No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

eSight V300R010C00 Maintenance Guide 08

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
eLTE Management

eLTE Management

This section describes the eLTE configuration files.

primaryNE.properties

Function

eLTE primary NE configuration file.

Path

eSight installation directory\AppBase\etc\ewl\primaryne\primaryNE.properties

Description
Table 9-202 Configuration items in primaryNE.properties

Parameter

Description

Setting

Effective Method

mmldefaultwd

Default MML or NETCONF protocol password for eLTE primary devices

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

soapdefaultwd

Default SOAP protocol password for eLTE primary devices

Data type: string

Value range: encrypted ciphertext for the password

Default value: 0bc954ce1dc14f0ebbbf62a7d7b3859186e1fcb4518eae848f9f5561969a959a

Restart

elteFtpPsd

Default password for the elteFtpuser user in the FTP system

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster and on both the active and standby nodes of a Veritas two-node cluster.

mml.properties

Function

Protocol stack connection figuration file for eLTE primary NEs.

Path

eSight installation directory\AppBase\etc\ewl\primaryne\mml.properties

Description
Table 9-203 Configuration items in mml.properties

Parameter

Description

Setting

Effective Method

sslksps

keyStore password for primary NEs

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

ssltsps

trustStore password for primary NEs

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart eSight for the settings to take effect

prikeyps

private key password for primary NEs

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster and on both the active and standby nodes of a Veritas two-node cluster.

AcsServer.xml

Function

Configuration file used to configure the ACS server.

Path

eSight installation directory/AppBase/etc/ewl/AcsServer.xml

Description
Table 9-204 Configuration items in AcsServer.xml

Parameter

Description

Setting

Effective Method

TR069ROA/tmshttpsport/port

TR069 protocol stack HTTPS port

Data type: An integer greater than 0

Default value: 8445

Restart

TR069ROA/tmshttpsport/ssl.keystore.path

TR069 protocol stack certificate library path

Data type: string

Default value: etc/ewl/cpe/ssl/serverKeyStore

Restart

TR069ROA/tmshttpsport/ssl.keystore.password

TR069 protocol stack certificate library password

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

TR069ROA/tmshttpsport/ssl.include.ciphers

TR069 protocol stack encryption algorithm

NOTE:

By default, the TR069 protocol stack uses an encryption algorithm with high security. The industry terminal also needs to support the encryption algorithm. Otherwise, the industry terminal cannot be added to eSight normally. If the industry terminal does not support the encryption algorithm, you can use another encryption algorithm for the TR069 protocol stack. However, security risks exist. Excise caution when using another encryption algorithm. For details, see Operation Guide > eLTE Management > FAQ and Troubleshooting > Why Cannot Industry Terminals Be Added to eSightNormally.

Data type: string

Value range:

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256;TLS_DHE_DSS_WITH_AES_128_GCM_SHA256;

TLS_RSA_WITH_AES_256_CBC_SHA256;TLS_RSA_WITH_AES_256_CBC_SHA;

TLS_RSA_WITH_AES_128_CBC_SHA

Default value:

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256;TLS_DHE_DSS_WITH_AES_128_GCM_SHA256

Restart

TR069ROA/tmshttpsport/ssl.protocol

TR069 protocol stack version number

Data type: string

Default value: TLSv1.1;TLSv1.2

Restart

TR069ROA/tmshttpsport/ssl.privatekey.password

TR069 protocol stack private key password

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

TR069ROA/WTTxhttpsport/port

HTTPS port of the WTTx TR069 protocol stack

Data type: An integer greater than 0

Default value: 7548

Restart

TR069ROA/WTTxhttpsport/ssl.keystore.path

Certificate library path of the WTTx TR069 protocol stack

Data type: string

Default value: etc/ewl/cpe/ssl/serverKeyStore

Restart

TR069ROA/WTTxhttpsport/ssl.keystore.password

Certificate password of the WTTx TR069 protocol stack

Data type: string

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

TR069ROA/WTTxhttpsport/ssl.privatekey.password

WTTx private key password

Data type: string

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

TR069ROA/WTTxhttpsport/ssl.include.ciphers

Encryption algorithm of the WTTx TR069 protocol stack

Data type: string

Default value: TLS_RSA_WITH_AES_256_CBC_SHA256;TLS_RSA_WITH_AES_256_CBC_SHA;

TLS_RSA_WITH_AES_128_CBC_SHA

Restart

TR069ROA/WTTxhttpsport/ssl.protocol

Protocol version number of the WTTx TR069 protocol stack

Data type: string

Default value: TLSv1.1;TLSv1.2

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster and on both the active and standby nodes of a Veritas two-node cluster.

fileserver.xml

Function

Configuration file used to configure the eLTE combination file server.

Path

eSight installation directory/AppBase/etc/ewl/fileserver.xml

Description
Table 9-205 Configuration items in fileserver.xml

Parameter

Description

Setting

Effective Method

EWLfileserver/path

Industry Terminal file server path name

Data type: string

Default value: webapps_ewl

Restart

EWLfileserver/httpsport

Industry Terminal file server HTTPS port

Data type: An integer greater than 0

Default value: 32106

Restart

EWLfileserver/authuser

Industry Terminal file server user name

Data type: string

Default value: admin

Restart

EWLfileserver/authpass

Industry Terminal file server user password

Data type: string

Value range: encrypted ciphertext for the password

Default value: e8ddac567f8c35944dc57a700a6f03c9a94d7ee5824705c5651509ede6e36ac1273a35eca60ad8c5f2c7c357b40c0462

Restart

EWLfileserver/keystore

Industry Terminal file server certificate library path

Data type: string

Default value: etc/ewl/cpe/ssl/serverKeyStore

Restart

EWLfileserver/keystorePassword

Industry Terminal file server certificate library password

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

EWLfileserver/ciphers

Encryption suite supported by the Industry Terminal file server HTTPS protocol

NOTE:

By default, the HTTPS protocol of the industry terminal file server uses an encryption suite with high security. The industry terminal also needs to support the encryption algorithm. Otherwise, the industry terminal cannot be added to eSight normally. If the industry terminal does not support the encryption suite, you can use another encryption suite for the HTTPS protocol. However, security risks exist. Excise caution when using another encryption suite. For details, see Operation Guide > eLTE Management > FAQ and Troubleshooting > Why Cannot Industry Terminals Be Added to eSightNormally.

Data type: string

Value range:

TLS_DHE_RSA_WITH_AES_128_GCM_SHA256;TLS_DHE_DSS_WITH_AES_128_GCM_SHA256;

TLS_RSA_WITH_AES_256_CBC_SHA256;TLS_RSA_WITH_AES_256_CBC_SHA;

TLS_RSA_WITH_AES_128_CBC_SHA

Default value: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256;TLS_DHE_DSS_WITH_AES_128_GCM_SHA256

Restart

EWLfileserver/protocol

Industry Terminal file server HTTPS protocol version number

Data type: string

Default value: TLSv1.1;TLSv1.2

Restart

EWLfileserver/prikeyPassword

Industry Terminal file server private key password

Data type: string

Value range: encrypted ciphertext for the password

Default value: fc318692132f59459a8b80010622ce92738e79c5ad19f68ed4dae5d856591278c555a4ac86bd8442afb134cb6c5f64bc

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster or a Veritas two-node cluster. After the configuration file is modified on the active node of a Veritas two-node cluster, the modification is automatically synchronized to the standby node.

cpeCommon.properties

Function

eLTE Industry Terminal connection and status monitoring parameter configuration file.

Path

eSight installation directory\AppBase\etc\ewl\cpeCommon.properties

Description
Table 9-206 Configuration items in cpeCommon.properties

Parameter

Description

Setting

Effective Method

single_poll_interval_min

Minimum interval of polling. Unit: second

Data type: An integer greater than 0

Default value: 60

Restart

status_detect_interval

Interval of status detection. Unit: second

Data type: An integer greater than 0

Default value: 2

Restart

status_detect_threadnum

Number of status detection threads of a single detection task

Data type: An integer greater than 0

Default value: 3

Restart

default_acs_user

Default authentication user which eSight used to authenticate the connection with Industry Terminal.

Data type: string

Value range: encrypted ciphertext for the user password

Default value: eee9061d7d8482daee3a1f6f6adc16ac61fbbb77b3b77798412e740f7c207c71

Restart

default_acs_password

Default authentication credentials which eSight used to authenticate the connection with Industry Terminal.

Data type: string

Value range: encrypted ciphertext for the user password

Default value: 80677c028ddfdb1a591a027e5eb99668e2c4d15d9359915a2732307fb27c26ea

Restart

default_dev_user

Default authentication user which eSight used to connect back to Industry Terminal.

Data type: string

Value range: encrypted ciphertext for the user password

Default value: eee9061d7d8482daee3a1f6f6adc16ac61fbbb77b3b77798412e740f7c207c71

Restart

default_dev_password

Default authentication credentials which eSight used to connect back to Industry Terminal.

Data type: string

Value range: encrypted ciphertext for the user password

Default value: 80677c028ddfdb1a591a027e5eb99668e2c4d15d9359915a2732307fb27c26ea

Restart

cpe_tr069_digest_algorithm

Digest authentication algorithm of the TR069 protocol

NOTE:

By default, the TR069 protocol uses a digest authentication algorithm with high security. The industry terminal also needs to support the digest authentication algorithm. Otherwise, the industry terminal cannot be added to eSight normally. If the industry terminal does not support the authentication algorithm, you can use another authentication algorithm for the TR069 protocol. However, security risks exist. Excise caution when using another authentication algorithm. For details, see Operation Guide > eLTE Management > FAQ and Troubleshooting > Why Cannot Industry Terminals Be Added to eSightNormally.

Data type: string

Value range: SHA-256 and MD5

Default value: SHA-256 (SHA-256)

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster and on both the active and standby nodes of a Veritas two-node cluster.

cipherSuiteConfig.xml

Function

Encryption suite used to configure SSL connection between eSight and NEs.

Path

eSight installation directory/AppBase/etc/ewl/primaryne/neconnection/ssl/cipherSuiteConfig.xml

Description
Table 9-207 Configuration items in cipherSuiteConfig.xml

Parameter

Description

Setting

Effective Method

cipherSuiteList

Certificate authentication algorithm suite list.

NOTE:

By default, the certificate authentication algorithm suite uses an algorithm suite with high security. The main device must support the algorithm suite. Otherwise, the main device cannot be added to eSight. If the main device does not support the authentication algorithm suite, you can use another authentication algorithm suite. However, security risks exist. Excise caution when using another authentication algorithm suite. For details, seeOperation Guide > eLTE Management > FAQ and Troubleshooting > Why Cannot eNodeBs and Core Network Devices Be Added to eSight Normally.

TLSv1.1

TLSv1.2

Restart

high configuration item:

Data type: string

Value range: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256:

TLS_RSA_WITH_AES_256_CBC_SHA

Default value: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

high configuration item:

Data type: string

Value range: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256:

TLS_RSA_WITH_AES_256_CBC_SHA256

Default value: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

all configuration item:

Data type: string

Value range: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256:

TLS_RSA_WITH_AES_256_CBC_SHA:

TLS_DH_anon_WITH_AES_256_CBC_SHA

Default value: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

all configuration item:

Data type: string

Value range: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256:

TLS_RSA_WITH_AES_256_CBC_SHA256:

TLS_DH_anon_WITH_AES_256_CBC_SHA256

Default value: TLS_DHE_RSA_WITH_AES_128_GCM_SHA256

anonCipherList

Anonymous authentication algorithm suite list

Data type: string

Value range: TLS_RSA_WITH_AES_256_CBC_SHA:TLS_RSA_WITH_AES_256_CBC_SHA256:

TLS_DH_anon_WITH_AES_256_CBC_SHA256:TLS_DH_anon_WITH_AES_256_CBC_SHA

Default value: none

Restart

NOTE:

To make eSight compatible with eCNS610 earlier than V100R004C00 and CGPOMU earlier than V200R016C10, the anonymous authentication algorithm is kept. Enabling the algorithm is risky. By default, it is disabled. To be compatible with old devices, open the eSight installation directory\AppBase\ jre\lib\security\java.security file and change the value range (deleting the anon value) of the jdk.tls.disabledAlgorithms parameter. Save the file and restart eSight.

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster and on both the active and standby nodes of a Veritas two-node cluster.

snmp_config.properties

Function

Encryption suite used to configure SNMP connection between eSight and NEs.

Path

eSight installation directory/AppBase/etc/ewl/primaryne/neconnection/snmp/snmp_config.properties

Description
Table 9-208 Configuration items in upgrade.properties

Parameter

Description

Setting

Effective Method

version

SNMP protocol version number

Data type: string

Value range: V3

Default value: V3

Restart

authProtocol

Authentication protocol

NOTE:

Using HMAC_SHA (more secure) is recommended.

Data type: string

Value range: HMAC_SHA; HMAC_MD5; None

Default value: HMAC_SHA

Restart

HostKeyAlgorithms

Privacy protocol

NOTE:

Using AES_256 (more secure) is recommended.

Data type: string

Value range: AES_256; AES_128; CBC_DES; None

Default value: AES_256

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster and on both the active and standby nodes of a Veritas two-node cluster.

ssh_config.properties

Function

Encryption suite used to configure SSH connection between eSight and NEs.

Path

eSight installation directory/AppBase/etc/ewl/primaryne/neconnection/ssh/ssh_config.properties

Description
Table 9-209 Configuration items in upgrade.properties

Parameter

Description

Setting

Effective Method

Ciphers

Indicates the transport layer encryption algorithm

Data type: string

Value range: aes128-ctr; aes192-ctr; aes256-ctr

Default value: N/A

Restart

MACs

Indicates the transport layer integrity algorithm

Data type: string

Value range: ahmac-sha2-256; hmac-sha2-512

Default value: N/A

Restart

HostKeyAlgorithms

Indicates the transport layer public-key algorithm

Data type: string

Value range: assh-rsa; ssh-dss

Default value: N/A

Restart

KexAlgorithms

Indicates the transport layer Diffie-Hellman algorithm

Data type: string

Value range: adiffie-hellman-group14-sha1; diffie-hellman-group-exchange-sha256; diffie-hellman-group-exchange-sha1

Default value: N/A

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster or a Veritas two-node cluster. After the configuration file is modified on the active node of a Veritas two-node cluster, the modification is automatically synchronized to the standby node.

eWLDiskSizeLimit.xml

Function

eWLDiskSizeLimit.xml is used to configure the size limit of the files uploaded by users or devices to the storage directory.

Path

eSight installation directory\AppBase\etc\ewl\eWLDiskSizeLimit.xml

Description
Table 9-210 Configuration items in eWLDiskSizeLimit.xml

Configuration item

Sub configuration

Description

Setting

Effective Method

med

path

Adaptation package upload storage directory (Relative eSight installation directory\AppBase).

/med

This parameter cannot be modified

maxsize

Size limit of the files uploaded to the storage directory.

Data type: long

Default value: 10737418240

Unit: byte

Restart

ftps

path

Storage directory of files related to eLTE primary devices software upgrade (Relative eSight installation directory\AppBase).

/var/iemp/data/ftp/elte/ewl

This parameter cannot be modified

maxsize

Size limit of the files uploaded to the storage directory.

Data type: long

Default value: 10737418240

Unit: byte

Restart

mrfs

path

Total size of the directory provided for the performance module of the main device to cache performance data (Relative eSight installation directory\Appbase)

/var/iemp/data/ftp/elte/pm

This parameter cannot be modified

maxsize

Size limit of the files uploaded to the storage directory.

Data type: long

Default value: 21474836480

Unit: byte

Restart

fileServer

path

Storage directory of exported industry terminal configuration files (Relative eSight installation directory\AppBase).

/fileServer/webapps_ewl/WebContent

This parameter cannot be modified

maxsize

Size limit of the files uploaded to the storage directory.

Data type: long

Default value: 10737418240

Unit: byte

Restart

ewlNbi

path

Total size of files that are provided for the northbound system to collect data (Relative eSight installation directory\Appbase).

/var/iemp/data/nbi/pmdatatemp/Northbound

This parameter cannot be modified

maxsize

Size limit of the files uploaded to the storage directory.

Data type: long

Default value: 524288000

Unit: byte

Restart

configbkpmgr

path

Total size of the directory for the backup management module to store configuration files (Relative eSight installation directory\Appbase).

/var/iemp/data/ftp/elte/configbkpmgr

This parameter cannot be modified

maxsize

Size limit of the files uploaded to the storage directory.

Data type: long

Default value: 1073741824

Unit: byte

Restart

eranmonitorFileReport

path

Total size of file storage directory for storing the reported eAN3710 and eAN3820 signaling trace files (Relative eSight installation directory\Appbase).

/var/iemp/data/ftp/elte/fars

This parameter cannot be modified

maxsize

Size limit of the files uploaded to the storage directory.

Data type: long

Default value: 10737418240

Unit: byte

Restart

Precautions

Modify this configuration file only when necessary.

If configuration items are modified manually, eSight must be restarted for the modifications to take effect.

To modify configuration items, you need to modify the configuration file on the active node of an OMMHA two-node cluster and on both the active and standby nodes of a Veritas two-node cluster.

Translation
Download
Updated: 2019-08-03

Document ID: EDOC1100044373

Views: 26831

Downloads: 86

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next