No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


Command Reference

CloudEngine 8800, 7800, 6800, and 5800 V200R002C50

This document describes all the configuration commands of the device, including the command function, syntax, parameters, views, default level, usage guidelines, examples, and related commands.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).



The tnl-policy command associates a tunnel policy with the current VPN instance address family.

The undo tnl-policy command dissociates the current VPN instance address family from a tunnel policy.

By default, no tunnel policy is associated with the VPN instance address family. By default, a tunnel is selected for a VPN in the sequence of the LSP, and Local_IfNet, and no load balancing is performed.


Only CE8860EI, CE8850EI, CE7855EI, CE7850EI, CE6880EI, CE6870EI, CE6860EI, CE6856HI, CE6855HI, CE6851HI, CE6850HI and CE6850U-HI support this command.


tnl-policy policy-name

undo tnl-policy


Parameter Description Value
policy-name Specifies the name of the tunnel policy to be associated with the VPN instance address family. The value is a string of 1 to 39 case-sensitive characters except spaces. When double quotation marks are used to include the string, spaces are allowed in the string.


VPN instance view, VPN instance IPv4 address family view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

By default, a device only uses an LSP tunnel to forward data on the backbone network and cannot implement multi-path load balancing at the same time. To improve transmission efficiency and implement load balancing, run the tunnel-policy command to configure a tunnel policy and run the tnl-policy command to reference the tunnel policy in the VPN address family view.


  1. The ip vpn-instance command has been executed to create a VPN instance and enter the VPN instance view.
  2. The ipv4-family command has been executed to create a VPN instance and enter the VPN instance IPv4 address family view.
  3. The route distinguisher command has been executed to set the RD of the VPN instance.


If the tunnel policy associated with a VPN instance enabled with the address family cannot match an existing tunnel on the network, the routes in the VPN instance enabled with the address family will have routes iterated to tunnels based on the default tunnel policy. If the iteration fails, services will be interrupted.

If the address family of a VPN instance changes or the associated tunnel policy is deleted, VPN services will be interrupted for a short time even if tunnels matching the tunnel policy are available on the network. Therefore, use the tnl-policy command with caution.

Follow-up Procedure

If the associated tunnel policy does not exist, run the tunnel-policy command to create the tunnel policy.


# Associate a tunnel policy named po1 with the VPN instance named vpn2.

<HUAWEI> system-view
[~HUAWEI] tunnel-policy po1
[*HUAWEI-tunnel-policy-po1] tunnel select-seq lsp load-balance-number 2
[*HUAWEI-tunnel-policy-po1] quit
[*HUAWEI] ip vpn-instance vpn2
[*HUAWEI-vpn-instance-vpn2] ipv4-family
[*HUAWEI-vpn-instance-vpn2-af-ipv4] route-distinguisher 100:1
[*HUAWEI-vpn-instance-vpn2-af-ipv4] tnl-policy po1
Updated: 2019-03-21

Document ID: EDOC1000166501

Views: 70581

Downloads: 376

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Previous Next