei-ui-console0]undo idle-timeout //Remove console timeout [Huawei-ui-vty0-4]undo idle-timeout //Remove VTY timeout ------------------- Optional / Advanced Commands ------------------- [Huawei]user-interface vty 0 4 logging synchronous //Display incoming logs properly on VTY [Huawei-ui-vty0-4]idle-timeout 10 0 //Set VTY idle timeout to 10 minutes [Huawei-ui-console0]idle-timeout 5 0 //Set console idle timeout to 5 minutes [Huawei-ui-vty0-4]protocol inbound all //Allow all inbound protocols (Telnet + SSH) ******************* Simple Network Management Protocol SNMP configs ******************* [nespkSW2] snmp-agent [nespkSW2] snmp-agent community read cipher nespk@123 [nespkSW2] snmp-agent sys-info version all display snmp-agent *********************** Link Layer Discovery Protocol (LLDP) Configurations *********************** IEEE 802.1ab Standard ------------------ Enable LLDP ------------------- [Huawei] lldp enable //Enable LLDP globally on the device [Huawei-GigabitEthernet0/0/1] lldp enable //Enable LLDP on a specific port ------------------ Disable LLDP ------------------- [Huawei] undo lldp enable //Disable LLDP globally [Huawei-GigabitEthernet0/0/1] undo lldp enable //Disable LLDP on a specific port ------------------ Optional / Advanced ------------------- [Huawei] lldp trap-interval 10 //Set LLDP trap interval to 10 seconds (default 5s) [Huawei-GigabitEthernet0/0/1] lldp tlv-select port-description system-name system-capabilities management-address //Customize TLV info sent on interface [Huawei] lldp holdtime 120 //Set holdtime for LLDP information (in seconds) [Huawei-GigabitEthernet0/0/1] lldp med enable //Enable LLDP-MED on interface (for VoIP / media devices) ------------------ Verification Commands ------------------- display lldp local //Display local LLDP information display lldp neighbor //Show all LLDP neighbors display lldp statistics //Show LLDP statistics display lldp neighbor interface GigabitEthernet0/0/1 //Show LLDP info for a specific interface display current-configuration section lldp //Show LLDP configuration ------------------ Undo / Delete Commands ------------------- [Huawei] undo lldp trap-interval //Revert LLDP trap interval to default [Huawei-GigabitEthernet0/0/1] undo lldp tlv-select //Remove custom TLV selection on interface [Huawei] undo lldp holdtime //Revert holdtime to default [Huawei-GigabitEthernet0/0/1] undo lldp med enable //Disable LLDP-MED on interface ************************************** Ether-Trunk / Ether-Channel / LACP Configurations ************************************** ------------------ Create Ether-Trunk ------------------- [Huawei] interface Eth-Trunk 1 [Huawei-Eth-Trunk1] description LACP-TRUNK //Set description for trunk [Huawei-Eth-Trunk1] mode lacp-static //Set Ether-Trunk mode (static LACP) [Huawei-Eth-Trunk1] port link-type trunk //Set trunk link type [Huawei-Eth-Trunk1] port trunk allow-pass vlan 10 20 30 //Allow VLANs on trunk ------------------ Assign physical interfaces ------------------- [Huawei] interface GigabitEthernet0/0/1 [Huawei-GigabitEthernet0/0/1] eth-trunk 1 //Add interface to Ether-Trunk [Huawei-GigabitEthernet0/0/1] lacp priority 100 //Optional: set LACP port priority [Huawei] interface GigabitEthernet0/0/2 [Huawei-GigabitEthernet0/0/2] eth-trunk 1 //Add second interface [Huawei-GigabitEthernet0/0/2] lacp priority 100 //Optional: set LACP port priority ------------------ Undo / Delete Ether-Trunk ------------------- [Huawei] interface GigabitEthernet0/0/1 [Huawei-GigabitEthernet0/0/1] undo eth-trunk //Remove interface from Ether-Trunk [Huawei] interface GigabitEthernet0/0/2 [Huawei-GigabitEthernet0/0/2] undo eth-trunk //Remove interface from Ether-Trunk [Huawei-Eth-Trunk1] undo port link-type trunk //Undo trunk configuration on Ether-Trunk [Huawei] undo interface Eth-Trunk 1 //Delete Ether-Trunk interface ------------------ Optional / Advanced ------------------- [Huawei-Eth-Trunk1] lacp enable //Enable LACP (if not in static mode) [Huawei-Eth-Trunk1] lacp system-priority 32768 //Set system priority for LACP [Huawei-GigabitEthernet0/0/1] lacp fast-suspend enable //Enable fast suspend for inactive link [Huawei-GigabitEthernet0/0/2] lacp fast-suspend enable ------------------ Verification / Troubleshooting ------------------- display eth-trunk 1 //Show Ether-Trunk summary display eth-trunk 1 verbose //Detailed Ether-Trunk info display lacp peer //Show LACP peers and negotiation display interface GigabitEthernet0/0/1 //Check if interface is in trunk and Ether-Trunk display interface GigabitEthernet0/0/2 display current-configuration section eth-trunk //Show Ether-Trunk configuration *********************************************** Huawei Switch Stacking Configurations *********************************************** ------------------ Configure Stack Ports on SW1 ------------------- [nespkSW1] interface stack-port 0/1 [nespkSW1-stack-port0/1] port interface XGigabitEthernet0/0/3 enable //Enable stack port, type Y to confirm [nespkSW1] interface stack-port 0/2 [nespkSW1-stack-port0/2] port interface XGigabitEthernet0/0/4 enable //Enable second stack port ------------------ Configure Stack Priority and Slot ------------------- [nespkSW1] stack slot 0 priority 200 //Change slot 0 priority from default 100 to 200 [nespkSW1] stack slot 0 renumber 1 //Renumber slot 0 to slot 1 (optional) ------------------ Configure Stack Ports on SW2 ------------------- [nespkSW2] interface stack-port 0/1 [nespkSW2-stack-port0/1] port interface XGigabitEthernet0/0/3 enable [nespkSW2] interface stack-port 0/2 [nespkSW2-stack-port0/2] port interface XGigabitEthernet0/0/4 enable [nespkSW2] stack slot 0 priority 190 //Change slot 0 priority from default 100 to 190 ------------------ Verification / Display ------------------- display stack //Show stack topology and status display stack member //Show stack member info display stack port //Show stack port status display stack configuration //Show stack configuration ------------------ Undo / Remove Stack Configurations ------------------- [nespkSW1-stack-port0/1] undo port interface XGigabitEthernet0/0/3 enable //Disable stack port 0/1 [nespkSW1-stack-port0/2] undo port interface XGigabitEthernet0/0/4 enable //Disable stack port 0/2 [nespkSW2-stack-port0/1] undo port interface XGigabitEthernet0/0/3 enable //Disable stack port 0/1 [nespkSW2-stack-port0/2] undo port interface XGigabitEthernet0/0/4 enable //Disable stack port 0/2 [nespkSW1] undo stack slot 0 priority //Reset priority to default [nespkSW2] undo stack slot 0 priority ******************* Spanning Tree Protocol (STP) Configurations ******************* Huawei supports: STP (802.1D) RSTP (802.1w) Rapid Spanning Tree Protocol MSTP (802.1s – default & recommended) Multiple Spanning Tree Protocol ✅ 1️⃣ Enable / Set STP Mode RSTP system-view stp mode rstp MSTP (default on most Huawei switches): system-view stp mode mstp Classic STP (Not recommended): system-view stp mode stp ✅ 2️⃣ Set Root Bridge / Secondary Root Set this switch as Primary Root: system-view stp priority 0 Secondary Root: system-view stp priority 4096 ✅ 3️⃣ Enable STP on Interface Huawei automatically enables STP globally, but you can tune per interface. Change Port STP Role Cost: interface GigabitEthernet 0/0/1 stp cost 20000 Set Port Priority: interface GigabitEthernet 0/0/1 stp port priority 16 ✅ 4️⃣ Edge Ports (PortFast Equivalent) Use for servers, endpoints — not switches. RSTP/MSTP: interface GigabitEthernet 0/0/10 stp edged-port enable Disable: stp edged-port disable ✅ 5️⃣ BPDU Guard / BPDU Protection Enable BPDU Protection stp bpdu-protection Disable an edge port if BPDU is received: interface GigabitEthernet 0/0/10 stp edged-port enable stp bpdu-protection enable ✅ 6️⃣ Loop Protection (recommended) Prevents loops if BPDUs stop arriving on a root/blocked port. system-view stp loop-protection Per interface: interface GigabitEthernet 0/0/2 stp loop-protection ✅ 7️⃣ TC (Topology Change) Protection Avoids massive MAC flushes. system-view stp tc-protection ✅ 8️⃣ MSTP Example Create instance 1 for VLANs 10–20 system-view stp mode mstp stp region-configuration region-name HUAWEI instance 1 vlan 10 to 20 active region-configuration ------------------ Enable BPDU Filter on Interface ------------------- [nespkSW2-GigabitEthernet0/0/1] stp bpdu-filter enable //Prevent interface from sending/receiving BPDU ------------------ Enable Port Isolation ------------------- [nespkSW2-GigabitEthernet0/0/1] port-isolate enable group 1 //Enable port isolation (group 1) --------------------- Verification commands --------------------- display stp display stp brief display stp interface Ethernet 0/0/1 display stp slot display stp vlan 1 display current-configuration | include stp display stp root //Show STP root bridge information display port-isolate group 1 //Show port isolation status display stp topology-change //Show recent STP topology changes ------------------ Undo / Remove Configurations ------------------- [nespkSW2-GigabitEthernet0/0/1] undo stp bpdu-filter //Disable BPDU filter on interface [nespkSW2-GigabitEthernet0/0/1] undo port-isolate //Disable port isolation on interface [nespkSW2] undo stp mode //Disable STP globally (revert to default) ************************************** Port Security Configurations ************************************** ------------------ Enable Port Security ------------------- [nespk] interface GigabitEthernet0/0/1 [nespk-GigabitEthernet0/0/1] port security enable //Enable port security on interface ------------------ Sticky MAC Address ------------------- [nespk-GigabitEthernet0/0/1] port-security mac-address sticky //Automatically learn and stick MAC addresses OR [nespk-GigabitEthernet0/0/1] port-security mac-address sticky H-H-H //Manually stick a specific MAC address ------------------ Verification Commands ------------------- display mac-address sticky //Show all sticky MAC addresses display mac-address static //Show all static MAC addresses display mac-address H-H-H //Show details of a specific MAC address ------------------ Undo / Remove Configurations ------------------- [nespk-GigabitEthernet0/0/1] undo port-security mac-address sticky //Remove sticky MAC addresses [nespk-GigabitEthernet0/0/1] undo port security //Disable port security on interface <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< UID (Unit Identifier) button / LED >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> display device id-led Shows whether the UID indicator is on or off 🔆 2. Turn ON the Device ID LED set device id-led on ➡ This turns the locator LED on to help identify the device. 🔇 3. Turn OFF the Device ID LED set device id-led off ➡ Turns the ID LED off after locating the device ******************************** Ports / Interfaces Configurations ******************************** | Speed | Full Name | Short Form | Example | | -------- | --------------------------- | ---------- | ----------------------------------- | | 1 Gbps | GigabitEthernet | GE | `GigabitEthernet0/0/1` or `GE0/0/1` | | 10 Gbps | Ten-GigabitEthernet | 10GE | `10GE1/0/1` | | 25 Gbps | Twenty-FiveGigabitEthernet | 25GE | `25GE1/0/12` | | 40 Gbps | Forty-GigabitEthernet | 40GE | `40GE1/0/1` | | 100 Gbps | Hundred-GigabitEthernet | 100GE | `100GE1/0/12` | | 400 Gbps | Four-HundredGigabitEthernet | 400GE | `400GE1/0/1` | Format: // Example: display interface 100GE1/0/12 | Vendor | 1G | 10G | 25G | 40G | 100G | Example | | --------| -- | ---- | ---- | ----- | ----- | ----------- | | Cisco | Gi | Te | Twe | Fo | Hu | Hu1/0/12 | | Huawei | GE | 10GE | 25GE | 40GE | 100GE | 100GE1/0/12 | | Juniper | ge | xe | et | xe/et | et | et-0/0/12 | ---------------------------------- Copper Ports Ethernet Loop -------------------------------- ==================== HUAWEI (VRP) ==================== ! 100M / 1G Copper system-view interface GigabitEthernet0/0/1 undo shutdown speed auto duplex auto negotiation auto quit ! Or force interface GigabitEthernet0/0/1 speed 1000 duplex full quit ! 10G RJ-45 interface 10GE1/0/1 undo shutdown negotiation auto quit ! Verify display interface GigabitEthernet0/0/1 display interface 10GE1/0/1 ------------------ Basic Interface Commands ------------------- [nespk] interface GigabitEthernet0/0/1 // Select interface [nespk-GigabitEthernet0/0/1] shutdown // Shut down the interface [nespk-GigabitEthernet0/0/1] undo shutdown // Bring up the interface [nespk-GigabitEthernet0/0/1] restart // Restart the interface [nespk-GigabitEthernet0/0/1] ip address 192.168.10.1 255.255.255.0 // Assign IP address [nespk-GigabitEthernet0/0/1] undo ip address // Remove IP address [nespk-GigabitEthernet0/0/1] speed 1000 // Set interface speed [nespk-GigabitEthernet0/0/1] duplex full // Set duplex mode [nespk-GigabitEthernet0/0/1] negotiation auto // Enable auto-negotiation ------------------ Port Description ------------------- [nespk-GigabitEthernet0/0/1] description Uplink to RouterA // Add description to interface [nespk-GigabitEthernet0/0/1] undo description // Remove interface description ------------------ Range / Group Operations ------------------- [nespk] interface range GigabitEthernet0/0/4 to GigabitEthernet0/0/16 // Select multiple interfaces [nespk] shutdown // Shut down multiple interfaces [nespk] undo shutdown // Bring up multiple interfaces [nespk] port-group group-member Gi0/0/4 to Gi0/0/16 // Group multiple ports for operations [nespk] undo port-group group-member Gi0/0/4 to Gi0/0/16 // Remove ports from group port-group group-member Ethernet 0/0/1 Ethernet 0/0/4 ------------------ Eth-Trunk or Ether-Channel Commands ------------------- interface Eth-Trunk 1 mode lacp interface GigabitEthernet 0/0/1 eth-trunk 1 quit interface GigabitEthernet 0/0/2 eth-trunk 1 quit // in case of VLANs Assignment interface Eth-Trunk 1 mode lacp port link-type trunk port trunk allow-pass vlan all ^^^^^^^^^^^^^^^^^^^^^^ OR ^^^^^^^^^^^^^^^^^^^^^^^^ sysname SW1 # vlan batch 50 60 interface Eth-Trunk10 port link-type trunk port trunk allow-pass all mode lacp-static # interface GigabitEthernet0/0/1 description Ether-Trunk-SW1-SW2 eth-trunk 10 # interface GigabitEthernet0/0/2 description Ether-Trunk-SW1-SW2 eth-trunk 10 # interface GigabitEthernet0/0/3 description Ether-Trunk-SW1-SW2 eth-trunk 10 # interface GigabitEthernet0/0/4 description ACCESS-PORT port link-type access port default vlan 50 # interface GigabitEthernet0/0/5 description ACCESS-PORT port link-type access port default vlan 60 ^^^^^^^^^^^^^^^^^^^^^^ Configure load-balancing (recommended) ^^^^^^^^^^^^^^^^^^^^^^ interface Eth-Trunk 1 load-balance src-dst-ip For servers / data traffic: load-balance src-dst-ip For L2-only networks: load-balance src-dst-mac 🧠 Why Convergence Is Still Slow In lacp-static: No LACP PDUs exchanged No fast/slow timers Link failure is detected only by: Physical link down Interface debounce MAC aging Forwarding-table updates ➡ Result: 3–10 seconds delay (sometimes more in eNSP) This is expected behavior, especially in simulators. ✅ What You CAN Do in eNSP (Best Possible Optimization) 🔹 1) Reduce interface down-delay (IMPORTANT) interface GigabitEthernet1/0/1 port link-type trunk carrier down-hold-time 0 ✔ Faster physical link-down detection 🔹 2) Disable STP delay on access/trunk links (LAB ONLY) interface Eth-Trunk 1 stp disable //this method works fine ⚠ Use ONLY in lab, never production blindly ==================== CREATE ETH-TRUNK ===================== [HUAWEI] interface Eth-Trunk 1 # Create Port-Channel (Eth-Trunk) interface [HUAWEI-Eth-Trunk1] mode lacp-dynamic # Enable LACP Dynamic (negotiated, safe, recommended) ==================== FAST LACP CONVERGENCE ================= [HUAWEI-Eth-Trunk1] lacp timeout fast # Enable FAST LACP timers (1s hello instead of 30s) # Reduces failover time to ~1–3 seconds ==================== LIMIT ACTIVE LINKS ==================== [HUAWEI-Eth-Trunk1] max active-linknumber 2 # Limits number of active member links # Prevents re-calculation delays, improves stability ==================== ENABLE PREEMPTION ===================== [HUAWEI-Eth-Trunk1] lacp preempt enable # Allows higher-priority links to rejoin automatically # Ensures preferred links are always active ==================== CONFIGURE SYSTEM PRIORITY ============== [HUAWEI] lacp system-priority 100 # Lower value = higher priority # Controls which switch becomes LACP master ==================== CONFIGURE MEMBER PORTS ================= [HUAWEI] interface range GigabitEthernet1/0/1 to 1/0/2 # Select physical interfaces [HUAWEI-if-range] eth-trunk 1 # Bind interfaces to Eth-Trunk 1 [HUAWEI-if-range] undo shutdown # Bring physical interfaces UP ==================== SET PORT PRIORITY ====================== [HUAWEI] interface GigabitEthernet1/0/1 [HUAWEI-GigabitEthernet1/0/1] lacp port-priority 100 # Higher priority member (preferred link) [HUAWEI] interface GigabitEthernet1/0/2 [HUAWEI-GigabitEthernet1/0/2] lacp port-priority 200 # Lower priority backup link ==================== OPTIONAL: VLAN TRUNK =================== [HUAWEI] interface Eth-Trunk 1 [HUAWEI-Eth-Trunk1] port link-type trunk # Set Eth-Trunk as VLAN trunk [HUAWEI-Eth-Trunk1] port trunk allow-pass vlan 10 20 30 # Allow VLANs across the Port-Channel ==================== VERIFICATION COMMANDS ================== display eth-trunk 1 # Shows Eth-Trunk status and selected member ports display eth-trunk trunkport # Shows which interfaces are selected by LACP display lacp peer # Shows LACP neighbor and negotiation status display lacp port GigabitEthernet1/0/1 # Shows LACP timer, state, and priority for the port display interface Eth-Trunk 1 # Shows total bandwidth and traffic utilization display interface GigabitEthernet1/0/1 display interface GigabitEthernet1/0/2 # Shows per-link traffic (load-balancing verification) ==================== FAILOVER TEST ========================== interface GigabitEthernet1/0/1 shutdown # Simulate link failure display eth-trunk 1 # Eth-Trunk should remain UP (fast convergence) undo shutdown # Restore link ============================================================ ------------------ Eth-Trunk or Ether-Channel Verification ------------------- display eth-trunk 1 // Check Eth-trunk status display interface Eth-Trunk 1 // Check Eth-trunk details display eth-trunk 1 verbose // Check members display lacp statistics eth-trunk 1 // check Stats display lacp peer display port trunk display port vlan Eth-Trunk 10 display lacp error packet display eth-trunk 1 load-balance display lacp brief ------------------ VLAN Interface Commands ------------------- [nespk] vlan 10 [nespk-vlan10] quit // Exit VLAN configuration [nespk] interface Vlanif10 [nespk-Vlanif10] ip address 192.168.1.2 255.255.255.0 // Assign VLAN interface IP [nespk-Vlanif10] undo ip address // Remove VLAN interface IP [nespk-Vlanif10] shutdown // Shut down VLAN interface [nespk-Vlanif10] undo shutdown // Bring up VLAN interface [nespk-Vlanif10] restart // Restart VLAN interface [nespk] interface Ethernet0/0/1 [nespk-Ethernet0/0/1] port link-type access // Set port as access [nespk-Ethernet0/0/1] port default vlan 10 // Assign port to VLAN 10 [nespk-Ethernet0/0/1] undo shutdown // Bring up port [nespk] interface Ethernet0/0/2 [nespk-Ethernet0/0/2] port link-type trunk // Set port as trunk [nespk-Ethernet0/0/2] port trunk allow-pass vlan 10 20 30 // Allow multiple VLANs on trunk [nespk-Ethernet0/0/2] undo shutdown // Bring up trunk port [nespk] interface Ethernet0/0/3 [nespk-Ethernet0/0/3] shutdown // Shut down port [nespk-Ethernet0/0/3] undo shutdown // Bring up port +++++++++++++++++++++++++ Ports / Interfaces Verification Commands +++++++++++++++++++++++++ display interface description // Verify interface descriptions display ip interface brief // Verify IP addresses and interface status display interface brief // Check interface status summary display interface GigabitEthernet0/0/1 // Check detailed interface status display vlan // Verify VLANs display vlan summary // Show VLAN summary display current-configuration section interface // Show interface configuration ------------------ Show Optical Interface Status ------------------- display transceiver interface GigabitEthernet0/0/1 //Show SFP/optical module details on interface display transceiver interface Ten-GigabitEthernet0/0/1 //Show SFP+ details for 10G interface display transceiver verbose //Show detailed optical module info for all interfaces display transceiver statistics //Show optical power statistics (Tx/Rx) display transceiver eeprom interface GigabitEthernet0/0/1 //Show SFP EEPROM info (vendor, type, serial number) display interface GigabitEthernet0/0/1 //Check interface admin/link state and speed display interface Ten-GigabitEthernet0/0/1 display interface description //Show interface description to identify optical links ------------------ Optical Power & Diagnostics ------------------- display transceiver diagnostic interface GigabitEthernet0/0/1 //Show Tx/Rx power, voltage, temperature display transceiver alarm //Show optical module alarm/warning events display interface GigabitEthernet0/0/1 counters errors //Check errors (CRC, FCS) on optical port ------------------ Configure / Enable / Disable ------------------- interface GigabitEthernet0/0/1 undo shutdown //Enable optical interface shutdown //Disable optical interface ------------------ Port Speed & Duplex ------------------- interface GigabitEthernet0/0/1 speed 1000 //Force 1G speed duplex full //Force full duplex ------------------ SFP Module Mode ------------------- interface GigabitEthernet0/0/1 transceiver detect enable //Enable SFP detection (auto-detect) transceiver detect disable //Disable SFP detection ------------------ Display SFP / Optical Statistics ------------------- display interface GigabitEthernet0/0/1 | include current display interface GigabitEthernet0/0/1 | include rate display transceiver interface GigabitEthernet0/0/1 | include temperature display transceiver interface GigabitEthernet0/0/1 | include voltage display transceiver interface GigabitEthernet0/0/1 | include tx-power display transceiver interface GigabitEthernet0/0/1 | include rx-power ------------------ Undo / Remove Optical Configurations ------------------- interface GigabitEthernet0/0/1 undo speed //Remove forced speed config undo duplex //Remove forced duplex config undo transceiver detect //Remove transceiver detection setting ------------------ Undo / Remove other interface Configurations ------------------- [nespk-GigabitEthernet0/0/1] undo shutdown // Remove shutdown on interface [nespk-GigabitEthernet0/0/1] undo ip address // Remove IP address [nespk-Ethernet0/0/1] undo port link-type // Revert port type [nespk-Ethernet0/0/2] undo port trunk allow-pass vlan // Remove allowed VLANs from trunk [nespk] undo vlan 10 // Delete VLAN 10 [nespk-Vlanif10] undo shutdown // Shut down VLAN interface ------------------ Optional / Advanced ------------------- display diagnostic interface GigabitEthernet0/0/1 //More detailed diagnostics display logbuffer | include transceiver //Check logs for optical events/errors display alarm active | include optical //Show optical alarms display interface GigabitEthernet0/0/1 | include link-status //Check if optical link is up/down ******************************** Advanced VLAN Configurations ******************************** // ------------------- Basic VLANs ------------------- [nespk]vlan 10 //Create VLAN 10 [nespk-vlan10]name Users //Assign name to VLAN 10 [nespk]vlan 20 //Create VLAN 20 [nespk-vlan20]name Management //Assign name to VLAN 20 [nespk-vlan10]description "User VLAN for general staff" //Add optional description // ------------------- Access Ports ------------------- [nespk]interface GigabitEthernet0/0/1 [nespk-GigabitEthernet0/0/1]port link-type access //Set port as access [nespk-GigabitEthernet0/0/1]port default vlan 10 //Assign VLAN 10 [nespk-GigabitEthernet0/0/1]port voice vlan 30 //Assign voice VLAN 30 (IP Phones) // ------------------- Trunk Ports ------------------- [nespk]interface GigabitEthernet0/0/2 [nespk-GigabitEthernet0/0/2]port link-type trunk //Set port as trunk [nespk-GigabitEthernet0/0/2]port trunk allow-pass vlan 10 20 30 //Allow multiple VLANs [nespk-GigabitEthernet0/0/2]port trunk pvid vlan 10 //Default VLAN for untagged frames [nespk-GigabitEthernet0/0/2]description "Trunk to Core Switch" [nespk-GigabitEthernet0/0/2]display this //Show config at this level // ------------------- Private VLANs (PVLAN) ------------------- [nespk]vlan 100 //Create Primary PVLAN [nespk-vlan100]private-vlan primary //Define as primary [nespk-vlan100]private-vlan association 101 102 //Associate secondary VLANs [nespk]vlan 101 //Create isolated secondary VLAN [nespk-vlan101]private-vlan isolated //Define as isolated [nespk]vlan 102 //Create community secondary VLAN [nespk-vlan102]private-vlan community //Define as community // ------------------- Q-in-Q (VLAN Stacking) ------------------- [nespk]interface GigabitEthernet0/0/3 [nespk-GigabitEthernet0/0/3]port link-type trunk //Set port as trunk [nespk-GigabitEthernet0/0/3]port trunk allow-pass vlan 10 20 //Allow inner VLANs [nespk-GigabitEthernet0/0/3]port vlan-stacking enable //Enable Q-in-Q tagging // ------------------- VLAN ACL Binding ------------------- [nespk]acl number 3000 //Create ACL 3000 [nespk-acl-basic-3000]rule permit ip source 192.168.10.0 0.0.0.255 //Permit subnet [nespk-acl-basic-3000]rule deny ip //Deny others [nespk-vlan10]acl 3000 inbound //Bind ACL 3000 inbound to VLAN 10 // ------------------- Batch VLAN Creation ------------------- [nespk]vlan batch 40 to 50 //Create VLANs 40-50 [nespk]vlan batch 60 70 80 //Create VLANs 60, 70, 80 // ------------------- Delete / Remove VLANs ------------------- [nespk]undo vlan 20 //Delete VLAN 20 [nespk-GigabitEthernet0/0/2]undo port trunk allow-pass vlan 20 //Remove VLAN 20 from trunk [nespk-vlan10]undo acl 3000 //Remove ACL binding // ------------------- Verification Commands ------------------- display vlan //Show all VLANs display vlan 10 //Show details of VLAN 10 display vlan summary //Show brief VLAN summary display port vlan //Show all port VLAN info display port vlan gig0/0/1 //Show VLAN info for specific port display private-vlan //Show PVLAN configuration display acl 3000 //Show ACL 3000 details display interface description //Show port descriptions display vlan trunk //Show trunked VLANs // ------------------- Optional / Advanced ------------------- [nespk-vlan30]description "Voice VLAN for IP Phones" //Add description for voice VLAN [nespk-vlan100]description "Primary PVLAN" //Description for PVLAN [nespk-GigabitEthernet0/0/3]port qos trust dscp //Enable QoS on trunk [nespk-GigabitEthernet0/0/3]port link-type trunk [nespk-GigabitEthernet0/0/3]port trunk allow-pass vlan all //Allow all VLANs on trunk ******************************** LLDP Configurations ******************************** Link Layer Dicovery Protocol system-view lldp enable ------------- LLDP configuration per interface ------------- ✅Enable LLDP Globally First Enable LLDP on one interface interface GigabitEthernet 0/0/1 lldp enable Disable LLDP on that interface interface GigabitEthernet 0/0/1 lldp disable ------------------ LLDP-MED ------------------- ✅LLDP-MED = LLDP for “Media Endpoint Devices” It is an extension of LLDP used mainly for: IP Phones (Cisco, Avaya, Huawei, Yealink, etc.) VoIP devices Video conferencing endpoints Medical / emergency devices Purpose: Provide automatic VLAN, QoS, location, and power information to endpoints. ------------------ LLDP TLVs ------------------- ✅TLV = Type – Length – Value LLDP transmits information in small blocks called TLVs. Each TLV carries one type of information such as: | TLV Name | Purpose | | ----------------------- | -------------------------------- | | Chassis ID TLV | Switch MAC | | Port ID TLV | Port number | | TTL TLV | Aging timer | | Port Description TLV | Port name/description | | System Name TLV | Hostname of switch | | System Description TLV | OS/version | | System Capabilities TLV | Switch/router/phone capabilities | | Management Address TLV | IP address of switch | lldp tlv-enable port-description-tlv lldp tlv-enable management-address-tlv lldp tlv-enable system-name-tlv lldp tlv-enable system-description-tlv -------------------- LLDP Timers ------------------- ✅ 1️⃣ lldp transmit-interval How often the switch sends LLDP packets out the interface. lldp transmit-interval 5 //Send LLDP packet every 5 seconds. Use: Smaller interval = faster neighbor discovery Larger interval = less traffic ✅ 2️⃣ lldp hold-multiplier How long the neighbor entry stays in the table if LLDP packets stop arriving. Formula: Hold Time = transmit-interval × hold-multiplier lldp hold-multiplier 4 // If interval = 5 sec → neighbor removed after 5 × 4 = 20 seconds of silence. Use: Higher multiplier = keep neighbor longer Lower = detect removal faster ✅ 3️⃣ lldp reinit-time Delay before LLDP starts sending packets when the interface comes up or LLDP is (re)enabled. lldp reinit-time 2 // Wait 2 seconds after port is up before starting LLDP advertisements. Use: Avoids sending LLDP during very early port flaps. ⭐ Full Picture Example If you configure: lldp transmit-interval 5 // LLDP packet every 5 seconds lldp hold-multiplier 4 // Neighbor entry timeout = 20 seconds lldp reinit-time 2 // When port comes up, LLDP waits 2 seconds before transmitting ------------------------ LLDP Verification ------------------------ display current-configuration | include lldp display lldp local display lldp local interface Ethernet 0/0/1 display lldp neighbor display lldp neighbor brief display lldp statistics display lldp statistics interface Ethernet 0/0/1 display lldp statistics | include Transmit display lldp statistics | include Received display lldp statistics | include Frames ******************************** Internet Protocol (IP) Address Configurations ******************************** [nespk] interface GigabitEthernet0/0/1 [nespk-GigabitEthernet0/0/1] ip address 192.168.10.1 255.255.255.0 // Assign static IP OR [Huawei-Vlanif50] ip address 192.168.10.1 24 // Assign static IP using subnet mask bits [nespk-GigabitEthernet0/0/1] ip address dhcp // Assign dynamic IP via DHCP [nespk] interface Vlanif10 [nespk-Vlanif10] ip address 192.168.0.10 255.255.255.0 // Assign IP to VLAN interface [nespk] interface Vlanif20 [nespk-Vlanif20] ip address 192.168.0.20 255.255.255.0 // Assign IP to VLAN interface # Enable DHCP globally [nespk] dhcp enable # ---------------- VLAN 10 DHCP ---------------- [nespk] ip pool VLAN10 [nespk-ip-pool-VLAN10] network 192.168.10.0 mask 255.255.255.0 [nespk-ip-pool-VLAN10] gateway-list 192.168.10.1 [nespk-ip-pool-VLAN10] excluded-ip-address 192.168.10.1 192.168.10.9 [nespk-ip-pool-VLAN10] dns-list 8.8.8.8 8.8.4.4 [nespk-ip-pool-VLAN10] lease day 7 [nespk-ip-pool-VLAN10] quit # Bind DHCP pool to VLANIF10 [nespk] interface Vlanif10 [nespk-Vlanif10] ip address 192.168.10.1 255.255.255.0 [nespk-Vlanif10] dhcp select global [nespk-Vlanif10] quit # ---------------- VLAN 20 DHCP ---------------- [nespk] ip pool VLAN20 [nespk-ip-pool-VLAN20] network 192.168.20.0 mask 255.255.255.0 [nespk-ip-pool-VLAN20] gateway-list 192.168.20.1 [nespk-ip-pool-VLAN20] excluded-ip-address 192.168.20.1 192.168.20.9 [nespk-ip-pool-VLAN20] dns-list 8.8.8.8 8.8.4.4 [nespk-ip-pool-VLAN20] lease day 7 [nespk-ip-pool-VLAN20] quit # Bind DHCP pool to VLANIF20 [nespk] interface Vlanif20 [nespk-Vlanif20] ip address 192.168.20.1 255.255.255.0 [nespk-Vlanif20] dhcp select global [nespk-Vlanif20] quit # ---------------- DHCP on Physical Interface ---------------- dhcp enable // Enable DHCP service globally ip pool PORT1 // Create DHCP address pool named PORT1 network 192.168.50.0 mask 255.255.255.0 // Define subnet for DHCP pool gateway-list 192.168.50.1 // Default gateway for clients excluded-ip-address 192.168.50.1 192.168.50.9 // Exclude reserved IP range dns-list 8.8.8.8 8.8.4.4 // Set DNS servers lease day 7 // Lease time = 7 days quit // Exit pool configuration interface GigabitEthernet0/0/1 // Enter physical interface ip address 192.168.50.1 255.255.255.0 // Assign IP to interface (same as POOL we want) dhcp select global // Use global DHCP pool mode quit // Exit interface mode # ---------------- Statically Bind IP to MAC ---------------- static-bind ip-address 10.10.10.60 mac-address 5489-98A0-79B9 # ---------- DHCP Verification Commands ---------- display ip interface brief // Verify IPs & interface status display dhcp server statistics // Show DHCP server stats display dhcp client // Show DHCP client info per interface display current-configuration section interface // Show interface config display current-configuration section dhcp // Show DHCP config display dhcp server // Show DHCP server info display dhcp server ip-in-use // Show assigned IPs display ip pool name LANR11 display current-configuration | include pool display dhcp server binding display dhcp server binding | include XXXX-XXXX-XXXX // display IP bind by MAC # ---------- Undo / Remove Configurations ---------- [R1-GigabitEthernet0/0/1] undo ip address // Remove IP from interface [R1-GigabitEthernet0/0/2] undo ip address // Remove IP from interface [R1-Vlanif10] undo ip address // Remove IP from VLAN [R1-Vlanif10] undo dhcp select interface // Disable DHCP on VLAN 10 [R1-Vlanif20] undo dhcp select interface // Disable DHCP on VLAN 20 [R1-GigabitEthernet0/0/1] undo dhcp select interface // Disable DHCP on G0/0/1 [R1-GigabitEthernet0/0/2] undo dhcp select interface // Disable DHCP on G0/0/2 [R1] undo dhcp enable // Disable DHCP globally >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>> Routing <<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< ******************************** Static Routing ******************************** ------------------- Configure IPv4 Static Routes on RouterA ------------------- system-view //Enter system view [Huawei] sysname RouterA //Set router hostname [RouterA]interface GigabitEthernet1/0/0 [RouterA-GigabitEthernet1/0/0]ip address 10.1.1.1 255.255.255.0 //Assign IPv4 address [RouterA-GigabitEthernet1/0/0]description LAN_INTERFACE //Interface description [RouterA]interface GigabitEthernet2/0/0 [RouterA-GigabitEthernet2/0/0]ip address 10.1.4.1 255.255.255.252 //Assign point-to-point link [RouterA-GigabitEthernet2/0/0]description LINK_TO_ROUTERB //Interface description [RouterA]ip route-static 10.1.2.0 255.255.255.0 10.1.4.2 //Static route to 10.1.2.0 via RouterB [RouterA]ip route-static 10.1.3.0 255.255.255.0 10.1.4.2 //Static route to 10.1.3.0 via RouterB ------------------- Configure IPv4 Static Routes on RouterB ------------------- system-view [Huawei] sysname RouterB [RouterB]interface GigabitEthernet1/0/0 [RouterB-GigabitEthernet1/0/0]ip address 10.1.2.1 255.255.255.0 //LAN interface [RouterB-GigabitEthernet1/0/0]description LAN_INTERFACE //Interface description [RouterB]interface GigabitEthernet2/0/0 [RouterB-GigabitEthernet2/0/0]ip address 10.1.4.2 255.255.255.252 //Link to RouterA [RouterB-GigabitEthernet2/0/0]description LINK_TO_ROUTERA //Interface description [RouterB]interface GigabitEthernet3/0/0 [RouterB-GigabitEthernet3/0/0]ip address 10.1.4.5 255.255.255.252 //Link to RouterC [RouterB-GigabitEthernet3/0/0]description LINK_TO_ROUTERC //Interface description [RouterB]ip route-static 10.1.1.0 255.255.255.0 10.1.4.1 //Static route to RouterA network [RouterB]ip route-static 10.1.3.0 255.255.255.0 10.1.4.6 //Static route to RouterC network ------------------- Configure IPv4 Static Routes on RouterC ------------------- system-view [Huawei] sysname RouterC [RouterC]interface GigabitEthernet1/0/0 [RouterC-GigabitEthernet1/0/0]ip address 10.1.3.1 255.255.255.0 //LAN interface [RouterC-GigabitEthernet1/0/0]description LAN_INTERFACE //Interface description [RouterC]interface GigabitEthernet2/0/0 [RouterC-GigabitEthernet2/0/0]ip address 10.1.4.6 255.255.255.252 //Link to RouterB [RouterC-GigabitEthernet2/0/0]description LINK_TO_ROUTERB //Interface description [RouterC]ip route-static 10.1.1.0 255.255.255.0 10.1.4.5 //Static route to RouterA network [RouterC]ip route-static 10.1.2.0 255.255.255.0 10.1.4.5 //Static route to RouterB network ------------------- Configure IPv4 Default Routes on RouterA ------------------- [RouterA]interface GigabitEthernet0/0/1 [RouterA-GigabitEthernet0/0/1]ip address 10.1.3.1 255.255.255.0 //LAN interface [RouterA]interface GigabitEthernet0/0/2 [RouterA-GigabitEthernet0/0/2]ip address 10.1.4.6 255.255.255.252 //WAN interface [RouterA]ip route-static 0.0.0.0 0.0.0.0 10.1.4.6 //Default route via WAN ------------------- Configure IPv4 Default Routes on RouterB ------------------- [RouterB]interface GigabitEthernet0/0/1 [RouterB-GigabitEthernet0/0/1]ip address 192.168.10.1 255.255.255. //LAN interface [RouterB]interface GigabitEthernet0/0/2 [RouterB-GigabitEthernet0/0/2]ip address 10.1.4.5 255.255.255.252 //WAN interface [RouterB]ip route-static 0.0.0.0 0.0.0.0 10.1.4.5 //Default route via WAN ------------------- Configure IPv6 Static Routes on RouterA ------------------- [RouterA]ipv6 //Enable IPv6 globally [RouterA]interface GigabitEthernet1/0/0 [RouterA-GigabitEthernet1/0/0]ipv6 enable [RouterA-GigabitEthernet1/0/0]ipv6 address 1::1/64 //Assign IPv6 address [RouterA]interface GigabitEthernet2/0/0 [RouterA-GigabitEthernet2/0/0]ipv6 enable [RouterA-GigabitEthernet2/0/0]ipv6 address 2::2/64 [RouterA]ipv6 route-static 3::/64 2::1 //Static IPv6 route to remote network [RouterA]ipv6 route-static 4::/64 2::1 [RouterA]ipv6 route-static 5::/64 2::1 ------------------- Configure IPv6 Static Routes on RouterB ------------------- [RouterB]ipv6 [RouterB]interface GigabitEthernet1/0/0 [RouterB-GigabitEthernet1/0/0]ipv6 enable [RouterB-GigabitEthernet1/0/0]ipv6 address 3::1/64 [RouterB]interface GigabitEthernet2/0/0 [RouterB-GigabitEthernet2/0/0]ipv6 enable [RouterB-GigabitEthernet2/0/0]ipv6 address 2::1/64 [RouterB]interface GigabitEthernet3/0/0 [RouterB-GigabitEthernet3/0/0]ipv6 enable [RouterB-GigabitEthernet3/0/0]ipv6 address 4::1/64 [RouterB]ipv6 route-static 1::/64 2::2 [RouterB]ipv6 route-static 5::/64 4::2 ------------------- Configure IPv6 Static Routes on RouterC ------------------- [RouterC]ipv6 [RouterC]interface GigabitEthernet1/0/0 [RouterC-GigabitEthernet1/0/0]ipv6 enable [RouterC-GigabitEthernet1/0/0]ipv6 address 5::1/64 [RouterC]interface GigabitEthernet2/0/0 [RouterC-GigabitEthernet2/0/0]ipv6 enable [RouterC-GigabitEthernet2/0/0]ipv6 address 4::2/64 [RouterC]ipv6 route-static 1::/64 4::1 [RouterC]ipv6 route-static 2::/64 4::1 [RouterC]ipv6 route-static 3::/64 4::1 ------------------- Troubleshooting Static Routes ------------------- [RouterA]display ip routing-table //Show IPv4 routing table [RouterA]display ipv6 routing-table //Show IPv6 routing table [RouterB]display ip routing-table [RouterB]display ipv6 routing-table [RouterC]display ip routing-table [RouterC]display ipv6 routing-table ******************************* RIP – Routing Information Protocol ******************************* ------------------ Description ------------------- RIP is commonly used in small to medium-sized networks due to its ease of configuration and fast deployment. RIP works by sending routing updates every 30 seconds to neighboring routers. Each router selects the path with the lowest hop count, with a maximum limit of 15 hops, making RIP suitable for smaller networks. RIP (Routing Information Protocol) // Distance-vector routing protocol for IGP Uses Hop Count as a Metric // Maximum 15 hops, 16 = unreachable Timers: Update, Invalid, Hold-Down, Flush // Control routing updates Supports IPv4 Only (RIPv1/RIPv2) // RIPv2 supports VLSM and multicast updates --------------------- RIP Versions --------------------- 1. RIPv1: classful (FLSM only), broadcast (255.255.255.255), no authentication, no IPv6 2. RIPv2: classless (Supports VLSM), supports authentication (plain text, MD5), multicast (224.0.0.9), no IPv6 3. RIP-NG: RIPv2 extension, supports IPv6, UDP 521, multicast (FF02::9) uses UDP port 25 for routing updates matric = hop count max hop count = 15 default update interval = 30 sec in cisco send full routing table uses less CPU and ram than OSPF or EIGRP etc RIP router sends directly connected routes and next do same then next do same and so on ------------------ How RIP Works ------------------- Periodic Updates // Sends routing table every 30 seconds Distance Vector Calculation // Chooses route with lowest hop count Route Advertisement // Shares routes with neighbors Loop Prevention Mechanisms // Split Horizon, Poison Reverse, Hold-down timers ------------------ RIP Advantages ------------------- Simple Configuration // Very easy to deploy Low Resource Usage // Minimal CPU/memory requirements Works in Small Networks // Effective in small or flat topologies ------------------ RIP Disadvantages ------------------- Slow Convergence // Can take 180 seconds to detect failures Hop Limit // Maximum 15 hops, not suitable for large networks Routing Loops // Can occur without proper timers and split horizon ------------------ Use Cases ------------------- Small LANs // Small office or campus networks Legacy Systems // Networks that still rely on RIP for simplicity Learning and Lab Environments // Good for learning basic distance-vector concepts ------------------- Configure RIP on RouterA ------------------- system-view //Enter system view (global configuration mode) [Huawei] sysname RouterA //Set router name [RouterA]interface GigabitEthernet1/0/0 //Enter interface GE1/0/0 view [RouterA-GigabitEthernet1/0/0]ip address 192.168.1.1 255.255.255.0 //Assign IP address [RouterA-GigabitEthernet1/0/0]description LINK_TO_ROUTERB //Add interface description [RouterA-GigabitEthernet1/0/0]quit //Exit interface view [RouterA]interface GigabitEthernet2/0/0 //Enter interface GE2/0/0 view [RouterA-GigabitEthernet2/0/0]ip address 10.1.1.1 255.255.255.0 //Assign IP address [RouterA-GigabitEthernet2/0/0]quit //Exit interface view [RouterA]rip 100 //Enter RIP process view (process ID 100) [RouterA-rip-100]version 2 //Set RIP version to 2 [RouterA-rip-100]network 192.168.1.0 //Enable RIP on 192.168.1.0/24 [RouterA-rip-100]network 10.0.0.0 //Enable RIP on 10.0.0.0/8 [RouterA-rip-100]quit //Exit RIP process view ------------------- Configure RIP on RouterB ------------------- system-view [Huawei] sysname RouterB [RouterB]interface GigabitEthernet1/0/0 [RouterB-GigabitEthernet1/0/0]ip address 172.16.1.1 255.255.255.0 //Assign IP address [RouterB-GigabitEthernet1/0/0]quit [RouterB]interface GigabitEthernet2/0/0 [RouterB-GigabitEthernet2/0/0]ip address 10.1.1.2 255.255.255.0 //Assign IP address [RouterB-GigabitEthernet2/0/0]quit [RouterB]rip 100 [RouterB-rip-100]version 2 [RouterB-rip-100]network 172.16.0.0 [RouterB-rip-100]network 10.0.0.0 ------------------- Secure RIP with Authentication ------------------- [RouterA]interface GigabitEthernet2/0/0 //Enter interface connected to RouterB [RouterA-GigabitEthernet2/0/0]rip authentication-mode md5 //Enable MD5 authentication [RouterA-GigabitEthernet2/0/0]rip authentication-key-chain ripkey //Link interface to key-chain "ripkey" [RouterA]key-chain ripkey //Create key-chain for RIP authentication [RouterA-keychain-ripkey]key-id 1 //Create key ID 1 [RouterA-keychain-ripkey]key-string rip@123 //Set key password [RouterB]interface GigabitEthernet2/0/0 [RouterB-GigabitEthernet2/0/0]rip authentication-mode md5 [RouterB-GigabitEthernet2/0/0]rip authentication-key-chain ripkey [RouterB-GigabitEthernet2/0/0]quit [RouterB]key-chain ripkey [RouterB-keychain-ripkey]key-id 1 [RouterB-keychain-ripkey]key-string rip@123 ------------------- Configure RIPng on RouterA ------------------- [RouterA]ipv6 //Enable IPv6 forwarding globally [RouterA]interface GigabitEthernet1/0/0 [RouterA-GigabitEthernet1/0/0]ipv6 enable //Enable IPv6 on interface [RouterA-GigabitEthernet1/0/0]ipv6 address 2001:1::1/64 //Assign IPv6 address [RouterA-GigabitEthernet1/0/0]ripng 100 enable //Enable RIPng process 100 on this interface [RouterA]interface GigabitEthernet2/0/0 [RouterA-GigabitEthernet2/0/0]ipv6 enable [RouterA-GigabitEthernet2/0/0]ipv6 address 2001:2::2/64 [RouterA-GigabitEthernet2/0/0]ripng 100 enable [RouterA]ripng 100 //Enter RIPng process 100 view ------------------- Configure RIPng on RouterB ------------------- [RouterB]ipv6 [RouterB]interface GigabitEthernet1/0/0 [RouterB-GigabitEthernet1/0/0]ipv6 enable [RouterB-GigabitEthernet1/0/0]ipv6 address 2001:3::1/64 [RouterB-GigabitEthernet1/0/0]ripng 100 enable [RouterB]interface GigabitEthernet2/0/0 [RouterB-GigabitEthernet2/0/0]ipv6 enable [RouterB-GigabitEthernet2/0/0]ipv6 address 2001:2::1/64 [RouterB-GigabitEthernet2/0/0]ripng 100 enable [RouterB]ripng 100 [RouterB-ripng-100]quit ------------------- Secure RIPng with Authentication ------------------- [RouterA]interface GigabitEthernet2/0/0 [RouterA-GigabitEthernet2/0/0]ripng authentication-mode hmac-sha256 //Enable secure HMAC-SHA256 authentication [RouterA-GigabitEthernet2/0/0]ripng authentication-key ripng@123 //Set RIPng password [RouterB]interface GigabitEthernet2/0/0 [RouterB-GigabitEthernet2/0/0]ripng authentication-mode hmac-sha256 [RouterB-GigabitEthernet2/0/0]ripng authentication-key ripng@123 ------------------- Troubleshooting RIP Routes ------------------- display rip //Show RIP process summary and status display rip 100 route //Show RIP routing table for process 100 display rip interface //Check RIP-enabled interfaces and authentication status display rip peer //Show RIP neighbors (peers) display rip statistics //Show RIP update/packet statistics display rip timer //Show RIP timers (update, invalid, hold-down, flush) display current-configuration section rip //Show only RIP configuration debugging rip //Enable live RIP debug messages undo debugging all //Disable all debugging messages display ip routing-table protocol rip [RouterA-rip-100]silent-interface GigabitEthernet2/0/0 //Prevent RIP updates on this interface [RouterA-rip-100]undo silent-interface GigabitEthernet2/0/0 //Re-enable RIP updates [RouterA-rip-100]undo network 10.0.0.0 //Remove advertised network from RIP process ------------------- Troubleshooting RIPng Routes ------------------- display ripng //Show RIPng process summary display ripng route //Show RIPng IPv6 routing table display ripng interface //Show RIPng interfaces and authentication status display ripng peer //Show RIPng neighbors display ripng statistics //Show RIPng update/packet statistics display ripng timer //Show RIPng timers display current-configuration section ripng //Show only RIPng configuration debugging ripng //Enable live RIPng debug messages undo debugging all //Disable all debugging messages [RouterA-ripng-100]silent-interface GigabitEthernet2/0/0 //Stop RIPng updates on this interface [RouterA-ripng-100]undo silent-interface GigabitEthernet2/0/0 //Re-enable RIPng updates [RouterA-ripng-100]undo network 2001:2::/64 //Remove advertised network from RIPng process ------------------- Delete or Undo RIP Configurations ------------------- [RouterA]undo rip 100 //Delete RIP process 100 [RouterA]undo ripng 100 //Delete RIPng process 100 [RouterA]undo key-chain ripkey //Delete authentication key-chain [RouterA]undo interface GigabitEthernet2/0/0 rip authentication-mode //Remove RIP MD5 authentication from interface [RouterA]undo interface GigabitEthernet2/0/0 ripng authentication-mode //Remove RIPng authentication from interface +++++++++++++++++++++++++ Summary Table (RIP vs OSPF) +++++++++++++++++++++++++ Feature RIP OSPF --------------------------------------------- Type Distance-vector Link-state Metric Hop count Cost (bandwidth-based) Max Hops 15 No fixed limit Convergence Slow Fast IPv6 Support RIPng OSPFv3 Updates Periodic Event-driven Use Case Small/simple nets Enterprise/large networks +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ ********************************* OSPF – Open Shortest Path First ********************************* ------------------ Description ------------------- OSPF (Open Shortest Path First) // Link-state routing protocol for intra-AS (IGP) Uses Dijkstra Algorithm // Computes shortest path tree for each router Area-based hierarchy // Supports multiple areas (Area 0 backbone required) Supports IPv4/IPv6 // Modern OSPF supports dual-stack networks Faster Convergence // Converges quickly during link changes ------------------ Types of OSPF ------------------- OSPFv2 // For IPv4 networks OSPFv3 // For IPv6 networks Single-Area OSPF // Entire AS in one area (simpler) Multi-Area OSPF // Reduces routing table size and LSDB overhead ------------------ How OSPF Works ------------------- Hello Protocol // Discover neighbors and maintain adjacency LSA (Link State Advertisement) // Exchange topology information with neighbors LSDB (Link State Database) // Stores all received LSAs SPF Calculation // Dijkstra algorithm computes shortest paths Route Advertisement // Best routes inserted into routing table ------------------ OSPF Advantages ------------------- Fast Convergence // Quick reaction to topology changes Hierarchical Design // Supports backbone (Area 0) and multiple areas Supports VLSM // Variable Length Subnet Mask Loop-Free Topology // Link-state prevents routing loops Authentication Support // MD5 or plain text passwords on interfaces ------------------ OSPF Disadvantages ------------------- Complexity // More configuration than RIP Resource Intensive // Requires more CPU and memory for LSDB Troubleshooting // Can be difficult in large multi-area networks ------------------ Use Cases ------------------- Enterprise Networks // Campus or enterprise backbone Large-Scale LANs // Multi-area design reduces flooding Data Center Networks // High availability and fast convergence ------------------- Configure OSPF on RouterA ------------------- sysname RouterA //Set router hostname router id 1.1.1.1 //Set router ID (use Loopback0 IP recommended) vlan batch 10 //Create VLAN 10 interface Vlanif10 ip address 192.168.1.1 255.255.255.0 //Assign IPv4 address to VLAN interface interface Ethernet2/0/0 port link-type trunk //Set interface as trunk port trunk allow-pass vlan 10 //Allow VLAN 10 on trunk interface GigabitEthernet3/0/0 ip address 192.168.0.1 255.255.255.0 //Assign IPv4 address to GE3/0/0 interface LoopBack0 ip address 1.1.1.1 255.255.255.255 //Loopback interface for Router ID ospf 2 //Create OSPF process 2 area 0.0.0.0 network 192.168.1.0 0.0.0.255 //Advertise VLAN10 subnet in Area 0 network 192.168.0.0 0.0.0.255 //Advertise GE3/0/0 subnet in Area 0 ------------------- Configure OSPF on RouterB ------------------- sysname RouterB //Set router hostname router id 2.2.2.2 //Set router ID (use Loopback0 IP recommended) vlan batch 20 //Create VLAN 20 interface Vlanif20 ip address 192.168.2.1 255.255.255.0 //Assign IPv4 address to VLAN interface interface Ethernet2/0/0 port link-type trunk //Set interface as trunk port trunk allow-pass vlan 20 //Allow VLAN 20 on trunk interface GigabitEthernet3/0/0 ip address 192.168.0.2 255.255.255.0 //Assign IPv4 address to GE3/0/0 interface LoopBack0 ip address 2.2.2.2 255.255.255.255 //Loopback interface for Router ID ospf 2 //Create OSPF process 2 area 0.0.0.0 network 192.168.2.0 0.0.0.255 //Advertise VLAN20 subnet in Area 0 network 192.168.0.0 0.0.0.255 //Advertise GE3/0/0 subnet in Area 0 ------------------- Configure Multi-Area OSPF on RouterA ------------------- interface GigabitEthernet0/0/0 ip address 10.10.10.1 255.255.255.0 //Assign IPv4 address for Area 0 interface GigabitEthernet0/0/1 ip address 192.168.10.1 255.255.255.0 //Assign IPv4 address for Area 0 ospf 1 area 0 network 192.168.0.0 0.0.0.255 //Advertise GE0/0/0 subnet in Area 0 network 192.168.1.0 0.0.0.255 //Advertise GE0/0/1 subnet in Area 0 """"""""""""""" OR """"""""""""""" sysname R1 interface GigabitEthernet0/0/0 description WAN-int-R2 ip address 10.10.10.1 255.255.255.252 # interface GigabitEthernet0/0/1 description LANR1 ip address 192.168.10.1 255.255.255.0 # interface GigabitEthernet0/0/2 # ospf 1 area 0.0.0.0 network 10.10.10.0 0.0.0.3 network 192.168.10.0 0.0.0.255 ------------------- Configure Multi-Area OSPF on RouterB ------------------- interface GigabitEthernet0/0/0 ip address 10.10.10.2 255.255.255.0 //Assign IPv4 address for Area 0 interface GigabitEthernet0/0/1 ip address 192.168.20.1 255.255.255.0 //Assign IPv4 address for Area 1 ospf 1 area 0 network 192.168.0.0 0.0.0.255 //Advertise GE0/0/0 subnet in Area 0 ospf 1 area 1 network 192.168.2.0 0.0.0.255 //Advertise GE0/0/1 subnet in Area 1 """"""""""""""" OR """"""""""""""" sysname R2 interface GigabitEthernet0/0/0 description WAN-int-R1 ip address 10.10.10.2 255.255.255.252 # interface GigabitEthernet0/0/1 description LANR2 ip address 192.168.20.1 255.255.255.0 # interface GigabitEthernet0/0/2 description WAN-int-R3 ip address 20.20.20.1 255.255.255.252 # ospf 1 area 0.0.0.0 network 10.10.10.0 0.0.0.3 network 192.168.20.0 0.0.0.255 area 0.0.0.1 network 20.20.20.0 0.0.0.3 ------------------- Configure Multi-Area OSPF on RouterC ------------------- sysname R3 interface GigabitEthernet0/0/0 # interface GigabitEthernet0/0/1 description LANR3 ip address 192.168.30.1 255.255.255.0 # interface GigabitEthernet0/0/2 description WAN-int-R2 ip address 20.20.20.2 255.255.255.252 # ospf 1 area 0.0.0.1 network 20.20.20.0 0.0.0.3 network 192.168.30.0 0.0.0.255 ------------------- Configure OSPFv3 on RouterA ------------------- ipv6 //Enable IPv6 forwarding ospfv3 2 router-id 10.10.10.10 //Set OSPFv3 router ID import-route direct //Import directly connected routes interface GigabitEthernet1/0/0 ipv6 enable //Enable IPv6 ipv6 address 1999::1/64 ospfv3 2 area 0.0.0.0 //Assign interface to Area 0 interface GigabitEthernet2/0/0 ipv6 enable //Enable IPv6 ipv6 address 2000::1/64 ospfv3 2 area 0.0.0.0 //Assign interface to Area 0 ------------------- Configure OSPFv3 on RouterB ------------------- ospfv3 2 router-id 20.20.20.20 //Set OSPFv3 router ID interface GigabitEthernet1/0/0 ipv6 enable ipv6 address 2001::1/64 ospfv3 2 area 0.0.0.1 //Assign interface to Area 0.1 interface GigabitEthernet2/0/0 ipv6 enable ipv6 address 2000::2/64 ospfv3 2 area 0.0.0.0 //Assign interface to Area 0.0 ------------------- Configure OSPFv3 on RouterC ------------------- ospfv3 2 router-id 30.30.30.30 //Set OSPFv3 router ID import-route direct //Import directly connected routes interface GigabitEthernet1/0/0 ipv6 enable ipv6 address 2002::1/64 ospfv3 2 area 0.0.0.0 //Assign interface to Area 0.0 interface GigabitEthernet2/0/0 ipv6 enable ipv6 address 2001::2/64 ospfv3 2 area 0.0.0.1 //Assign interface to Area 0.1 ------------------- OSPF Authentication Commands ------------------- interface ip address //Assign IPv4 address to interface ospf authentication-mode simple password //Enable plain-text OSPF authentication ospf authentication-mode md5 //Enable MD5 OSPF authentication ospf authentication-key //Set MD5 key for OSPF authentication ------------------- OSPFv2 Verification ------------------- [RouterA]display ospf peer //Show OSPF neighbors and their states [RouterA]display ospf interface //Show OSPF-enabled interfaces and their states [RouterA]display ospf routing //Show OSPF routes in routing table [RouterA]display ospf brief //Brief summary of OSPF process, neighbors, and routes [RouterA]display ospf statistics //Show OSPF packet and LSA statistics [RouterA]display ospf timer //Show OSPF timers (Hello, Dead intervals) [RouterA]display current-configuration section ospf //Show only OSPF configuration display ip routing-table display ip routing-table protocol ospf ------------------- OSPFv3 Verification ------------------- [RouterA]display ospfv3 peer //Show OSPFv3 neighbors and their states [RouterA]display ospfv3 interface //Show OSPFv3-enabled interfaces and their states [RouterA]display ospfv3 routing //Show OSPFv3 routes in IPv6 routing table [RouterA]display ospfv3 brief //Brief summary of OSPFv3 process, neighbors, and routes [RouterA]display ospfv3 statistics //Show OSPFv3 packet and LSA statistics [RouterA]display ospfv3 timer //Show OSPFv3 timers [RouterA]display current-configuration section ospfv3 //Show only OSPFv3 configuration display current-configuration | include ospf display ip routing-table ------------------- Debugging Commands ------------------- [RouterA]debugging ospf //Enable live OSPFv2 debug messages [RouterA]debugging ospfv3 //Enable live OSPFv3 debug messages [RouterA]undo debugging all //Disable all debugging messages ------------------- OSPFv2 Interface Control ------------------- [RouterA-ospf-2]passive-interface GigabitEthernet1/0/0 //Set interface as passive [RouterA-ospf-2]undo passive-interface GigabitEthernet1/0/0 //Re-enable OSPF hello on interface ------------------- OSPFv3 Interface Control ------------------- [RouterA-ospfv3-2]passive-interface GigabitEthernet1/0/0 //Set interface as passive [RouterA-ospfv3-2]undo passive-interface GigabitEthernet1/0/0 //Re-enable OSPFv3 neighbor discovery ------------------- OSPF Deletion / Undo ------------------- [RouterA]undo ospf 1 //Delete OSPFv2 process 1 [RouterA]undo ospf 2 //Delete OSPFv2 process 2 [RouterA]undo ospfv3 1 //Delete OSPFv3 process 1 [RouterA]undo ospfv3 2 //Delete OSPFv3 process 2 interface undo ospf authentication-mode //Remove OSPF authentication from interface ******************************** BGP – Border Gateway Protocol ******************************** ------------------ Description ------------------- BGP (Border Gateway Protocol) // Path-vector routing protocol used between Autonomous Systems (AS) TCP Port 179 // BGP uses TCP for reliable updates EGP (Exterior Gateway Protocol) // Used for inter-AS routing, unlike OSPF or RIP (IGPs) Supports IPv4/IPv6/MPLS VPN // Multi-protocol support for modern networks ------------------ Types of BGP ------------------- eBGP // External BGP between different ASes iBGP // Internal BGP within same AS, requires full mesh or Route Reflectors ------------------ How BGP Works ------------------- Neighbor Establishment // Routers form TCP session on port 179 to become peers Route Exchange // Initial full table exchange, then incremental updates Path Selection // Uses attributes: Weight, Local_Pref, AS_PATH, MED, eBGP over iBGP Route Advertisement // Best routes advertised to neighbors based on policies ------------------ BGP Attributes ------------------- AS_PATH // List of ASes the route passed through, used for loop prevention NEXT_HOP // IP address to reach the destination network LOCAL_PREF // Preference inside AS for outgoing traffic, highest preferred MED // Multi-Exit Discriminator, prefer lower value COMMUNITY // Route tagging for policy application ------------------ Advantages ------------------- Scalable // Can handle very large networks (ISPs) Policy-based Routing // Control traffic flow between ASes Reliable // Runs over TCP Supports multiple protocols // IPv4, IPv6, VPN, MPLS ------------------ Disadvantages ------------------- Complex Configuration // More difficult than IGPs like OSPF/RIP Slower Convergence // Slower than IGPs during link failure Requires careful policy planning // To avoid loops or traffic blackholes ------------------ Use Cases ------------------- Multi-homing // Connect enterprise networks to multiple ISPs Internet backbone // ISP to ISP routing Traffic Engineering // Policy-based route selection VPN Distribution // MP-BGP used in MPLS VPN networks ------------------ Basic BGP Setup ------------------- [nespk]bgp 65001 //Enable BGP process with AS 65001 [nespk-bgp]router-id 1.1.1.1 //Set Router ID for BGP (unique identifier) [nespk-bgp]network 192.168.1.0 255.255.255.0 //Advertise internal network 192.168.1.0/24 [nespk-bgp]network 192.168.2.0 255.255.255.0 //Advertise internal network 192.168.2.0/24 ------------------ Configure BGP Neighbors ------------------- [nespk-bgp]peer 2.2.2.2 as-number 65002 //Define BGP neighbor with remote AS [nespk-bgp]peer 2.2.2.2 description "Primary ISP Link" //Optional: Add description for neighbor [nespk-bgp]peer 2.2.2.2 connect-interface GigabitEthernet0/0/1 //Bind neighbor to interface [nespk-bgp]peer 2.2.2.2 enable //Enable the BGP neighbor [nespk-bgp]peer 2.2.2.2 password cipher BGPpass123 //Optional: Set MD5 password for neighbor authentication ------------------ Network Advertisement / Route Import ------------------- [nespk-bgp]network 10.10.10.0 255.255.255.0 //Advertise additional network [nespk-bgp]import-route static //Import static routes into BGP [nespk-bgp]import-route ospf 1 //Import OSPF routes into BGP [nespk-bgp]import-route rip 1 //Import RIP routes into BGP ------------------ Route Policies / Filtering ------------------- [nespk]route-policy EXPORT_POLICY permit node 10 //Create export policy node [nespk-route-policy-node10]if-match ip-prefix PREFIX_LIST1 //Match specific prefixes [nespk-route-policy-node10]apply cost 100 //Optional: modify route attribute [nespk-route-policy-node10]quit [nespk-bgp]peer 2.2.2.2 route-policy EXPORT_POLICY export //Apply export policy to neighbor [nespk-bgp]peer 2.2.2.2 route-policy IMPORT_POLICY import //Apply import policy to neighbor ------------------ Optional / Advanced BGP Features ------------------- [nespk-bgp]peer 2.2.2.2 route-refresh enable //Enable route-refresh capability [nespk-bgp]peer 2.2.2.2 next-hop-self //Set next-hop as self for EBGP [nespk-bgp]peer 2.2.2.2 enable ebgp-multihop 2 //Allow EBGP neighbor via multiple hops [nespk-bgp]peer 2.2.2.2 weight 200 //Assign local weight for route preference [nespk-bgp]peer 2.2.2.2 as-override //Override private AS in EBGP ------------------ Verification Commands ------------------- display bgp peer //Show BGP neighbor status display bgp routing-table //Show BGP routing table display bgp vpnv4 all //Show BGP VPNv4 routes display bgp vpnv6 all //Show BGP VPNv6 routes display bgp ipv4 unicast all //Show IPv4 BGP routes display bgp ipv6 unicast all //Show IPv6 BGP routes display bgp peer 2.2.2.2 //Show details of a specific neighbor display bgp peer summary //Show summary of all BGP peers display bgp route-policy //Show applied route-policies display ip routing-table protocol bgp ------------------ Undo / Remove Configurations ------------------- [nespk-bgp]undo peer 2.2.2.2 //Remove a BGP neighbor [nespk-bgp]undo network 192.168.1.0 255.255.255.0 //Remove advertised network undo bgp 65001 //Remove entire BGP process [nespk]undo route-policy EXPORT_POLICY //Delete export route-policy [nespk]undo route-policy IMPORT_POLICY //Delete import route-policy ------------------ Optional Best Practices ------------------- [nespk-bgp]maxas-limit 5 //Limit AS path length to 5 [nespk-bgp]timer bgp 30 90 //Set BGP keepalive / hold timers [nespk-bgp]suppress 192.168.100.0 255.255.255.0 //Suppress specific network advertisement [nespk-bgp]peer 2.2.2.2 description "Backup ISP Link" //Optional: Document neighbor usage