1.4.1.1.8.1 Physical Specifications 1.4.1.1.8.2 Optical Module Attributes 1.4.1.1.8.3 System Configuration 1.4.1.1.8.4 List of Software Features 1.4.1.1 S2700 Product Description About This Document Product Positioning and Characteristics Product Architecture Link Features Service Features Networking and Applications Maintenance and Network Management System...
Page 3
The device provides the mirroring function for network monitoring and fault management, during which communication data of users may be collected. Huawei alone is unable to collect or save the content of users' communications. It is suggested that you activate the interception-related functions based on the applicable laws and regulations in terms of purpose and scope of usage.
1.4.1.1.2.1 Product Positioning NOTICE: The S2700 Series Ethernet Switches are class A products. The switches that are operating may cause radio interference. Customers need to take prevention measures. The S2700 Series Ethernet Switches (hereinafter referred to as the S2700) provide the access and data transport functions.
The S2700 can be used to construct a tree, star, or ring Ethernet network. For the ring Ethernet, the S2700 supports the Spanning Tree Protocol (STP) to prevent loops and provide rapid switchover.
In addition to collecting traffic statistics based on interfaces and VLANs, the S2700 provides fault detection and location tools such as ping and traceroute on an IP network. It can also work with the Huawei eSight network management system (NMS) to implement performance monitoring, alarm report, and fast fault location.
Product Characteristics 1.4.1.1.2.2.7 Intelligent PoE Power Supply The S2700 PoE switches has the PoE function. It provides centralized power supply for the attached IP phone, wireless access point (AP), portable device charger, POS machine, camera, and data collector through twisted pairs.
Page 8
HEEX Startpage Page 8 of 34 The S2700 Ethernet switches adopt an integrated hardware platform. An S2700 consists of the chassis, power supply unit, fan, and switch control unit (SCU). NOTE: The figures in this document are for reference only.
Page 9
If the optical port has an optical module installed and the electrical port has a network cable connected, the optical port is used for data switching after the switch restarts. You can configure a combo port as an electrical or optical port using the combo-port command. shows the rear views of S2700. Table 2 Table 2 S2700 rear views...
S2700. Figure 1 Figure 1 Logical structure of hardware modules of the S2700 Hardware modules of the S2700 refer to the SCU, power supply, and fan. Power Supply http://localhost:7890/printtopics.html?time=Thu Dec 10 16:53:17 UTC-0200 2015...
Page 11
Product Architecture 1.4.1.1.3.3.1 SCU The SCU is fixed on the S2700. Each S2700 has one SCU. The SCU is responsible for packet switching and device management. It integrates multiple functional modules, namely, the main control module, switching module, and interface module.
Parent topic: Hardware Modules 1.4.1.1.3.4 Software Architecture The S2700 runs on the latest VRP version 5 (VRPv5) to provide various features. VRPv5 consists of the following parts: Figure 1 Software architecture System service plane This plane provides task and memory management, timer, software loading and patching on the basis of the operating system.
Parent topic: Product Architecture 1.4.1.1.4 Link Features Ethernet Features STP/RSTP/MSTP Interface Security Link Detection Parent topic: S2700 Product Description 1.4.1.1.4.1 Ethernet Features Link Aggregation Flow Control on an Interface Traffic Suppression VLAN QinQ GVRP Parent topic: Link Features 1.4.1.1.4.1.1 Link Aggregation...
1.4.1.1.4.1.2 Flow Control on an Interface Flow control on an interface is a method of congestion management. It applies to all types of flows. The S2700 implements flow control on an interface by using the hardware backpressure mechanism. When an interface works in full duplex mode, the S2700 implements flow control complying with IEEE 802.3x.
VLAN members are defined according to source MAC addresses of packets. When an interface of the S2700 receives a packet, the S2700 determines the VLAN ID of the packet according to the source MAC address of the packet and sends the packet on the corresponding VLAN.
In this way, packets from user networks are transmitted transparently on the public network, and thus user networks are separated from the public network. The S2700 supports the basic QinQ function. That is, all the frames that reach the public network through an interface are tagged with the same public VLAN ID.
Loop Protection After loop protection is enabled on the S2700, it sets the root port to the Blocking state if the root port does not receive protocol BPDUs from the upstream device. If the port receives protocol BPDUs again, it becomes the root port and changes to the Forwarding state.
BPDU Tunnel On a partitioned STP network, the S2700 considers the tagged BPDUs as common Layer 2 frames. That is, the S2700 forwards the BPDUs within the VLAN to which the tag belongs rather than sending them to the MSTP module.
Stacking Parent topic: S2700 Product Description 1.4.1.1.5.1 IPv6 The S2700 provides the IPv6 host function, which protects the investment of customers and prevents repeat investment during network upgrade. The IPv6 functions supported by the S2700 include: IPv6 protocol stack ND, ICMP v6, Traceroute v6, Telnet v6, DNS, and IPv6 static route...
When a multicast member leaves a multicast group, the host sends an IGMP Leave message. When an interface on the S2700 is connected to only one host, the S2700 deletes the multicast forwarding entry of the interface immediately after receiving the IGMP Leave message. This saves bandwidth and system resources and http://localhost:7890/printtopics.html?time=Thu Dec 10 16:53:17 UTC-0200 2015...
When receiving unknown multicast packets, the S2700 discards the packets or broadcasts them on the VLAN that the inbound interface belongs to. The S2700 can also control inbound multicast traffic volume by limiting the percentage of multicast packets on an Ethernet interface.
S2700, the S2700 performs traffic policing and access control for the packets according to the committed information rate (CIR); when packets exit an S2700, the S2700 shapes the traffic of packets and re-marks the priorities of packets.
The S2700 uses the token bucket algorithm to control the Committed Access Rate (CAR) of network traffic. The S2700 controls the rate of traffic by adjusting the rate of placing tokens. Each token equals a forwarding rate of 64 kbit/s. The S2700 "punishes" the excessive traffic to limit the incoming traffic within a proper range and to protect the network resources.
1.4.1.1.5.4.1 Device Security Hierarchical Command Protection When a user logs in to the S2700 from an Ethernet interface through Telnet, the S2700 authenticates the user to ensure security. The user can configure and maintain the S2700 only after passing the authentication.
HWTACAS+ authentication. CPU Channel Protection The S2700 can filter the protocol packets and management packets sent to the CPU based on the protocol ID, interface, and combination of interface and VLAN. This protects the CPU channels against Denial of Service (DoS) attacks.
HEEX Startpage Page 26 of 34 Parent topic: Security 1.4.1.1.5.4.3 Security Authentication The 802.1x protocol is a port-based network access control protocol. It authenticates and controls access devices on a LAN based on interfaces. A user device can access resources on the LAN only after it passes the authentication on the access interface.
Parent topic: Service Features 1.4.1.1.5.6 Reliability The S2700 supports MSTP to eliminate broadcast storms on a network and provide backup links for data transmission. The S2700 provides the root protection function. When the designated port receives a BPDU of higher priority, it remains the designated port for a certain period of time to protect the role of the root switch.
Thus the NMS can manage a larger area on the network. The LLDP-enabled interfaces on the S2700 periodically notify the neighbors of its own status. If the status of an interface changes, the interface sends status update messages to the directly connected neighboring device. The neighboring device stores the status update message in the standard SNMP MIB.
Page 29
S2700-26TP-EI-AC: 15.5 W S2700-26TP-EI-DC: 15.5 W S2700-52P-EI-AC: 38 W S2700-9TP-PWR-EI: 154 W (Device power: 30 W, PoE: 124 W) S2700-26TP-PWR-EI: 808 W (Device power: 68 W, PoE: 740 W) S2700-52P-PWR-EI: 880 W (Device power: 128 W, PoE: 740 W) S2710-52P-SI-AC: 38 W...
Relative humidity 5%RH to 95%RH, non-condensing Altitude S2700-9TP-SI-AC, S2700-9TP-EI-AC, S2700-18TP-SI-AC, S2700- 18TP-EI-AC, S2700-26TP-SI-AC, and S2700-26TP-EI-AC: 0 m to 5000 m; others: 0 m to 2000 m Parent topic: System Technical Specifications 1.4.1.1.8.2 Optical Module Attributes Table 1 Attributes of the SFP (FE) optical module...
Page 31
HEEX Startpage Page 31 of 34 Transmitting power -15.0 dBm to -8.0 -15.0 dBm to -8.0 -15.0 dBm to -8.0 -5.0 dBm to 0 -5.0 dBm to 0 Receiver sensitivity -31.0 dBm -32.0 dBm -32.0 dBm -34.0 dBm -34.0 dBm Overload power -8.0 dBm -8.0 dBm...
S2710-52P 13.2Mpps Stacking bandwidth S2700-52P-EI-AC, S2710-52P-PWR-SI, S2710-52P-SI-AC and S2700-52P-PWR-EI: support 10 Gbit/s bidirectional stacking bandwidth DDR memory 128 MB for S2700-52P, S2710-52P and 64 MB for others Flash Memory 16 MB Parent topic: System Technical Specifications 1.4.1.1.8.4 List of Software Features...
Page 33
HEEX Startpage Page 33 of 34 VLAN Access modes of access, trunk, hybrid, and QinQ Default VLAN VLAN mapping Voice VLAN Automatic learning and aging of MAC addresses Static, dynamic, and blackhole MAC address entries Packet filtering based on source MAC addresses Limitation on MAC address learning on interfaces Static and dynamic ARP entries ARP on a VLAN...
Page 34
Online upgrade of the BootROM In-service patching Security and System security Hierarchical command line protection to prevent unauthorized users from management accessing the S2700 SSH v2.0 RADIUS authentication and HWTACACS authentication ACL filtering DHCP packet filtering (with Option 82) Defense against control packet attacks...