No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

AR500, AR510, and AR530 V200R007 Commands Reference

This document describes all the configuration commands of the device, including the command function, syntax, parameters, views, default level, usage guidelines, examples, and related commands.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
SAC Configuration Commands

SAC Configuration Commands

NOTE:

AR500 series (except for AR503GW-LM7, AR503GW-LcM7, AR509G-L-D-H, AR509G-Lc and AR509GW-L-D-H) and AR530 series do not support SAC.

application name cache type aging-time

Function

The application name cache type aging-time command sets the aging time of the entry associated with pre-defined application identification.

The undo application name cache type aging-time command restores the default setting.

By default, the value of the aging time of the entry generated upon multi-channel application identification for ftp is 180 seconds and for other applications is 300 seconds.

Format

application name name cache type multi-channel aging-time aging-time

undo application name name cache type multi-channel aging-time

Parameters

Parameter Description Value
name name Specifies the name of a predefined application. The value must be the name of an existing application.
multi-channel aging-time aging-time Specifies the aging time of the entry generated upon multi-channel application identification. The value is an integer ranging from 1 to 60,000, in seconds. The default value of FTP is 180 seconds, The default value of other applications is 300 seconds.

Views

SA view

Default Level

2: Configuration level

Usage Guidelines

The application name cache type aging-time command sets the aging time of the entry associated with the identification of predefined applications. The entry associated with the identification of user-defined applications never ages.

Example

# Set the aging time of the entry associated with FTP data channel application identification to 100 seconds.

<Huawei> system-view
[Huawei] sa
[Huawei-sa] application name FTP cache type multi-channel aging-time 100

detect max-bytes

Function

The detect max-bytes command specifies the maximum number of bytes to be detected by the SA module.

The undo detect max-bytes command restores the default maximum number of bytes to be detected by the SA module.

By default, the maximum number of bytes to be detected by the SA module is 2048.

Format

detect max-bytes max-bytes

undo detect max-bytes

Parameters

Parameter Description Value
max-bytes Specifies the maximum number of bytes to be detected. The value is an integer ranging from 1 to 10240.

Views

SA view

Default Level

2: Configuration level

Usage Guidelines

This command is used to specify the maximum number of bytes detected by the SA module to prevent certain applications from evading the detection by using small packets.

In common cases, the default maximum value can meet the requirement. If the value is too large, the device performance may deteriorate. If the value is too small, the device may fail to detect certain applications.

Example

# Set the maximum number of bytes to be detected by the SA module to 4096.

<Huawei> system-view
[Huawei] sa
[Huawei-sa] detect max-bytes 4096

detect max-packets

Function

The detect max-packets command specifies the maximum number of packets to be detected by the SA module.

The undo detect max-packets command restores the maximum number of packets detected by the SA module to the default value.

By default, the maximum number of packets to be detected by the SA module is 8.

Format

detect max-packets max-packets

undo detect max-packets

Parameters

Parameter Description Value
max-packets Specifies the maximum number of packets in a session. The value is an integer ranging from 1 to 64. The default value is 8.

Views

SA view

Default Level

2: Configuration level

Usage Guidelines

The specified maximum number of packets to be detected covers both directions in a session.

Example

# Set the maximum number of packets to be detected by the SA module to 20.

<Huawei> system-view
[Huawei] sa
[Huawei-sa] detect max-packets 20

detect uni-direction

Function

The detect uni-direction command configures the unidirectional detection on the SA module.

The undo detect uni-direction command cancels the unidirectional detection and restores the bidirectional detection.

By default, the SA module works in bidirectional detection mode.

Format

detect uni-direction

undo detect uni-direction

Parameters

None

Views

SA view

Default Level

2: Configuration level

Usage Guidelines

SA detection falls into unidirectional detection and bidirectional detection. By default, the SA module works in bidirectional detection mode. If the device is deployed in unidirectional mode, use the detect uni-direction command to configure the unidirectional detection mode of the SA module.

Example

# Configure the unidirectional detection mode of the SA module.

<Huawei> system-view
[Huawei] sa
[Huawei-sa] detect uni-direction

display application

Function

The display application command displays information about applications in the system.

Format

display application [ pre-defined | name name ]

Parameters

Parameter Description Value
pre-defined Indicates predefined applications. -
name name Specifies the name of an application. The value must be the name of an existing application.

Views

All views

Default Level

1: Monitoring level

Usage Guidelines

None

Example

# View the information about all applications.

<Huawei> display application
Service Awareness Signature Database Information:                               
Total Applications: 1622                                                        
--------------------------------------------------------------------------------
-----------------------                                                         
  AppID   Name                                Category          Sub-category    
          RiskLevel State                                                       
  1       BT                                  General_Internet  FileShare_P2P   
          3         activated                                                   
  2       PPLive                              Entertainment     PeerCasting     
          5         activated                                                   
  3       Thunder                             General_Internet  FileShare_P2P   
          5         activated                                                   
  5       FTP                                 Network           Infrastructure  
          3         activated                                                   
  6       FTPS                                Network           Infrastructure  
          4         activated                                                   
  7       eDonkey_eMule                       General_Internet  FileShare_P2P   
          5         activated                                                   
  8       FeiDian                             Entertainment     PeerCasting     
          4         activated                                                   
  9       QQLive                              Entertainment     PeerCasting     
          4         activated                                                   
  11      Fasttrack                           General_Internet  FileShare_P2P   
          5         activated                                                   
  12      PPStream                            Entertainment     PeerCasting     
          5         activated                                                   
  14      DirectConnect                       General_Internet  FileShare_P2P   
          3         activated                                                   
  15      KuGoo                               General_Internet  FileShare_P2P   
          5         activated                                                   
  16      Fring_VoIP                          Entertainment     VoIP            
          4         activated                                                   
  17      PPGou                               General_Internet  FileShare_P2P   
          3         activated                                                   
  18      POCO                                General_Internet  FileShare_P2P   
          5         activated                                                   
  19      BaiBao                              General_Internet  FileShare_P2P   
          3         activated                                                   
  20      Maze                                General_Internet  FileShare_P2P   
          3         activated                                                   
  21      TVAnts                              Entertainment     PeerCasting     
          4         activated                                                   
  22      UUSee                               Entertainment     PeerCasting     
          4         activated                                                   
  23      Vagaa                               General_Internet  FileShare_P2P   
          4         activated                                                   
  ---- More ----                                                                
Table 15-21  Description of the display application command output

Item

Description

AppID

Application ID

Name

Name of an application

Category

Category of an application.

Sub-category

Subcategory of an application.

display application name aging-time

Function

The display application name aging-time command displays the aging time of the entry associated with application identification.

Format

display application name name aging-time

Parameters

Parameter Description Value
name name Specifies the name of an application. The value must be the name of an existing application.

Views

All views

Default Level

2: Configuration level

Usage Guidelines

The display application name aging-time command displays the aging time of the entry associated with the identification of predefined applications. The entry associated with the identification of user-defined applications never ages.

Example

# Display the aging time of the entry associated with FTP identification.

<Huawei> display application name FTP aging-time
Aging Time:   
--------------------------------------------------------------------------------                        
  Application Name                   : FTP                
  Acceleration Aging-time(sec)       : 300              
  Multi-channel Aging-time(sec)      : 180   
--------------------------------------------------------------------------------   
Table 15-22  Description of the display application name aging-time command output

Item

Description

Application Name

Name of an application

Acceleration Aging-time(sec)

Aging time of the entry generated upon application identification acceleration

Multi-channel Aging-time(sec)

Aging time of the entry generated upon multi-channel application identification If the queried application is not a multi-channel application, - is displayed.

display sa application-list

Function

The display sa application-list command displays applications in the SA signature file.

Format

display sa application-list

Parameters

None

Views

All views

Default Level

1: Monitoring level

Usage Guidelines

The SA signature file contains different application protocols. After a signature file is loaded successfully, run the display sa application-list command to view application protocols in the signature file.

Example

# Display SA application protocols in the system.

<Huawei> display sa application-list
  SA application list                                                           
------------------------------------------------------------------------------  
                                                                                
  Index    Protocol Name                    Description                         
  1        BT                               BitTorrent (BT) is a P2P protocol   
                                            for multi-point downloading and can 
                                            be used for many different kinds of 
                                            applications. The client downloads  
                                            and uploads data at the same time.  
                                            Example: BitTorrent, BitSpirit, and 
                                            BitComet.                           
  2        PPLive                           PPLive is a kind of software for    
                                            watching online videos. It supports 
                                            the live and on-demand functions.   
                                            Example: PPLive, TTver, PPTV,       
                                            Wanneng TV.                         
  3        Thunder                          Thunder is a kind of P2P-based      
                                            software for downloading. Example:  
                                            Thunder, Thunder movie, Web         
                                            Thunder, Diandian, Thunder Kankan,  
                                            and Thunder Tingting.               
  4        FTP                              FTP is the abbreviation of File     
                                            Transfer Protocol  which also has a 
                                            specific software can be applied to 
                                            various applications to control     
                                            file' s two-way transmission on the 
                                            Internet. Example: CuteFTP.         
  5        eDonkey_eMule                    eMule is a kind of P2P client       
                                            software which supports files       
                                            sharing through the Internet.       
                                            Example: eMule Xtreme, easyMule.    
  6        QQLive                           QQLive is a kind of software for    
                                            watching online videos developed by 
                                            Tencent. Example: QQLive Web TV,    
                                            Wanneng Web TV, and TTver Web TV.   
  7        Fasttrack                        FastTrack is a protocol used in P2P 
                                            softwares such as Kazaa, Grokster,  
                                            iMesh, and Morpheus. It is called   
                                            the second generation P2P protocol. 
                                            Example: Fasttrack.                 
  8        PPStream                         PPStream is a kind of software for  
                                            watching Web videos which supports  
                                            multiple channels. It is quite      
                                            popular all over China. Example:    
                                            PPS Web TV, PPStream VOD, TTver,    
                                            Wanneng Web TV.                     
  9        DirectConnect                    DirectConnect, developed by         
                                            Neo-Modus, is a kind of free P2P    
                                            client software with the open       
                                            source code which supports file     
                                            exchange and chat. Example:         
                                            DirectConnect++, StrongDC++.        
  10       KuGoo                            KuGou/KuGoo is a kind of P2P music  
                                            sharing software in China which     
                                            supports downloading and online     
                                            listening. Example: KuGoo music.    
  11       Fring_VoIP                       Fring is a kind of free VoIP        
                                            software and is used for a mobile   
                                            phone to connect to the Internet    
                                            for communication and IM. Fring for 
                                            Android does not supporting flow    
                                            blocking in text chat. Example:     
                                            Fring                               
  12       PPGou                            PPGou is a kind of downloading      
                                            software which supports  HTTP and   
                                            P2P downloading. Example: PPGou.    
  13       POCO                             POCO, developed by PoCo, is a kind  
                                            of P2P-based software for resources 
                                            sharing, albums management, and     
                                            electronic magazine online reading. 
                                            Example: POCO multimedia sharing    
                                            platform.                           
  ---- More ----                         
------------------------------------------------------------------------------  
  Total: 945                                                                    
Table 15-23  Description of the display sa application-list command output

Item

Description

SA application list

SA application protocol list.

Index

Index of an application protocol in the SA signature file.

Protocol Name

Application protocol name in the SA signature file, for example, QQLive.

Description

Description of the application protocol, for example, QQLive, an online video player software developed by Tencent.

Total

Total number of application protocols in the SA signature file.

display sa application-statistic

Function

The display sa application-statistic command displays statistics on packets of different SA application protocols on an interface.

Format

display sa application-statistic { application application-name | top-n number | all } interface { interface-type interface-number | virtual-template vt-number virtual-access va-number } [ inbound | outbound ]

Parameters

Parameter

Description

Value

application application-name Displays statistics on packets of a specified application.

The value is a string of 1 to 31 case-sensitive characters without spaces.

top-n number Displays statistics on packets with the largest number of bytes of the first Nth SA application protocols.

The value is an integer that ranges from 1 to 20.

all

Displays statistics on packets of all SA application protocols.

-

interface interface-type interface-number
Displays statistics on packets of an SA application protocol on a specified interface.
  • interface-type specifies the interface type.
  • interface-number specifies the interface number.

-

virtual-template vt-number virtual-access va-number
Displays statistics on packets of an SA application protocol on a specified virtual interface.
  • virtual-template vt-number specifies the number of a virtual template interface. The value is an integer that ranges from 0 to 1023.
  • virtual-access va-number specifies the number of a virtual access interface. The value is an integer that ranges from 0 to 1023.

-

inbound

Displays packet statistics on the inbound interface.

-

outbound

Displays packet statistics on the outbound interface.

-

Views

All views

Default Level

1: Monitoring level

Usage Guidelines

Usage Scenario

After the SA statistics function is enabled on an interface, run the display sa application-statistic command to view statistics on packets of different SA application protocols.

Precautions

If there is no packet of an SA application protocol on an interface, statistics are empty.

Example

# Display statistics on packets of SA applications.

<Huawei> display sa application-statistic all interface GigabitEthernet 0/0/0
Protocol         Direction         Packets               Bytes        Rate(bps)
-------------------------------------------------------------------------------
DNS               Inbound         34,883,510          2,999,981,860   6,443,200
-------------------------------------------------------------------------------
Table 15-24  Description of the display sa application-statistic command output

Item

Description

Protocol

SA application protocol.

Direction

  • Inbound: indicates the statistics on incoming packets.
  • Outbound: indicates the statistics on outgoing packets.

Packets

Number of forwarded packets on an SA-enabled interface.

Bytes

Number of forwarded bytes on an SA-enabled interface.

Rate(bps)

Rate of forwarded packets on an SA-enabled interface, in bps.

display sa category

Function

The display sa category command displays SA group information in the system.

Format

display sa category [ category-name ]

Parameters

Parameter Description Value
category-name

Displays names of SA groups supported by the device. If this parameter is not specified, the command displays information about all the SA groups.

The value is a string of 1 to 31 case-insensitive characters without spaces.

Views

All views

Default Level

1: Monitoring level

Usage Guidelines

This command displays SA groups supported by the device and application protocols in the SA groups.

Before and after configuring an SA group and application protocols, you can run the display sa category command to check whether application protocols in the SA group meet service requirements.

Example

# Display the configuration of the SA group Email.

<Huawei> display sa category Email
  SA Category                                                                   
  Name: Email                                                                   
--------------------------------------------------------------------------------
                                                                                
  Index    Application Name                 Description                         
  1        MAPI_OETP_Exchange               Mail or Messaging Application       
                                            Programming Interface (MAPI) is a   
                                            kind of open interface that         
                                            programmers used to create mail     
                                            writing and workgroup programs (for 
                                            example, Email, plan, agenda, and   
                                            file management). Example:          
                                            OETP_MAPI_ExchangeMapiCdo and       
  2        Mail.ru                          Mail.Ru is the most popular Russian 
                                            Internet portal. This portal        
                                            provides some kinds of services     
                                            including e-mail, on-line diaries,  
                                            social networking, video and photo  
                                            hosting and so on.                  
  3        Kuikoo                           kuikoo is a website which provides  
                                            easy-to-use mail services, allowing 
                                            you to send and receive emails      
                                            anytime anywhere conveniently and   
                                            quickly . This service can be       
                                            applied to computer or mobile phone 
                                            platform freely.                    
  4        In_Mail                          In.com is an Indian website         
                                            providing easy-to-use mail          
                                            services, allowing you to           
                                            conveniently and quickly send and   
                                            receive emails anytime anywhere.    
                                            This service can be applied on      
                                            computers or mobile phone platforms 
                                            freely.                             
  5        ShangMail                        ShangMail is a professional mobile  
                                            mail service provided based on the  
                                            leading push technology.            
--------------------------------------------------------------------------------
  Total: 5                                                                      
Table 15-25  Description of the display sa category command output

Item

Description

Name

SA group name.

Index

Index of an application protocol in the SA group.

Application Name

Application protocol name in the SA group.

Description

Description of the application protocol.

Total

Total number of application protocols in the SA group.

display sa information

Function

The display sa information command displays the SA configuration.

Format

display sa information

Parameters

None

Views

All views

Default Level

1: Monitoring level

Usage Guidelines

The display sa information command displays the SA configuration, including the SA status, number of protocols, and signature file status, and name.

Before and after configuring SA, run the display sa information command to check whether the SA configuration is correct.

Example

# Display the SA configuration.

<Huawei> display sa information
------------------------------------------------------------------------------  
  SA status: enabled                                                            
  App protocol num      : 1622                                                  
  SA signature status   : loaded                                                
  SA signature name     : sd1:/update/sa-sdb/sa_h30071000_2015030601.zip        
------------------------------------------------------------------------------  
Table 15-26  Description of the display sa information command output

Item

Description

SA status

Whether SA is enabled:
  • enabled: SA is enabled.
  • disabled: SA is disabled.
NOTE:

If SA is disabled, the information is not displayed.

To enable SA, run the update restore sdb-default command.

App protocol num

Number of application protocols.

SA signature status

Whether the signature file is loaded:
  • loaded: The signature file has been loaded.
  • not loaded: The signature file is not loaded.

SA signature name

SA signature file name. To enable SA and load a signature file, run the update restore sdb-default command.

if-match application

Function

The if-match application command configures a matching rule in a traffic classifier based on application protocols.

The undo if-match application command deletes a matching rule in a traffic classifier based on application protocols.

By default, a matching rule based on application protocols is not configured in a traffic classifier.

Format

if-match application application-name [ time-range time-name ]

undo if-match application application-name

Parameters

Parameter Description Value
application-name

Specifies the name of an application protocol.

The value is a character string without spaces. The value depends on the applications supported in the signature database. You can run the display sa application-list command to check the value.

time-range time-name

Specifies the name of a time range during which ACL rules take effect. If this parameter is not specified, ACL rules are always valid.

The value is a string of 1 to 32 case-sensitive characters without spaces, starting with an uppercase or a lowercase letter. In addition, the word all cannot be specified as a time range name.

Views

Traffic classifier view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

You can run the if-match application command to classify traffic based on the application protocol. The device implements the same traffic policy for the packets of the same application protocol.

You can flexibly configure the time range during which a matching rule takes effect. If the specified time range does not exist, the matching rule does not take effect.

Prerequisites

The deep security function has been enabled and a SAC signature file has been loaded using the engine enable command.

Precautions

If you run the if-match application command multiple times in the same traffic classifier view, multiple matching rules are configured.

If a traffic policy contains a matching rule configured using the if-match application and the traffic policy need to be applied to packets encapsulated by multiple link layer protocols, apply the traffic policy to a Layer 3 interface that has an IP address. For example, PPPoA packets are generated by encapsulating ATM cells in a PPP header, while PPP packets are encapsulated by IP or other protocols. You must create a virtual template (VT) interface and map the VT interface to the ATM interface. In this case, apply the traffic policy to the VT interface. if-match application in the traffic policy does not take effect if the traffic policy is applied to the ATM interface.

If a traffic policy contains a matching rule configured using the if-match app-protocol command and the traffic policy needs to be applied to packets on a sub-interface, apply the traffic policy to the sub-interface. if-match application in the traffic policy does not take effect if the traffic policy is applied to the main interface.

Example

# Define the traffic classifier class1 to match packets of the SA application protocol 91farm.

<Huawei> system-view
[Huawei] traffic classifier class1
[Huawei-classifier-class1] if-match application 91farm
Related Topics

if-match category

Function

The if-match category command configures a matching rule in a traffic classifier based on an SA group.

The undo if-match category command deletes a matching rule in a traffic classifier based on an SA group.

By default, a matching rule based on an SA group is not configured in a traffic classifier.

Format

if-match category category-name [ time-range time-name ]

undo if-match category category-name

Parameters

Parameter Description Value
category-name Specifies the name of an SA group. The value is a string of 1 to 31 case-sensitive characters without spaces.
time-range time-name Specifies the name of a time range during which ACL rules take effect. If this parameter is not specified, ACL rules are always valid. The value is a string of 1 to 32 case-sensitive characters without spaces, starting with an uppercase or a lowercase letter. The value cannot be all.

Views

Traffic classifier view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

You can run the if-match category command to configure a matching rule in a traffic classifier based on an SA group so that the device processes packets matching the same traffic classifier in the same manner.

The if-match category command defines a time range during which ACL rules take effect. You can flexibly configure the time range during which a matching rule takes effect. If the specified time range does not exist, the matching rule does not take effect.

Prerequisites

The SA application group specified by category-name already exists in the signature database. You can run the display sa category command to check whether the application group exists in the signature database.

Precautions

When a traffic classifier contains if-match category, the relationship between rules in the traffic classifier must be or.

If you run the if-match category command multiple times in the same traffic classifier view, multiple matching rules are configured.

If a traffic policy contains a matching rule configured using the if-match category and needs to be applied to packets encapsulated by multiple link-layer protocols, apply it to a Layer 3 interface that has an IP address.
NOTE:

For example, PPPoA packets are generated by encapsulating ATM cells in a PPP header, while PPP packets are encapsulated by IP or other protocols. You must create a virtual template (VT) interface and apply the VT interface to the ATM interface. In this case, apply the traffic policy to the VT interface. if-match protocol-group in the traffic policy that applies to an ATM interface does not take effect.

If a traffic policy contains a matching rule configured using the if-match category command and needs to be applied to packets on a sub-interface, apply it to the sub-interface. if-match category in the traffic policy that applies to a main interface does not take effect.

Example

# Define the traffic classifier class1 to match the SA group Email.

<Huawei> system-view
[Huawei] traffic classifier class1
[Huawei-classifier-class1] if-match category Email
Related Topics

port-identification packet-number-threshold

Function

The port-identification packet-number-threshold command sets the threshold of packet quantity for port identification in the SA module.

The undo port-identification packet-number-threshold command restores the default threshold of packet quantity for port identification in the SA module.

The default threshold of packet quantity for port identification in the SA module is 16.

Format

port-identification packet-number-threshold packets

undo port-identification packet-number-threshold

Parameters

Parameter Description Value
packets Specifies the number of packets. The value is an integer ranging from 1 to 64.

Views

SA view

Level

2: Configuration level

Usage Guidelines

If packets exceeding the threshold are sent to the IAE and their applications cannot be identified, the SA module identifies the application by port. A high threshold compromises the application identification performance while a low threshold increases the false positive rate. The default value (16) is recommended.

Example

# Set the threshold of packet quantity for port identification in the SA module to 32.

<Huawei> system-view
[Huawei] sa
[Huawei-sa] port-identification packet-number-threshold 32

reset sa application-statistic

Function

The reset sa application-statistic command deletes statistics on SA application protocol packets.

Format

reset sa application-statistic { application application-name | all } interface { interface-type interface-number | virtual-template vt-number virtual-access va-number }

Parameters

Parameter

Description

Value

application application-name Clears statistics on packets of a specified application.

The value is a string of 1 to 31 case-sensitive characters without spaces.

all

Clear statistics on packets of all SA application protocols.

-

interface interface-type interface-number
Clears statistics on packets on a specified interface.
  • interface-type specifies the interface type.
  • interface-number specifies the interface number.

-

virtual-template vt-number virtual-access va-number
Clears statistics on packets on a specified virtual interface.
  • virtual-template vt-number specifies the number of a virtual template interface.
  • virtual-access va-number specifies the number of a virtual access interface.

The value of vt-number is an integer that ranges from 0 to 1023.

The value of va-number is an integer that ranges from 0 to 1023.

Views

User view

Default Level

3: Management level

Usage Guidelines

Usage Scenario

The display sa application-statistic command displays all the previous statistics on SA application protocol packets. Before recollecting statistics, run the reset sa application-statistic command to delete the original statistics.

Precautions

The cleared packet statistics cannot be restored. Exercise caution when you use the command.

Example

# Delete statistics on packets of all SA application protocols on GE2/0/0.

<Huawei> reset sa application-statistic all interface gigabitethernet 2/0/0

sa

Function

The sa command displays the SA view.

Format

sa

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

None

Example

# Access the SA view.

<Huawei> system-view
[Huawei] sa

sa application-statistic enable

Function

The sa application-statistic enable command enables the SA statistics function on an interface.

The undo sa application-statistic enable command disables the SA statistics function on an interface.

By default, the SA statistics function is disabled on an interface.

Format

sa application-statistic enable

undo sa application-statistic enable

Parameters

None

Views

Interface view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

To collect statistics on Layer 4 to Layer 7 traffic on an interface, run the sa application-statistic enable command to enable the SA statistics function.

After the SA statistics function is enabled on an interface, you can use the display sa application-statistic command to view SA statistics.

Precautions

Only Layer 3 interfaces support SA traffic statistics.

Example

# Enable the SA statistics function on GE1/0/0.

<Huawei> system view
[Huawei] interface gigabitethernet 1/0/0
[Huawei-GigabitEthernet1/0/0] sa application-statistic enable
Translation
Download
Updated: 2019-05-29

Document ID: EDOC1000097293

Views: 90165

Downloads: 124

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next