CloudCampus Solution V100R022C00 Design and Deployment Guide for Multi-Campus Network Interconnection
Deployment Configuration
- Site Deployment
- Deployment Process, Device Models and Application Scenarios in Different Deployment Modes
- Email-based Deployment
- Overview of Email-based Deployment
- Email-based Deployment Process
- Device and Feature Requirements for Email-based Deployment
- Configuring an Email Server
- (Optional) Configuring an Email Template
- Performing Email-based Deployment (by Sending an Email)
- Performing Email-based Deployment (by Downloading the ZTP File)
- USB-based Deployment
- DHCP Option-based Deployment
- Deployment Through the Registration Query Center
- Overview of Deployment Through the Registration Query Center
- Process of Deployment Through the Registration Query Center
- Device and Feature Requirements for Deployment Through the Registration Query Center
- Configuring Interconnection with the Registration Query Center
- Configuring Deployment Through the Registration Query Center
- (Optional) Data Synchronization from the Registration Query Center
- Cloud Site Deployment
- Manual Deployment
- Quick Deployment
Site Deployment
Definition and Classification
In traditional site deployment mode, professional IT engineers are required to deploy devices onsite. Misoperations may occur due to scattered devices and time-consuming online operations, and errors may occur due to manual operations during initial configuration. Huawei SD-WAN Solution uses zero touch provisioning (ZTP), including email-, USB-, and DHCP option-based deployment, to address these issues.
Both the ESN and hostname can uniquely identify a CPE. A CPE can be deployed through ZTP only when the ESN is configured as the CPE's unique identifier on iMaster NCE-Campus. By default, iMaster NCE-Campus uses the ESN of a CPE as the CPE's unique identifier.
Roles and Responsibilities
Table 2-101 describes roles involved in the deployment process and their corresponding responsibilities.
Role |
Major Responsibilities |
---|---|
Network administrator |
A network administrator is responsible for network deployment, planning, and maintenance. In an email-based deployment scenario, the network administrator configures and sends a deployment email. The email must contain the URL used to activate the deployment process. It is recommended that the email contain operation instructions for deployment engineers. |
Site deployment engineer (device administrator) |
A site deployment engineer, also referred to the device administrator of the system integrator, is responsible for managing purchased devices. In a USB-based deployment scenario, the device administrator can import initial configurations to a CPE using a USB flash drive before delivery. |
Site deployment engineer (network installation or maintenance engineer) |
Site deployment can be completed by onsite network installation or maintenance engineers, eliminating the need of onsite deployment by professional network engineers.
|
Deployment Plan and Procedure
- Before the deployment, a southbound IP address needs to be planned for iMaster NCE-Campus to ensure that CPEs can connect to iMaster NCE-Campus through the Internet or a private network.
If a CPE has been successfully connected to iMaster NCE-Campus after deployment, iMaster NCE-Campus automatically delivers the southbound IP address of the secondary cluster to the CPE. In this case, an active/standby cluster switchover does not affect the connection between the CPE and iMaster NCE-Campus. If a deployment operation has been performed (for example, a deployment email has been sent, the DHCP server has been configured, or files have been created for USB-based deployment) but a CPE has never been online, the CPE cannot automatically initiate a connection request to the new active cluster upon an active/standby cluster switchover. In this case, perform the following operation :
- Email-based deployment: Send a deployment email again on iMaster NCE-Campus and deploy the CPE according to the email.
- USB-based deployment: Regenerate USB-based deployment files on iMaster NCE-Campus.
- DHCP option-based deployment: Configure a new southbound IP address on the DHCP server.
- Deployment through the registration query center: Change the address of the new active cluster in the registration query center.
- The network administrator plans and designs the network, selects site devices, configures ZTP on iMaster NCE-Campus, and completes deployment preparations based on the deployment mode. It is recommended that wired WAN links be used for controller registration. If wireless links such as LTE/5G links are used, there is a high risk that devices cannot be managed by the controller.
- Email-based deployment: After configuring ZTP, the network administrator needs to confirm that the deployment email has been sent to the onsite deployment engineer.
- USB-based deployment: After configuring ZTP, the network administrator needs to download and send the ZTP deployment file to the onsite deployment engineer.
- DHCP option-based deployment: The network administrator needs to configure DHCP options on the DHCP server to ensure that deployment configurations are correctly delivered through DHCP messages.
- Deployment through the registration query center: The network administrator needs to interconnect the controller with the registration query center.
- The deployment engineer completes the deployment and checks whether the deployment is successful onsite.
Deployment Process, Device Models and Application Scenarios in Different Deployment Modes
In the SD-WAN Solution, both edge and RR devices need to be deployed. The deployment mode varies depending on device models. You can perform device deployment according to Table 2-102.
No. |
Step |
Deployment Mode |
Task |
Supported by Devices |
Application Scenario Description |
|||
---|---|---|---|---|---|---|---|---|
AR600&6100&6200&6300 series |
SRG series |
AR5700&6700&8000 series |
AR1000V |
|||||
1 |
Deployment |
Scenario 1: email-based deployment |
Y |
Y |
Y |
N |
This deployment mode is recommended for non-AR1000V devices. This deployment mode is simple and has low skill requirements for deployment personnel. However, a PC and network cables are required onsite. |
|
Scenario 2: USB-based deployment |
Y |
Y |
N |
N |
The deployment mode is simple and applies to batch deployment in warehouses. In addition, deployment personnel do not need to have any professional skills or carry tools such as PCs. However, the device ESNs must be bound to sites before deployment, devices may be incorrectly delivered. |
|||
Scenario 3: DHCP option-based deployment |
Y |
Y |
Y |
N |
The permission for configuring a DHCP server is required in DHCP option-based deployment mode. |
|||
Scenario 4: Deployment through the registration query center |
Y |
N |
N |
N |
Only AR600 (AR650 sub-series) and AR6100&6200&6300 (AR6280/AR6300+SRU-400H and AR6280/AR6300+SRU-600H) series routers can be deployed through the registration query center. In addition, the WAN-side interface of a CPE at a site must apply for an IP address from the DHCP server in DHCP mode. |
|||
Scenario 5: Cloud site deployment |
N |
N |
N |
Y |
Only the AR1000V can be automatically deployed on HUAWEI CLOUD or AWS. The cloud site deployment mode is recommended because the AR1000V can be installed and deployed the same time. |
|||
Scenario 6: Manual deployment |
Y |
N |
N |
N |
Manual deployment is complex and inefficient. Email-based deployment is recommended if there are no special requirements. If the interface type of the WAN-side link is Eth-Trunk, only the manual deployment mode can be used. |
|||
N |
N |
Y |
N |
This deployment mode is supported by AR5700&6700&8000 series devices. If the WAN link of a device is an Eth-Trunk or Eth-Trunk sub-interface, this device can be deployed only in manual mode. |
||||
N |
N |
N |
Y |
The AR1000V can also be manually deployed. However, cloud site deployment is recommended for the AR1000V on HUAWEI CLOUD or AWS. |
||||
2 |
Deployment verification |
- |
- |
- |
- |
- |
- |
Email-based Deployment
Overview of Email-based Deployment
Definition
Email-based deployment, also called URL-based deployment. After a network administrator completes ZTP configuration on iMaster NCE-Campus, iMaster NCE-Campus automatically generates a deployment email or ZTP file carrying the deployment information in URL parameters, such as the encryption parameters that provide the WAN interface configurations required by devices to register iMaster NCE-Campus. After receiving the deployment email or ZTP file, a deployment engineer clicks the URL in the email or ZTP file to start the deployment process. Subsequently, devices automatically complete the deployment.
Application Scenarios
The email-based deployment mode is used when a CPE is installed at a site and deployment needs to be performed onsite. Email-based deployment greatly simplifies the operation process of a deployment engineer. The deployment engineer can start the deployment process with one click on the web UI. Then, the deployment can be completed automatically. This lowers skill requirements for the deployment engineer, minimizes labor costs, and shortens the deployment time.
When you perform email-based deployment for a CPE using a mobile phone through a Wi-Fi network, you are advised to disable the mobile data connection function on the mobile phone and then connect the mobile phone to the Wi-Fi network of the CPE.
Email-based Deployment Modes
Email-based deployment can be performed in either of the following two modes:
- Sending an email: The URL containing deployment information is sent to the deployment engineer by email.
- Downloading the ZTP file: The URL containing deployment information is sent to the deployment engineer in the ZTP file. In this mode, no email server is required.
Automatic Recording of ESNs
Email-based deployment applies to the scenario where ESNs are not bound to CPEs and are automatically recorded on iMaster NCE-Campus after deployment.
If only the CPE model is specified but the ESN of the CPE is not specified when a CPE is allocated to a site on iMaster NCE-Campus, iMaster NCE-Campus automatically allocates a token to the CPE when generating a deployment email for the site. When the deployment engineer deploys the CPE, the CPE sends the token, ESN, and other registration information to iMaster NCE-Campus for registration. iMaster NCE-Campus then associates the CPE with the ESN based on the token to complete the registration of the CPE.
Email-based Deployment Process
Deployment Process
Figure 2-17 shows the email-based deployment process.
The following describes the email-based deployment process:
- Configure an email server.
This step is mandatory if you require email-based deployment in email sending mode. If you require email-based deployment in ZTP file downloading mode, skip this step.
- Configure network parameters, and then send a deployment email or download the ZTP file.
- On iMaster NCE-Campus, add the device (CPE) to be deployed, create a site, and set network deployment parameters for the device.
- Perform as follows based on the deployment mode:
- Sending an email: Configure the email content on iMaster NCE-Campus, which then sends the email to the specified email address. The URL in the email carries encrypted network configurations of the CPE.
- Downloading the ZTP file: Obtain the ZTP file from iMaster NCE-Campus. The URL in the file carries encrypted network configurations of the CPE.
- Obtain the URL containing deployment parameters through the email or ZTP file.Perform as follows based on the deployment mode:
- Sending an email: Log in to the mailbox, check the received deployment email, and carry it to the customer site.
- Downloading the ZTP file: Obtain the ZTP file, verify that the ZTP file is available, and carry it to the customer site.
- Power on the device and obtain the configurations in the URL.
- After the device is installed and started, connect the device to a deployment terminal in wired or wireless mode and click the URL in the deployment email or ZTP file to start the deployment process.
- The device resolves the URL information and pushes the Portal page to the deployment terminal. After the deployment engineer confirms deployment on the Portal page, the device automatically completes configurations (including interface, network access, and VPN configurations) based on the parameters in the URL.
- The device is connected to the WAN and registers with iMaster NCE-Campus.
The device automatically registers with iMaster NCE-Campus based on the address and port number of iMaster NCE-Campus in the URL.
- If the CPE is registered successfully, iMaster NCE-Campus delivers all the service data that is configured offline to the device.
- If the CPE fails to be registered, it initiates registration with iMaster NCE-Campus again after the fault causing the registration failure is eliminated.
Device and Feature Requirements for Email-based Deployment
Device Requirements
Email-based deployment is supported on AR600&6100&6200&6300&SRG series and AR5700&6700&8000 series devices.
Feature Requirements
Phase |
Requirement |
---|---|
Before deployment |
After a user logs in to an undeployed AR5700&6700&8000 series device through the console port,this device cannot be deployed in email-based mode. |
When you perform email-based deployment for a CPE using a mobile phone through a Wi-Fi network, you are advised to disable the mobile data connection function on the mobile phone and then connect the mobile phone to the Wi-Fi network of the CPE. |
|
During URL-based deployment for a site, you need to disconnect the LAN-side links. For a dual-gateway site, disconnect the interlink between the two gateways. After the deployment is completed, re-connect the LAN-side links and the interlink between the two gateways. This prevents a deployment failure caused due to a management address conflict of the two gateways. |
|
If a SIM card needs to be inserted into a device at the deployment site, you are advised to insert the SIM card into slot 1 instead of other slots. Otherwise, the device may fail to register after being restarted, causing a deployment failure. |
|
To perform email-based deployment for AR5700&6700&8000 series devices, enable Encryption and Web login in WAN Global Configuration. |
|
In the scenario where an AR5700&6700&8000 series device uses an LTE link for email-based deployment, since board registration takes several minutes, you need to perform deployment configuration for the device 5 minutes after the device is restored to factory settings. This prevents deployment failures caused by deployment parameter delivery failures when boards are not registered. |
|
After deployment |
If the interface protocol type or link access mode of the WAN link is changed, email-based deployment needs to be performed again. If the interface description, uplink or downlink capacity, or link ID is changed, email-based deployment does not need to be performed again. For details about the parameters involved in re-deployment, see the description of the parameters on the WAN Link page. |
Configuring an Email Server
Application Scenario
If iMaster NCE-Campus needs to send emails to users, you need to configure an email server first.
iMaster NCE-Campus needs to send emails in the following scenarios:
- If the system administrator, MSP administrator, or tenant administrator forgets the password, iMaster NCE-Campus needs to send a reset password to the administrator through an email.
- After the system administrator configures alarm settings on iMaster NCE-Campus, iMaster NCE-Campus sends alarm notifications to users via email.
- When the system administrator deletes ESNs or devices, iMaster NCE-Campus sends a notification email to the tenant administrator.
- If a tenant administrator wants to use the email-based deployment function, iMaster NCE-Campus sends a deployment email to deployment personnel.
- iMaster NCE-Campus sends a notification email to a tenant if a tenant license is about to expire.
- When Portal authentication is configured for guests, iMaster NCE-Campus sends a notification email to approvers or guests.
Feature Requirements
- If the email server uses a non-official CA certificate, you are advised to toggle off Validate server certificate.
- There must be reachable routes between the email server and iMaster NCE-Campus nodes.
Procedure
- Upload an email server certificate.
- Contact the email server provider to obtain a certificate file.
- Log in to iMaster NCE-Campus as the system administrator and choose System > Security Management > Certificate Management from the main menu.
- Choose Service Certificate Management from the navigation pane. On the Services page, click CampusBaseServiceServerConfigMoudle.
- Click the Trust Certificate tab and click Import. On the displayed page, enter the certificate information, select the desired email server certificate, and click Submit to upload the certificate to iMaster NCE-Campus.
- Choose from the main menu and click the Email Server tab.
- Set parameters for interconnection with the email server.
- Click Test to verify the email sending function.
- If the message "The test succeeds" is displayed and the mailbox receives the test email, the configuration is successful. Click Save.
- If the message "The test succeeds" is displayed but the mailbox does not receive the test email, check whether the email function of the SMTP server is normal.
- If the message "Failed to connect to the email server" is displayed, check whether the above parameters are correctly configured.
- Affected by the performance of the SMTP server and network quality, the time of receiving test emails will be delayed for at most two minutes.
- Some SMTP providers set right control for third-party application access. If the test fails, check whether third-party application access control is enabled on the SMTP server and set password to the authentication password of the SMTP server.
- Limited by security policies of email service providers, administrators may fail to receive emails in some scenarios. If this occurs, log in to the email service website or contact the email service provider to check whether the email is returned or any other exception occurs. Alternatively, configure interconnection between iMaster NCE-Campus and another email server, and try again
Parameter Description
Parameter |
Description |
Data Plan in Advance |
---|---|---|
SMTP address |
SMTP is short for Simple Mail Transfer Protocol, and is mainly used to transfer system emails and provide email notifications. This parameter specifies the IP address of the email server used by iMaster NCE-Campus to send emails. Constraints: The email server must be accessible to iMaster NCE-Campus. You can specify an IP address or a domain name, for example, smtp.mail.com. |
Y |
Port |
Port used by the email server to provide the SMTP service for external systems. You can obtain the port number from the email service provider. In most cases, the port number is 25. Constraints: The port number must be the same as that provided by the email server provider. |
Y |
Enable STARTTLS |
Whether to enable the STARTTLS protocol. NOTE:
When the STARTTLS protocol is enabled, Secure connection is enabled by default. |
- |
Secure connection |
Whether secure connection is enabled. |
- |
Encrypted connection type |
Protocol for establishing an encrypted communication channel between iMaster NCE-Campus and the SMTP server. Constraints: This parameter takes effect only when Secure connection is selected. NOTE:
TLSv1.2 and TLSv1.3 are recommended, because they are more secure than TLSv1.0 and TLSv1.1. Exercise caution when configuring TLSv1.0 and TLSv1.1. |
- |
Validate server certificate |
For security purposes, select Secure connection and Validate server certificate. Whether to enable certificate verification. |
- |
Certificate File |
Certificate file of the email server. This certificate ensures communication security between iMaster NCE-Campus and the email server. |
- |
Authentication |
Whether to enable the email account and password authentication. |
- |
Account |
The two parameters take effect only when Authentication is selected. Username and password for logging in to the SMTP server. |
- |
Password |
- |
|
Sender Email |
Sender email address, which must have been registered on the email server. During the email test, this address is used as a recipient email address. After the connectivity test succeeds and the email server configurations are saved, this address is used as the sender email address. |
Y |
Customized email subject |
Email subject. An administrator can customize the prefix and suffix of the email subject. When an email is sent, the prefix and suffix are automatically placed before and after the email subject. |
- |
Customized email signature |
Email signature. An administrator can customize the email signature, and the signature is automatically attached to emails. |
- |
(Optional) Configuring an Email Template
In the email-based deployment scenario, deployment emails need to be configured on multiple CPEs. That is, emails with the same subject and body format need to be configured on different CPEs. To reduce repeated operations, you can configure an email template. When configuring email-based deployment parameters for each device, you can reference the email template to set the parameters automatically.
iMaster NCE-Campus provides a default email template ZTP email template. If the default email template can meet your requirements or email-based deployment is not required, skip this section. Otherwise, you need to configure an email template as needed.
Procedure
- Choose from the main menu and click the WAN Template tab.
- Click the Email Template tab.
- Click Create to create an email template.
In normal cases, you only need to set Email Template, Subject, and Content. You can set other parameters as needed.
- Click OK.
Parameter Description
Parameter |
Description |
---|---|
Email template |
Name of an email template. If multiple CPEs need to be deployed, the personnel responsible for email-based deployment can create an email template to configure general information for the CPEs. |
Subject |
Subject of an email to be sent. |
Content |
Body of a deployment email. You are advised to change the default settings only when required. To add a fixed field to a deployment email, click the label of the target field:
|
Default template |
Whether to configure a template as the default email template. If you set the email template as the default template, this template is selected by default when you configure the email sending function of the site. |
Recipients |
Recipient list. If a template is selected for a deployment email, the recipients of the deployment email are automatically set to those in the template. The recipients can be changed in the deployment email. |
CC |
CC list. If a template is selected for a deployment email, the CCs of the deployment email are automatically set to those in the template. The CCs can be changed in the deployment email. |
Performing Email-based Deployment (by Sending an Email)
Email-based deployment enables CPEs to connect to the WAN, register with iMaster NCE-Campus, and go online.
Prerequisites
- Ensure that the device to be deployed uses its factory settings. If the device has other configurations, the deployment will fail.
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restart the device, clear the service configuration and data files on the device, and restore the device to its factory settings.
reset factory-configuration
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- For AR600&6100&6200&6300 series devices, run the following commands to clear the configuration file used for next startup, and then restart the devices to restore the factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restore the factory settings after the device restarts:
factory-configuration reset
- Run the following command to restart the system and restore the factory settings of the device:
reboot fast
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
- An email server has been configured. For details, see Configuring an Email Server.
- To perform email-based deployment for AR5700&6700&8000 series devices, enable Encryption and Web login in WAN Global Configuration. For details, see 2.e.
- The network access mode has been configured for the site where devices need to be deployed, and the ZTP mode has been set to URL/U Disk. For details, see Configuring ZTP.
- You have obtained the following tools before performing email-based deployment onsite.
Tool
Description
PC or laptop
Used to receive deployment emails. After a PC or laptop is connected to a CPE, deployment personnel can perform deployment operations.
Network cable
Used to connect the PC or laptop to a CPE.
Procedure
- Create a site and add devices to the site on iMaster NCE-Campus. For details, see Adding an AR Device.Check the state of each device to be deployed. Ensure that all the devices to be deployed have been added successfully and are in Unregistered state.
- Choose from the main menu of iMaster NCE-Campus.
- On the device page that is displayed, check whether Status of each device is Unregistered.
If the device is in a state other than the Unregistered state, the device has been deployed and goes online.
- Choose from the main menu, click the ZTP tab, select the site to be activated, check its configuration.
- Use the email server configured on the controller to send deployment emails to deployment personnel.
- Click Send Email.
- On the Send Email page, select the target site and set the email content.
- In the Select Site area, select the site to which the deployment email is to be sent. You can search for sites by site name, template name, or activation status.
- Click
and then click Next.
- Enable certificate authentication as needed.
Enable certificate authentication: After certificate authentication is enabled, the URL in the deployment email contains certificate application information. During URL-based deployment, a device applies for a certificate based on the certificate application information in the URL and then registers with the controller.
Certificate authentication type: Set this parameter to ESN or Controller Address based on the serial number source of the voucher file generated by the system administrator.
Certificate authentication info: This parameter can be configured when Certificate authentication type is set to Controller Address. Select the corresponding device certificate.
- Set the email addresses of recipients on the email sending page.
- Set the email addresses of CC recipients in CC.
- Select an email template from the Email Template drop-down list.
- Enter the subject and content of the email.
- Click OK.
- After the deployment email is sent successfully (indicating that the site is activated), the icon on the right of the site is displayed as
.
- Check all deployment emails and carry emails to the customer site.
- If a SIM card is inserted into a device at the deployed site, check whether the SIM card is inserted into slot 1. If so, the device cannot register with iMaster NCE-Campus after being restarted, causing a deployment failure.
- Install CPEs at the customer site and perform email-based deployment. You can select either of the following methods to deploy the CPEs as required.
- To deploy a CPE in wired mode, perform the following operations:
- Install, connect, and power on CPEs.
- Use an Ethernet cable to connect a PC to the management network port of each CPE.
- Configure an IP address for the PC. This address must be on the network segment that contains the IP address of the CPE's management network port. As such, the PC can set up a logical connection with this network segment.
- Choose Control Panel > Network and Internet > Network and Sharing Center. In the dialog box that is displayed, click Connection for the active network.
- In the Local Area Connections Status dialog box, click Properties.
- In the dialog box that is displayed, select Internet Protocol Version 4 (TCP/IPv4) and click Properties.
- In the Internet Protocol Version 4 (TCP/IPv4) Properties dialog box, select Use the following IP address, and enter the IP address and subnet mask planned for the PC. Then, click OK.
- The default IP address of the CPE's management network port is 192.168.1.1 and the subnet mask is 255.255.255.0.
- Ensure that the PC is on the same network segment as the CPE's management network port.
A device's management network port is often marked with the management or MGMT silkscreen. For models without these silkscreens, see the product documentation of the corresponding model (for example, see section "Get to Know the Product > Hardware Description > Chassis" in the NetEngine AR Product Documentation).
- To deploy a CPE in wireless mode, perform the following operations:
In factory settings of a CPE, the SSID of the deployment Wi-Fi network is a character string that consists of PnP_ and the last six digits of the device's ESN, in the PnP_xxxxxx format. The password for the deployment Wi-Fi network is a character string that consists of AR and the last six digits of the network SSID, in the ARxxxxxx format.
The deployment engineer uses a deployment terminal to search for the deployment Wi-Fi network SSID and enters the password to access the device. When the deployment terminal has been connected to the specified deployment Wi-Fi network and obtained an IP address, this deployment terminal has been connected to the device.
You can only use this mode to access devices with the AP mode as the default WLAN mode.
- To deploy a CPE in wired mode, perform the following operations:
- Perform email-based deployment.
- Open the deployment email on the PC and copy the deployment URL to the address box of a browser or directly click the URL in the email.
Only the latest URL can be used for deployment. If iMaster NCE-Campus repeatedly generates URLs, the old URLs become invalid. You need to use the latest URL for deployment and use the URL within the validity period.
- In the displayed browser window, enter the password as prompted. The password must be the same as the URL encryption key set in the global parameter configuration on iMaster NCE-Campus. The login page of AR600&6100&6200&6300&SRG series devices is different from that of AR5700&6700&8000 series devices.Figure 2-18 AR600&6100&6200&6300&SRG seriesFigure 2-19 AR5700&6700&8000 series
- Click Check Parameters to check automatically parsed parameters and click Confirm Deployment. The page of AR600&6100&6200&6300&SRG series devices is different from that of AR5700&6700&8000 series devices.
Check the parameter values in Check Parameters. Modify them only when the data is incorrect.
Figure 2-20 AR600&6100&6200&6300&SRG seriesFigure 2-21 AR5700&6700&8000 series
- Open the deployment email on the PC and copy the deployment URL to the address box of a browser or directly click the URL in the email.
- Wait one to two minutes and check the deployment result. In normal cases, you need to wait for 1 to 2 minutes. The deployment duration varies according to the actual situation.
If Deployment Security Check is enabled when devices are added to the controller, select devices on the device management page of the controller and click Deploy to deliver configurations to them.
- If the deployment is successful, a deployment success message is displayed.
- Choose from the main menu of iMaster NCE-Campus. Find the CPEs deployed through email-based deployment and check their status.
If Status of a CPE is Normal, the CPE has been successfully registered with iMaster NCE-Campus and is online.
- Determine the deployment status of the device based on the CTRL indicator:
- Steady green: The device has been connected to the controller.
- Blinking green: The device is being deployed. (Some device models do not support this indicator status.)
- Steady off: The device is not connected to the controller.
- If the deployment fails, rectify the fault based on the failure cause displayed on the page. For details, see Email-based Deployment Failures.
If the CPE needs to be deployed again, click Restore Factory Settings and then perform email-based deployment again.
Performing Email-based Deployment (by Downloading the ZTP File)
Prerequisites
- Ensure that the device to be deployed uses its factory settings. If the device has other configurations, the deployment will fail.
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restart the device, clear the service configuration and data files on the device, and restore the device to its factory settings.
reset factory-configuration
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- For AR600&6100&6200&6300 series devices, run the following commands to clear the configuration file used for next startup, and then restart the devices to restore the factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restore the factory settings after the device restarts:
factory-configuration reset
- Run the following command to restart the system and restore the factory settings of the device:
reboot fast
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
- The network access mode has been configured for the site where devices need to be deployed, and the ZTP mode has been set to URL/U Disk. For details, see Configuring ZTP.
- You have obtained the following tools before performing email-based deployment:
Tool
Description
PC or laptop
Used to receive deployment emails. After a PC or laptop is connected to a CPE device, deployment personnel can perform deployment operations.
Ethernet cable
Used to connect the PC or laptop to the CPE device.
Procedure
- Choose from the main menu, click the ZTP tab, select the site to be activated, check its configuration.
- Download the ZTP file.
- Click Download ZTP File.
- In the Download ZTP File window that is displayed, select the site to be deployed, click
to add the site to the lower area, and click OK.
Enable certificate authentication: After certificate authentication is enabled, the ZTP file contains certificate application information. After loading the ZTP file, the device applies for a certificate based on the certificate application information in the ZTP file and then registers with the controller.
Certificate authentication type: Set this parameter to ESN or Controller Address based on the serial number source of the voucher file generated by the system administrator.
Certificate authentication info: This parameter can be configured when Certificate authentication type is set to Controller Address. Select the corresponding device certificate.
If the downloaded CSV file contains the fields starting with the at sign (@), hyphen (-), plus sign (+), or equal sign (=), CSV injection risks may exist.
- The system automatically downloads the ZTP file ZTP_xxxx.csv to the default download path of the browser.
- Click Download ZTP File.
- Open the ZTP file on the PC, confirm the information, and submit the file to the deployment personnel.
- If a SIM card is inserted into a device at the deployed site, check whether the SIM card is inserted into slot 1. If so, the device cannot register with iMaster NCE-Campus after being restarted, causing a deployment failure.
- The deployment personnel perform the following operations on each device to be deployed according to the content in the ZTP file:
- Use an Ethernet cable to connect your PC to the management network port of the CPE. Configure an IP address for the PC. This address must be on the network segment that contains the IP address of the CPE's management network port. As such, the PC can set up a logical connection with this network segment.
- Choose Control Panel > Network and Internet > Network and Sharing Center. In the dialog box that is displayed, click Connection for the active network.
- In the Local Area Connections Status dialog box, click Properties.
- In the dialog box that is displayed, select Internet Protocol Version 4 (TCP/IPv4) and click Properties.
- In the Internet Protocol Version 4 (TCP/IPv4) Properties dialog box, select Use the following IP address, and enter the IP address and subnet mask planned for the PC. Then, click OK.
- The default IP address of the CPE's management network port is 192.168.1.1 and the subnet mask is 255.255.255.0.
- Ensure that the PC is on the same network segment as the CPE's management network port.
A device's management network port is often marked with the management or MGMT silkscreen. For models without these silkscreens, see the product documentation of the corresponding model (for example, see section "Get to Know the Product > Hardware Description > Chassis" in the NetEngine AR Product Documentation).
- Open the ZTP file on the PC and copy the deployment URL to the address box of a browser or directly click the URL in the ZTP file.
Only the latest URL can be used for deployment. If iMaster NCE-Campus repeatedly generates URLs, the old URLs become invalid. You need to use the latest URL for deployment and use the URL within the validity period.
- In the displayed browser window, enter the password as prompted. The password must be the same as the URL encryption key set in the global parameter configuration on iMaster NCE-Campus. The login page of AR600&6100&6200&6300&SRG series devices is different from that of AR5700&6700&8000 series devices.Figure 2-22 AR600&6100&6200&6300&SRG seriesFigure 2-23 AR5700&6700&8000 series
- Click Check Parameters to check automatically parsed parameters and click Confirm Deployment. The page of AR600&6100&6200&6300&SRG series devices is different from that of AR5700&6700&8000 series devices.
Check the parameter values in Check Parameters. Modify them only when the data is incorrect.
Figure 2-24 AR600&6100&6200&6300&SRG seriesFigure 2-25 AR5700&6700&8000 series
- Use an Ethernet cable to connect your PC to the management network port of the CPE. Configure an IP address for the PC. This address must be on the network segment that contains the IP address of the CPE's management network port. As such, the PC can set up a logical connection with this network segment.
- Wait one to two minutes and check the deployment result. In normal cases, you need to wait for 1 to 2 minutes. The deployment duration varies according to the actual situation.
If Deployment Security Check is enabled when devices are added to the controller, select devices on the device management page of the controller and click Deploy to deliver configurations to them.
- If the deployment is successful, a deployment success message is displayed.
- Choose from the main menu of iMaster NCE-Campus. Find the CPEs deployed through email-based deployment and check their status.
If Status of a CPE is Normal, the CPE has been successfully registered with iMaster NCE-Campus and is online.
- Determine the deployment status of the device based on the CTRL indicator:
- Steady green: The device has been connected to the controller.
- Blinking green: The device is being deployed. (Some device models do not support this indicator status.)
- Steady off: The device is not connected to the controller.
- If the deployment fails, rectify the fault based on the failure cause displayed on the page. For details, see Email-based Deployment Failures.
If the CPE needs to be deployed again, click Restore Factory Settings and then perform email-based deployment again.
USB-based Deployment
Overview of USB-based Deployment
Definition
During USB-based deployment (refers to streamlined USB-based in this document), after the network administrator completes the ZTP configuration for a site on iMaster NCE-Campus, iMaster NCE-Campus automatically generates the ZTP files (configuration file and index file) that record the CPE deployment configuration. The deployment engineer saves these files in a USB flash drive and inserts the USB flash drive into the CPE to complete the deployment.
AR routers support two USB-based deployment modes: USB-based deployment and streamlined USB-based deployment. The following describes their differences:
- USB-based deployment: An index file is manually made for deployment. After the deployment is complete, the device needs to be restarted.
- Streamlined USB-based deployment: ZTP files (configuration file and index file) are generated on iMaster NCE-Campus. After the deployment is complete, the device does not need to be restarted.
Currently, the SD-WAN Solution supports only streamlined USB-based deployment.
Application Scenarios
USB-based deployment is mainly used in batch deployment scenarios. The device administrator of a system integrator or an enterprise inserts the USB flash drive that contains ZTP files to a CPE in the warehouse and then dispatches the CPE to a site for installation and deployment.
Device and Feature Requirements of USB-based Deployment
Device Requirements
USB-based deployment applies only to AR600&6100&6200&6300&SRG series devices.
Feature Requirements
Phase |
Requirement |
---|---|
Before deployment |
When USB-based deployment is used for batch deployment and CPEs are added by ESN, the ESNs of the CPEs distributed to sites must be the same as those configured on iMaster NCE-Campus. Otherwise, the deployment may fail. |
To prevent key disclosure, it is strongly recommended that the device administrator use a keystroke encrypted or fingerprint encrypted USB flash drive for deployment. During deployment, keep the USB flash drive with the deployment configuration file secure. After the deployment is complete, delete the deployment configuration file in a timely manner. |
|
If a SIM card needs to be inserted into a device at the deployment site, you are advised to insert the SIM card into slot 1 instead of other slots. Otherwise, the device may fail to register after being restarted, causing a deployment failure. |
Configuring USB-based Deployment
USB-based deployment enables CPEs to connect to the WAN, register with iMaster NCE-Campus, and go online.
Prerequisites
- Ensure that the device to be deployed uses its factory settings. If the device has other configurations, the deployment will fail.
- For AR600&6100&6200&6300 series devices, run the following commands to clear the configuration file used for next startup, and then restart the devices to restore the factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restore the factory settings after the device restarts:
factory-configuration reset
- Run the following command to restart the system and restore the factory settings of the device:
reboot fast
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- For AR600&6100&6200&6300 series devices, run the following commands to clear the configuration file used for next startup, and then restart the devices to restore the factory settings.
- The network access mode has been configured for the site where devices need to be deployed, and the ZTP mode has been set to URL/U Disk. For details, see Configuring ZTP.
Procedure
- Choose from the main menu, click the ZTP tab, select the site to be activated, check its configuration.
- Click Download ZTP File.
- In the Download ZTP File dialog box that is displayed, select the site where USB-based deployment needs to be performed and enable U Deploy.
Enable certificate authentication: After certificate authentication is enabled, the ZTP file contains certificate application information. After loading the ZTP file, the device applies for a certificate based on the certificate application information in the ZTP file and then registers with the controller.
Certificate authentication type: Set this parameter to ESN or Controller Address based on the serial number source of the voucher file generated by the system administrator.
Certificate authentication info: This parameter can be configured when Certificate authentication type is set to Controller Address. Select the corresponding device certificate.
- Click OK. The system then automatically downloads the configuration file ZTP.INI and the index file USB_AR.INI to the default download path of the browser.
- Save the index file USB_AR.INI and configuration file ZTP.INI to the root directory of the USB flash drive.
- Perform USB-based deployment.
- If a SIM card is inserted into a device at the deployed site, check whether the SIM card is inserted into slot 1. If so, the device cannot register with iMaster NCE-Campus after being restarted, causing a deployment failure.
Power on a CPE.
Install the prepared USB flash drive to the USB port on the CPE. The CPE automatically starts the USB-based deployment process.
During deployment, the CPE obtains the configuration file from the USB flash drive based on the description in the index file and saves the configuration file to the default storage medium. The deployment configuration in the configuration file is delivered to the CPE if its ESN matches. The CPE then saves the configuration to the configuration file for next startup.
Observe the USB indicator on the CPE to check the progress of USB-based deployment. After USB-based deployment succeeds, remove the USB flash drive.
If the indicator is steady yellow, the USB-based deployment has not started yet and the interface card is to be registered.
- Only the AR1610-X6 supports the steady yellow status.
- Some AR models do not have a USB indicator. To check the status of such a CPE, wait for about 5 minutes until the deployment completes, choose from the main menu of iMaster NCE-Campus, and find the CPE deployed in USB-based mode. If Status is Normal, the CPE has been successfully registered with iMaster NCE-Campus and onboarded.
If the indicator is blinking green, USB-based deployment is ongoing.
If the indicator is steady green, USB-based deployment is successful.
If the indicator is steady red, USB-based deployment fails.
DHCP Option-based Deployment
Overview of DHCP Option-based Deployment
Definition
During DHCP option-based deployment, the network administrator completes the ZTP configuration for a site on iMaster NCE-Campus, and configures an IP address and gateway for a CPE's interface as well as the southbound IP address and port number of iMaster NCE-Campus on the DHCP server. The CPE's interface obtains an IP address from the DHCP server through DHCP. When allocating an IP address to the CPE, the DHCP server also sends iMaster NCE-Campus information to the CPE through an Option field in DHCP messages. After obtaining an IP address and accessing the underlay network, the CPE automatically registers with iMaster NCE-Campus to complete the deployment.
DHCP Option-based Deployment Modes
Two DHCP option-based deployment modes are supported:
- Through Option 148: This mode is used when an IPv4 network is deployed on the WAN side.
- Through Option 17: This mode is used when an IPv6 network is deployed on the WAN side.
DHCP Option-based Deployment Process
Deployment Process
No. |
Description |
Link |
---|---|---|
1 |
A network administrator configures sites, global parameters, and ZTP on iMaster NCE-Campus. |
|
2 |
The network administrator configures a DHCP server. |
|
3 |
Site deployment engineers connect and power on the CPE to be deployed. |
|
4 |
The DHCP server uses DHCP Option 148 or Option 17 to send information about iMaster NCE-Campus to the CPE while assigning an IP address to it. |
- |
5 |
The CPE initiates a registration request to iMaster NCE-Campus based on the obtained information. |
- |
DHCP option-based deployment can be implemented in either of the following ways based on the networking:
- The CPE communicates with the DHCP server through a WAN-side Layer 3 interface.
Figure 2-27 shows the deployment process, in which each number corresponds to the same number in Table 2-107.
In this scenario, after being powered on, the CPE obtains a temporary IP address for its WAN-side Layer 3 interface from the DHCP server and sends a registration request to iMaster NCE-Campus. After the registration succeeds, iMaster NCE-Campus allocates a new IP address to the interface on the CPE. Assume that the DHCP server assigns the IP address 10.1.1.1 to the WAN-side interface GE1/0/1 on the CPE and you have configured 10.1.1.2 for this interface in the ZTP configuration on iMaster NCE-Campus. The CPE first uses the IP address 10.1.1.1 to register with iMaster NCE-Campus. After successful registration, iMaster NCE-Campus delivers the ZTP configuration to the CPE, which then uses 10.1.1.2 in the ZTP configuration as the IP address for GE1/0/1. - The CPE communicates with the DHCP server through a non-WAN Layer 3 interface.
Figure 2-28 shows the deployment process, in which each number corresponds to the same number in Table 2-107.
In this scenario, after being powered on, the CPE obtains an IP address for its non-WAN Layer 3 interface from the DHCP server, connects to the management network through this interface, and sends a registration request to iMaster NCE-Campus. After the registration succeeds, iMaster NCE-Campus assigns an IP address to a WAN-side Layer 3 interface on the CPE. Assume that the DHCP server assigns the IP address 192.168.1.1 to GE1/0/6, which is a non-WAN interface, on the CPE and you have configured 10.1.1.2 for this interface in the ZTP configuration on iMaster NCE-Campus. The CPE first uses the IP address 192.168.1.1 to register with iMaster NCE-Campus. After successful registration, iMaster NCE-Campus delivers the ZTP configuration to the CPE, which then uses 10.1.1.2 in the ZTP configuration as the IP address for the WAN-side interface GE1/0/1.
Device and Feature Requirements of DHCP Option-based Deployment
Device Requirements
DHCP Option-based deployment is applicable only to AR600&6100&6200&6300&SRG series and AR5700&6700&8000 series devices.
Feature Requirements
Phase |
Requirement |
---|---|
Before deployment |
Before using a sub-interface as the deployment link interface, create the *.defcfg and usb.ini files, save them to the root directory of the USB flash drive, and insert the USB flash drive into the device whose factory settings have been restored. |
Configuring a DHCP Server
Context
After an unconfigured CPE is powered on, it automatically sends a request to apply for an IP address from a DHCP server. Therefore, a network administrator needs to configure the DHCP server before powering on the CPE. The DHCP server not only assigns an IP address to an interface on the CPE for network access, but also notifies the CPE of the iMaster NCE-Campus information, such as the address, through a DHCP option.
Procedure (Configuring a DHCPv4 Server)
When the WAN is an IPv4 network, you need to configure a DHCPv4 server.
- Log in to a DHCPv4 server.
- Enable the DHCP function.
The configuration of a router running V300 is slightly different from that of a router running V600.
- For a router running V300:
system-view //Enter the system view. dhcp enable //Enable the DHCP function in the system view.
- For a router running V600:
system-view //Enter the system view. dhcp enable ipv4 //Enable the DHCPv4 function in the system view.
- For a router running V300:
- Configure the DHCPv4 server.
- If the DHCPv4 server and the CPE reside on different network segments, configure the DHCP server to use a global address pool.
- Create a global DHCPv4 address pool, which is used for assigning IPv4 addresses to CPEs.
ip pool ip-pool-name //Create a global address pool and enter the global address pool view. network ip-address mask mask-length //Configure the range of IP addresses that can be assigned dynamically in the global address pool view.
- Configure the gateway address. If a relay server is deployed on the network, the gateway address is the IP address of the interface enabled with the DHCP relay function.
gateway-list ip-address //Configure the gateway address in the global address pool view.
- Configure Option 148. For details, see Table 2-109.The configuration of a router running V300 is slightly different from that of a router running V600.
- For a router running V300:
option 148 ascii agilemode=agilemode;agilemanage-mode=mode;agilemanage-domain=domain;agilemanage-port=port; //Configure Option 148 in the global address pool view. force insert option 148 //Configure the DHCPv4 server to insert Option 148 into response packets. quit //Return to the system view.
- For a router running V600:
option 148 ascii agilemanage-domain=domain;agilemanage-port=port; //Configure Option 148 in the global address pool view. force insert option 148 //Configure the DHCPv4 server to insert Option 148 into response packets. quit //Return to the system view.
- For a router running V300:
- Enable the DHCPv4 server function on an interface.
interface interface-type interface-number [.subinterface-number ] //In the system view, run this command to enter the interface or sub-interface view. ip address ip-address mask //Configure an IP address for the interface that provides the DHCPv4 server function. dhcp select global //Configure the interface to use the global IP address pool for providing the DHCPv4 server function.
If the DHCPv4 server function is enabled on a sub-interface, you also need to configure the sub-interface to terminate single-tagged packets. The value of low-pe-vid must be the same as the sub-interface VLAN ID set when you configure a link for ZTP deployment.
dot1q termination vid low-pe-vid //In the sub-interface view, configure the sub-interface to terminate single-tagged packets.
- Create a global DHCPv4 address pool, which is used for assigning IPv4 addresses to CPEs.
- If the DHCPv4 server and the CPE reside on the same network segment, configure the DHCP server to use an interface address pool.
- Configure a DHCPv4 interface address pool, which is used for assigning IPv4 addresses to CPEs.
interface interface-type interface-number [.subinterface-number ] //In the system view, run this command to enter the interface or sub-interface view. ip address ip-address mask //Configure an IP address for the interface that provides the DHCP server function. The network segment where the interface is located is the interface address pool.
- Enable the DHCPv4 server function on the interface.
interface interface-type interface-number [.subinterface-number ] //In the system view, run this command to enter the interface or sub-interface view. dhcp select interface //Configure the interface to use the interface address pool for providing the DHCPv4 server function.
If the DHCPv4 server function is enabled on a sub-interface, you also need to configure the sub-interface to terminate single-tagged packets. The value of low-pe-vid must be the same as the sub-interface VLAN ID set when you configure a link for ZTP deployment.
dot1q termination vid low-pe-vid //In the sub-interface view, configure the sub-interface to terminate single-tagged packets.
- Configure the gateway address.
dhcp server gateway-list ip-address //In the interface or sub-interface view, set the gateway address to the IP address of the interface enabled with the DHCP server function.
- Configure Option 148. For details, see Table 2-109.The configuration of a router running V300 is slightly different from that of a router running V600.
- For a router running V300:
dhcp server option 148 ascii agilemode=agilemode;agilemanage-mode=mode;agilemanage-domain=domain;agilemanage-port=port; //Configure Option 148 in the interface or sub-interface view. force insert option 148 //Configure the DHCPv4 server to insert Option 148 into response packets. quit //Return to the system view.
- For a router running V600:
dhcp server option 148 ascii agilemanage-domain=domain;agilemanage-port=port; //Configure Option 148 in the interface view or sub-interface view. force insert option 148 //Configure the DHCPv4 server to insert Option 148 into response packets. quit //Return to the system view.
- For a router running V300:
- Configure a DHCPv4 interface address pool, which is used for assigning IPv4 addresses to CPEs.
Table 2-109 Parameters in Option 148Field
Meaning
Value Description
Example
agilemode
Management mode.
tradition: uses the traditional management mode.
- Select this mode when an AR device running V300 functions as a DHCP client.
- When a device running V600 functions as a DHCP client, you do not need to set this parameter.
Assume that the southbound IP address and port number of iMaster NCE-Campus are 10.1.1.1 and 10020, respectively, and the site authentication code of the site to be deployed is 9cc1171d782cddd4.
When an AR6300 series device functions as a DHCP client, set Option 148 on the DHCP server as follows: agilemode=tradition;agilemanage-mode=ip;agilemanage-domain=10.1.1.1;agilemanage-port=10020;sitecode=9cc1171d782cddd4.
When an AR6700 series device functions as a DHCP client, set Option 148 on the DHCP server as follows: agilemanage-domain=10.1.1.1;agilemanage-port=10020;sitecode=9cc1171d782cddd4.
agilemanage-mode
Whether the agilemanage-domain field is set to an IP address or a domain name.
- ip: indicates that the value of the agilemanage-domain field is an IP address.
- domain: indicates that the value of the agilemanage-domain field is a domain name.NOTE:
This parameter does not need to be set when a device running V600 functions as a DHCP client. In this case, the agilemanage-domain field is set to the southbound IP address of the controller by default.
agilemanage-domain
Southbound IP address or domain name of iMaster NCE-Campus, which is obtained by the CPE for controller registration. You can configure one or more IP addresses. Use ampersands (&) to separate multiple IP addresses.
- If agilemanage-mode is set to ip, set this parameter to an IP address.
- If agilemanage-mode is set to domain, set this parameter to the southbound domain name of iMaster NCE-Campus, starting with http:// or https://. HTTPS is recommended because it is more secure than HTTP.
agilemanage-port
Port number of iMaster NCE-Campus.
The port number of iMaster NCE-Campus is 10020.
agilemanage-domain and agilemanage-port must be set together. The number of IP addresses or domain names specified by agilemanage-domain must be the same as the number of port numbers specified by agilemanage-port.
sitecode
Site authentication code. This parameter needs to be set when the ESN is not used as the CPE identifier.
After you create a site and enable ESN-free switch, iMaster NCE-Campus automatically allocates a site authentication code.
- If the DHCPv4 server and the CPE reside on different network segments, configure the DHCP server to use a global address pool.
Procedure (Configuring a DHCPv6 Server)
When the WAN is an IPv6 network, you need to configure a DHCPv6 server. The following uses commands on a device running V300 as an example.
- Log in to a DHCPv6 server.
- Enable the DHCP function.
system-view //Enter the system view. dhcp enable /Enable the DHCP function in the system view.
- Create an IPv6 address pool, which is used for assigning IPv6 addresses to CPEs. You can only configure a global address pool for a DHCPv6 server.
dhcpv6 pool pool-name //Create a global IPv6 address pool and enter the IPv6 address pool view. address prefix ipv6-prefix/ipv6-prefix-length //Configure an IPv6 prefix and the prefix length. excluded-address start-ipv6-address [ to end-ipv6-address] //Configure the range of IPv6 addresses that cannot be automatically assigned. dns-server ipv6-address //Configure the IPv6 address of a DNS server.
- Configure Option 17. Run the vendor-specific command to enter the vendor-defined mode and configure a vendor-defined DHCPv6 option. vendor-id indicates the vendor ID, which is uniformly allocated by the Internet Assigned Numbers Authority (IANA). The vendor ID of Huawei is 2011. For details about other parameters, see Table 2-110.
vendor-specific vendor-id //Configure a vendor-defined option for the IPv6 address pool and enter the vendor-defined mode view. suboption suboption-code ascii agilemode=agilemode;agilemanage-mode=mode;agilemanage-domain=domain;agilemanage-port=10020; //Configure a vendor-defined DHCPv6 sub-option in the vendor-defined mode view.
Table 2-110 Parameters in Option 17Field
Meaning
Value Description
Example
suboption-code
Code of a vendor-defined DHCPv6 sub-option.
The value is an integer that ranges from 1 to 65535.
-
agilemode
Management mode.
tradition: uses the traditional management mode.
- Select this mode when an AR device running V300 functions as a DHCP client.
- When a device running V600 functions as a DHCP client, you do not need to set this parameter.
Assume that the southbound IP address and port number of iMaster NCE-Campus are 2001:0db8:1::1 and 10020. When an AR6300 series device functions as a DHCP client, set Option 17 on the DHCP server as follows: agilemode=tradition;agilemanage-mode=ip;agilemanage-domain=2001:0db8:1::1;agilemanage-port=10020;sitecode=9cc1171d782cddd4.
agilemanage-mode
Whether the agilemanage-domain field is set to an IP address or a domain name.
- ip: indicates that the value of the agilemanage-domain field is an IP address.
- domain: indicates that the value of the agilemanage-domain field is a domain name.NOTE:
This parameter does not need to be set when a device running V600 functions as a DHCP client. In this case, the agilemanage-domain field is set to the southbound IP address of the controller by default.
agilemanage-domain
Southbound IP address or domain name of iMaster NCE-Campus, which is obtained by the CPE for controller registration. You can configure one or more IP addresses. Use ampersands (&) to separate multiple IP addresses.
- If agilemanage-mode is set to ip, set this parameter to an IP address.
- If agilemanage-mode is set to domain, set this parameter to the southbound domain name of iMaster NCE-Campus, starting with http:// or https://. HTTPS is recommended because it is more secure than HTTP.
agilemanage-port
Port number of iMaster NCE-Campus.
The default port number of iMaster NCE-Campus is 10020.
agilemanage-domain and agilemanage-port must be set together. The number of IP addresses or domain names specified by agilemanage-domain must be the same as the number of port numbers specified by agilemanage-port.
sitecode
Site authentication code. This parameter needs to be set when the ESN is not used as the CPE identifier.
After you create a site and enable ESN-free switch, iMaster NCE-Campus automatically allocates a site authentication code.
- Enable the DHCPv6 server function in the interface view.
interface interface-type interface-number [.subinterface-number ] //In the system view, run this command to enter the interface or sub-interface view. ipv6 enable //Enable the IPv6 function on the interface. ipv6 address ipv6-prefix/ipv6-prefix-length //Configure a global unicast IPv6 address for the interface. undo ipv6 nd ra halt //Enable the CPE to send RA messages. ipv6 nd autoconfig managed-address-flag //Configure the M flag of stateful autoconfiguration in an RA message. ipv6 nd autoconfig other-flag //Configure the "other configuration" flag (O flag) of stateful autoconfiguration in an RA message. dhcpv6 server pool-name //Enable the DHCPv6 server function for the interface.
If the DHCPv6 server function is enabled on a sub-interface, you also need to configure the sub-interface as a Dot1q VLAN termination sub-interface to terminate single-tagged packets and enable this sub-interface to send NS multicast packets. The value of low-pe-vid must be the same as the sub-interface VLAN ID set when you configure a link for ZTP deployment.
dot1q termination vid low-pe-vid //In the sub-interface view, configure the sub-interface to terminate single-tagged packets. ipv6 nd ns multicast-enable //In the sub-interface view, enable the Dot1q VLAN termination sub-interface to send NS multicast packets.
Configuring DHCP Option-based Deployment
Context
DHCP option-based deployment applies only to WAN-side interfaces that work in Layer 3 mode by default. This function is not supported on WAN-side interfaces whose working mode is switched from Layer 2 to Layer 3. ARs of different models must connect to the DHCP server through specified interfaces, as shown in Table 2-111. Otherwise, DHCP option-based deployment will fail. For details about other AR models, see the "Components" sheet of the corresponding model in the "Chassis" section of the device documentation.
Series |
Sub-series |
Device Model |
Interface Connected to a DHCP Server |
---|---|---|---|
AR600&6100&6200&6300 series |
AR610 |
AR611W |
GE0/0/4 |
AR611W-LTE4CN, AR611W-LTE6EA, AR631I-LTE4EA, AR631I-LTE4CN |
|||
AR617VW |
|||
AR617VW-LTE4EA |
|||
AR650 (uCPE) |
AR651-X8 |
GE0/0/4, GE0/0/5 |
|
AR651W-X4 |
|||
AR650 |
AR651U-A4 |
GE0/0/8, GE0/0/9 |
|
AR651F-Lite |
GE0/0/6, GE0/0/7, GE0/0/10, GE0/0/11 |
||
AR651C |
GE0/0/8, GE0/0/9, GE0/0/10, GE0/0/11 |
||
AR651 |
GE0/0/8, GE0/0/9 |
||
AR651W |
|||
AR657 |
|||
AR657W |
|||
AR6120 |
AR6120 |
GE0/0/8, GE0/0/9, XGE0/0/0 |
|
AR6120-S |
|||
AR6120-VW |
|||
AR6140 |
AR6140-9G-2AC |
GE0/0/2, GE0/0/3, GE0/0/6, GE0/0/7 |
|
AR6140H-9G-2AC |
|||
AR6140-16G4XG |
GE0/0/12 to GE0/0/15, XGE0/0/0 to XGE0/0/3 |
||
AR6140-S |
AR6140-S |
GE0/0/2, GE0/0/3, GE0/0/6, GE0/0/7 |
|
AR6280/AR6300 |
SRU-100H |
GE0/0/1 to GE0/0/4, XGE0/0/0, XGE0/0/1 |
|
SRU-200H |
|||
SRU-400H |
GE0/0/0 to GE0/0/9, XGE0/0/0 to XGE0/0/13 |
||
SRU-600H |
|||
AR6300-S |
SRU-400H |
GE0/0/0 to GE0/0/9, XGE0/0/0 to XGE0/0/13 |
|
AR5700&6700&8000 series |
AR5700 |
AR5710-H8T2TS1, AR5710-H8T2TS1-T |
GE0/0/8, GE0/0/9 |
AR6700 |
AR6710-L26T2X4, AR6710-L26T2X4-T |
GE0/0/24, GE0/0/25, XGE0/0/0, XGE0/0/1 |
|
AR6710-L50T2X4, AR6710-L50T2X4-T |
GE0/0/48, GE0/0/49, XGE0/0/0, XGE0/0/1 |
||
AR6710-L8T3TS1X2, AR6710-L8T3TS1X2-T |
GE0/0/9, GE0/0/10, XGE0/0/0 |
||
AR8000 |
AR8140-12G10XG, AR8140-T-12G10XG |
GE0/0/0 to GE0/0/11, XGE0/0/0~XGE0/0/9 |
Prerequisites
- ZTP has been configured and the ZTP mode has been set to DHCP Option. For details, see Configuring ZTP.
- A DHCP server has been configured and Option parameters have been set on the DHCP server.
- Ensure that the device to be deployed uses its factory settings. If the device has other configurations, the deployment will fail.
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restart the device, clear the service configuration and data files on the device, and restore the device to its factory settings.
reset factory-configuration
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- For AR600&6100&6200&6300 series devices, run the following commands to clear the configuration file used for next startup, and then restart the devices to restore the factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restore the factory settings after the device restarts:
factory-configuration reset
- Run the following command to restart the system and restore the factory settings of the device:
reboot fast
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
Procedure
- Check the device status. Ensure that the device to be deployed has been added successfully, its ESN has been set, and the device status is unregistered.
- Log in to iMaster NCE-Campus as a tenant administrator and choose from the main menu.
- On the Device page that is displayed by default, check the device ESN.
If a value is displayed in the ESN column, verify that the ESN is correct and go to the next step. If no value is displayed in the ESN column, click
. On the Modify Device tab page, enter the ESN and go to the next step.
For an AR5700&6700&8000 series device, run the following command to check the device ESN:display device esn
For an AR600&6100&6200&6300 series or AR1000V device, run the following command to check the device ESN:display esn
- On the Device page that is displayed by default, check the device status.
If the device status is not unregistered, the device has been deployed and goes online.
- Choose from the main menu, click the ZTP tab, select the site to be activated, check its configuration.
- If a SIM card is inserted into a device at the deployed site, check whether the SIM card is inserted into slot 1. If so, the device cannot register with iMaster NCE-Campus after being restarted, causing a deployment failure.
- (Optional) When a sub-interface is used as the interface of the deployment link, create *.defcfg and usb.ini files and save them to the root directory of the USB flash drive before the deployment.
- Configure the following commands in the *.defcfg file:
interface interface-type interface-number.subinterface-number //Run this command in the system view to enter the sub-interface view. encapsulation dot1q-termination //Configure the sub-interface as a Dot1q VLAN tag termination sub-interface. dot1q termination vid low-pe-vid //Run this command in the sub-interface view to configure the sub-interface to terminate single-tagged frames. The value of low-pe-vid must be the same as the VLAN ID configured for the sub-interface of the deployment link.
- For details about how to configure the usb.ini file, see section "Intermediate File Format" in the corresponding device documentation.
- Save the *.defcfg and usb.ini files to the root directory of the USB flash drive, and insert the USB flash drive into the device that has been restored to factory settings.
- Configure the following commands in the *.defcfg file:
- Power on the CPE and connect it to the DHCP server so that the CPE can obtain an IP address and iMaster NCE-Campus information through the DHCP option to connect to the WAN and register with iMaster NCE-Campus.
- Wait 1 to 2 minutes and check the deployment result. In normal cases, you need to wait for 1 to 2 minutes. The deployment duration varies according to the actual situation.
- Determine the deployment status of the device based on the CTRL indicator:
- Steady green: The device has been connected to the controller.
- Blinking green: The device is being deployed. (Some device models do not support this indicator status.)
- Steady off: The device is not connected to the controller.
- Choose from the main menu of iMaster NCE-Campus. Find the CPE that has been deployed and check its status.
- (Optional) If Mode is set to Device Model when you add a device, check whether the ESN of the device has been identified. If the device is not added based on the device model, skip this step.
- If Status is Normal, the device has been successfully registered with iMaster NCE-Campus and is online.
- Determine the deployment status of the device based on the CTRL indicator:
Example for Configuring a DHCPv4 Server Based on a Global Address Pool
iMaster NCE-Campus can implement DHCP option-based deployment only after a DHCP server is configured. This section describes how to configure a Huawei V300 router to function as a DHCPv4 server as an example. For other devices, see the corresponding device configuration guide.
Configuring DHCP Option 148
A device functioning as a DHCPv4 server can allocate vendor-defined network parameters to clients (that is, CPEs to be deployed), such as WAN interface IP address and gateway information. In addition, the DHCPv4 server can use a DHCP option to deliver the iMaster NCE-Campus information to the CPEs, including the southbound IP address and port number of iMaster NCE-Campus. As such, the CPEs can register with iMaster NCE-Campus based on the information obtained from this option. DHCP Option 148 is such a field applicable to the scenario where an external DHCPv4 server is deployed.
Networking Requirements
In Figure 2-29, DeviceA functions as a DHCPv4 server, and the CPE on the network segment 10.1.1.0/24 needs to be deployed.
Configuration Roadmap
The configuration roadmap is as follows:
- Enable the DHCP service on DeviceA.
- Configure interface 10GE0/0/1 on DeviceA to work in Layer 3 mode and configure an IP address for this interface.
- Configure a DHCP address pool on DeviceA.
- Enable the DHCPv4 server function on 10GE0/0/1 of DeviceA.
Procedure
- Enable DHCPv4.
<DeviceA> system-view [DeviceA] dhcp enable
- Set the IPv4 address of interface 10GE 0/0/1 to 10.1.1.1/24.
[DeviceA] interface 10ge 0/0/1 [DeviceA-10GE0/0/1] undo portswitch [DeviceA-10GE0/0/1] ip address 10.1.1.1 24 [DeviceA-10GE0/0/1] quit
- Create a DHCPv4 address pool named pool1. Assuming that the southbound IP address of iMaster NCE-Campus is 192.168.1.1 and the port number is 10020, run the following commands:
[DeviceA] ip pool pool1 [DeviceA-ip-pool-pool1] network 10.1.1.0 mask 24 [DeviceA-ip-pool-pool1] gateway-list 10.1.1.1 [DeviceA-ip-pool-pool1] option 148 ascii agilemode=agilemode;agilemanage-mode=ip;agilemanage-domain=192.168.1.1;agilemanage-port=10020; [DeviceA-ip-pool-pool1] quit
- Configure the Layer 3 Ethernet interface enabled with the DHCPv4 server function to use the global address pool.
[DeviceA] interface 10ge 0/0/1 [DeviceA-10GE0/0/1] dhcp select global [DeviceA-10GE0/0/1] quit
- Run the display ip pool command to check the address pool configuration and address assignment information. Check for the Used field, which displays the number of assigned IPv4 addresses.
[DeviceA] display ip pool name pool1 Pool-name : pool1 Pool-No : 7 Lease : - Domain-name : - DNS-server0 : - NBNS-server0 : - Netbios-type : - Position : Local Status : Unlocked Gateway-0 : 10.1.1.1 Network : 10.1.1.0 Mask : 255.255.255.0 VPN instance : -- Logging : Disable Conflicted address recycle interval: - Address Statistic: Total :253 Used :1 Idle :252 Expired :0 Conflict :0 Disabled :0 ------------------------------------------------------------------------------------- Network section Start End Total Used Idle(Expired) Conflict Disabled ------------------------------------------------------------------------------------- 10.1.1.1 10.1.1.254 253 1 252(0) 0 0 -------------------------------------------------------------------------------------
- Run the display ip interface brief command on the CPE to check IPv4 addresses of its interfaces. The command output shows that interface 10GE0/0/1 has obtained an IPv4 address.
<HUAWEI> display ip interface brief *down: administratively down (l): loopback (s): spoofing (d): Dampening Suppressed (ed): error down The number of interface that is UP in Physical is 3 The number of interface that is DOWN in Physical is 0 The number of interface that is UP in Protocol is 3 The number of interface that is DOWN in Protocol is 0 Interface IP Address/Mask Physical Protocol VPN 10GE0/0/1 10.1.1.13/24 up up -- MEth0/0/0 192.168.190.129/16 up up -- NULL0 unassigned up up(s) --
Deployment Through the Registration Query Center
Overview of Deployment Through the Registration Query Center
Definition
During deployment through the registration query center, the network administrator configures the interconnection with Huawei's registration query center on iMaster NCE-Campus and configures ZTP for sites. The WAN interface of a CPE at a site applies for an IP address from the DHCP server in DHCP mode. In addition, the DNS server is used to resolve the domain name of the registration query center. After obtaining an IP address and connecting to the underlay network, the CPE sends a query request to the registration query center to obtain the IP address and port number of iMaster NCE-Campus. Then, the CPE automatically registers with iMaster NCE-Campus to complete the deployment.
Application Scenarios
This deployment mode is applicable to scenarios where iMaster NCE-Campus can connect to Huawei's registration query center, including Huawei public cloud, MSP-owned cloud, and on-premises scenarios.
Process of Deployment Through the Registration Query Center
Deployment Process
Figure 2-30 shows the process of deployment through the registration query center.
iMaster NCE-Campus can be deployed in the following scenarios:
- Huawei public cloud scenario: The unique domain name of the registration query center is provided to cloud managed devices. You only need to write the domain name into cloud managed devices upon factory delivery to implement plug-and-play of cloud managed devices.
- MSP-owned cloud scenario: iMaster NCE-Campus can interconnect with Huawei registration query center to provide the unique domain name of the registration query center to cloud managed devices. You only need to write the domain name into cloud managed devices upon factory delivery to implement plug-and-play of cloud managed devices.
- On-premises scenario: iMaster NCE-Campus can interconnect with Huawei registration query center. However, the southbound addresses of iMaster NCE-Campus vary. Cloud managed devices can go online only after the default iMaster NCE-Campus address is manually changed and the domain name of the registration query center is written to implement plug-and-play of cloud managed devices.
Device and Feature Requirements for Deployment Through the Registration Query Center
Device Requirements
Only AR600 (AR650 sub-series) and AR6100&6200&6300 (AR6280/AR6300+SRU-400H and AR6280/AR6300+SRU-600H) series routers can be deployed through the registration query center.
Feature Requirements
Phase |
Requirement |
---|---|
Before deployment |
If a SIM card needs to be inserted into a device at the deployment site, you are advised to insert the SIM card into slot 1 instead of other slots. Otherwise, the device may fail to register after being restarted, causing a deployment failure. |
Configuring Interconnection with the Registration Query Center
Application Scenario
If the registration query center is used for deployment, you need to connect iMaster NCE-Campus to the registration query center. Huawei provides a unique registration query center address. By default, the registration query center address is configured on a device before delivery. After connecting iMaster NCE-Campus to the registration query center, you can perform device deployment through the registration query center to manage the device, implementing plug-and-play.
Among devices running V600, switches can connect to the registration query center only when they run a version later than V600R22C10 and iMaster NCE-Campus runs V300R022C00SPC130 or later version.
Procedure
- Configure network connectivity between iMaster NCE-Campus and the registration query center. On iMaster NCE-Campus, configure the service NIC of the iMaster NCE-Campus node to access the domain name (register.naas.huawei.com) and corresponding ports of the registration query center.
- Connect iMaster NCE-Campus to the registration query center.
Log in to the server node and run the following commands to change the DNS server address (x.x.x.x) on the server node for accessing the registration query center. Then, restart the network service.
vi /etc/resolv.conf nameserver X.X.X.X service network restart
Run the following command to check the network connectivity:
ping register.naas.huawei.com
- Connect iMaster NCE-Campus to ports of the registration query center.
Connect the service NIC of the NCE-Campus node to ports 26335 and 31943 corresponding to the domain name of the registration query center.
- Check whether the account on the registration query center is in normal status. If the account is not interconnected for a long time, it is automatically disabled. As a result, the interconnection verification fails. In this case, contact the administrator of the registration query center.
- Connect iMaster NCE-Campus to the registration query center.
- Import the certificate of the registration query center on iMaster NCE-Campus.
- Contact the administrator to obtain the account, password, and trust certificate of the registration query center.
By default, the northbound certificate of the registration query center is a Huawei PKI certificate signed by Huawei CA. You can download the Huawei CA certificate from the Huawei PKI website as the trust certificate.
- Log in to Huawei PKI website, choose CA Certificate Download from the navigation pane, and download the root certificate Huawei Equipment Root CA and level-2 CA certificate Huawei Enterprise Network Product CA.
- Copy the content in the Huawei_Enterprise_Network_Product_CA.cer file to a place behind the -----END CERTIFICATE----- line in the Huawei_Equipment_Root_CA.der file and save the file as RegisterCenterTrust.cer.
- Log in to iMaster NCE-Campus as the system administrator and choose from the main menu.
- Choose Service Certificate Management from the navigation pane. On the Services page, click RegisterCenter.
- On the Trust Certificate tab page, click Import, enter information about the certificate file to upload, select the certificate file, and click Submit to upload the certificate file to iMaster NCE-Campus.
- According to standards, the trust certificate of the registration query center is named as RegisterCenterTrust.cer. If the obtained trust certificate does not have a standard name, correct the name before you upload it.
- Contact the administrator to obtain the account, password, and trust certificate of the registration query center.
- Configure interconnection between iMaster NCE-Campus and the registration query center.Choose and click the Registration Center Settings tab. Set Registration center address, Account, and Password, and select the registration query center's certificate file. Then click Test.
The address of the registration query center is register.naas.huawei.com.
- If the authentication is successful, the system displays a dialog box, indicating that the configuration is successful.
- If the account or password is incorrect, the system displays a dialog box, indicating that the account or password is wrong. In this case, check whether the account and password are correct.
- If a network exception occurs, the system displays a dialog box, indicating that the network is abnormal. In this case, check the network connection.
Parameters
Parameter |
Description |
---|---|
Registration query center address |
The address of the registration query center is register.naas.huawei.com. |
Certificate file |
Contact technical support engineers to obtain the trust certificate of the registration query center. By default, the system is preset with a certificate for interconnection with the registration query center. If the certificate of the registration query center is changed, obtain a new certificate and update the certificate on the system to the latest one. According to standards, the trust certificate of the registration query center is named as RegisterCenterTrust.cer. If the obtained trust certificate does not have a standard name, correct the name before you upload it. |
Account |
Contact technical support engineers to obtain the account and password for logging in to the registration query center. The registration query center does not allow multiple controller systems to use the same account for interconnection at the same time. Otherwise, the registration query center considers that the service IP address of the controller is changed. |
Password |
Configuring Deployment Through the Registration Query Center
You can configure interconnection between the registration query center and a device to be deployed on iMaster NCE-Campus. In this case, after the device is powered on and connected to the network, it can automatically register with iMaster NCE-Campus to complete deployment. After a device is deployed successfully through the registration query center, iMaster NCE-Campus synchronizes the device information to the registration query center. After the device is upgraded or goes offline, it can go online on iMaster NCE-Campus again through the registration query center.
Prerequisites
- To ensure successful deployment, ensure that the device uses factory settings, has no console port input, and has no user login.
- The system administrator has configured a registration query center on iMaster NCE-Campus. For details, see Configuring Interconnection with the Registration Query Center.
- The tenant administrator has performed the following operations:
- Configure an IP address pool for assigning IP addresses to devices and other required network configurations on a DHCP server.
- Configure a DNS server, so that devices can resolve the IP address corresponding to the domain name of the registration query center.
Procedure
- Check the device status. Ensure that the device to be deployed has been added successfully, is in Unregistered state, and its ESN has been entered.
- Choose from the main menu of iMaster NCE-Campus.
- On the Device page that is displayed, verify that the Status of the device is Unregistered.
- Ensure that the device to be deployed has been added to the target site. Devices not added to any sites cannot register and go online.
- Ensure that the ESN of the device to be deployed has been identified. If not, the device cannot register with the controller and go online.
- If a SIM card is inserted into a device at the deployed site, check whether the SIM card is inserted into slot 1. If so, the device cannot register with iMaster NCE-Campus after being restarted, causing a deployment failure.
- After a device is powered on and connected to the network, the device connects to the registration query center through the preset address of the registration query center and obtains the domain name and port number of iMaster NCE-Campus from the registration query center using the device ESN.
- After a device is powered on and connected to the network, hold down the reset button on the device for more than five seconds. The device switches to the cloud management mode, restarts, and sends a connection request to iMaster NCE-Campus based on the domain name.
- Wait 1 to 2 minutes and check the deployment result. After the device is registered with and managed by iMaster NCE-Campus, iMaster NCE-Campus delivers configurations to the device based on the ESN.
- Determine the deployment status of the device based on the CTRL indicator:
- Steady green: The device has been connected to the controller.
- Blinking green: The device is being deployed. (Some device models do not support this indicator status.)
- Steady off: The device is not connected to the controller.
- Choose from the main menu of iMaster NCE-Campus. Find the device that has been deployed and check its status.
- (Optional) If Mode is set to Device Model when you add a device, check whether the device's ESN has been identified. If the device is not added based on the device model, skip this step.
- (Optional) If devices have been added to the controller before interconnection with a registration query center is configured, perform operations in (Optional) Data Synchronization from the Registration Query Center on the controller to manually synchronize device information to the interconnected registration query center.
- If Status is Normal, the device has been successfully registered with iMaster NCE-Campus and is online.
- Determine the deployment status of the device based on the CTRL indicator:
(Optional) Data Synchronization from the Registration Query Center
Context
The registration query center checks device ESNs to identify potential errors that may occur when users manually enter device information. When the ESN of a device to be synchronized is the same as an existing one in the registration query center, the device's information fails to be synchronized to the registration query center. In this case, check the device information based on the MAC address. Device information will be synchronized to the registration query center only when both the device ESN and MAC address are correct.
Prerequisites
The function of synchronizing device information to the registration query center has been enabled. This function is enabled by default when a tenant administrator adds devices.
Procedure
- Choose from the main menu, click the Management Settings tab, and choose Registration Center Synchronization from the navigation pane, and check whether there are devices whose information fails to be synchronized.
If a device is added based on the device type (no ESN recorded in the system), the device is not displayed on the Registration Center Synchronization page before the device ESN is entered.
- If device information fails to be synchronized, click Resynchronize to synchronize the device information to the registration query center again.
If the ESN of a device is the same as that of an existing device in the registration query center, click Verify MAC Address in the Operation column of the device to confirm and enter the MAC address that matches the ESN.
Cloud Site Deployment
Introduction to Cloud Site Deployment
If the vCPE is deployed on Huawei Cloud or AWS, cloud site deployment and manual deployment are supported. Cloud site deployment is recommended.
Definition
In cloud site deployment, the network administrator plans the networking environment on the public cloud, configures the vCPE to be managed by iMaster NCE-Campus, and completes the ZTP configuration for the cloud site.
Application Scenario
Cloud site deployment applies to scenarios where the vCPE needs to be installed and deployed on Huawei Cloud or AWS, and greatly simplifies the deployment operations. After planning the network on the public cloud and uploading the image file, the deployment personnel can complete the deployment by performing operations only on iMaster NCE-Campus, without the need to perform configurations on the public cloud or device. This greatly reduces the deployment labor and time costs.
Cloud Site Deployment Process
Deployment Process
Figure 2-31 shows the cloud site deployment process.
- The user obtains the AS/SK on the public cloud and creates cloud network credentials on iMaster NCE-Campus.
- The user uploads the required device image files to the public cloud.
- The tenant administrator creates a vCPE and adds it to a site on iMaster NCE-Campus.
- The tenant administrator configures ZTP on iMaster NCE-Campus. iMaster NCE-Campus invokes cloud APIs through cloud network credentials to provide available public cloud image files, VM specifications, VPC network parameter settings, and WAN-side link settings.
- After the configuration is complete, the vCPE automatically registers with iMaster NCE-Campus to complete the deployment. iMaster NCE-Campus automatically generates an ESN, invokes the cloud API to start the vCPE, and applies the ESN to the vCPE.
Device and Feature Requirements of Cloud Site Deployment
Device Requirements
Cloud site deployment applies only to AR1000Vs on Huawei public cloud or AWS.
Configuring a Cloud Network Credential
Context
Deployment personnel need to create cloud network credentials to configure interconnection between iMaster NCE-Campus and public clouds. By invoking public cloud APIs, iMaster NCE-Campus can automatically deploy cloud sites. iMaster NCE-Campus can successfully invoke public cloud APIs only after you have obtained an access key from the public cloud and has created a cloud network credential on iMaster NCE-Campus.
A pair of an access key ID (AK) and a secret access key (SK) is used as a long-term identity credential to sign requests for public cloud APIs.
The following procedure uses Huawei Cloud as an example. The operations on AWS are similar. For details, see the corresponding AWS guide.
Prerequisites
You have obtained a public cloud account.
Procedure
- Use a Huawei account to log in to the Huawei Cloud console (at https://console.huaweicloud.com/console/).
- Purchase a public NAT gateway. If you have purchased a public NAT gateway, skip this step.
- Click
on the left and choose from the navigation pane. In the upper right corner of the Public NAT Gateways page, click Buy Public NAT Gateway.
- Set the parameters of the public network NAT gateway as required and click Next.
- Click
- Purchase an EIP. If you have purchased an EIP, skip this step.
- Click
on the left of the page and choose from the navigation pane. In the upper right corner of the page, click Buy EIP.
- Set EIP parameters as required and click Next.
- Click
- Configure SNAT rules for the public NAT gateway.
- Click
on the left, choose from the navigation pane, and click the name of the public NAT gateway to be configured.
- Click the SNAT Rules tab and click Add SNAT Rule.
- Configure an SNAT rule, including the application scenario, CIDR block, and EIP.
- Click OK.
- Click
- Obtain the access key for accessing public cloud APIs from the public cloud.
- Click the login account in the upper right corner and choose My Credential.
- Click the Access Key tab and click Add Access Key to create an AK.
- In the dialog box that is displayed, click Download to download the access key file. The access key file can be downloaded only once.
- Keep the key file properly and obtain the values of Access Key Id (AK) and Secret Access Key (SK) in the file.
- Click the login account in the upper right corner and choose My Credential.
- Log in to iMaster NCE-Campus as a tenant administrator and create a cloud network credential. After the configuration is complete, the controller can invoke public cloud APIs successfully.
- Choose System > System Settings > Third-party Service from the main menu.
- Click the Credential Management tab. The page for creating a cloud network credential is displayed.
- Click Create. On the page that is displayed, select a public cloud, set Account Name, and set AK and SK based on the values obtained from Huawei Cloud.
- Click OK. The cloud network credential is created.
Creating an Image File
Context
To implement automated deployment of sites on a public cloud, you need to create or obtain image files on the public cloud. Image files on public cloud are classified into private, shared, and marketplace images.
- Private image: A private image created on a public cloud is visible only to the user who created it.
- Shared image: A shared image is a private image shared by another user.
- Marketplace image: A marketplace image is provided by a cloud service provider or a third party.
The following procedure uses Huawei Cloud as an example. The operations on AWS are similar. For details, see the corresponding AWS guide.
Procedure (Huawei Cloud Private Image)
- Obtain the required image file. The following uses the AR1000V as an example.
- Obtain the image file of devices to be deployed at cloud sites at the following websites:
To obtain the AR1000V image file, visit https://support.huawei.com/enterprise/en/routers/ar1000v-pid-21768212/software.
- Select the desired version and download the corresponding image file.
The name of the AR1000V image file applicable to Huawei Cloud is AR1000V-ALLINONE-HWCLOUD-version.img.
The name of the AR1000V image file applicable to the AWS cloud is AR1000V-ALLINONE-AWS-version.img.
- Obtain the image file of devices to be deployed at cloud sites at the following websites:
- Upload the image file.
- Use a Huawei account to log in to the Huawei Cloud console (at https://console.huaweicloud.com/console/).
- Choose Service List. under
- Click Create Bucket to create a bucket as needed.
Table 2-114 Parameters for creating a bucket
Parameter
Description
Region
Select the region where the image file is to be uploaded.
Data Redundancy Policy
Set this parameter based on user requirements.
Bucket Name
Set a bucket name.
Default Storage Class
Set this parameter based on user requirements.
Bucket Policy
Set this parameter based on user requirements.
Default Encryption
Set this parameter based on user requirements. This parameter is optional. You are advised to select Enable to ensure key data security.
Direct Reading
Set this parameter based on user requirements. This parameter is optional.
Tags
Set this parameter based on user requirements. This parameter is optional.
- Go to the Object Storage Service page and click the name of the created bucket to go to the object overview page.
- Click the Objects tab and then click Upload Object.
Upload the image file of the cloud device to Huawei Cloud. When the status reaches 100%, the file is uploaded successfully.
- Create a private image.
- Use a Huawei account to log in to the Huawei Cloud console (at https://console.huaweicloud.com/console/).
- Choose Service List. under
- Click Create image in the upper right corner. Select the name of the bucket where the image file is located and select the image file.
Table 2-115 Parameters for creating a private image
Parameter
Description
Type
Select Import Image.
Region
The value is determined by the region where the image file is uploaded. You do not need to set this parameter.
Image Type
Select System disk image.
Select Image File
Click an image file that has been uploaded to the bucket.
Enable automatic configuration
Clear this check box.
Function
Select ECS system disk image.
Architecture
Select x86.
Boot Mode
Select BIOS.
OS
Select Other and Linux(64 bit).
System Disk (GB)
This example uses 40 GB. The minimum size is 10 GB. You can select a value based on the actual requirements.
Name
Set a name.
Encryption
Set this parameter based on user requirements. This parameter is optional.
Tags
Set this parameter based on user requirements. This parameter is optional.
Description
Set this parameter based on user requirements. This parameter is optional.
- After the image is created, you can view the status of the new image on the Image Management Service page.
Procedure (Huawei Cloud Shared Image)
- Share a private image with other users.
- Use a Huawei account to log in to the Huawei Cloud console (at https://console.huaweicloud.com/console/).
- Choose Service List. under
- On the Private Images tab page, locate the row that contains the image to be shared, click More in the Operation column, and select Share.
- Enter the project ID of another user with whom the selected private image is to be shared. (To obtain the project ID, choose My Credentials > API Credentials and obtain the project ID in the same region.)
- Receive the shared image as the user with whom the image is shared.
- Log in to the Huawei Cloud console as the user with whom the image is shared and choose Compute > Image Management Service.
- Choose Service List. under
- On the Shared Images tab page, you can view the status of the image shared by other users.
Loading an AR1000V Certificate
Context
In Huawei Cloud and AWS scenarios, CA and AR1000V device certificates can be automatically imported to iMaster NCE-Campus. In other scenarios, before manually registering an AR1000V with iMaster NCE-Campus and onboarding the device, the system administrator needs to apply for and download CA and device certificates from iMaster NCE-Campus, create a certificate update task, and load the certificates on the device.
Procedure
- Create a CA certificate.
- Log in to iMaster NCE-Campus as the admin user and choose .
- Choose PKI Management > CA from the navigation pane and click New.
- Set Signature algorithm, Certificate profile, and Country/Region(C). Click Next.
- RSASSA-PSS is more secure than RSA. Currently, only TLS 1.3 supports certificates signed by RSASSA-PSS. TLS 1.2 and earlier versions do not support certificates signed by RSASSA-PSS.
- RSA (with a 2047-bit or shorter key) is an insecure encryption algorithm. You are advised to use RSA (with a 3072-bit or longer key).
- Select an end entity profile to be associated as needed and set it as the default profile. Click Next.
- Set parameters related to the CA certificate and verify the configuration.
Set Signature algorithm and Certificate profile. After the configuration is completed, click Submit. On the page that is displayed, click Restart Later.
- View information about the created CA certificate on the CA page. Click Download CA Certificate, set File format to PEM, and click Submit to download the created CA certificate file (.pem) to the local PC.
- Apply for a device certificate.
- Log in to iMaster NCE-Campus as the admin user and choose .
- On the Certificate Authority Service page, choose Certificate Application > Certificate Application from the navigation pane, and set parameters on the Apply by Basic Info tab page.
Set Associated CA to the CA certificate created in Step 1. Set Certificate profile to the certificate profile associated in 1.d. Set Country/Region(C) to the value specified in Step 1 and click Submit.
- Go to the Application List page, click
, and click Download Certificate.
- File name: Set this parameter as needed. The file name can be a string of 1 to 20 characters, including digits, uppercase letters, lowercase letters, underscores (_), and hyphens (-), but cannot be null or all (case-insensitive).
- File format: Select PKCS#12.
- File password: Set a password for the certificate file, which will be used when the certificate is imported to the target device. The password can be a string of 8 to 32 characters and contains at least three types of the following: digits, uppercase letters, lowercase letters, and special characters. In addition, the password cannot contain more than two consecutive identical characters.
- On the Application List page, click Download Certificate in the Operation column. In the displayed dialog box, enter the file password configured in 3 as prompted, and click Submit to download the certificate file (.p12).
- Configure CA proxy.
- Choose CA Server Connection. and choose
- Click New. On the Create CA Server Connection Settings page, click the Local CA tab, set the following parameters as prompted, and click Submit.
- Update certificates online.
- Log in to iMaster NCE-Campus as the admin user and choose .
- On the Certificate Management page, choose Online Certificate Update > Certificate Update Tasks and click Create. On the Create Task page, set Template to default, CA Server to the created CA server, and Certificate format to PEM, and set other parameters as planned. It is recommended that Key length be the same as that configured in 1.d. After configuration is completed, click OK.
- On the Certificate Update Tasks page, find the created certificate update task and click
. On the Select Service page, select CampusBaseServiceDeviceMoudle__thirdparty_cert and click OK.
- After a certificate is applied to a service, the functions dependent on the service may be unavailable. Exercise caution when performing this operation.
- Before selecting CampusBaseServiceDeviceMoudle__thirdparty_cert, ensure that no certificate has been applied to the service. Otherwise, other devices cannot go online.
- Check the binding status between the certificate and service.
- Log in to iMaster NCE-Campus as the admin user and choose .
- Choose Service Certificate Management from the navigation pane, select CampusBaseServiceDeviceMoudle__thirdparty_cert, and check whether the information about the service's identity and trust certificates is correct.
Deploying a Cloud Site
Context
The AR1000V supports automated deployment on Huawei Cloud and the AWS. That is, the controller can invoke public cloud APIs to automatically configure vCPEs, VPCs, subnets, and BGP on the cloud, implementing automated deployment of cloud sites.
- Charged resources are created on public clouds during automated cloud site deployment. For the pricing details, see the official website of the corresponding public cloud.
- If a user's balance is insufficient, the user's cloud server will be shut down due to arrears and cloud sites will go offline. After the user renews services and restarts the cloud server, cloud sites will automatically go online again.
Prerequisites
- You have obtained the access key for invoking public cloud APIs and configured a cloud network credential on iMaster NCE-Campus. For details, see Configuring a Cloud Network Credential.
- You have created an image for devices to be deployed at a public cloud site. For details, see Creating an Image File.
Procedure
- The deployment personnel log in to iMaster NCE-Campus and configure cloud site deployment.
- Choose from the main menu and click the ZTP tab.
- Choose the cloud site to be deployed from the navigation pane, and click Click to Deploy under Cloud Site.
- In the Site Configuration area, set the cloud network type for the cloud site. Select a cloud network type based on the actual situation.
- Set parameters in the Configuration on the Cloud area.
- Set parameters in the Basic Config area. Set parameters based on your selected public cloud resources.
Select a flavor based on the public cloud requirements. Select c3ne.xxxx.2 or c6.xxxx.2 for Huawei Cloud and c4.xxxx for the AWS cloud. The performance value set here must be the same as that set when devices are added to the site.
- Set parameters in the Certificate Configuration area. Configure a temporary device identity certificate for devices to go online on the controller.
- Compatible with Earlier Versions of Devices: If devices running versions earlier than V300R022C00 are deployed, toggle on this item. Otherwise, the devices cannot go online. If devices running V300R022C00 and later versions are deployed, toggle off this item.
- Certificate Validity Period: specifies the validity period of the certificate. The default validity period is 7 days. Upload a formal certificate before the validity period of the temporary certificate ends. Otherwise, devices need to go online again. For details, see Loading an AR1000V Certificate.
- Private Key: specifies the private key required for loading the temporary device identity certificate. You can set a private key as needed.
- Country/Region, Province/State, City, Company, and Department: Set these parameters based on the certificate update task parameters set by the system administrator on the page.
- Set parameters in the Network Configuration area.
- If VPC Mode is set to Create a VPC, the controller creates a VPC on the public cloud. You can also set this parameter to Select an existing VPC.
- Set Subnet Network to a subnet in the VPC subnet. It cannot conflict with existing subnets on the public cloud.
- When Cloud Network Type is set to HUAWEI, you can set Public Address Type, Charging mode, and Select Bandwidth to select the access mode of the public IP address, charging mode for the public cloud elastic IP address (EIP), and bandwidth.
- When Cloud Network Type is set to AWS, Public Address Type, Charging mode, and Select Bandwidth are not configurable.
- Set parameters in the Link Config area. Select a cloud site device and click Create. In the Link Config window, set WAN link parameters and click OK.
- Click Deploy and wait until the cloud site deployment is completed. The time required for deploying a cloud site varies depending on the network environment. The overall deployment duration is about 5 to 15 minutes.
iMaster NCE-Campus automatically generates an ESN, invokes the cloud API to start the vCPE, and applies the ESN to the vCPE.
- Set parameters in the Basic Config area. Set parameters based on your selected public cloud resources.
- Verify that devices at the site go online successfully.
- Choose from the main menu.
- Click the Device tab to view the status of devices at the site. If the status of a device is normal, the device goes online successfully.
- Verify that the site configuration is delivered successfully.
- Choose from the main menu.
- Click the Configuration Result tab, choose the site from the navigation pane, and check whether the device configuration status is Success or Info. If so, service deployment is successful.
Parameter Description
Parameter |
Description |
Data Plan in Advance |
|
---|---|---|---|
Site configuration |
Cloud Network Type |
Public cloud for cloud site deployment. The controller uses the cloud resource orchestration service of the selected public cloud and invokes public cloud services through the SDK provided by the public cloud. |
Y |
Basic configuration |
Select Account |
Cloud network credential that has been configured. It is used by iMaster NCE-Campus to invoke public cloud APIs to for automated deployment of devices at cloud sites. |
Y |
Select Region |
Select the region to be deployed on the public cloud. |
Y |
|
Flavor |
Select the VM specifications of an elastic cloud server (ECS). The specifications must be the same as those of the device added during cloud site creation. |
Y |
|
Image |
Image file for deploying devices at the cloud site:
|
Y |
|
Certificate Configuration |
Compatible with Earlier Versions of Devices |
In V300R022C00, iMaster NCE-Campus no longer provides pre-configured device identity certificates, to reduce spoofing risks caused by device identity certificate leakage.
|
- |
Certificate Validity Period |
Validity period of the temporary certificate. Yiou can set the validity period as needed. The default validity period is 7 days and the maximum validity period is 20 years. |
Y |
|
Private Key |
Private key required for loading the temporary device identity certificate. The private key must contain at least six characters and contain at least two types of the following: uppercase letters, lowercase letters, digits, special characters (`~!@#$%^&*()-_ =+\|[{}];:" ,<.>/?), and spaces. |
Y |
|
Network configuration |
VPC Mode |
Create a VPC: The controller creates a VPC. Select an existing VPC: Select a VPC that has been configured on the public cloud (AWS or Huawei Cloud). |
Y |
VPC |
Select the VPC that has been configured on the public cloud. |
Y |
|
VPC network segment |
Network segment where the VPC to be created resides. |
Y |
|
Subnet Network |
The network segment where the subnet is located must be included in the VPC network segment. Constraints: Configure a subnet in an unoccupied network segment in the VPC to avoid network segment conflicts. |
Y |
|
Public Address Type |
This parameter is applicable only to Huawei Cloud. Fully dynamic BGP: When changes occur on a network using dynamic BGP, network configuration can be promptly adjusted using routing policies, ensuring network stability and optimal user experience. Static BGP: Static routes are manually configured by network carriers. |
- |
|
Charging mode |
Charging mode for the public cloud EIP. This parameter is applicable only to Huawei Cloud. |
- |
|
Select Bandwidth |
Bandwidth of the public cloud EIP. This parameter is applicable only to Huawei Cloud. |
Y |
|
Link configuration |
Link Name |
Name of a WAN link. |
- |
Transfer Network |
Type of the transport network to which the WAN link belongs. It specifies the WAN-side network to be accessed. The value is specified by Transport network created in WAN Global Configuration. |
Y |
|
Role |
Link role, which can be active or standby.
|
Y |
|
Interface |
WAN interface specified by the public cloud. |
- |
|
Interface Address |
IP address assigned to the WAN link interface by the public cloud. |
- |
|
Interface Description |
Interface description. You can centrally plan the WAN links of a site and describe the CPE and site to which the interface belongs. |
Y |
|
VN instance |
VN instance name. It specifies the name of the VN instance on the underlay network to which the interface is to be added. The value is a character string starting with underlay_, for example, underlay_1. |
Y |
|
IPv4 Interface Protocol Type |
Interface protocol type of the physical link between the vCPE and WAN. The default value is IPoE. |
- |
|
IPv4 Link Access Mode |
Mode for assigning an IP address for the interface connecting the vCPE to the WAN. By default, the static mode is used. |
- |
|
Public Address |
Public address assigned to the interface by the public cloud. |
- |
|
Overlay Tunnel |
Whether to enable the overlay tunnel function. This function is enabled by default, which indicates that an overlay tunnel is created over the WAN link. |
- |
|
Southbound Access |
IP address of the southbound access service of iMaster NCE-Campus. By default, WAN links in the predefined site template use the default southbound access service. If the system administrator has enabled other southbound access services, you can select other customized access services for the WAN links. The southbound access services applied to WAN links cannot be changed after deployment. |
Y |
|
NAT traversal |
Whether to enable the function of traversing NAT devices. NAT traversal is used to establish and maintain TCP/IP networks and UDP connections. After this function is enabled, external users can access intranet servers and intranet users can access external networks. |
- |
|
Uplink capacity (Mbps) |
Maximum uplink and downlink rates. Set the parameters based on the actual link bandwidth. In the Huawei Cloud scenario, the uplink and downlink capacities are automatically set based on the network configuration. You can manually change the values. In the AWS scenario, you need to manually set the parameters. |
Y |
|
Downlink capacity (Mbps) |
Y |
||
Link ID |
You can plan a unique ID for each link in an SD-WAN network. This helps you query link information by ID during maintenance. |
Y |
Manual Deployment
Device and Feature Requirements of Manual Deployment
Device Requirements
AR600&6100&6200&6300 series, AR5700&6700&8000 series, and AR1000V support manual deployment.
Feature Requirements
Scenario |
Requirement |
---|---|
The device model is AR5700&6700&8000 series. |
If a user logs in to a device through Telnet and remains online when the device goes online on the controller, the system fails to deliver configurations to the device. To prevent this, log out all online users from the device before onboarding it. |
After a device goes online, the AAA users manually configured on the device are lost. |
|
If a device is manually deployed and Telnet or SSH is enabled, before logging in to the device, you need to set the authentication mode to username and password authentication and set the username and password in the AAA view. Otherwise, security risks exist. |
|
Before the deployment, you need to query the certificate on the device. If the certificate is not imported to the device, the device cannot register with iMaster NCE-Campus. |
|
Before deployment |
If a SIM card needs to be inserted into a device at the deployment site, you are advised to insert the SIM card into slot 1 instead of other slots. Otherwise, the device may fail to register after being restarted, causing a deployment failure. |
Manually Deploying AR600&6100&6200&6300 Series Devices
Context
AR600&6100&6200&6300 series devices support both email-based deployment and manual deployment. Manual deployment is complex and inefficient. Email-based deployment is recommended. Devices can register with and be managed by iMaster NCE-Campus only after the following configurations are complete on iMaster NCE-Campus and the devices.
Prerequisites
- Ensure that the device to be deployed uses its factory settings. If the device has other configurations, the deployment will fail.For AR600&6100&6200&6300 series devices, run the following commands to clear the configuration file used for next startup and RDB file, and then restart the devices to restore the factory settings.
- Run the following command in the user view to delete the RDB file:
delete /un *.rdb
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restore the factory settings after the device restarts:
factory-configuration reset
- Run the following command to restart the system and restore the factory settings of the device:
reboot fast
- Run the following command in the user view to delete the RDB file:
- The network access mode has been configured for the site where devices need to be deployed, and the ZTP mode has been set to URL/U Disk. For details, see Configuring ZTP.
Procedure
- Check the device status. Ensure that the device to be deployed has been added successfully, its ESN has been set, and the device status is unregistered.
- Log in to iMaster NCE-Campus as a tenant administrator and choose from the main menu.
- On the Device page that is displayed by default, check the device ESN.
If a value is displayed in the ESN column, verify that the ESN is correct and go to the next step. If no value is displayed in the ESN column, click
. On the Modify Device tab page, enter the ESN and go to the next step.
For an AR5700&6700&8000 series device, run the following command to check the device ESN:display device esn
For an AR600&6100&6200&6300 series or AR1000V device, run the following command to check the device ESN:display esn
- On the Device page that is displayed by default, check the device status.
If the device status is not unregistered, the device has been deployed and goes online.
- Choose ZTP tab, select the site to be activated, and check the configuration. from the main menu. Click the
- If a SIM card needs to be inserted into a device at the deployment site, you are advised to insert the SIM card into slot 1 instead of other slots. Otherwise, the device may fail to register after being restarted, causing a deployment failure.
- Create a VPN instance on the device and configure an address family. The VPN instance must be the same as that in the step "Configure WAN-side links for the site." in the section "Configuring ZTP." The VPN route distinguisher does not need to be configured.
If the user network is an IPv4 network, run the following commands:
ip vpn-instance vpn-instance ipv4-family
If the user network is an IPv6 network, run the following commands:
ip vpn-instance vpn-instance ipv6-family
- Configure an IP address for the interface and bind it to a VPN instance. ip-address specifies the IP address of the interface, which is used for interconnection with iMaster NCE-Campus. If the WAN interface is a Layer 2 interface, run the undo portswitch command to switch its working mode to Layer 3.
If the user network is an IPv4 network, run the following commands:
interface interface-type interface-number ip binding vpn-instance vpn-instance ip address ip-address mask
If the user network is an IPv6 network, run the following commands:
interface interface-type interface-number ipv6 enable ip binding vpn-instance vpn-instance ipv6 address ipv6-address prefix-length
After the preceding commands are configured, you can run the following command to check whether the interface address is reachable to the gateway address: In the following command, ip-address indicates the gateway address of the device.
ping -vpn-instance vpn-instance ip-address
- Configure a route on the device to ensure connectivity between the device and iMaster NCE-Campus. ac_south_ip(v6)-address indicates the southbound IP address of iMaster NCE-Campus.
If the user network is an IPv4 network, run the following commands:
ip route-static vpn-instance vpn-instance ac_south_ip-address mask nexthop-address
If the user network is an IPv6 network, run the following commands:
ipv6 route-static vpn-instance vpn-instance ac_south_ipv6-address prefix-length nexthop-ipv6-address
- (Optional) Configure the IP address or domain name, and port number of the bootstrap server and specify the voucher verification mode based on the bootstrap service configuration performed by the system administrator. The value of host must be the same as the controller address in the bootstrap service configuration. You can configure ESN-based or verification code-based verification based on the serial number source in the bootstrap service configuration.
- Configure bootstrap server information and ESN-based verification.
agile controller bootstrap host host port 10020 vpn-instance vpn-instance verifytype esn
- Configure bootstrap server information and verification code-based verification. Set verifycode to the southbound IP address of iMaster NCE-Campus.
agile controller bootstrap host host port 10020 vpn-instance vpn-instance verifytype code verifycode verifycode
- Configure bootstrap server information and ESN-based verification.
- Set parameters on the device for interconnection with iMaster NCE-Campus based on the ZTP configuration that has been performed by the tenant administrator. ac_south_ip-address indicates the southbound IP address of iMaster NCE-Campus.
agile controller host ac_south_ip-address port 10020 vpn-instance vpn-instance
When deploying AR600&6100&6200&6300 series devices, you need to configure interconnection with iMaster NCE-Campus on the devices so that the devices can be managed by iMaster NCE-Campus.
- Save all configurations to the configuration file.
save
If the device is online on the controller, running this command will not save the device's configuration. You need to save the device's configuration on the
page. For details, see Saving Device Configurations. - Determine the deployment status of the device based on the CTRL indicator:
- Steady green: The device has been connected to the controller.
- Blinking green: The device is being deployed. (Some device models do not support this indicator status.)
- Steady off: The device is not connected to the controller.
Manually Deploying an AR5700&6700&8000 Series Device
Context
AR5700/AR6700/AR8000 series devices support manual deployment. Devices can register with and be managed by iMaster NCE-Campus only after the following configurations are complete.
Prerequisites
- Ensure that the device to be deployed uses its factory settings. If the device has other configurations, the deployment will fail.
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restart the device, clear the service configuration and data files on the device, and restore the device to its factory settings.
reset factory-configuration
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- On an AR5700&6700&8000 series device, run the following command to clear the configuration file for next startup and restart the device to restore factory settings.
- A CA certificated has been imported to the device to be deployed. Otherwise, the device cannot register with iMaster NCE-Campus successfully.
- Before deployment, perform the following operations to check or import a CA certificate to the device.
display pki certificate ca realm default
Run the following command to check the CA certificate on the device. If a CA certificate is found, proceed with the deployment process and skip the following step. If no CA certificate is found, proceed to the next step to import a CA certificate.
- Run the following command to import the preset CA certificate to the default domain. After the CA certificate is imported, perform the previous step again to verify certificate information. If the CA certificate fails to be imported, contact Huawei technical support.
pki import-certificate default_ca realm default
- Before deployment, perform the following operations to check or import a CA certificate to the device.
- The network access mode has been configured for the site where devices need to be deployed, and the ZTP mode has been set to URL/U Disk. For details, see Configuring ZTP.
Procedure
- Check the device status. Ensure that the device to be deployed has been added successfully, its ESN has been set, and the device status is unregistered.
- Log in to iMaster NCE-Campus as a tenant administrator and choose from the main menu.
- On the Device page that is displayed by default, check the device ESN.
If a value is displayed in the ESN column, verify that the ESN is correct and go to the next step. If no value is displayed in the ESN column, click
. On the Modify Device tab page, enter the ESN and go to the next step.
For an AR5700&6700&8000 series device, run the following command to check the device ESN:display device esn
For an AR600&6100&6200&6300 series or AR1000V device, run the following command to check the device ESN:display esn
- On the Device page that is displayed by default, check the device status.
If the device status is not unregistered, the device has been deployed and goes online.
- Choose from the main menu, click the ZTP tab, select the site to be activated, check its configuration.
- If a SIM card is inserted into a device at the deployed site, check whether the SIM card is inserted into slot 1. If so, the device cannot register with iMaster NCE-Campus after being restarted, causing a deployment failure.
- Log in to the device CLI and perform the following configurations:
- Enable NETCONF.
snetconf server enable
- Create an SSH user.
ssh user huawei ssh user huawei authentication-type x509v3-rsa ssh user huawei assign pki default ssh user huawei service-type snetconf
The username must be huawei. Otherwise, the device cannot go online, causing a deployment failure.
- Specify the source interface for an SSH server.
ssh server-source all-interface
When the following information is displayed, type y and press Enter.
Warning: SSH server source configuration will take effect in the next login. Continue? [Y/N]:y
- Configure an SSH authentication mode.
ssh server assign pki default
Configure the authorization type for SSH connections.
ssh authorization-type default root
Set the public key algorithm of the SSH server to X509-SSH-RSA.ssh server publickey x509v3-ssh-rsa
- Enable NETCONF.
- Choose from the main menu, click the ZTP tab, select the site to be activated, check its configuration.
- Log in to the device and configure interconnection with iMaster NCE-Campus. When deploying a device, you need to configure interconnection with iMaster NCE-Campus on the device. As such, the device can be managed by iMaster NCE-Campus.
- Configure a common physical interface for a WAN link.
- Create a VPN instance on the device.
If the user network is an IPv4 network, run the following commands:
ip vpn-instance vpn-instance ipv4-family
If the user network is an IPv6 network, run the following commands:
ip vpn-instance vpn-instance ipv6-family
- Optional: (Optional) Configure a route distinguisher (RD) and import or export VPN targets for the VPN instance address family.
route-distinguisher route-distinguisher vpn-target vpn-target &<1-8> [ both | export-extcommunity | import-extcommunity ]
- Configure an IP address for a WAN interface and bind a VPN instance to the interface. ip-address specifies the IP address of the interface, which is used for interconnection with iMaster NCE-Campus. If the WAN interface is a Layer 2 interface, run the undo portswitch command to switch its working mode to Layer 3.
If the user network is an IPv4 network, run the following commands:
interface interface-type interface-number ip binding vpn-instance vpn-instance ip address ip-address mask
If the user network is an IPv6 network, run the following commands:
interface interface-type interface-number ipv6 enable ip binding vpn-instance vpn-instance ipv6 address ipv6-address prefix-length
After the preceding commands are configured, you can run the following command to check whether the interface address is reachable to the gateway address: In the following command, ip-address indicates the gateway address of the device.
ping -vpn-instance vpn-instance ip-address
- Configure a route on the device to ensure connectivity between the device and iMaster NCE-Campus. ac_south_ip(v6)-address indicates the southbound IP address of iMaster NCE-Campus.
If the user network is an IPv4 network, run the following commands:
ip route-static vpn-instance vpn-instance ac_south_ip-address mask nexthop-address
If the user network is an IPv6 network, run the following commands:
ipv6 route-static vpn-instance vpn-instance ac_south_ipv6-address prefix-length nexthop-ipv6-address
- Set parameters for interconnection with iMaster NCE-Campus on the device based on the ZTP configuration that has been performed on iMaster NCE-Campus. The callhome name must be set to default-callhome, and ac_south_ip-address must be set to the southbound IP address of iMaster NCE-Campus. For details about how to set interface-name_ac_south_ip-address, see the endpoint naming rules in the following note.
netconf callhome default-callhome endpoint interface-name_ac_south_ip-address peer-ip ac_south_ip-address port 10020 vpn-instance vpn-instance
The endpoint name must be in the format of name of the WAN link interface used to register with iMaster NCE-Campus_controller southbound IP address, for example:- Assume that the WAN link uses interface GE0/0/1 and the controller southbound IP address is 192.168.10.10. Set the endpoint name to GE0/0/1_192.168.10.10.
- Assume that the WAN link uses interface XGE0/0/1 and the controller southbound IP address is 192.168.10.10. Set the endpoint name to 10GE0/0/1_192.168.10.10.
- Create a VPN instance on the device.
- Use an LTE interface on a WAN link to connect to the Internet through 5G signals. Currently, LTE interfaces are supported only on IPv4 networks.
- Configure the automatic dial-up function and IP address obtaining function on the interface. interface-number specifies the interface number. When using an LTE interface on a WAN link, use an LTE sub-interface.
interface cellular interface-number ip address modem-alloc
- Configure a default route on the device to ensure connectivity between the device and iMaster NCE-Campus.
ip route-static 0.0.0.0 0 cellular interface-number
- Set parameters for interconnection with iMaster NCE-Campus on the device based on the ZTP configuration that has been performed on iMaster NCE-Campus. The callhome name must be set to default-callhome, and ac_south_ip-address must be set to the southbound IP address of iMaster NCE-Campus. For details about how to set interface-name_ac_south_ip-address, see the endpoint naming rules in the following note.
netconf callhome default-callhome endpoint interface-name_ac_south_ip-address peer-ip ac_south_ip-address port 10020
The endpoint name must be in the format of name of the WAN link interface used to register with iMaster NCE-Campus_controller southbound IP address, for example:
Assume that the WAN link uses interface LTE1/0/0:1 and the controller southbound IP address is 192.168.10.10. Set the endpoint name to LTE1/0/0.1_192.168.10.10.
- Configure the automatic dial-up function and IP address obtaining function on the interface. interface-number specifies the interface number. When using an LTE interface on a WAN link, use an LTE sub-interface.
- Configure an Eth-Trunk interface for the device's WAN link. Currently, Eth-Trunk interfaces are supported only on IPv4 networks.
- Create a VPN instance on the device.
ip vpn-instance vpn-instance ipv4-family
- Create an Eth-Trunk interface on the device, for example, Eth-Trunk 1, and add member interfaces to the Eth-Trunk interface.
interface Eth-Trunk 1 trunkport interface-name1 trunkport interface-name2
- Configure an IP address for the interface and bind a VPN instance to it. ip-address specifies the IP address of the interface, which is used for interconnection with iMaster NCE-Campus. If the WAN link interface is a Layer 2 interface, run the undo portswitch command to switch its working mode to Layer 3.
interface Eth-Trunk 1 ip binding vpn-instance vpn-instance ip address ip-address mask
- Configure a route to ensure that the device can communicate with iMaster NCE-Campus. Set ac_south_ip-address to the southbound IP address of iMaster NCE-Campus.
ip route-static vpn-instance vpn-instance ac_south_ip-address mask nexthop-address
- Set parameters for interconnection with iMaster NCE-Campus on the device based on the ZTP configuration that has been performed on iMaster NCE-Campus. The callhome name must be set to default-callhome, and ac_south_ip-address must be set to the southbound IP address of iMaster NCE-Campus. For details about how to set interface-name_ac_south_ip-address, see the endpoint naming rules in the following note.
netconf callhome default-callhome endpoint interface-name_ac_south_ip-address peer-ip ac_south_ip-address port 10020 vpn-instance vpn-instance
The endpoint name must be in the format of name of the WAN link interface used to register with iMaster NCE-Campus_controller southbound IP address, for example:- Assume that the WAN link uses the Eth-Trunk 1 interface and the controller southbound IP address is 192.168.10.10. Set the endpoint name to Eth-Trunk1_192.168.10.10.
- Create a VPN instance on the device.
- Configure an Eth-Trunk sub-interface for the device's WAN link. Currently, Eth-Trunk sub-interfaces are supported only on IPv4 networks.
- Create a VPN instance on the device.
ip vpn-instance vpn-instance ipv4-family
- Create an Eth-Trunk interface on the device, for example, Eth-Trunk 1, and add member interfaces to the Eth-Trunk interface.
interface Eth-Trunk 1 trunkport interface-name1 trunkport interface-name2
- Create an Eth-Trunk sub-interface, for example, Eth-Trunk 1.1, and configure the sub-interface to terminate user VLANs. The sub-interface and VLAN IDs for termination must be the same as the sub-interface number and VLAN IDs specified on the ZTP page of the controller. Configure an IP address for the interface and bind a VPN instance to it. ip-address specifies the IP address of the interface, which is used for interconnection with iMaster NCE-Campus. If the WAN link interface is a Layer 2 interface, run the undo portswitch command to switch its working mode to Layer 3.
interface Eth-Trunk 1.1 dot1q termination vid vlan_id ip binding vpn-instance vpn-instance ip address ip-address mask
- Configure a route to ensure that the device can communicate with iMaster NCE-Campus. Set ac_south_ip-address to the southbound IP address of iMaster NCE-Campus.
ip route-static vpn-instance vpn-instance ac_south_ip-address mask nexthop-address
- Set parameters for interconnection with iMaster NCE-Campus on the device based on the ZTP configuration that has been performed on iMaster NCE-Campus. The callhome name must be set to default-callhome, and ac_south_ip-address must be set to the southbound IP address of iMaster NCE-Campus. For details about how to set interface-name_ac_south_ip-address, see the endpoint naming rules in the following note.
netconf callhome default-callhome endpoint interface-name_ac_south_ip-address peer-ip ac_south_ip-address port 10020 vpn-instance vpn-instance
The endpoint name must be in the format of name of the WAN link interface used to register with iMaster NCE-Campus_controller southbound IP address, for example:- Assume that the WAN link uses the Eth-Trunk 1.1 interface and the controller southbound IP address is 192.168.10.10. Set the endpoint name to Eth-Trunk1.1_192.168.10.10.
- Create a VPN instance on the device.
- Configure a common physical interface for a WAN link.
- Save all configurations to the configuration file.
save
If the device is online on the controller, running this command will not save the device's configuration. You need to save the device's configuration on the
page. For details, see Saving Device Configurations. - Determine the deployment status of the device based on the CTRL indicator:
- Steady green: The device has been connected to the controller.
- Blinking green: The device is being deployed. (Some device models do not support this indicator status.)
- Steady off: The device is not connected to the controller.
Manually Deploying an AR1000V Device
Context
It is recommended that AR1000Vs be deployed in cloud site mode on Huawei Cloud and AWS, and be deployed in manual mode on other cloud platforms. Before manual deployment, you need to perform required configurations on the target devices and iMaster NCE-Campus, so that the devices can go online and be managed by iMaster NCE-Campus.
Prerequisites
- AR1000V devices have been installed on the public cloud. For details about how to install an AR1000V, see "AR1000V Installation Guide" in the NetEngine AR1000V V300R022 Product Documentation.
- Ensure that the device to be deployed uses its factory settings. If the device has other configurations, the deployment will fail.For an AR1000V, run the following commands to clear the configuration file for next startup, and then restart the device to restore the factory settings.
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
reset saved-configuration
- Run the following command to restore the factory settings after the device restarts:
factory-configuration reset
- Run the following command to restart the system and restore the factory settings of the device:
reboot fast
- Run the following command in the user view to clear the configuration file used for next startup and cancel the setting of specifying a configuration file for next startup, thereby restoring the default device settings:
- You have applied for a CA certificate (a .pem file) and a device identity certificate (a .p12 file) on iMaster NCE-Campus and updated the certificates on iMaster NCE-Campus. For details, see Loading an AR1000V Certificate.
- The network access mode has been configured for the site where devices need to be deployed, and the ZTP mode has been set to URL/U Disk. For details, see Configuring ZTP.
Procedure
- Check the device status. Ensure that the device to be deployed has been added successfully, its ESN has been set, and the device status is unregistered.
- Log in to iMaster NCE-Campus as a tenant administrator and choose from the main menu.
- On the Device page that is displayed by default, check the device ESN.
If a value is displayed in the ESN column, verify that the ESN is correct and go to the next step. If no value is displayed in the ESN column, click
. On the Modify Device tab page, enter the ESN and go to the next step.
For an AR5700&6700&8000 series device, run the following command to check the device ESN:display device esn
For an AR600&6100&6200&6300 series or AR1000V device, run the following command to check the device ESN:display esn
- On the Device page that is displayed by default, check the device status.
If the device status is not unregistered, the device has been deployed and goes online.
- Log in to the device on the public cloud console or directly log in to the device for configuration.
If a public IP address has been set for an AR1000V device when the AR1000V device is created and the SSH function has been configured during the device initial configuration, you can directly log in to the AR1000V to perform operations, without the need to use the public cloud console for device login.
- Load required certificates on the device. A device can successfully register with iMaster NCE-Campus only after the device has the CA certificate and device identity certificate loaded.
If iMaster NCE-Campus running a version other than V300R022C00 is used together with the AR1000V running V300R022C00, certificates cannot be manually imported. To prevent this problem, ensure that the software version of iMaster NCE-Campus is the same as that of the AR1000V.
- Upload the CA certificate (a .pem file) and device identity certificate (a .p12 file) to the root directory of the flash memory of the device through FTP or SFTP. SFTP is recommended, because it is more secure than FTP.
- In the system view, run the following command to import the CA certificate. In the command, realm-name indicates the domain name of the certificate, which is set to default in this example; filename indicates the certificate name, which is the name of the obtained .pem file.
pki import-certificate ca realm realm-name pem filename filename
- In the system view, run the following commands to import the RSA key pair and device identity certificate.
- Import the RSA key pair to the device memory:
- key-name in the command indicates the name of the RSA key pair on the device and can be customized.
- file-name in the command indicates the name of the file that stores the RSA key pair. In this example, it is the name of the obtained .p12 file.
- password in the command indicates the file password configured when the device identity certificate is downloaded.
pki import rsa-key-pair key-name pkcs12 file-name password password
- Import the device identity certificate to the device memory:
- realm-name in the command indicates the domain name of the certificate, which is set to default in this example.
- file-name in the command indicates the name of the certificate file to be imported. In this example, it is the name of the obtained .p12 file.
- password in the command indicates the file password configured when the device identity certificate is downloaded.
pki import-certificate local realm realm-name pkcs12 filename file-name password password
- Import the RSA key pair to the device memory:
- Create a VPN instance on the device.
If the user network is an IPv4 network, run the following commands:
ip vpn-instance vpn-instance //The vpn-instance name must be the same as that configured for ZTP. ipv4-family
If the user network is an IPv6 network, run the following commands:
ip vpn-instance vpn-instance //The vpn-instance name must be the same as that configured for ZTP. ipv6-family
- Configure an IP address for an interface and bind a VPN instance to the interface. ip-address specifies the IP address used by the device to register with iMaster NCE-Campus.
If the user network is an IPv4 network, run the following commands:
interface interface-type interface-number ip binding vpn-instance vpn-instance ip address ip-address mask
If the user network is an IPv6 network, run the following commands:
interface interface-type interface-number ipv6 enable ip binding vpn-instance vpn-instance ipv6 address ipv6-address prefix-length
- Configure a route to ensure connectivity between the device and iMaster NCE-Campus. You are advised to configure a host route. ip(v6)-address is the southbound IP address of iMaster NCE-Campus, and nexthop-address is the IP address of the next hop connected to the WAN interface.If the user network is an IPv4 network, run the following commands:
ip route-static vpn-instance vpn-instance ip-address 32 nexthop-address
If the user network is an IPv6 network, run the following commands:
ipv6 route-static vpn-instance vpn-instance ipv6-address 128 nexthop-ipv6-address
- (Optional) Configure the IP address or domain name, and port number of the Bootstrap server and specify the voucher verification mode based on the Bootstrap service configuration performed by the system administrator. The value of host must be the same as the controller address in the Bootstrap service configuration. You can configure ESN-based or verification code-based verification based on the serial number source in the Bootstrap service configuration.
- Configure Bootstrap server information and ESN-based verification.
agile controller bootstrap host host port 10020 vpn-instance vpn-instance verifytype esn
- Configure Bootstrap server information and verification code-based verification. Set verifycode to the southbound IP address of iMaster NCE-Campus.
agile controller bootstrap host host port 10020 vpn-instance vpn-instance verifytype code verifycode verifycode
- Configure Bootstrap server information and ESN-based verification.
- Set parameters for interconnection with iMaster NCE-Campus on the device based on the ZTP configuration performed by the tenant administrator. Set ip-address to the southbound IP address of iMaster NCE-Campus and set port to the fixed value 10020.
agile controller host ip-address port 10020 vpn-instance vpn-instance
- Save all configurations to the configuration file.
save
If the device is online on the controller, running this command will not save the device's configuration. You need to save the device's configuration on the
page. For details, see Saving Device Configurations.
Quick Deployment
Quick deployment can be implemented in two modes: simplified deployment and batch deployment. Simplified deployment applies to a single site for automatic deployment. Deployment personnel only need to power on and connect devices, and services such as mutual access between enterprise branches and Internet access of enterprise branches, are then automatically deployed. Batch deployment applies to a batch of sites. You can copy an existing site or import a site template for batch deployment.
Prerequisites
- Global parameters have been set. For details, see Setting Global Parameters.
- To guarantee the successful deployment, it is advised that the device to be deployed uses factory settings. If the device has other configurations, the deployment will fail.
Procedure (Simplified Deployment)
- Choose from the main menu and click the Quick Deployment tab.
- Click Go in the Simplified Deployment area. The Create Site page is displayed.
- Set site parameters in the upper part of the page.
- Enter a site name and select whether to enable the RR function.
- Set the site to a single-gateway site or dual-gateway site based on actual requirements.
- Click Bind device to add devices to the site.
- Click
. The RR, gateway, and device information of the site cannot be modified after the site is deployed.
- Configure ZTP for the site.
- Select the ZTP mode.
- URL/U Disk: Select this mode if USB-based, email-based, or manual deployment is required.
- DHCP Option: Select this mode if DHCP option-based deployment is required.
- Choose whether to enable Multiple sub-interfaces. After this function is enabled, multiple sub-interfaces can be configured on a device's physical interface. If this function is disabled, only one sub-interface can be configured.
- Choose whether to enable RDB-based deployment. By default, RDB-based deployment is disabled. This function cannot be disabled once being enabled.
After RDB-based deployment is enabled, the WAN link for URL-based deployment can be modified and deleted online. After the WAN link configuration is updated, the system delivers the updates to the target device. The device does not need to be deployed again.
Determine whether to enable RDB-based deployment based on the deployment mode and device model. For details, see Table 2-118.
Table 2-118 Mapping between device models and functionsFunction/Device Model
AR600&6100&6200&6300&SRG series
AR1000V
AR5700&6700&8000 series
RDB-based deployment
This function is disabled in USB-based deployment and manual deployment scenarios and is optional in the email-based deployment scenario.
This function is disabled in manual deployment scenarios.
This function is enabled by default and is not displayed on the GUI.
- Select the ZTP mode.
- Configure WAN links.
- When Device Configuration is set to List:
- Use a WAN link template. Click Select Template, select a site template, and click OK.
- If the template does not meet requirements, you can create a WAN link as needed. In the device area, select the device added when creating the site and click Create.
When an AR1000V is added, you need to configure a performance value for it. The corresponding license is deducted based on the forwarding capability of the AR1000V. The actual performance value of the AR1000V must be less than or equal to the configured Performance value on the controller. Otherwise, the AR1000V cannot go online.
- Set basic WAN link parameters as prompted, including Link name, Interface, Interface protocol, IP address access mode, IPv4 address, Subnet mask, IPv4 gateway, Southbound interface service, Uplink bandwidth, and Downlink bandwidth. If some parameters are not set, their default values take effect. For details, see Configuring ZTP.
- (Optional) Click
on the right to modify WAN link parameters.
- If Dual gateways is selected, you need to configure an interlink (inter-CPE link) connecting the dual gateways.
- Click OK.
- The system automatically completes subsequent deployment configurations, including NTP and WAN-side routing, and displays the configuration results. Click View configurations and view the detailed parameter settings.
- If Config default NTP is disabled on the WAN Global Configuration page, NTP cannot be automatically configured during simplified deployment. In this case, you can click View configurations to configure NTP. If Config default NTP is enabled on the WAN Global Configuration page, all sites use the default time zone specified on the WAN Global Configuration page.
- During the simplified deployment process, connections to RRs cannot be configured automatically. You can click
in the Connect to RRs area to select an RR to configure a connection with it as needed.
- Activate the site, in either Send Email or Download ZTP File mode.
- Devices are deployed successfully after they are connected and go online. You can click Site configuration details to view the detailed configurations about the site and devices.
- When Device Configuration is set to Topology:
The configuration process is the same as that in list mode. You can click
in the topology to configure a link for the selected device.
- When Device Configuration is set to List:
Procedure (Batch Deployment)
- Choose from the main menu.
- Click Go in the Batch Deployment area on the right.
- Set the number of sites to be deployed in batches.
- Click
next to Site Model. Select a site template or click the Site tab to select an existing site and click OK. Then the interface and link configuration of the selected site is copied.
- Set ZTP Mode to URL/U Disk or DHCP Option.
- Configure WAN links. If you have copied the configuration of an existing site, skip this step. Click the device icon in the topology to configure the interface and link information for the selected device.
When an AR1000V is added, you need to configure a performance value for it. The corresponding license is deducted based on the forwarding capability of the AR1000V. The actual performance value of the AR1000V must be less than or equal to the configured Performance value on the controller. Otherwise, the AR1000V cannot go online.
- Click Save and then Next.
- In the Site List area, set information about a batch of sites. The site list is automatically generated based on the number of configured sites. You can select New device or Existing device in the Device column. In the WAN area, view the verification status of each WAN link.
- Click Start Task. The system automatically starts batch deployment.
- Check the deployment progress on the Batch Configuration Result page.
Follow-up Procedure
Simplified deployment provides configuration wizards of physical networks and virtual networks. By following the configuration wizards, you can perform subsequent configurations, and view or modify existing configurations.
- Click Site configuration details on the configuration result page of simplified deployment.
- Access the Configure Map page.
- On the site configuration page, you can view and modify ZTP, NTP, and RR connection configurations as needed.
- On the configuration page of each device, you can view and modify the underlay and overlay configurations about the device at the site.
- Alternatively, click a keyword in the navigation pane or enter a keyword in the search box to search for the configuration page of your desired function.
- Click Edit to modify the function configuration.
Parameter Description
Parameter |
Description |
|
---|---|---|
Basic information |
Site Name |
Name of the site to be deployed. |
Enable RR |
Site role. To create an edge site, toggle off this item. To create an edge-RR site, toggle on this item.
|
|
Gateway |
Gateway type. The options include Single gateway and Dual gateways. To create a dual-gateway site, you are advised to add two devices of the same model. |
|
ZTP Mode |
ZTP mode. The options include:
|
|
Multiple sub-interfaces |
Whether to enable multiple sub-interfaces. |
|
Number of sites (The parameter is configurable only in batch deployment.) |
Number of sites to be deployed in batches. |
|
Device interface information |
Interface |
WAN link parameters to be planned vary according to the interface type selected in the site plan. This parameter specifies the type and number of the physical interface used by the current link. Similar to the link name, this parameter value cannot be modified. The interface can be a physical WAN interface or a virtual interface (that is, a loopback interface). When iMaster NCE-Campus is deployed on the LAN side of a data center (DC), multiple physical interfaces and one virtual interface can be configured for the site. The physical interfaces are used for connecting iMaster NCE-Campus and the site, and the virtual interface is used to transmit traffic on the overlay network. The physical and virtual interfaces must belong to the same VN instance. NOTICE:
|
Transport network |
Type of the transport network to which a WAN link belongs. |
|
Uplink bandwidth (The parameter needs to be set only for GE and Eth-Trunk interfaces.) |
Maximum uplink and downlink rates of the interface. Set the two parameters based on the actual link bandwidth. NOTE:
If traffic distribution or QoS of inbound traffic on the overlay network is not configured, the downlink bandwidth limit does not take effect. |
|
Downlink bandwidth (The parameter needs to be set only for GE and Eth-Trunk interfaces.) |
||
Interface protocol (The parameter needs to be set only for GE and Eth-Trunk interfaces.) |
Interface protocol type of the physical link connecting the PE to the WAN. When the interface type is set to GE, the following protocol types are supported:
|
|
IP address access mode |
Mode for assigning an IP address for the interface connecting the CPE to the WAN. The following options are supported:
|
|
IPv4 address. |
IP address statically assigned to the interface connecting the CPE to the WAN. At a central or an aggregation site, this IP address must be the same as the public IP address. In the NAT scenario, for central, aggregation, RR or edge sites, this parameter must be set to the private IP address of the device corresponding to the public IP address. |
|
Subnet mask |
||
IPv6 address |
||
Default gateway |
IP address of the interface used by the PE on the WAN side to communicate with the current site. |
|
Inter-CPE link (The parameters need to be set for a dual-gateway site.) |
Use LAN-side L2 interface |
Whether to use Layer 2 physical LAN interfaces on the interlink connecting the two gateways.
|
VLAN ID |
VLAN IDs for the interlinks between the two gateways. In the dual-gateway scenario, iMaster NCE-Campus creates a separate sub-interface for each VPN (that is, department) on the interfaces of the interlinks between the two gateways to isolate departments. The number of VLAN IDs must be the same as the number of departments. The start VLAN ID ranges from 1 to 4086 and the end VLAN ID ranges from 9 to 4094. The difference between the start and end VLAN IDs must be greater than or equal to 8 and less than or equal to 300. A maximum of 16 VLAN ranges can be set, and the total number of VLANs cannot exceed 301. |
|
WAN link |
Link name |
Name of a WAN link. If a WAN link is created using the default site template, the link name is Internet or MPLS. If a WAN link is created using a customized site template, the link name is specified when the template is created. This setting cannot be modified after the WAN link configuration is completed. |
Role |
Link role.
|
|
Alarm for standby links (This parameter can be configured only when Role is set to Standby.) |
After this item is toggled on, when a tunnel is established over the standby link and traffic is switched to this tunnel for forwarding, an alarm indicating that the standby link is used is reported. This item is toggled on by default. NOTE:
|
|
Sub-interface |
Whether to use sub-interfaces. Currently, only dot1q sub-interfaces are supported. |
|
Number (The parameter needs to be set only after the sub-interface function is enabled.) |
Sub-interface number, which is used to identify a sub-interface. The value ranges from 1 to 4094. |
|
VLAN ID (The parameter needs to be set only after the sub-interface function is enabled.) |
VLAN ID of a sub-interface. The value ranges from 1 to 4094. |
|
Port description |
Interface description. |
|
VN instance |
VN instance name. |
|
IPv4 Overlay tunnel |
Whether to enable the overlay tunnel function. If this function is enabled, an overlay tunnel is created over the WAN link. |
|
NAT traversal |
Whether to enable NAT traversal on the WAN. If a NAT device is deployed between the site on a private network and the WAN side, enable the NAT traversal function to set up overlay tunnels with other sites and RRs. NAT traversal does not need to be enabled for IPv6 WAN links. After this function is enabled, external network users can access internal servers and internal network users can access the external network in the NAT scenario. NOTE:
If NAT traversal is enabled, IPsec encryption must be enabled for transport networks in routing domains. For details about how to enable IPsec encryption, see Setting Global Parameters. |
|
URL-based deployment |
Whether to enable URL-based deployment for the current link.
NOTE:
|
|
Set as southbound device access address (This parameter needs to be set only when URL-based deployment is enabled.) |
When configuring a WAN link, you need to set Southbound interface service. If Set as southbound device access address is toggled on, the primary IP address of the specified southbound access service is used as the onboarding IP address in the deployment email.
|
|
Southbound interface service |
IP address of an iMaster NCE-Campus southbound access service. By default, WAN links in the predefined site template use the default southbound access service. If the system administrator has customized and enabled other southbound access services, you can select customized access services for the WAN links as needed. The southbound access services applied to WAN links cannot be changed after deployment. |
|
Link ID |
ID of a WAN link. |
- Site Deployment
- Deployment Process, Device Models and Application Scenarios in Different Deployment Modes
- Email-based Deployment
- Overview of Email-based Deployment
- Email-based Deployment Process
- Device and Feature Requirements for Email-based Deployment
- Configuring an Email Server
- (Optional) Configuring an Email Template
- Performing Email-based Deployment (by Sending an Email)
- Performing Email-based Deployment (by Downloading the ZTP File)
- USB-based Deployment
- DHCP Option-based Deployment
- Deployment Through the Registration Query Center
- Overview of Deployment Through the Registration Query Center
- Process of Deployment Through the Registration Query Center
- Device and Feature Requirements for Deployment Through the Registration Query Center
- Configuring Interconnection with the Registration Query Center
- Configuring Deployment Through the Registration Query Center
- (Optional) Data Synchronization from the Registration Query Center
- Cloud Site Deployment
- Manual Deployment
- Quick Deployment