ZXA10 C220 (V1.2.1) XPON Optical Access Convergence Equipment Configuration Manual (CLI)
ZXA10 C220 (V1.2.1) XPON Optical Access Convergence Equipment Configuration Manual (CLI)
ZXA10 C220 (V1.2.1) XPON Optical Access Convergence Equipment Configuration Manual (CLI)
Version: V1.2.1
ZTE CORPORATION
NO. 55, Hi-tech Road South, ShenZhen, P.R.China
Postcode: 518057
Tel: +86-755-26771900
Fax: +86-755-26770801
URL: http://ensupport.zte.com.cn
E-mail: [email protected]
LEGAL INFORMATION
Copyright © 2011 ZTE CORPORATION.
The contents of this document are protected by copyright laws and international treaties. Any reproduction or
distribution of this document or any portion of this document, in any form by any means, without the prior written
consent of ZTE CORPORATION is prohibited. Additionally, the contents of this document are protected by
contractual confidentiality obligations.
All company, brand and product names are trade or service marks, or registered trade or service marks, of ZTE
CORPORATION or of their respective owners.
This document is provided “as is”, and all express, implied, or statutory warranties, representations or conditions
are disclaimed, including without limitation any implied warranty of merchantability, fitness for a particular purpose,
title or non-infringement. ZTE CORPORATION and its licensors shall not be liable for damages resulting from the
use of or reliance on the information contained herein.
ZTE CORPORATION or its licensors may have current or pending intellectual property rights or applications
covering the subject matter of this document. Except as expressly provided in any written license between ZTE
CORPORATION and its licensee, the user of this document shall not acquire any license to the subject matter
herein.
ZTE CORPORATION reserves the right to upgrade or make technical change to this product without further notice.
Users may visit ZTE technical support website http://ensupport.zte.com.cn to inquire related information.
The ultimate right to interpret this product resides in ZTE CORPORATION.
Revision History
R1.1 2010-12-30 Update information about GCSA, GCSAS and EIGMP cards
I
2.1.9 Managing the ONU Remotely.................................................................. 2-23
2.1.10 Configuring the OLT Port ...................................................................... 2-27
2.2 10G EPON Data Service Configuration.............................................................. 2-30
2.2.1 Overview ............................................................................................... 2-30
2.2.2 Configuring the 10G EPON Data Service ................................................. 2-30
II
Chapter 6 CES Service Configuration ...................................................... 6-1
6.1 Overview ........................................................................................................... 6-1
6.2 Configuring the EPON E1/T1 Uplink CES Service (MEF8) .................................... 6-2
6.3 Configuring the EPON E1/T1 Uplink CES Service (PWE3).................................... 6-9
6.4 Configuring the EPON STM-1/OC3 Uplink CES Service ..................................... 6-16
6.5 Configuring the GPON E1/T1 Uplink CES Service (MEF8) .................................. 6-23
6.6 Configuring the GPON STM-1/OC3 Uplink CES Service ..................................... 6-31
6.7 Configuring the CES TDM Profile ...................................................................... 6-38
6.8 Configuring the CES TDM Interface................................................................... 6-40
III
Chapter 12 Uplink Protection Configuration.......................................... 12-1
12.1 Overview ....................................................................................................... 12-1
12.2 Configuring the UAPS..................................................................................... 12-1
12.3 Configuring the CL1A 1+1 Protection ............................................................... 12-4
12.4 Configuring the Link Aggregation..................................................................... 12-7
12.5 Configuring the ZTE Ethernet Switch Ring ....................................................... 12-9
IV
15.7 Configuring the Ethernet OAM......................................................................... 15-9
Figures............................................................................................................. I
Tables ............................................................................................................ III
Index ...............................................................................................................V
Glossary .......................................................................................................VII
V
VI
About This Manual
Purpose
The ZXA10 C220 xPON Optical Access Convergence Equipment (ZXA10 C220 for short)
is a full-service optical access platform. It supports the video, data, voice, TDM, and CATV
services. The ZXA10 C220 can be connected with ONUs of medium or larger capacity
through various networking technologies.
The ZXA10 C220 device consists of the main control and switching card, xPON subscriber
cards, CES uplink card, and Ethernet uplink card. It provides large-capacity controllable
multicast and high QoS control.
This manual provides detailed information about configurations (CLI) on the ZXA10 C220
xPON Optical Access Convergence Equipment.
Intended Audience
This document is intended for:
l Installation and debugging engineer
l System maintenance engineer
l Data configuration engineer
Chapter Summary
Chapter 2, EPON Service Describes EPON data service configuration and 10G EPON data
Configuration service configuration.
I
Chapter Summary
Chapter 3, GPON Service Describes GPON data service configuration, ONU type profile
Configuration configuration, ONU authentication, T-CONT profile configuration,
traffic profile configuration, service channel configuration, flow
VLAN parameters configuration, ONU UNI VLAN parameters
configuration, ONU in-band IP address configuration, and OLT
port configuration.
Chapter 5, VoIP Service Describes EPON VoIP service configuration, and GPON VoIP
Configuration service configuration.
Chapter 6, CES Service Describes EPON CES service configuration, GPON CES service
Configuration configuration, CES TDM profile configuration, and CES TDM
interface configuration.
Chapter 7, VLAN Configuration Describes basic VLAN configuration, TLS VLAN configuration,
VLAN smart QinQ configuration, 1:1 VLAN configuration, and
service port VLAN configuration.
Chapter 10, ACL Configuration Describes standard ACL configuration, extended ACL
configuration, Layer-2 ACL configuration, and hybrid ACL
configuration.
Chapter 11, PON Protection Describes EPON PON port protection configuration and GPON
Configuration PON port protection configuration.
Chapter 12, Uplink Protection Describes UAPS configuration, CL1A 1+1 protection configuration,
Configuration link aggregation configuration, and ZTE Ethernet Switch Ring
configuration.
Chapter 13, QoS Configuration Describes traffic limit configuration based on ACL rules, traffic
shaping configuration, queue scheduling configuration, CoS and
DSCP mapping configuration, and bridge port QoS configuration.
II
Chapter Summary
Chapter 14, User Security Describes port location configuration, ARP anti-spoofing
Configuration configuration, ARP agent configuration, PON port loopback
detection configuration, and dual-layer VLAN interconnection
configuration.
Chapter 15, System Security Describes SSH configuration, TACACS+ configuration, RADIUS
Configuration configuration management ACL configuration, anti-DoS attack
configuration, and Ethernet OAM configuration.
Related Documentation
The following documentation is related to this manual:
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Documentation
Guide
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Feature Guide
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Product De-
scription
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Hardware
Description
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Cabinet
Installation Guide
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Configuration
Manual (NetNumen) Volume I
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Configuration
Manual (NetNumen) Volume II
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Maintenance
Manual
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Alarm and
Notification Message Reference
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Command
Reference (Volume I)
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Command
Reference (Volume II)
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Command
Reference (Volume III)
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Command
Reference (Volume IV)
l ZXA10 C220 (V1.2.1) xPON Optical Access Convergence Equipment Command
Reference (Volume V)
Conventions
ZTE documents employ the following typographical conventions.
III
Typeface Meaning
Bold Menus, menu options, function names, input fields, radio button names, check
boxes, drop-down lists, dialog box names, window names.
CAPS Keys on the keyboard and buttons on screens and company name.
Typeface Meaning
Click Refers to clicking the primary mouse button (usually the left mouse button) once.
Double-click Refers to quickly clicking the primary mouse button (usually the left mouse button)
twice.
Right-click Refers to clicking the secondary mouse button (usually the right mouse button)
once.
IV
Declaration of RoHS
Compliance
To minimize the environmental impact and take more responsibility to the earth we live,
this document shall serve as formal declaration that the ZXA10 C220 manufactured by
ZTE CORPORATION is in compliance with the Directive 2002/95/EC of the European
Parliament - RoHS (Restriction of Hazardous Substances) with respect to the following
substances:
l Lead (Pb)
l Mercury (Hg)
l Cadmium (Cd)
l Hexavalent Chromium (Cr (VI))
l PolyBrominated Biphenyls (PBB’s)
l PolyBrominated Diphenyl Ethers (PBDE’s)
The ZXA10 C220 manufactured by ZTE CORPORATION meets the requirements of EU 2002/95/EC;
however, some assemblies are customized to client specifications. Addition of specialized,
customer-specified materials or processes which do not meet the requirements of EU 2002/95/EC
may negate RoHS compliance of the assembly. To guarantee compliance of the assembly, the
need for compliant product must be communicated to ZTE CORPORATION in written form. This
declaration is issued based on our current level of knowledge. Since conditions of use are outside
our control, ZTE CORPORATION makes no warranties, express or implied, and assumes no liability
in connection with the use of this information.
I
II
Chapter 1
Basic Configuration
Table of Contents
Access Methods.........................................................................................................1-1
NM Configuration .......................................................................................................1-5
Physical Configuration..............................................................................................1-13
Clock Configuration ..................................................................................................1-19
This manual describes configuration in the CLI after logging in to the ZXA10 C220
through HyperTerminal or Telnet. Refer to the ZXA10 C220 (V1.2.1) xPON Optical Access
Convergence Equipment Configuration Manual (NetNumen) for NetNumen configuration.
Prerequisites
Before this operation, make sure that:
l Device installation is complete.
l The serial port of the maintenance console computer is connected to the CLI port of
the ZXA10 C220 control and switching card through a serial port cable.
l The operation system supports HyperTerminal.
l The ZXA10 C220 device is powered on.
Context
This topic takes the Windows XP operating system as an example.
To log in to the ZXA10 C220 through HyperTerminal, perform the following steps:
1-1
Steps
1. In Windows XP, choose Start > All Programs > Accessories > Communications
> HyperTerminal. The Connection Description dialog box appears, as shown in
Figure 1-1.
2. Enter Name and click OK. The Connect To dialog box appears, as shown in Figure
1-2.
3. Select COM1 or COM2, and then click OK. The COM1 Properties dialog box appears,
as shown in Figure 1-3.
Select 9600 for Bits per second, 8 for Data bits, None for Parity, 1 for Stop bits,
and None for Flow control. Or click Restore Defaults. Click OK.
1-2
4. If the system runs properly, the HyperTerminal windows appears. The system enters
the operator mode (ZXAN>). Carry out the enable command and enter the enable
password zxr10 to enter the administrator mode (ZXAN#), as shown in Figure 1-4.
– End of Steps –
Result
The user successfully logs in to the ZXA10 C220 through HyperTerminal.
1-3
Prerequisites
Before this operation, make sure that:
l The in-band or out-of-band NM IP address is configured.
l The Telnet computer can ping the in-band or out-of-band NM IP address.
Context
To log in to the ZXA10 C220 through Telnet, perform the following steps:
Steps
1. In the Windows operating system, choose Start > Run to open the Run dialog box.
2. In the dialog box, enter Telnet x.x.x.x. where, x.x.x.x is the NE IP address,
as shown in Figure 1-5, and then click OK to start the Telnet client.
3. If the connection is proper, the login window pops up. Enter the user name and
password zte to enter the administrator mode (ZXAN#), as shown in Figure 1-6.
– End of Steps –
Result
The user successfully logs in to the ZXA10 C220 through Telnet.
1-4
1.2 NM Configuration
The ZXA10 C220 supports both in-band NM and out-of-band NM.
l In-band NM is implemented through the uplink port. It is usually used in practical
engineering.
l Out-of-band NM is implemented through the Q port on the control and switching card.
It uses the non-service channel to transmit the management information so that the
management channel and the service channel are separated. It is usually used in
local management and maintenance.
1-5
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The shelf, rack, and cards are added.
l The user has logged in to the ZXA10 C220 through HyperTerminal.
Context
In the in-band NM mode, the NMS information is transmitted through the service channel
of the ZXA10 C220. It is flexible in networking without any auxiliary devices, and low in
cost. But it is hard to maintain the ZXA10 C220 when the service is down.
Networking Diagram
Figure 1-8 shows the in-band NM networking diagram.
Configuration Data
Table 1-1 lists the in-band NM configuration data.
Item Data
1-6
Configuration Flow
Figure 1-9 shows the in-band NM configuration flow.
Note:
This section describes the configuration on the ZXA10 C220. The corresponding data must be config-
ured on the router as well.
Steps
1. Configure the in-band NM VLAN.
a. Enter the global configuration mode.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#
1-7
Note:
When you use the switchport vlan command to configure a port VLAN, the system add the
VLAN automatically.
The out-of-band and in-band NM IP addresses cannot be in the same network segment.
1-8
Note:
Besides the ZTE NetNumen NMS, the network may contain a third-party NMS that receives traps.
Multiple SNMP server hosts can be configured.
Result
The ZXA10 C220 can be managed through the in-band NM IP address.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The shelf, rack, and cards are added.
l The user has logged in to the ZXA10 C220 through HyperTerminal.
Context
In the out-of-band NM mode, the NMS information is transmitted through the non-service
channel. The management channel is independent from the service channel. Thus,
out-of-band NM is more reliable compared with in-band NM.
1-9
Networking Diagram
Figure 1-10 shows the out-of-band NM networking diagram.
Configuration Data
Table 1-2 lists the out-of-band NM configuration data.
Table 1-2 Out-Of-Band NM Configuration Data
Items Data
Configuration Flow
Figure 1-11 shows the out-of-band NM configuration flow.
1-10
Note:
This section describes the configuration on the ZXA10 C220. The corresponding data must be config-
ured on the router as well.
Steps
1. Configure the IP address of the out-of-band NM interface.
a. Enter the global configuration mode.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#
1-11
Note:
The out-of-band and in-band NM IP addresses cannot be in the same network segment.
Note:
Besides the ZTE NetNumen NMS, the network may contain a third-party NMS that receives traps.
Multiple SNMP server hosts can be configured.
The ZXA10 C220 supports six types of traps: SNMP, BGP, OSPF, RMON, STALARM,
and VPN. All traps are enabled by default and do not need to be configured. To
configure the trap type, use the snmp-server enable trap command. For detailed
information, refer to the ZXA10 C220 (V1.2.1) xPON Optical Access Convergence
Equipment Command Manual.
1-12
Result
The ZXA10 C220 can be managed through the out-of-band NM IP address.
Prerequisites
Before this operation, make sure that:
l The network devices work properly.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
To add a rack, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
1-13
Note:
The ZXA10 C220 supports only one rack at present, and thus rackno can only be 0.
– End of Steps –
Result
The rack is added successfully.
Prerequisites
Before this operation, make sure that:
l The network devices work properly.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
l The rack is successfully added.
Context
The ZXA10 C220 supports two types of shelves:
l ZXA10C220-A: ZXA10 C220 shelf of type A, front outlet shelf
l ZXA10C220-B: ZXA10 C220 shelf of type B, back outlet shelf
To add a shelf, perform the following steps:
Steps
1. Enter the global configuration mode.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
Note:
The ZXA10 C220 supports only one shelf at present, and the shelfno can only be 0.
3. Use the show shelf command to check whether the shelf is successfully added.
1-14
ZXAN(config)#show shelf
Rack Shelf ShelfType HwNo CleiCode
--------------------------------------------------------------------------
0 0 ZXA10C220-B 0 ZXA10C220-B_CleiCode
– End of Steps –
Result
l The shelf is added successfully.
l After the shelf is added, the system automatically adds two main control cards. Use
the show card command to view the information on the main control cards.
ZXAN(config)#show card
Rack Shelf Slot CfgType RealType Port HardVer SoftVer Status
-------------------------------------------------------------------------
0 0 7 GCSD GCSD 0 V1.6 V1.2.1 INSERVICE
0 0 8 GCSD GCSD 0 V1.7 V1.2.1 STANDBY
Prerequisites
Before this operation, make sure that:
l The network devices work properly.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
l The rack is added successfully.
l The shelf is added successfully.
Context
The card can be added in the following ways:
l Enable card auto-configuration.
After this function is enabled, the system automatically identifies the card in each slot
and you do not need to add the cards manually.
l Add a card to each slot manually.
According to the actual configuration, use the add-card command to add a card to
each slot.
To add a card, perform the following steps:
Steps
1. Enter the global configuration mode.
1-15
ZXAN#configure terminal
Enter configuration commands,one per line. End with CTRL/Z.
2. Add cards.
a. Enable card auto-configuration.
ZXAN(config)#set-pnp enable
ZXAN(config)#show pnp
pnp function is enable.
b. Use the add-card command to add a subscriber card or uplink card according to
the slot number and card type.
To add the XUTQ card in slot 21:
ZXAN(config)#add-card slotno 21 XUTQ
3. Use the show card command to check whether the card is successfully added.
ZXAN(config)#show card
Rack Shelf Slot CfgType RealType Port HardVer SoftVer Status
--------------------------------------------------------------
0 0 6 EIGM EIGM 4 V0.0 V1.2.1 INSERVICE
0 0 7 GCSD GCSD 0 V1 V1.2.1 INSERVICE
0 0 8 GCSD GCSD 0 V1 V1.2.1 STANDBY
0 0 10 GPFA GPFAE 4 V1.19 V1.2.1 INSERVICE
0 0 11 GPFA GPFAC 4 V0 V1.2.1 INSERVICE
0 0 12 GPFA GPFAB 4 V0 V1.2.1 INSERVICE
0 0 14 GPFA GPFAB 4 V0 V1.2.1 INSERVICEE
– End of Steps –
Result
The cards is added successfully.
Context
The ZXA10 C220 supports the following card states:
l DISABLE: The card is added and is online, but the system fails to receive the card
information.
l INSERVICE: The card is working properly.
l STANDBY: The card is in standby state.
l OFFLINE: The card is added but is offline.
l CONFIGING: The card is being configured.
1-16
Steps
1. Use the show card command to show the configuration and status of all the cards in
the ZXA10 C220 system.
ZXAN(config)#show card
Rack Shelf Slot CfgType RealType Port HardVer SoftVer Status
--------------------------------------------------------------
0 0 7 GCSD GCSD 0 V1 V1.2.1 INSERVICE
0 0 8 GCSD GCSD 0 V1 V1.2.1 STANDBY
0 0 10 GPFA GPFAE 4 V1.19 V1.2.1 INSERVICE
– End of Steps –
Result
The system displays the shelf, rack, and slot numbers of the main control cards and
subscriber cards, as well as the card configured type, actual type, hardware version,
software version, and card states.
Prerequisites
Before this operation, make sure that:
l The network devices work properly.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
When the card in a slot needs to be changed, it needs to be deleted first. The main control
card cannot be deleted.
To delete a card, perform the following steps:
Steps
1. Enter the global configuration mode.
1-17
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
– End of Steps –
Result
The card is deleted successfully.
Prerequisites
Before this operation, make sure that:
l The network devices work properly.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
When a card is faulty, it needs to be reset.
To reset a card, perform the following steps:
Steps
1. Enter the privilege mode.
ZXAN(config)#exit
ZXAN#
ZXAN#reset-card slotno 5
Confirm to reset card? [yes/no]:y
– End of Steps –
Result
The card is reset successfully.
1-18
Prerequisites
Before this operation, make sure that:
Context
When the active control and switching card is faulty, swap it to the standby control and
switching card.
To swap the active control and switching card with the standby control and switching card,
perform the following steps:
Steps
1. Enter the privilege mode.
ZXAN(config)#exit
ZXAN#
2. Use the swap command to swap the active main control card to the standby main
control card.
ZXAN#swap
Confirm to master swap? [yes/no]:y
– End of Steps –
Result
The active control and switching card is swapped with the standby control and switching
card.
1-19
1.4.1 Overview
Principle
The ZXA10 C220 provides the solution to carry TDM service on PSN.
All the devices in the TDM network must synchronize with the unified clock to ensure that
the data is transmitted correctly.
There are two solutions for data synchronization in the digital network: pseudo-
synchronization and master/subordinate synchronization. Table 1-3 describes the clock
synchronization methods.
Method Description
Master/subordinate There is one clock master office in the network, and this master
synchronization office is equipped with the clock of high accuracy. The other offices
in this network are subject to the clock master office (That is, they
follow the master office clock, and use the master office clock as
the timing reference.) and control the devices of lower levels until
the NEs in the terminal exchanges.
Service Specifications
The ZXA10 C220 master/subordinate synchronization is used to synchronize the devices
in the network. There are three clocks: internal clock (in three levels), external clock,
and line clock. The line clock extracts the clock signals from the line. These signals are
processed by the related cards and sent to the main control card through the backplane.
The procedures for the system clock synchronization are as follows:
1. The system selects the best one based on the priority and clock quality of the clock
sources. The clock chip of the main control card locates that clock source and
synchronizes the output clock with this clock source.
2. The clock signal processed by the main control card is sent to the related service cards
and the output port of the external clock.
1-20
Networking Diagram
Figure 1-12 shows the networking diagram of configuring the system clock.
The ZXA10 C220 is connected to the TDM network through the E1 uplink port of the CE1B
card. The CE1B card obtains the clock signals with higher priority from the TDM device
of the upper level network. The CE1B card processes the clock signals and sends them
to the main control card through the backplane. The main control card sends the clock
signals to each service card, from which the TDM terminal device of the ONU obtains the
clock signals.
Configuration Data
Table 1-4 describes the system clock configuration data.
1-21
Item Data
Clock type E1
Priority 1
Steps
1. Use the clock command to enter the global clock configuration mode.
ZXAN(config)#clock
ZXAN(config-clock)#
2. Use the show source active command to query the active clock source.
ZXAN(config-clock)#show source active
Interface Type InS1 OutS1 Status
..........................................................
0/8/0 internal 11 11 FREE_RUN
nitially, the clock status is ‘internal clock free oscillation’ and the priority is ‘251’.
3. Use the source command to create the E1 clock source.
ZXAN(config-clock)#source 0/13/1 type e1 priority 1
Note:
If various clock sources are configured, the system selects the best one based on the priority and
actual quality of each clock source. The selection criteria is as follows: the one with normal clock
status, the highest priority, and the best quality. If these options are the same, select the clock
which is configured earlier.
4. (Optional) Use the no source priority command to delete the configured clock source.
ZXAN(config-clock)#no source id 0/13/1
Note:
The default internal clock with the priority 251 cannot be deleted.
5. Use the show clock config command to query the system reference clock source
configuration.
ZXAN(config-clock)#show clock config
Shelf/card/slot Type Priority CfgSSM Mode Species
1-22
..........................................................
0/13/1 e1 1 - - Source
clock source count: 1
6. (Optional) Use the show source alarm command to query the configured clock source
alarms.
ZXAN(config-clock)#show source alarm
Interface Type Priority Alarm
..........................................................
0/13/1 e1 1 LOS/LOF
Result
The system clock is configured successfully.
Context
Table 1-5 describes the external input clock parameters.
Parameter Description
external-input quality Configure the external input clock quality and display the
clock frequency and phrase accuracy. The clock ranges
are Level_2, Level_4, Level_8, and Level_11.
l primary: Level_2, primary clock (G.811)
l enhanced2: Level_4, enhanced 2 clock (G.812)
l enhanced3: Level_8, enhanced 3 clock (G.812)
l sec: Level_11, SEC clock (G.813)
Steps
1. Use the clock command to enter the global clock configuration mode.
1-23
2. Use the external-input command to configure the external input clock quality and
mode.
– End of Steps –
Result
The external input clock is configured successfully.
Example
Set the ZXA10 C220 external input clock to bits mode, and the clock quality to Level_11.
ZXAN(config)#clock
ZXAN(config-clock)#external-input 0/20/1 quality sec mode bits
Prerequisites
Before this operation, make sure that:
Context
Table 1-6 describes the external output clock parameters.
Parameter Description
1-24
Steps
1. Use the clock command to enter the global clock configuration mode.
2. Use the external-output mode command to configure the external output clock mode.
3. Use the external-output ssmThreshold command to configure the external output clock
SSM threshold.
– End of Steps –
Result
The external output clock is configured successfully.
Example
Set the ZXA10 C220 external output clock to bits mode and SSM threshold to SEC clock.
ZXAN(config)#clock
ZXAN(config-clock)#external-output mode bits ssmThreshold sec
1-25
1-26
2.1.1 Overview
Service Description
EPON access is a flexible access technology that provides super bandwidth access in
both broadband and narrowband service environment. It supports multiple rate modes
and uses a single optical fiber to provide user with data, voice, and video services.
Service Specifications
The ZXA10 C220 provides EPON access through the EPFC/EPFCB card.
Each EPFC/EPFCB card provides four EPON interfaces, supports the splitting ratio of 1:64
at the maximum, and provides up to 2560 ports for ONU access.
2-1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The VLAN of the upper-layer device interface corresponds to the VLAN configured on
the uplink interface.
l The EPON service card status is proper.
Context
The EPON data service can be applied in the following scenarios: FTTH, FTTB, and FTTC.
The basic configuration steps are the same for different scenarios. This instance takes the
Internet service in FTTB application as an example.
Networking Diagram
Figure 2-1 shows the networking diagram of the EPON data service.
In the networking, the user computer is connected to the ONU FE port. User data frames
are added with the VLAN tag on the ONU FE port. User data is distributed to each
2-2
service channel according to the user-side VLAN. The ZXA10 C220 completes VLAN tag
translation (from user-side VLAN to uplink VLAN) and sends data out through the uplink
port.
Configuration Data
Table 2-1 lists the EPON data service data scheme.
Table 2-1 Configuration Data of EPON Data Service
Requirements for upstream l Ethernet Switch: configure For detailed ES and BRAS
devices the same VLAN as the device configuration, refer to the
ZXA10 C220 service VLAN relevant operation manual.
(transparently transmits the
ZXA10 C220 services).
l BRAS: configure
parameters according
practical application.
Configuration Flow
Figure 2-2 shows the configuration flow of the EPON data service.
2-3
Steps
1. Create the service VLAN (optional).
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 100
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
2-4
ZXAN(config)#
4. Enter the EPON-OLT interface mode and authenticate the ONU by the MAC address.
ZXAN(config)#interface epon-olt_0/5/4
ZXAN(config-if)#onu 1 type ZTE-F820 mac 0019.c600.0011
ZXAN(config-if)#exit
5. Enter the EPON-ONU interface mode and enable the interface authentication protocol.
ZXAN(config)#interface epon-onu_0/5/4:1
ZXAN(config-if)#admin enable
Note:
You can use the show onu detail-info command to display the detailed information of the ONU.
8. Enter the ONU remote management mode, and configure the VLAN of the ONU
Ethernet port.
ZXAN(config)#pon-onu-mng epon-onu_0/5/4:1
ZXAN(epon-onu-mng)#vlan port eth_0/1 mode tag vlan 100 priority 0
ZXAN(epon-onu-mng)#exit
Note:
2-5
Building configuration...
..[OK]
Result
The EPON data service is configured successfully.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The in-band or out-of-band NM is configured.
Context
When the new ONU type does not exist in the system, perform this procedure.
Users can use the show onu-type epon command to query the default ONU types in the
system.
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pon command to enter the PON configuration mode.
3. Use the onu-type command to add an ONU type profile.
Note:
In the ZXA10 C220 system, the ONU type name must be unique in EPON and GPON service.
4. Use the onu-type-if command to configure the user port of the new ONU type.
2-6
Note:
After the auto-dispatch function is enabled, when the ONU gets online, the OLT automatically
dispatches the configuration, and the ONU local configuration data is overwrited.
7. Use the show onu-type epon command to view the properties of the new ONU type.
– End of Steps –
Result
The ONU type profile is configured successfully.
Example
Add a 10G EPON ONU with the type name of ZTE-F822A, supporting 24 Ethernet ports
and 24 POTS ports. Disable ZTE-F822A auto-dispatch funciton.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#pon
ZXAN(config-pon)#onu-type ZTE-F822A epon description 24FE,
24POTS speed 10g-asymmetric
ZXAN(config-pon)#onu-type-if ZTE-F822A eth_0/1-24
ZXAN(config-pon)#onu-type-if ZTE-F822A pots_0/1-24
ZXAN(config-pon)#exit
ZXAN(config)#epon
ZXAN(config-epon)#auto-dispatch-set ZTE-F822A disable
ZXAN(config-epon)#show onu-type epon ZTE-F822A
Onu type name : ZTE-F822A
Pon type : epon
Description : 24FE,24POTS
Protect type: none
Speed: 10g-asymmetric
Prerequisites
Before this operation, make sure that:
2-7
Context
The ZXA10 C220 supports the following ONU authentication modes:
l MAC address authentication: using the ONU PON MAC address for authentication.
By default, this mode is used.
l Logical ID authentication: using the ONU logical ID for authentication.
l SN authentication: using the ONU SN for authentication.
l Hybrid authentication: using any of the MAC address, logical ID, or SN for
authentication.
l SN+MAC authentication: using the ONU SN for authentication when the ONU enters
the network for the first time, and using the PON MAC address for authentication when
the ONU gets online for the second time.
In EPON configuration mode, the user can use the onu-authentication-mode service
command to change the ONU authentication mode. For example, to change the
authentication mode of the ONU in slot 0/5 to SN, carry out the following commands:
ZXAN(config)#epon
ZXAN(config-epon)#onu-authentication-mode service 0/5 sn
ZXAN(config-epon)#exit
Steps
1. Use the show onu unauthentication command to query the unauthenticated ONU
information.
2. Use the configure terminal command to enter the global configuration mode.
3. Use the interface command to enter the OLT interface configuration mode.
4. Use the onu command to authenticate the ONU.
5. User the show onu authentication command to query the authenticated ONU
information.
6. Use the interface command to enter the ONU interface configuration mode.
7. Use the admin enable command to enable the ONU interface authentication protocol.
– End of Steps –
Result
ONU authentication is complete.
Example
Query the unauthenticated ONU information on port epon-olt_0/6/4 and authenticate the
ONU.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
2-8
ZXAN(config)#interface epon-olt_0/6/4
ZXAN(config-if)#show onu unauthentication epon-olt_0/6/4
Onu interface : epon-onu_0/6/4:1
MAC address : 0019.c600.0011
SN :
AuthState State : deny
OnTime : 2009/08/19 11:12:29
ZXAN(config-if)#onu 1 type ZTE-F820 mac 0019.c600.0011
ZXAN(config-if)#exit
ZXAN(config)#show onu authentication epon-olt_0/6/4
Onu interface : epon-onu_0/6/4:1
Onu type : ZTE-F820
MAC address : 0019.c600.0011
SN :
LOID :
Active status : active
State : Online
LastAuthTime : 2009/08/19 11:12:29
ZXAN(config)#interface epon-onu_0/6/4:1
ZXAN(config-if)#admin enable
Prerequisites
Before this operation, make sure that:
Context
The ZXA10 C220 supports the following ONU bandwidth configuration methods:
l Configure the bandwidth for a single ONU.
l Create a bandwidth profile.
This topic describes how to configure the bandwidth for a single ONU.
Table 2-2 lists the parameters for configuring the ONU bandwidth.
2-9
Parameter Description
Assured bandwidth The assured upstream bandwidth that the system allocates to the ONU
when the ONU sends the request message
Maximum bandwidth The maximum upstream/downstream bandwidth that the system can
allocate to the ONU in the idle period
Maximum burst size The maximum burst upstream/downstream traffic on the ONU
Priority The ONU priority compared with other ONUs on extra bandwidth
allocation (except the assured bandwidth)
By default, all the ONUs have the same priority. The default value is
recommended.
Fixed bandwidth The bandwidth that the OLT allocates to the ONU after the ONU is
enabled, regardless whether the ONU has the upstream traffic
Fixed packet length The fixed length of a packet reported by the ONU
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the interface command to enter the ONU interface configuration mode.
3. Use the sla upstream command to configure the ONU upstream bandwidth.
4. Use the sla downstream command to configure the ONU downstream bandwidth.
5. Use the show onu sla upstream command to query the ONU upstream bandwidth.
6. Use the show onu sla downstream command to query the ONU downstream bandwidth.
– End of Steps –
Result
The ONU bandwidth is configured successfully.
Example
Configure the bandwidth of ONU 1 under epon-olt_0/5/4 and query the configuration
information. Table 2-3 lists the configuration information.
Table 2-3 ONU Bandwidth Configuration Data
Item Data
2-10
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#interface epon-onu_0/5/4:1
ZXAN(config-if)#sla upstream assured 10000 maximum 10000
ZXAN(config-if)#sla downstream maximum 10240
ZXAN(config-if)#show onu sla upstream epon-onu_0/5/4:1
Prerequisites
Before this operation, make sure that:
Context
The ZXA10 C220 supports the following ONU bandwidth configuration methods:
l Configure the bandwidth for a single ONU.
l Create a bandwidth profile.
The bandwidth profile is used in batch configuration of ONU bandwidth.
The system default profile is default. Table 2-4 lists its parameters.
2-11
Fixed bandwidth 0
Priority 0
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the epon command to enter the EPON configuration mode.
3. Use the onu-sla-profile profile-name create command to create a bandwidth profile.
4. Use the onu-sla-profile profile-set command to configure the downstream and
upstream parameters of the bandwidth profile.
Note:
In the upstream bandwidth configuration, the assured bandwidth and maximum bandwidth param-
eters are mandatory. The default values are recommended for other parameters.
5. Use the show epon onu-sla-profile command to query the bandwidth profile.
6. Use the exit command to exit the EPON configuration mode.
7. Use the interface command to enter the ONU interface configuration mode.
8. Use the sla-profile command to apply the bandwidth profile to the ONU.
9. Use the show onu sla command to query the ONU bandwidth configuration.
– End of Steps –
Result
The bandwidth profile is configured successfully.
2-12
Example
Configure the bandwidth profile and apply it to ONU 1 under epon-olt_0/5/4. Table 2-5 lists
the configuration information.
Item Data
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#epon
ZXAN(config-epon)#onu-sla-profile profile-name create zte
ZXAN(config-epon)#onu-sla-profile profile-set zte upstream assured 2000
maximum 5000
ZXAN(config-epon)#onu-sla-profile profile-set zte downstream maximum 10000
ZXAN(config-epon)#show epon onu-sla-profile zte
ProfileName :zte
UpStream MaxBw MinBw FixBw FixPktSize MaxBurstSize Priority
(Kbps) (Kbps) (Kbps) (Bytes) (Bytes)
-----------------------------------------------------------------------
5000 2000 0 64 45000 0
Downstream MaxBw(Kbps) MaxBurstSize(Bytes)
------------------------------------------------------------------
10000 205000
Onu reference:
ZXAN(config-epon)#exit
ZXAN(config)#interface epon-onu_0/5/4:1
ZXAN(config-if)#sla-profile zte
ZXAN(config-if)#show onu sla upstream epon-onu_0/5/4:1
ID MaxBw MinBw FixBw FixPkt MaxBurst Pri ProfileName
(Kbps) (Kbps) (Kbps) (Bytes) (Bytes)
------------------------------------------------------------
1 5000 2000 0 64 45000 0 zte
ZXAN(config-if)#show onu sla downstream epon-onu_0/5/4:1
ID MaxBw(Kbps) MaxBurstSize(Bytes) ProfileName
---------------------------------------------------------------
1 10000 205000 zte
2-13
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The EPON service card status is proper.
l The ONU is authenticated.
Context
The ZXA10 C220 manages configuration on EPON ONUs in the following ways:
l In-band configuration
Create an ONU in-band NM channel, and then log in to the ONU to implement
configuration.
In this mode, data is configured and saved on the ONU. You can access the ONU
through its in-band NM IP address from the ZXA10 C220 uplink port. The ONU can
be configured and upgraded through this IP address.
l Extended OAM configuration
The EPON technology provides the OAM channel for remote configuration.
In this mode, in-band NM does not need to be configured. This configuration can be
implemented only when the ONU is successfully registered and authenticated. The
configuration data is saved on the OLT and delivered to the ONU to take effect through
the OAM channel.
Note:
In practical applications, there is no need to configure the in-band NM IP addresses for all the ONUs.
The configuration is required for ONUs that only supports local VoIP services configuration or upgrade,
such as ZTE-F820 and ZTE-F822.
It is recommended to configure the ONU in-band NM IP address in the same management VLAN and
network segment as the ZXA10 C220, so that the NMS server can connect the ONU when it connects
the OLT.
Steps
1. Use the configure terminal command to enter the global configuration mode.
2-14
Result
The ONU in-band IP address is configured successfully.
Example
Set the in-band NM VLAN of No.1 ONU F820 under interface 4 of slot 5 to 2600 and the
in-band IP address to 198.2.128.5/24.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 2600
ZXAN(config-vlan)#exit
ZXAN(config)#interface epon-onu_0/5/4:1
ZXAN(config-if)#switchport mode hybrid
ZXAN(config-if)#switchport vlan 2600 tag
ZXAN(config-if)#exit
ZXAN(config)#interface gei_0/6/1
ZXAN(config-if)#switchport mode trunk
ZXAN(config-if)#switchport vlan 2600 tag
ZXAN(config)#pon-onu-mng epon-onu_0/5/4:1
ZXAN(epon-onu-mng)#mgmt-ip 192.2.128.5 255.255.255.0 vlan 2600 priority 7 route
192.2.128.0 255.255.255.0 192.2.128.1 status enable
ZXAN(epon-onu-mng)#end
ZXAN#
Follow-Up Action
Carry out the ping command on the OLT to check whether the ONU in-band IP address is
successfully configured.
ZXAN#ping 198.2.128.5
2-15
Short Description
Perform this procedure to configure the D-series/F-series ONU data service.
Prerequisites
Before this operation, make sure that:
Context
The ONU port supports six VLAN modes, as listed in Table 2-6.
Transparent Upstream The system does not change the tagged frame (reserving
the old VLAN tag) and forwards the frame.
The system does not change the untagged frame and
forwards the frame.
Downstream The system does not change the tagged frame (reserving
the old VLAN tag) and forwards the frame.
The system does not change the untagged frame and
forwards the frame.
2-16
Translation Upstream If the original VID of the tagged frame has a corresponding
entry (input VID) in the VLAN translation list of the related
port, the system transfers the VID to the output VID
according to the entry, and then forwards the frame. If the
VID has no corresponding entry in the VLAN translation
list of the related port, the system discards the frame.
The system adds the default VLAN ID to the untagged
frame and forwards the frame.
2-17
Hybrid (for the Upstream If the VLAN ID of the tagged frame is permitted by the
ONUs that do port, the system forwards the frame to the upper-layer
not support the device. If the VLAN ID of the tagged frame is denied by
CTC2.1 standard) the port, the system discards the frame.
The system adds the default VLAN ID to the untagged
frame and forwards the frame.
To configure the D-series/F-series ONU data service, perform the following steps:
2-18
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pon-onu-mng command to enter the ONU remote management mode.
3. Use the vlan port command to configure the ONU Ethernet port VLAN.
4. Use the show remote onu vlan to query the ONU VLAN configuration information.
– End of Steps –
Result
The ONU data service is configured successfully.
Example
Add VLAN tag 100 and priority 1 to the upstream Ethernet frames on port eth_0/1 of an
F822.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#pon-onu-mng epon-onu_0/5/4:1
ZXAN(epon-onu-mng)#vlan port eth_0/1 mode tag vlan 100 priority 1
ZXAN(epon-onu-mng)#show remote onu vlan epon-onu_0/5/4:1
Ethport : Eth_0/1
Mode : tag
vlan : 100
priority : 1
Ethport : Eth_0/2
Mode : tag
vlan : 4092
priority : 0
Ethport : Eth_0/3
Mode : tag
vlan : 4092
priority : 0
……
Short Description
Perform this procedure to configure the 9806H ADSL data service.
2-19
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The EPON data service configuration is completed.
l The 9806H device runs properly.
Context
To configure the 9806H ADSL data service, perform the following steps:
Steps
1. Authenticate the ONU.
2. Use the vlan command to create a service VLAN.
3. Use the interface command to enter the OLT uplink port and EPON-ONU interface
configuration mode respectively.
4. Use the switchport mode command to configure the OLT uplink port and EPON-ONU
interface mode respectively.
5. Use the switchport vlan command to configure the VLAN properties for the OLT uplink
port and the EPON-ONU interface respectively.
6. Log in to the 9806H device (user name/password: admin). Use the enable command
to enter the administrator mode (password: admin).
7. Use the configure command to enter the global configuration mode.
8. Configure the in-band NM service VLAN.
a. Use the add-vlan command to configure the in-band NM service VLAN.
b. Use the vlan command to configure the VLAN uplink port.
9. Configure the in-band NM IP address and route.
a. Use the ip subnet command to configure the in-band NM IP address.
b. Use the ip route command to configure the in-band NM route.
10. Configure the broadband service VLAN.
a. Use the add-vlan command to configure the broadband service VLAN.
b. Use the vlan command to configure the VLAN uplink port and service port.
11. Use the adsl-profile command to configure the line profile.
12. Use the adsl-alarm-profile command to configure the alarm profile.
13. Configure the service port properties.
a. Use the pvid command to configure the port PVID.
b. Use the atm pvc command to configure the port PVC.
c. Use the adsl profile command to apply the line profile to the port.
2-20
d. Use the adsl alarm-profile command to apply the alarm profile to the port.
e. Use the adsl trans-mode command to configure the line transmission mode.
– End of Steps –
Result
The 9806H ADSL data service is configured successfully.
Example
The 9806H device is connected to ONU 1 under port 2 of slot 3. Table 2-7 shows the
9806H ADSL data service configuration data.
Item Data
2-21
ZXAN(config)#interface epon-onu_0/3/2:1
ZXAN(config-if)#switchport mode trunk
ZXAN(config-if)#switchport vlan 100 tag
ZXAN(config-if)#exit
2-22
AturConfMinDownshiftTime(0..16383):[0]
AturChanConfFastMaxTxRate(0..10240kbps):[512]
AturChanConfFastMinTxRate(0..512kbps):[32]
AturChanConfInterleaveMaxTxRate(0..10240kbps):[512]
AturChanConfInterleaveMinTxRate(0..512kbps):[32]
AturChanConfMaxInterleaveDelay(0..255ms):[16]
AtucDMTConfFreqBinsOperType(1-open,2-cancel):[2]
AturDMTConfFreqBinsOperType(1-open,2-cancel):[2]
LineDMTConfEOC(1-byte ,2-streaming ):[1]
LineDMTConfTrellis(1-on,2-off):[1]
AtucConfMaxBitsPerBin(0..15):[15]
AtucConfTxStartBin(6..511):[32]
AtucConfTxEndBin(32..511):[511]
AtucConfRxStartBin(6..63):[6]
AtucConfRxEndBin(6..63):[31]
AtucConfUseCustomBins(1-on,2-off):[2]
AtucConfDnBitSwap(1-on,2-off):[2]
AtucConfUpBitSwap(1-on,2-off):[2]
AtucConfREADSL2Enable(1-on,2-off):[2]
AtucConfPsdMaskType(1-DMT_PSD_MSK,2-ADSL2_PSD_MSK,3-ADSL2_READSL_WIDE_PSD_MSK,4-
ADSL2_READSL_NARROW_PSD_MSK):[3]
AtucConfPMMode(1-DISABLE,2-L2_ENABLE,3-L3_ENABLE,4-L3_ENABLE | L2_ENABLE):[1]
AtucConfPML0Time(0..255s):[240]
AtucConfPML2Time(0..255s):[120]
AtucConfPML2ATPR(0..31db):[3]
AtucConfPML2Rate(512..1024kbps):[512]
Press M or m key to modify, or the other key to complete?[C]
9806(config)# interface range adsl 2/1-24
9806(cfg-if-range-adsl)# pvid 100 pvc 1
9806(cfg-if-range-adsl)# adsl profile zte2m.prf
9806(cfg-if-range-adsl)# atm pvc 1 vpi 8 vci 81
9806(cfg-if-range-adsl)# end
9806# save
Prerequisites
Before this operation, make sure that:
2-23
Context
To manage the ONU remotely, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pon-onu-mng command to enter the ONU remote management mode.
3. Use the active pon-if command to enable the primary or secondary uplink EPON port
of the ONU.
4. Use the alarm command to enable or disable the ONU alarm reporting function. The
ZXA10 C220 supports enabling or disabling the alarm function on the ONU, user port,
and uplink EPON port.
a. Use the alarm enable/disable command to enable or disable the global alarm
function.
b. Use the alarm onu command to enable or disable the alarm function at the ONU
level, for example, the ONU temperature alarm and ONU power supply alarm.
c. Use the alarm interface command to enable or disable the alarm function on the
ONU user port, including the Ethernet port, VoIP port, and E1 port.
d. Use the alarm pon-if command to enable or disable the alarm function on the
uplink EPON port of the ONU, including the optical output power alarm and optical
input power alarm.
5. Use the alarm-threshold command to set the alarm report threshold and clearance
threshold on the ONU or uplink EPON port.
6. Use the auto-config command to enable or disable ONU configuration auto-dispatch
by the OLT. If this function is enabled, when the ONU gets online or is restarted after
power-off, the OLT automatically delivers the configuration, covering the ONU local
configuration data.
7. Use the auto-config voip command to enable or disable ONU VoIP service
auto-dispatch by the OLT.
8. Use the classification command to configure the upstream classification rule and
mapping control rule on the ONU Ethernet port.
a. Use the classification rule-profile command to add the mapping rule between the
user port queue and the 802.1p priority.
2-24
to the classification profile, map service stream to the specified queue with the
corresponding 802.1p priority.
9. Use the mac command to configure the MAC address information on the user port. Set
the maximum MAC addresses supported by the port. Add or delete three types of MAC
address information: filtered the MAC address/VLAN, bound MAC address/VLAN, and
static MAC address/VLAN.
a. Use the mac aging-time command to set the aging time of the ONU MAC address.
b. Use the mac add command to add the user port MAC address information,
including the filtered the MAC address/VLAN, bound MAC address/VLAN, and
static MAC address/VLAN.
c. Use the mac delete command to delete the user port MAC address information,
including the filtered the MAC address/VLAN, bound MAC address/VLAN, and
static MAC address/VLAN.
d. Use the mac clear command to clear all the user port MAC address information,
including the filtered the MAC address/VLAN, bound MAC address/VLAN, and
static MAC address/VLAN.
e. Use the mac limit-num command to set the maximum MAC addresses that the
user port can learn.
10. Use the dba command to set the DBA queue parameter of the ONU.
a. Use the dba queue-set command to set the threshold of Queue Set in the Report
frame sent by the ONU.
b. Use the dba queue-set active command to activate the DBA queue parameter of
the ONU.
11. Use the holdover command to set the ONU state holding function. This function
protects the ONU from offline. To enable the state holding function, set the state
holding time.
12. Use the interface command to set the ONU user port properties.
a. Use the interface eth eth_slot/portId auto-neg command to set the auto-negotiation
function on the ONU Ethernet port.
Note:
b. Use the interface eth eth_slot/portId flow-control command to set traffic control on
the ONU Ethernet port.
c. Use the interface eth eth_slot/portId mode command to configure the ONU Ethernet
port mode.
d. Use the interface eth eth_slot/portId phy-state command to enable or disable the
Ethernet port.
2-25
e. Use the interface eth eth_slot/portId policing command to set the upstream and
downstream traffic control parameters on the ONU Ethernet port, including CIR,
CBS, and EBS.
f. Use the interface eth eth_slot/portId policing-profile command to set the bandwidth
profile on the ONU Ethernet port.
Note:
Before carrying out this command, you can create a bandwidth profile on the ONU user port
by using the following commands:
ZXAN(config)#epon
ZXAN(config-epon)#onu-uni-profile profile-name create zte
ZXAN(config-epon)#onu-uni-profile profile-set
zte downstream cir 2000 cbs 1522 ebs 1522
ZXAN(config-epon)#onu-uni-profile
profile-set zte upstream cir 2000
g. Use the interface voip command to enable or disable the ONU POTS port.
h. Use the interface e1 command to enable or disable the ONU E1 port.
13. Use the interface-loopdetect command to set the loopback detection function on the
ONU port.
14. Use the isolation command to enable or disable ONU port isolation.
15. Use the llid-queue command to set the binding relations between the LLIDs and
queues on the ONU when multiple LLIDs exist.
16. Use the mng-snmp command to set the ONU SNMP parameters, such as the SNMP
version, trap host IP address, read community name, and write community name.
17. Use the onu-queue command to use the ONU queue scheduling profile.
Note:
Before carrying out this command, you can create an ONU queue scheduling profile by using the
following commands:
ZXAN(config)#epon
ZXAN(config-epon)#onu-queue-profile zte queue1 64 0 20 25 4
18. Use the pon-buffer command to set the upstream and downstream buffer capacity of
the ONU.
2-26
Note:
The total upstream and downstream buffer capacity of each SFU cannot be less than 256 KB.
19. Use the pon-downstream-shaping command to set the traffic shaping parameter on the
ONU user port.
20. Use the reboot command to restart the ONU.
21. Use the reset-card command to restart the ONU card.
22. Use the transceiver command to set the threshold detection function of the ONU optical
module performance.
a. Use the transceiver enable command to enable the detection function.
b. Use the transceiver disable command to disable the detection function.
c. Use the transceiver alarm command to set the threshold detection alarm of the
ONU optical module performance.
23. Use the save command to save the configuration data of the ONU.
– End of Steps –
Result
ONU remote management is complete.
Example
Limit the downstream rate on Ethernet port 1 of the ONU F820 (epon-onu_0/5/4:1) to 3
Mbps.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#pon-onu-mng epon-onu_0/5/4:1
ZXAN(epon-onu-mng)#interface eth eth_0/1 flow-control enable
ZXAN(epon-onu-mng)#interface eth eth_0/1 policing downstream enable cir
3000 cbs 10000 ebs 1522
Prerequisites
Before this operation, make sure that:
2-27
Context
To configure the OLT port, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the epon command to enter the EPON configuration mode.
3. Use the onu-authentication-mode command to configure the ONU authentication
mode. All the ONUs on the same EPON service card must use the same
authentication mode.
l Use the onu-authentication-mode register command to set the ONU authentication
mode to hardware authentication.
l Use the onu-authentication-mode service command to set the ONU authentication
mode to software authentication. The software authentication includes five
modes: LOID, SN, MAC, Hybrid, and SN+MAC.
4. Use the encrypt algorithm command to configure the OLT encryption algorithm. The
encryption algorithm includes AES and Triple-churning.
5. Use the pon command to enter the PON configuration mode.
6. Use the ip-pool command to configure the OLT IP address pool.
7. Use the ip-pool-bind command to select the IP address pool name on the OLT port.
This address pool is used to configure the ONU in-band IP address.
8. Use the interface command to enter the OLT interface configuration mode.
9. Use the alarm command to configure the alarm function on the OLT port.
10. Use the als command to set the auto-control of the laser on the OLT port. After the
auto-control is enabled, the system turns off the laser when there is no ONU online on
the OLT port. That provides low power cost and safety.
11. Use the linktrap command to configure the alarm report mode when a link break occurs
on the OLT port.
12. Use the maxrtt command to set the maximum ONU distance.
Note:
13. Use the multi-llid command to set multi-LLID function and the maximum LLID number.
This command is applicable for the ONU that support multiple LLIDs.
2-28
14. Use the dba-priority command to set the rolling rates for different DBA priorities. To
allocate bandwidth to the services with higher priorities first, set shorter rolling period
and higher authority frequency for these priorities.
15. Use the fec command to enable or disable the FEC function on the PON port.
16. Use the high-priority-frame command to set the downstream frame with the specified
priority to high-priority frame.
17. Use the priority-queue-map command to set mapping relations between the priorities
of the upstream/downstream frame on the OLT port and the queues.
a. Use the priority-queue-map downstream command to set mapping relations
between the priorities of the downstream frame on the OLT port and the queues.
b. Use the priority-queue-map upstream command to set mapping relations between
the priorities of the upstream frame on the OLT port and the queues.
18. Use the performance start command to start the performance statistic function on the
OLT port.
19. Use the loopback phy system command to set OLT port loopback.
20. Use the loopback-detection command to enable or disable loopback detection on the
OLT port.
21. Use the rx-hec command to set whether the HEC receiving mode at the OLT side is
compatible with the HEC mode defined in the 802.3AH standard draft. This affects the
registration of the interworking ONU and uninterworking ONU on the OLT.
22. Use the reset command to reset the OLT port.
23. Use the reset counter command to reset the performance statistic counter of the OLT
port.
24. Use the security packet-limit command to limit the forwarding rate of the broadcast
packets, multicast packets, and unknown packets on the OLT port. The unit is pps.
25. Use the shutdown command to shutdown the OLT port.
26. Use the speed command to configure the bandwidth capability on the OLT port. That
is, the total bandwidth of all the ONUs on the OLT port cannot exceed the bandwidth
configured by this command.
– End of Steps –
Result
The OLT port is configured successfully.
Example
Set the EPON card in slot 3 to SN authentication mode, enabling the tribple-churning
encryption algorithm.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
2-29
ZXAN(config)#epon
ZXAN(config-epon)#onu-authentication-mode service 0/3 sn
ZXAN(config-epon)#encrypt algorithm 0/3 triple-churning
Note:
2.2.1 Overview
Service Description
The principle of the 10G EPON service is similar with that of the EPON service. 10G EPON
can provide 10 Gbps bandwidth for subscribers.
Service Specifications
The ZXA10 C220 provides the 10G EPON access through the EPXS service card. Each
card provides one 10G EPON ports. A 10G EPON port can reach up to 1.25 Gbps
upstream rate and 10.3125 Gbps downstream rate. A single port supports up to 128
ONUs and a single shelf supports up to 1280 ONUs.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The interface VLAN of the upper-layer device is consistent with the VLAN configured
on the uplink port.
l The 10G EPON service card status is proper.
2-30
Context
The EPON data service can be applied in the following scenarios: FTTH, FTTB, and FTTC.
The basic configuration steps are the same for different scenarios. This instance takes the
Internet service in FTTB application as an example.
Networking Diagram
Figure 2-3 shows the networking diagram of the 10G EPON data service.
The user computer is connected to the FE port of the ONU, on which the user data frames
are tagged with the user-side VLAN IDs. The user data is dispatched to the corresponding
service channels according to the user-side VLAN IDs. ZXA10 C220 transfers the
user-side VLAN to the uplink VLAN, and sends data out through the uplink port.
Configuration Data
Table 2-8 lists the configuration data for the 10G EPON data service.
2-31
Requirements on the uplink l Ethernet Switch: configure For detailed ES and BRAS
device the same VLAN as the device configuration, refer to the
ZXA10 C220 service VLAN relevant operation manual.
(transparently transmits the
ZXA10 C220 services).
l BRAS: configure
parameters according
practical application.
Configuration Flow
Figure 2-4 shows the configuration flow of the 10G EPON data service.
To configure the 10G EPON data service, perform the following steps:
2-32
Steps
1. Create the service VLAN (optional).
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 100
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
ZXAN(config)#
The speed of the default ZTE-F822 ONU type profile is 1 Gbps. The speed can be
configured accordingly.
ZXAN(config)#show onu-type epon ZTE-F822
Onu type name : ZTE-F822
Pon type : epon
Description : 24FE
Protect type: none
Speed: 1g
2-33
Create an ONU type profile ZTE-F822A, which supports 24 FE ports and 24 POTS
ports. The rate is 10 Gbps asymmetrically, that is, the ONU upstream rate is 1 Gbps
and downstream rate is 10 Gbps. Disable the auto-dispatch function of ZTE-F822A.
ZXAN(config)#pon
ZXAN(config-pon)#onu-type ZTE-F822A epon description 24FE,
24POTS speed 10g-asymmetric
ZXAN(config-pon)#onu-type-if ZTE-F822A eth_0/1-24
ZXAN(config-pon)#onu-type-if ZTE-F822A pots_0/1-24
ZXAN(config-pon)#exit
ZXAN(config)#epon
ZXAN(config-epon)#auto-dispatch-set ZTE-F822A disable
ZXAN(config-epon)#show onu-type epon ZTE-F822A
Onu type name : ZTE-F822A
Pon type : epon
Description : 24FE,24POTS
Protect type: none
Speed: 10g-asymmetric
ZXAN(config-epon)#exit
5. Enter the EPON-OLT interface mode. Authenticate the ONU through the MAC
address.
ZXAN(config)#interface epon-olt_0/5/1
ZXAN(config-if)#onu 1 type ZTE-F822A mac 001e.7391.5f36
ZXAN(config-if)#exit
6. Enter the EPON-ONU interface mode. Enable the interface authentication protocol.
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#admin enable
Note:
You can use the show onu detail-info command to display the detailed information of the current
ONU.
9. Enter the ONU remote management mode. Configure the ONU Ethernet port VLAN.
ZXAN(config)#pon-onu-mng epon-onu_0/5/1:1
ZXAN(epon-onu-mng)#vlan port eth_0/1 mode tag vlan 100 priority 0
2-34
ZXAN(epon-onu-mng)#exit
Result
The 10G EPON data service is configured successfully.
2-35
2-36
3.1 Overview
Service Description
GPON access is a flexible access technology that provides super bandwidth access in
both broadband and narrowband service environment. It supports multiple rate modes
and uses a single optical fiber to provide user with voice, data, and video services.
Service Specifications
The ZXA10 C220 provides GPON access through the GPFAB/GPFAC/GPFAE card.
Each GPFAB/GPFAC/GPFAE card provides four GPON interfaces, supports the splitting
ratio of 1:128 at the maximum. A single shelf supports up to 5120 ONUs.
3-1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The VLAN of the upper-layer device interface corresponds to the VLAN configured on
the uplink interface.
l The GPON service card status is proper.
Context
The GPON data service can be applied in the following scenarios: FTTH, FTTB, and FTTC.
The basic configuration steps are the same for different scenarios. This instance takes the
Internet service in FTTH application as an example.
Networking Diagram
Figure 3-1 shows the networking diagram of the GPON data service.
In the networking, the user computer is connected to the ONU FE port. The user data
frame is added with the VLAN tag on the ONU FE port. The user data is distributed to
each service channel according to the user-side VLAN. The ZXA10 C220 completes the
mapping from GEM port to Ethernet frame and sends data out through the upstream port.
3-2
Configuration Flow
Figure 3-2 shows the configuration flow of the GPON data service.
Configuration Data
Table 3-1 lists the GPON data service configuration data.
Item Data
Service priority 0
3-3
Item Data
Steps
1. Create the service VLAN (optional).
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 100
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
3-4
-------------------------------------------------------------
gpon-onu_0/10/1:1 ZTEG00000002 unknown
4. Enter the GPON-OLT interface mode and authenticate the ONU by the SN.
ZXAN(config)#interface gpon-olt_0/10/1
ZXAN(config-if)#onu 1 type ZTE-F621 sn ZTEG00000002
ZXAN(config-if)#exit
ZXAN(config)#show gpon onu state gpon-olt_0/10/1
OnuIndex Admin State Omcc State O7 State Phase State
-----------------------------------------------------------------
gpon-onu_0/10/1:1 enable enable operation working
6. Create a T-CONT.
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#tcont 2 name Tcont100M profile T1-100M
Note:
3-5
Result
The GPON data service is configured successfully.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The in-band or out-of-band NM is configured.
Context
When the new ONU type does not exist in the system, perform this procedure.
Users can use the show onu-type gpon command to query the default ONU types on the
ZXA10 C220.
To configure the ONU type profile, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pon command to enter the PON configuration mode.
3. Use the onu-type command to add an ONU type profile.
Note:
In the ZXA10 C220, the ONU type name must be unique in EPON and GPON service.
4. Use the onu-type-if command to configure the user port of the new ONU type.
5. Use the onu-type-attr command to configure attributes of the new ONU type.
– End of Steps –
Result
The ONU type profile is configured successfully.
Example
Create a GPON ONU type ZTE-F820, which supports 24 Ethernet ports.
ZXAN#configure terminal
3-6
Prerequisites
Before this operation, make sure that:
Context
The ZXA10 C220 supports two types of ONU SN authentication mode:
l Learn
When the system discovers an ONU, the ONU is registered to the configuration list
automatically.
l Provision
When the system discovers an ONU, if the ONU is configured, the configuration takes
effect. If the ONU is not configured, it is displayed in the list of unregistered ONU.
When the authentication mode is learn, users do not need to configure the unauthenticated
ONU manually, but the OLT cannot recognize the ONU type. Therefore, it is recommended
to use the default SN authentication mode provison.
3-7
In OLT interface configuration mode, use the auto-learning enable command to enable the
ONU SN auto-learning authentication mode. By default, it is disabled.
To authenticate an ONU, perform the following steps:
Steps
1. Use the show gpon onu uncfg command to query the unauthenticated ONU information.
2. Use the configure terminal command to enter the global configuration mode.
3. Use the interface command to enter the OLT interface configuration mode.
4. Use the onu command to authenticate the ONU.
5. User the show gpon onu state command to query the authenticated ONU information.
Table 3-2 lists the ONU phase states.
Value Description
offline The OLT does not find the ONU. The ONU is offline.
LOS The fiber link between the OLT and ONU is faulty.
– End of Steps –
Result
The ONU authentication is completed.
Example
Query the unauthenticated ONU information on port gpon-olt_0/10/1 and authenticate the
ONU.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#show gpon onu uncfg gpon-olt_0/10/1
OnuIndex Sn State
---------------------------------------------------------------------
gpon-onu_0/10/1:1 ZTEG00000002 unknown
ZXAN(config)#interface gpon-olt_0/10/1
ZXAN(config-if)#onu 1 type ZTE-F621 sn ZTEG00000002
ZXAN(config-if)#exit
ZXAN(config)#show gpon onu state gpon-olt_0/10/1
3-8
Prerequisites
Before this operation, make sure that:
Context
The T-CONT profile describes T-CONT traffic parameters. The ZXA10 C220 supports 512
T-CONT profiles.
There are five upstream bandwidth types:
l Fixed
The bandwidth that the OLT assigns to the T-CONT after the T-CONT is enabled
whether it has traffic or not
l Assured
The bandwidth that the OLT must assign to the T-CONT when the T-CONT has a
request for bandwidth
If the requested bandwidth is less than the assured bandwidth, the redundant
bandwidth can be used by other T-CONTs.
l Non-assured
The bandwidth that the OLT does not assign to the T-CONT when the T-CONT has a
request for bandwidth
The non-assured bandwidth is not assigned until all fixed and assured bandwidth are
assigned.
l Best Effort
l Maximum
3-9
The bandwidth which is the summary of the fixed, assured, non-assured, and best
effort bandwidth
No matter what the actual upstream traffic of T-CONT is, the assigned bandwidth
cannot exceed the maximum bandwidth.
There are five T-CONT bandwidth types:
l Fixed
This bandwidth type has certain bandwidth and time slot. Fixed bandwidth is suitable
for services which are sensitive to time slot, jittering, and services which have fixed
traffic rate, such as voice service.
l Assured
Assured bandwidth type has certain bandwidth but its time slot is uncertain. Assured
bandwidth is suitable for services which are not sensitive to time slots, jittering and
services for which the traffic rate is limited, such as VoD service.
l Assured and Non-assured
It assures the minimum bandwidth and shares redundant bandwidth dynamically.
Assured and non-assured bandwidth is suitable for services which require quality of
service and have burst of traffic, such as signed downloading service.
l Best Effort
This is the best effort bandwidth. After the fixed bandwidth, assured bandwidth, adn
non-assured bandwidth are assigned, the rest bandwidth is used through competition.
Best effort bandwidth is suitable for services which is not sensitive to time slot or
jittering, such as web browsing service.
l All
This bandwidth type is a combination of other types and is suitable for most services.
Table 3-3 lists the relationship between upstream bandwidth and T-CONT bandwidth.
Fixed RF RF 0 0 0 RF
Assured RA 0 RA RA 0 RA
Steps
1. Use the configure terminal command to enter the global configuration mode.
3-10
Result
The T-CONT bandwidth profile is configured successfully.
Example
Configure the T-CONT bandwidth profile T1–100M. The fixed bandwidth is 100 Mbit/s. On
the gpon-onu_0/10/1:1 ONU interface, create T-CONT 1 and apply the bandwidth profile
T1–100M.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#gpon
ZXAN(config-gpon)#profile tcont T1-100M type 1 fixed 100000
ZXAN(config-gpon)#show gpon profile tcont T1-100M
Name :T1-100M
Type FBW(kbps) ABW(kbps) MBW(kbps)
1 100000 0 0
ZXAN(config-gpon)#exit
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#tcont 1 name Tcont100M profile T1-100M
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The GPON service card status is proper.
l The GPON service is configured.
3-11
Context
The ZXA10 C220 does not support the traffic limit to GEM Port directly. By default, one
GEM port corresponds to one V-port. Therefore, limiting the V-port rate implements the
traffic control on the GEM port.
The ZXA10 C220 supports 512 traffic profiles.
To configure the traffic profile, perform the following steps:
Steps
1. Use the configure terminal command to enter global configuration mode.
2. Use the traffic-profile command to configure the traffic profile.
3. Use the interface command to enter the ONU interface configuration mode.
4. Use the traffic-profile command to configure the upstream and downstream rates.
– End of Steps –
Result
The traffic profile is configured successfully.
Example
Configure a traffic profile. The upstream name is UP-10M. The downstream name is
DOWN-10M. The assured and peak rates are 10 Mbit/s. On the gpon-onu_0/10/1:1 ONU
interface, configure the upstream/downstream limit of the VPORT 1.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#traffic-profile DOWN-10M ip cir 10000 cbs 100 pir 10000 pbs 100
ZXAN(config)#traffic-profile UP-10M ip cir 10000 cbs 100 pir 10000 pbs 100
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#traffic-profile DOWN-10M vport 1 direction egress
//Configure the downstream limit of VPORT 1
ZXAN(config-if)#traffic-profile UP-10M vport 1 direction ingress
//Configure the upstream limit of VPORT 1
Prerequisites
Before this operation, make sure that:
3-12
Context
The ZXA10 C220 supports service connection based on the three types of mapping.
l 802.1p
The upstream frames arriving on the UNI of an ONU are mapped to a GEM port
according to UNI and 802.1p priority. Through the traffic shaping or priority queue, it
is sent to the relevant T-CONT, and then to the OLT.
l Bridge
The upstream frames arriving on the UNI of an ONU are mapped to a GEM port
according to VLAN ID. Meanwhile, the VLAN tag can be processed according VLAN
filter rules. Through the traffic shaping or priority queue, it is sent to the relevant
T-CONT, and then to the OLT.
l 802.1p + bridge
The upstream frames arriving on the UNI of an ONU are mapped to a GEM port
according to VLAN ID and 802.1p priority. Meanwhile, the VLAN tag can be processed
according VLAN filter rules. Through the traffic shaping or priority queue, it is sent to
the relevant T-CONT, and then to the OLT.
To configure a service connection based on 80.21p mapping, you can only use the
traditional method (flow and gemport commands).
To configure a service connection based on other two mapping modes, you can use either
the optimized method (service command) or the traditional method.
To configure the service connection between Ethernet frames and GEM port, perform the
following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pon-onu-mng command to enter the ONU remote management mode.
3-13
Note:
You can configure four types of service connection by using the service command.
When VLAN ID and CoS priority is no specified, the type of a service connection is transpar-
ent transmission, that is, services are mapped to a GEM port.
One ONU supports only one type of service connection at the same time. The connection
that is configured first takes effect.
After you use the service command to configure a service connection, the commands for
traditional configuration, which includes service connection, flow VLAN parameters, and UNI
VLAN parameters, are invalid.
l Use the to flow and gemport commands configure the service connection
(traditional method).
l Configure the bridge service connection.
a. Use the flow command to configure the service flow. The flow type is switching
unit.
Note:
Flow 1 is the default flow 1 on the ZXA10 C220. By default, flow 1 is bound to the bridge
switch_0/1.
Note:
By default, all UNI interfaces are bound to the bridge switch_0/1. You can use the no
switchport-bind command to delete the binding.
– End of Steps –
3-14
Result
The service connection is configured successfully.
Example
On the gpon-onu_0/10/1:1 interface, configure the connection between the Ethernet frame
and the GEM Port: the service connection type is 802.1p + bridge, GEM Port ID is 1, and
the priority is 0.
l Use the service command to configure the service connection.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#pon-onu-mng gpon-onu_0/10/1:1
ZXAN(gpon-onu-mng)#service dataservice type internet gemport 1 cos 0
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The GPON service card status is proper.
l The ONU is authenticated.
l The T-CONT and GEM Port are configured.
Context
After you configure a service connection with flow and gemport commands, you need to
configure the flow VLAN parameters.
To configure the flow VLAN parameters, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pon-onu-mng command to enter ONU remote management mode.
3. Use the flow command to configure VLAN ID and priority of the flow.
3-15
4. Use the flow mode command to configure VLAN filter mode of the flow.
– End of Steps –
Example
On the gpon-onu_0/10/1:1 interface, configure VLAN parameters of the default flow 1.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#pon-onu-mng gpon-onu_0/10/1:1
ZXAN(gpon-onu-mng)#flow 1 vid 100
ZXAN(gpon-onu-mng)#flow mode 1 tag-filter vid-filter untag-filter discard
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The GPON service card status is proper.
l The ONU is authenticated.
l The T-CONT and GEM Port are configured.
Context
ZXA10 C220 supports the following VLAN modes on UNI.
l Transparent transmission: transparent transmit tagged frames and untagged frames.
l Tag: add PVID to untagged frames, and discard tagged frames.
l Trunk: permit tagged frames that match the port VID, and discard other tagged frames
and all untagged frames.
l Hybrid: add PVID to untagged frames, permit tagged frames that match the port VID,
and discard other tagged frames.
l VLAN translate: in trunk or hybrid mode
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pon-onu-mng command to enter ONU remote management mode.
3-16
a. Use the vlan port mode command to configure UNI VLAN mode.
b. Use the vlan port vlan command to configure UNI VLAN ID.
c. Use the vlan port vlan translate command to configure UNI VLAN translation
entry.
l Use the traditional method to configure UNI VLAN parameters.
a. Use the vlan ethuni command to configure UNI VLAN tag process mode.
b. Use the vlan-filter-mode command to configure UNI VLAN filter mode.
c. Use the vlan-filter ethuni command to configure UNI VLAN filter entry.
– End of Steps –
Example
On the gpon-onu_0/10/1:1 interface, configure VLAN parameters of eth_0/1: add VLAN
tag 101 and priority 1 to untagged frames.
l Use the optimized method to configure UNI VLAN parameters.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#pon-onu-mng gpon-onu_0/10/1:1
ZXAN(gpon-onu-mng)#vlan port eth_0/1 mode tag vlan 101 priority 1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The GPON service card status is proper.
l The ONU is authenticated.
l The T-CONT and GEM Port are configured.
3-17
Context
The ZXA10 C220 manages configuration on GPON ONUs in the following ways:
l In-band configuration
Create an ONU in-band NM channel, and then log in to the ONU to implement
configuration.
In this mode, data is configured and saved on the ONU. You can access the ONU
through its in-band NM IP address from the ZXA10 C220 uplink port. The ONU can
be configured and upgraded through this IP address.
l OMCI channel configuration
OMCI is a transmission channel defined in GPON standard. OMCI packets are
transmitted between the OLT and the ONU through the GEM Port. OMCI channel is
created after the ONU is successfully registered. The OLT controls the ONU through
OMCI channel.
OMCI supports offline configuration on the ONU. The ONU does not need to save
configurations locally.
Note:
In practical applications, there is no need to configure the in-band NM IP addresses for all the ONUs.
The configuration is required for ONUs that only supports local VoIP services configuration or upgrade,
such as ZTE-F820 and ZTE-F822.
It is recommended to configure the ONU in-band NM IP address in the same management VLAN and
network segment as the ZXA10 C220, so that the NMS server can connect the ONU when it connects
the OLT.
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the vlan command to create the ONU in-band NM VLAN.
3. Use the pon-onu-mng command to enter the ONU remote management mode.
4. Configure the service connection.
l Use the service command to configure the service connection.
l User the flow and gemport commands to configure the service connection.
a. Use the flow command to configure the service flow, the type of which is
switching unit.
b. Use the gemport gemportid flow flowid command to configure the service
connection, the type of which is bridge.
5. Use the mgmt-ip command to set the ONU in-band NM IP address.
3-18
6. Use the interface command to enter the ONU interface configuration mode.
7. Use the switchport mode command to change the PON-ONU interface mode.
8. Use the switchport vlan command to add the PON-ONU interface to the NM VLAN in
tagged mode.
9. Use the interface command to enter the OLT uplink port configuration mode.
10. Use the switchport mode command to change the OLT uplink port mode.
11. Use the switchport vlan command to add the OLT uplink port to the NM VLAN in tagged
mode.
– End of Steps –
Result
The ONU in-band IP address is configured successfully.
Example
On the gpon-onu_0/10/1:1 interface, set the in-band NM VLAN of the F822 to 2600, and
the in-band IP address to 198.2.128.5/24.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 2600
ZXAN(config-vlan)#exit
ZXAN(config)#pon-onu-mng gpon-onu_0/10/1:1
ZXAN(gpon-onu-mng)#gemport 1 flow 1
ZXAN(gpon-onu-mng)#mgmt-ip 192.2.128.5 255.255.255.0 vlan 2600 priority 0
route 0.0.0.0 0.0.0.0 192.2.128.4
ZXAN(gpon-onu-mng)#exit
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#switchport mode hybrid vport 1
ZXAN(config-if)#switchport vlan 2600 tag vport 1
ZXAN(config-if)#exit
ZXAN(config)#interface xgei_0/2/1
ZXAN(config-if)#switchport mode trunk
ZXAN(config-if)#switchport vlan 2600 tag
Follow-Up Action
Carry out the ping command on the OLT to check whether the ONU in-band IP address is
successfully configured.
ZXAN#ping 198.2.128.5
sending 5,100-byte ICMP echos to 10.1.1.2,timeout is 2 seconds.
!!!!!
Success rate is 100 percent(5/5),round-trip min/avg/max= 0/8/40 ms.
//The ONU in-band IP address is successfully configured.
3-19
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The GPON service card status is proper.
Context
To configure the OLT port, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the interface command to enter the OLT interface configuration mode.
3. Use the auto-learning command to enable the ONU SN auto-learning authentication
mode. By default, it is disabled.
4. Use the clear command to clear the configuration data on the OLT port.
5. Use the discover-period command to configure the ONU testing period, including the
new registered ONU and the offline ONU.
6. Use the fec command to enable/disable the PON FEC function.
7. Use the linktrap command to configure the alarm reporting mode when there is a link
break on the OLT port.
8. Use the range-mode command to configure the ONU distance that the OLT supports.
The maximum range between the ONUs of the same PON port cannot exceed 20 km.
9. Use the reset command to reset the OLT port.
10. Use the shutdown command to shut down the OLT port.
– End of Steps –
Result
The OLT port is configured successfully.
Example
Configure the ONU distance of the gpon-olt_0/10/1 port to the range from 20 km to 40 km.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#interface gpon-olt_0/10/1
3-20
3-21
3-22
4.1 Overview
Service Description
With the appearance of the multimedia video and data warehouse in the IP network, the
multicast application is becoming a new service requirement. The multicast service is
applied in the areas of stream media, remote education, video conference, IPTV, network
game, data replication, and other point-to-multipoint data transmission applications.
Service Specification
The ZXA10 C220 supports IGMP protocols and controllable multicast service.
The multicast service of ZXA10 C220 supports the following:
l IGMP V1/V2/V3
l IGMP snooping, IGMP proxy, and IGMP router
l 1024 multicast groups
l Channel preview: configuration of preview times, duration, and interval
l Audience rating statistics
l Controllable multicast: including deny, permit, and preview.
l IPTV package management, 1024 packages and 1024 channels at maximum
4-1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The multicast source exits in the network.
l The EPON service card status is proper.
Networking Diagram
Figure 4-1 shows the networking diagram of the IGMP snooping multicast service.
Configuration Data
Table 4-1 lists the configuration data for the IGMP snooping multicast service.
Item Data
4-2
Item Data
Configuration Flow
Figure 4-2 shows the configuration flow of the IGMP snooping multicast service.
To configure the IGMP snooping multicast service, perform the following steps:
Steps
1. Create the service VLAN.
ZXAN#configure terminal
4-3
Note:
You can use the show vlan summary command to display the created VLAN information.
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
Create a new ZTE-F822 type profile ZTE-F822A, including 24 FE ports and 24 POTS
ports. The rate is 10 Gbps asymmetrically, that is, the ONU upstream rate is 1 Gbps
and downstream rate is 10 Gbps. Disable the auto-dispatch of ZTE-F822A.
ZXAN(config)#pon
4-4
5. Enter the EPON-OLT interface mode. Authenticate the ONU through the MAC
address.
ZXAN(config)#interface epon-olt_0/5/1
ZXAN(config-if)#onu 1 type ZTE-F822A mac 0019.c600.0011
ZXAN(config-if)#exit
6. Enter the EPON-ONU interface mode. Enable the interface authentication protocol.
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#admin enable
Note:
You can use the show onu detail-info command to display the detailed information of the current
ONU.
4-5
When the IP addresses of the multicast groups are continuous, they can be
configured in batch.
ZXAN(config)#igmp mvlan 500 group 224.1.1.1 to 224.1.1.3
Note:
If the OLT uses the IGMP snooping protocol, the ONU can use the IGMP snooping protocol
and controllable multicast protocol. If the OLT uses the IGMP proxy protocol, the ONU can
use any protocols. This instance uses the IGMP snooping protocol.
4-6
e. Configure the maximum multicast groups supported by the ONU user port.
ZXAN(epon-onu-mng)#multicast group-max-number eth_0/1 255
ZXAN(epon-onu-mng)#end
Result
The IGMP snooping multicast service is configured successfully. The subscribers can
watch the programs from 224.1.1.1 to 224.1.1.3.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The multicast source exits in the network.
l The GPON service card status is proper.
Networking Diagram
Figure 4-3 shows the networking diagram of the IGMP snooping multicast service.
4-7
Configuration Data
Table 4-2 lists the configuration data for the IGMP snooping multicast service.
Item Data
IPTV priority 5
Bandwidth: 50 Mbit/s
4-8
Item Data
Configuration Flow
Figure 4-4 shows the configuration flow of the IGMP snooping multicast service.
To configure the IGMP snooping multicast service, perform the following steps:
Steps
1. Create the service VLAN.
4-9
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 500
ZXAN(config-vlan)#exit
ZXAN(config)#vlan 10
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
4. Enter the GPON-OLT interface mode and authenticate the ONU by the SN.
ZXAN(config)#interface gpon-olt_0/10/1
ZXAN(config-if)#onu 1 type ZTE-F621 sn ZTEG70002926
ZXAN(config-if)#exit
ZXAN(config)#show gpon onu state gpon-olt_0/10/1
OnuIndex Admin State Omcc State O7 State Phase State
---------------------------------------------------------------
gpon-onu_0/10/1:1 enable enable operation working
6. Create a T-CONT.
ZXAN(config)#interface gpon-onu_0/10/1:1
4-10
Note:
4-11
ZXAN(config-if)#exit
When the IP addresses of the multicast groups are continuous, they can be
configured in batch.
ZXAN(config)#igmp mvlan 500 group 224.1.1.1 to 224.1.1.3
Note:
Only the uplink ports that are added to MVLAN 500 can be set to the source port.
b. Configure the maximum multicast groups that the ONU user port supports.
ZXAN(gpon-onu-mng)#igmp eth_0/1 max-groups 255
d. Configure the IGMP bandwidth control function of the ONU user port. By default,
it is disabled.
Bandwidth control is used to reject the user join request when the multicast group
bandwidth exceeds the remaining bandwidth of the current physical channel.
ZXAN(gpon-onu-mng)#igmp eth_0/1 bandwidth-enforce enable
4-12
Note:
Before applying the ONU IGMP profile, you need to create the ONU IGMP profile with the
following commands:
ZXAN(config)#gpon
ZXAN(config-gpon)#onu profile igmp zte fast-leave enable version v3
ZXAN(config-gpon)#exit
Result
The IGMP snooping multicast service is configured successfully. The subscribers can
watch the programs from 224.1.1.1 to 224.1.1.3.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The multicast source exits in the network.
l The xPON service card status is proper.
Context
To configure the IGMP proxy multicast service, perform the following steps:
Steps
Most of the steps are the same as those of IGMP snooping service configuration. The
following describes only the different steps.
4-13
The IP address of the proxy host is the source IP address of the report/leave packet
sent in proxy mode. By default, the IP address is 0.0.0.0. It can be configured
according to actual situations.
ZXAN(config)#igmp mvlan 500 host-ip 10.1.1.1
3. Configure the IGMP interface parameters, such as fast leaving and proxy IP address.
The proxy IP address is the source IP address of the downstream query packet in
proxy mode. By default, the IP address is 192.168.2.14.
In this instance, other IGMP port parameters use the default values.
ZXAN(config)#interface epon-onu_0/6/4:1
ZXAN(config-if)#igmp proxy-ip 192.168.2.14 vport 1
Result
The IGMP proxy multicast service is configured successfully.
Prerequisites
Before this operation, make sure that:
Context
To configure the MVLAN parameters, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
4-14
Note:
In IGMP snooping mode, the host, pre-join, active report, and static join functions are invalid.
5. Use the igmp mvlan group command to configure the MVLAN group.
6. Use the igmp mvlan group bandwidth command to configure the multicast bandwidth.
The multicast bandwidth ranges from 100 to 65535. The default bandwidth is 2048.
The unit is Kbps.
7. Use the igmp mvlan group prejoin command to configure the multicast pre-join
function.
Note:
By default, this function is disabled. After it is enabled, the OLT sends the report packet to the
server periodically. The IGMP report is not sent to the pre-joined multicast group.
8. Use the igmp mvlan group static-port command to configure the MVLAN static
receiving port.
9. Use the igmp mvlan group source-address command to configure the IP address of the
multicast client. By default, it is 0.0.0.0.
10. Use the igmp mvlan group-filter command to configure MVLAN group management.
Note:
l When MVLAN group management is enabled, the IGMP join packets must check whether
the group address is configured. The group configured with an address is called the
management group.
l When MVLAN group management is disabled, the IGMP join packets do not check whether
the group address is configured. The learned group is called the dynamic group.
l When span-VLAN is enabled, MVLAN group-filter must be enabled. By default, it is enabled.
11. Use the igmp mvlan max-group command to configure the MVLAN maximum group
number.
12. Use the igmp mvlan source-port command to configure the MVLAN source port.
13. Use the igmp mvlan receive-port command to configure the MVLAN receiving port.
14. Use the igmp mvlan host-ip command to configure the IP address of the proxy host in
IGMP proxy mode.
15. Use the igmp mvlan host-version command to configure the version number of the
IGMP request packet sent by the uplink port.
16. Use the igmp mvlan priority command to configure the IGMP packet priority.
4-15
Note:
Only in IGMP proxy mode, the IGMP packets sent by the ZXA10 C220 to the network side are
processed according to the IGMP packet priority in the multicast VLAN. In IGMP snooping mode,
the IGMP packets sent by the ZXA10 C220 to the network side are processed according to the
priority of the IGMP service traffic.
17. Use the show igmp mvlan group command to query the MVLAN configuration
information.
– End of Steps –
Result
The MVLAN parameters are configured successfully.
Example
Configure the MVLAN 500. Table 4-3 lists the configuration data.
Item Data
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#igmp mvlan 500
ZXAN(config)#igmp mvlan 500 enable
ZXAN(config)#igmp mvlan 500 work-mode proxy
ZXAN(config)#igmp mvlan 500 group 224.1.1.1 to 224.1.1.10
ZXAN(config)#igmp mvlan 500 group-filter enable
ZXAN(config)#igmp mvlan 500 max-group 16
ZXAN(config)#igmp mvlan 500 source-port gei_0/14/1
ZXAN(config)#igmp mvlan 500 receive-port epon-onu_0/6/4:2
ZXAN(config)#igmp mvlan 500 host-ip 10.63.196.50
ZXAN(config)#show igmp mvlan 500
4-16
Receive Port
----------------------------
epon-onu_0/6/4:2:1
Group
----------------------------
224.1.1.1 - 224.1.1.10
Prerequisites
Before this operation, make sure that:
Context
Table 4-4 lists the IGMP global parameters.
IGMP snooping aging time To set the aging time of the IGMP Range: 30 – 3600 seconds
group members, which takes effect Default: 300 seconds
only in IGMP snooping mode
IGMP proxy general query To set the global query interval in IGMP Range: 60 – 300 seconds
interval proxy mode Default: 125 seconds
4-17
IGMP proxy maximum To set the maximum query response Range: 1 – 25 seconds
query response time time in IGMP proxy mode Default: 10 seconds
The maximum query response time
affects the time that the multicast user
responds to the report packet. The
burst response packet traffic can be
reduced by increasing the maximum
query response time.
IGMP proxy last member To set the global query interval of the Range: 0.1 – 25.5 seconds
query interval last member in IGMP proxy mode Default: 1 second
IGMP proxy last member To set the query counts of the last Range: 2 – 5
query counts member in IGMP proxy mode Default: 2
When the configured query counts
are complete, if there is no response
packet during the maximum query
response time, the subscriber is
considered to leave.
IGMP proxy unsolicited re- To set the interval of sending the Range: 1 – 60 seconds
port interval unsolicited report packet in IGMP Default: 10 seconds
proxy mode
Refer to RFC2236 unsolicit report
interval. In IGMP snooping mode,
the multicast active report function is
ineffective.
Host tracking function To set the host tracking function under l Enable
the user port in fast leaving mode l Disable
Default: disable
4-18
Steps
1. Use the igmp enable command to enable the global IGMP protocol.
2. Use the igmp snooping-aging-time command to set the aging time in IGMP snooping
mode.
3. Use the igmp query-interval command to set the general query interval in IGMP proxy
mode.
4. Use the igmp query-max-resp command to set the maximum query response time in
IGMP proxy mode.
5. Use the igmp last-query-interval command to set the query interval of the last member
in IGMP proxy mode.
6. Use the igmp last-query-count command to set the query counts of the last member in
IGMP proxy mode.
7. Use the igmp unsolicited-report-interval command to set the IGMP unsolicited report
interval.
8. Use the igmp robustness command to set the robustness factor in IGMP proxy mode.
9. Use the igmp log command to enable the log function.
10. Use the igmp host-tracking command to enable the host tracking function.
11. Use the igmp bandwidth-control command to enable the bandwidth control function.
12. Use the igmp span-vlan command to enable the span-VLAN function.
4-19
13. Use the igmp statistics clear command to clear the IGMP packet statistics data.
14. Use the igmp non-match-group command to set the processing mode of the unmatched
multicast group.
15. Use the igmp mcm command to enalbe the multi-copy multicast function.
16. Use the show igmp command to query the global IGMP configuration.
– End of Steps –
Result
The IGMP global parameters are configured successfully.
Example
Configure and query the global IGMP parameters.
4-20
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The xPON service is configured.
Context
Table 4-5 lists the IGMP port parameters.
IGMP proxy maximum query re- To set the maximum query Range: 1 – 25 seconds
sponse interval response time on the ONU Default: 10 seconds
interface in IGMP proxy mode
IGMP proxy last member query To set the query interval of Range: 0.1 - 25.5 seconds
interval the last member on the ONU Default: 1 second
interface in IGMP proxy mode
IGMP proxy last member query To set the query counts of Range: 2 – 5
counts the last member on the ONU Default: 2
interface in IGMP proxy mode
IGMP maximum group nubmer To set the maximum multicast Range: 0 – 4094
group number on the ONU Default: 4094
interface
4-21
IGMP proxy router IP address To set the source IP address of Default: 192.168.2.14
the downstream query packet in
IGMP proxy mode
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the interface command to enter the interface configuration mode.
3. Use the igmp enable command to enable the port IGMP protocol.
4. Use the igmp drop command to discard the IGMP packets.
5. Use the igmp fast-leave command to set the IGMP fast leaving function.
6. Use the igmp query-max-resp command to set the maximum query response time in
IGMP proxy mode.
7. Use the igmp last-query-interval command to set the query interval of the last member
in IGMP proxy mode.
8. Use the igmp last-query-count command to set the query counts of the last member in
IGMP proxy mode.
9. Use the igmp max-groups command to set the maximum IGMP multicast group
number.
10. Use the igmp version command to set the IGMP version.
11. Use the igmp proxy-ip command to set the IP address of the IGMP proxy router.
12. Use the igmp robustness command to set port robustness in IGMP proxy mode.
13. Use the igmp mcm-cvlan command to enable the user VLAN for multi-copy multicast.
14. Use the show igmp interface command to query the IGMP port configuration.
– End of Steps –
Result
The IGMP port parameters are configured successfully.
Example
Configure and query the IGMP port parameters.
ZXAN(config)#interfac epon-onu_0/6/4:2
ZXAN(config-if)#igmp enable
ZXAN(config-if)#igmp fast-leave enable
4-22
ZXAN(config-if)#igmp max-groups 32
ZXAN(config-if)#igmp query-max-resp 150
ZXAN(config-if)#igmp last-query-interval 30
ZXAN(config-if)#igmp last-query-count 3
ZXAN(config-if)#igmp proxy-ip 10.63.196.50
ZXAN(config-if)#show igmp interface epon-onu_0/6/4:2
IGMP interface epon-onu_0/6/4:2 vport 1 parameters:
----------------------------------------------------
IGMP status is enable.
IGMP version is v2.
Fast leave is enable.
Max concurrent group num is 32.
Proxy ip is 10.63.196.50.
Robustness variable is 2.
Query max response time is 150(0.1second).
Last membership query interval is 30(0.1second).
Last membership query count is 3.
Mcm cvlan is 0.
Prerequisites
Before this operation, make sure that:
Context
To configure the IPTV package, perform the following steps:
Steps
1. Use the iptv channel mvlan group command to configure the multicast channels.
2. Use the iptv view-profile command to configure the multicast preview profile.
Table 4-6 lists the parameters for multicast preview profile configuration.
4-23
Parameter Value
3. Use the iptv channel view-profile command to apply the preview profile to the channels.
4. Use the iptv packgae name command to create the multicast package.
5. Use the iptv packgae channel command to configure the multicast package channels.
– End of Steps –
Result
The IPTV package is configured successfully.
Example
Configure an IPTV package.
l Name: stv
l Channel: stv1 – stv10, IP address 224.1.1.1 – 224.1.1.10
l Preview profile
à Name: abc
à Maximum preview count: 3
à Maximum preview duration: 120 seconds
à Preview interval: 60 seconds
l Channel rights
à Preview: stv1 – stv5
à Watch: stv6 – stv9
à Deny: stv10
ZXAN(config)#iptv channel mvlan 10 group 224.1.1.1
to 224.1.1.10 prename stv
ZXAN(config)#iptv view-profile abc count 3 duration 120 blackout 60
ZXAN(config)#iptv channel stv1 view-profile abc
ZXAN(config)#iptv channel stv2 view-profile abc
ZXAN(config)#iptv channel stv3 view-profile abc
ZXAN(config)#iptv channel stv4 view-profile abc
ZXAN(config)#iptv channel stv5 view-profile abc
4-24
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The multicast source exits in the network.
l The MVLAN is configured.
l The IPTV package is configured.
Context
The ZXA10 C220 supports the multicast service of two-level control.
l When global CAC is enabled, user port rights take effect. Only the users who order
package can watch the channels in the package.
l When global CAC disabled, user port rights do not take effect. Users can watch the
channels in the MVLAN when they are on the receiving port of the MVLAN.
By default, global CAC is disabled.
To configure the CAC, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the iptv cac command to enable global CAC.
3. Use the interface command to enter the interface configuration mode.
4. Use the iptv right-mode command to set the port right mode to channel access mode
or package control mode.
5. Set the port right.
4-25
l Use the iptv channel command to set the port channel right.
l Use iptv package command to set the port package.
– End of Steps –
Result
The CAC is configured successfully.
Example
Enable global CAC and set port right mode to package control mode and apply this
package to the port.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#iptv cac enable
ZXAN(config)#interface epon-onu_0/6/4:1
ZXAN(config-if)#iptv right-mode package
ZXAN(config-if)#iptv package stv
Prerequisites
Before this operation, make sure that:
Context
Table 4-7 lists the CDR configuration parameters.
4-26
Steps
1. Use the iptv sms-server command to set the IP address of SMS (the CDR server).
2. Use the iptv cdr enable command to enable the global CDR function.
3. Use the iptv cdr max-records command to set the maximum CDRs.
4. Use the iptv cdr report command to set CDR manual report.
5. Use the iptv cdr report-interval command to set the CDR automatic report interval.
6. Use the iptv cdr report-threshold command to set the CDR automatic report threshold.
7. Use the iptv cdr create-period command to set the CDR generation period when the
user right is permit.
8. Use the iptv cdr deny-right command to enable or disable the CDR function when the
user right is deny.
9. Use the iptv cdr prw-right command to enable or disable the CDR function when the
user right is preview.
10. Use the iptv cdr prw-overcount command to enable or disable the CDR function when
the user preview times exceed the threshold.
11. Use the iptv cdr clear command to clear the CDRs.
4-27
12. Use the show iptv cdr command to query the CDR configuration information.
– End of Steps –
Result
CDR is configured successfully.
Example
Enable CDR and set the maximum CDRs to 6000, automatic reporting threshold to 300.
ZXAN(config)#iptv sms-server 10.61.97.156
ZXAN(config)#iptv cdr enable
ZXAN(config)#iptv cdr max-records 1000
ZXAN(config)# iptv cdr report-threshold 300
ZXAN(config)#show iptv cdr
CDR : enable
CDR current-state : idle
CDR socket-status : close
CDR deny-right : disable
CDR prw-right : enable
CDR prw-over-count : disable
CDR create-period : 60(minute)
Max-records : 1000
Report-interval : 5(minute)
Report-threshold : 300
Records in cache : 0
4-28
5.1 Overview
Service Description
In the VoIP service, voice signals are compressed and packed, and then transmitted on
the IP packet switching network.
Service Specifications
The ZXA10 C220 provides the VoIP service access to the IP network through the xPON
service card. The VoIP service is implemented on the ONUs.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The EPON service card status is proper.
l The communication between the MG and the SS is proper.
l The VoIP user data is configured on the SS.
5-1
Networking Diagram
Figure 5-1 shows the networking diagram of the VoIP service.
Configuration Data
Table 5-1 lists configuration data of the VoIP service .
Item Data
5-2
Item Data
MG l IP address: 10.63.172.190
l Gateway: 10.63.172.254
Configuration Flow
Figure 5-2 shows the configuration flow of the VoIP service.
5-3
Steps
1. Create the VoIP service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 200
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
5-4
4. Enter the EPON-ONU interface mode. Enable the authentication protocol and set the
ONU bandwidth.
ZXAN(config)#interface epon-onu_0/5/1:5
ZXAN(config-if)#admin enable
ZXAN(config-if)#sla upstream maximum 5120
ZXAN(config-if)#sla downstream maximum 10240
6. Enter the EPON configuration mode and configure the VoIP IP profile.
ZXAN(config)#epon
ZXAN(config-epon)#voip-ip profile TestProfile relation independent
mode static gateway 10.63.172.254
9. Enter the PON-ONU management mode and apply the profile to the ONU.
ZXAN(config)#pon-onu-mng epon-onu_0/5/1:5
ZXAN(epon-onu-mng)#voip-module global-profile apply ip TestProfile vlan vlan_200
ZXAN(epon-onu-mng)#voip-module protocol-profile apply sip SIP
5-5
Note:
If the IP address mode in the VoIP IP profile is static or PPPoE, you need to configure the VoIP
connection.
Result
The VoIP service is configured successfully. Users can make phone calls.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The EPON service card status is proper.
l The communication between the MG and the MGC (SS)is proper.
l The VoIP user data is configured on the MGC.
Networking Diagram
Figure 5-3 shows the networking diagram of the VoIP service.
5-6
Configuration Data
Table 5-2 lists configuration data of the VoIP service .
Item Data
5-7
Item Data
MG l IP address: 10.63.172.190
l Gateway: 10.63.172.254
l Domain name: iad.zte.com.cn
MG IP address 10.63.172.190
Gateway 10.63.172.254
Configuration Flow
Figure 5-4 shows the configuration flow of the VoIP service.
5-8
Steps
1. Create the VoIP service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 200
ZXAN(config-vlan)#exit
ZXAN(config)#
5-9
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
4. Enter the EPON-ONU interface mode. Enable the authentication protocol and set the
ONU bandwidth.
ZXAN(config)#interface epon-onu_0/5/1:5
ZXAN(config-if)#admin enable
ZXAN(config-if)#sla upstream maximum 5120
ZXAN(config-if)#sla downstream maximum 10240
6. Enter the EPON configuration mode and configure the VoIP IP profile.
ZXAN(config)#epon
ZXAN(config-epon)#voip-ip profile TestProfile relation independent
mode static gateway 10.63.172.254
9. Enter the PON-ONU management mode and apply the profile to the ONU.
ZXAN(config)#pon-onu-mng epon-onu_0/5/1:5
ZXAN(epon-onu-mng)#voip-module global-profile apply ip TestProfile vlan vlan_200
ZXAN(epon-onu-mng)#voip-module protocol-profile apply h248 H.248
5-10
Note:
If the IP address mode in the VoIP IP profile is static or PPPoE, you need to configure the VoIP
connection.
Note:
If the MG register mode in the VoIP H.248/MGCP protocol profile is domain name, you need to
configure the domain name.
Note:
If the VoIP protocol profile is for H.248 or MGCP protocol, you need to configure SLC TID.
Result
The VoIP service is configured successfully. Users can make phone calls.
Prerequisites
Before this operation, make sure that:
5-11
Networking Diagram
Figure 5-5 shows the networking diagram of the VoIP service.
Configuration Data
Table 5-3 lists configuration data of the VoIP service.
Item Data
Service priority 7
Bandwidth: 1 Mbit/s
5-12
Item Data
Configuration Flow
Figure 5-6 shows the configuration flow of the VoIP service through the SIP protocol.
5-13
Steps
1. Create the service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 200
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
5-14
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
4. Enter the GPON-OLT interface mode and authenticate the ONU by the SN.
ZXAN(config)#interface gpon-olt_0/10/1
ZXAN(config-if)#onu 1 type ZTE-F628 sn ZTEG00000002
ZXAN(config-if)#exit
ZXAN(config)#show gpon onu state gpon-olt_0/10/1
OnuIndex Admin State Omcc State O7 State Phase State
----------------------------------------------------------------
gpon-onu_0/10/1:1 enable enable operation working
6. Create a T-CONT.
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#tcont 3 name voip-tcont profile voip-tcont
Note:
5-15
Note:
Note:
Result
The VoIP service is configured successfully. Users can make phone calls.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The GPON service card status is proper.
5-16
Networking Diagram
Figure 5-7 shows the networking diagram of the VoIP service.
Configuration Data
Table 5-4 lists configuration data of the VoIP service.
Item Data
Service priority 7
Bandwidth: 1 Mbit/s
5-17
Item Data
Configuration Flow
Figure 5-8 shows the configuration flow of the VoIP service.
5-18
To configure the VoIP service through the H.248 protocol, perform the following steps:
Steps
1. Create the service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 200
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
5-19
ZXAN(config)#interface xgei_0/2/1
ZXAN(config-if)#switchport mode trunk
ZXAN(config-if)#switchport vlan 200 tag
ZXAN(config-if)#exit
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
5. Enter the GPON-OLT interface mode. Authenticate the ONU by the SN.
ZXAN(config)#interface gpon-olt_0/10/1
ZXAN(config-if)#onu 1 type ZTEG-F660 sn ZTEG00000002
ZXAN(config-if)#exit
5-20
7. Create a T-CONT.
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#tcont 3 name voip-tcont profile voip-tcont
Note:
5-21
Note:
The ZXA10 C220 does not support configuring the user circuit TID and VoIP resource TID through
the OMCI channel. If the default settings on the ONU is different from the data on the MGC, you
need to modify the settings on the F660 web page.
On the F660 web page, choose Application > VoIP > H248 Termination.
On the H248 Termination Configuration page, configure the TIDs, as shown in
Figure 5-9.
Result
The VoIP service is configured successfully. Users can make phone calls.
Prerequisites
l The network devices and lines are proper.
l The EPON service card status is proper.
Context
To configure the EPON VoIP IP profile, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
5-22
– End of Steps –
Result
The VoIP IP profile is configured successfully.
Example
Configure a VoIP IP profile with the following parameters:
l Profile name: TestProfile
l Relation of VoIP IP address and management IP address: independent
l IP address allocation mode: static
l Gateway: 10.63.172.254
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#epon
ZXAN(config-epon)#voip-ip profile TestProfile relation independent
mode static gateway 10.63.172.254
5-23
Prerequisites
l The network devices and lines are proper.
l The EPON service card status is proper.
Context
To configure the EPON VoIP VLAN profile, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the epon command to enter EPON configuration mode.
3. Use the voip-vlan profile command to configure VoIP VLAN profile.
Table 5-6 lists parameters description for a VoIP VLAN profile.
– End of Steps –
Result
The VoIP VLAN profile is configured successfully.
Example
Configure a VoIP VLAN profile with the following parameters:
5-24
Prerequisites
l The network devices and lines are proper.
l The EPON service card status is proper.
Context
ZXA10 C220 supports three types of VoIP protocol profiles:
l H.248 protocol profile
l MGCP protocol profile
l SIP protocol profile
Configuration of H.248 and MGCP protocol profiles are similar. This topic describes
configuration of H.248 and SIP protocol profiles.
To configure the EPON VoIP protocol profile, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the epon command to enter the EPON configuration mode.
3. Configure the VoIP protocol profile.
l Configure H.248 protocol profile.
a. Use the h248-profile register-server command to configure H.248 primary
MGC.
b. Use the h248-profile backup-register-server command to configure H.248
secondary MGC.
c. Use the h248-profile mg register-mode command to configure MG registration
mode.
5-25
à IP address
à Device name
Domain name or IP address is
recommended.
à Enable
Disable is recommended.
cycle Heartbeat cycle 10 sec - 120 sec, the default value 30 sec
is recommended.
Note:
Use the mgcp-profile related commands to configure MGCP protocol profile. For the MGCP
protocol, the default port on an MGC is 2727, and on an MG is 2427.
5-26
à Enable
register-interval Register interval 0 - 65535 sec, the default value 3600 sec
is recommended.
Note:
– End of Steps –
Result
The VoIP protocol profile is configured successfully.
Example
l Configure a VoIP H.248 protocol profile with the following parameters:
à Profile name: H.248
à Primary MGC IP address: 10.63.172.55
à Secondary MGC IP address: 10.63.172.61
à MG register mode: domain
à Other parameters: default values
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#epon
ZXAN(config-epon)#h248-profile H.248 register-server ip 10.63.172.55 port 2944
ZXAN(config-epon)#h248-profile H.248 backup-register-server ip 10.63.172.61 port 2944
ZXAN(config-epon)#h248-profile H.248 mg register-mode domainname port 2944
ZXAN(config-epon)#h248-profile H.248 heartbeat-mode h248ctc rtp-link-test disable
5-27
cycle 30 count 3
5-28
6.1 Overview
Service Description
CES is a technology to transmit TDM services over PSN.
At present, two implementation agreements support CES:
l PWE3 of IETF: Implement circuit emulation over IP network, namely, which is based
on IP address.
l MEF8 of MEF: Implement circuit emulation over Ethernet, namely, which is based on
MAC address.
Service Specification
The ZXA10 C220 implements CES service on CES cards (CE1B/CE1BB/CT1BB/CL1A).
The TDM interface on CES card is connected to the upper-layer device. The xPON
interface connects to the remote ONU.
The ZXA10 C220 supports maximum 63 E1 channels with two uplink modes:
6-1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The in-band NM of the OLT is configured.
l The CES uplink card status is proper.
l The EPON service card status is proper.
Networking Diagram
Figure 6-1 shows the CES service networking diagram.
The E1 user connects to the ONU E1 port. The ZXA10 C220 connects theTDM network
through the E1 port on CE1B card.
6-2
Configuration Data
Table 6-1 describes the CES service configuration data.
Item Data
Priority 7
Configuration Flow
Figure 6-2 shows the CES service configuration flow.
6-3
Steps:
1. Create the service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 1000
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
6-4
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
ZXAN(config)#
5. Enter the EPON-ONU interface mode. Enable the interface authentication protocol.
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#admin enable
Note:
You can use the show onu detail-info command to display the detailed information of the current
ONU.
6-5
Note:
In practical networking, it is recommended to use the default values for the OLT TDM interface
configuration.
This instance uses the default CES profile. To configure the CES property profile
of the OLT, refer to 6.7 Configuring the CES TDM Profile.
Note:
There is a default profile on the ZXA10 C220. It is recommended to use the default profile.
d. Create the PW link and configure the TDM property of the PW link.
ZXAN(config)#ces
ZXAN(config-ces)#pw pw_0/13/1
ZXAN(config-ces-pw)#tdm-service type e1Satop rate 32 tdm_0/13/1 tdm-profile-name
default
Note:
l TDM service type of CE1B/CE1BB card is e1Satop.
l TDM service type of CT1BB card is t1Satop.
6-6
Note:
When PSN network type is Ethernet, the in-ecid/out-ecid configured on OLT must correspond
to those on ONU. In this instance, the in-ecid/out-ecid value is 0x1102.
The in-ecid and out-ecid of the same PW can be different. For convenience, they are gener-
ally configured same.
6-7
Note:
In practical networking, it is recommended to use the default ONU TDM interface configura-
tion.
Note:
The CES property profile parameters of two ends of the same PW must be consistent.
h. Configure the binding between the PW link and the TDM interface.
F429(config)#pw relation 1 rate 32 1 1 creat
11. Save the configuration data on the OLT and the ONU.
6-8
Result
The EPON CES service is configured successfully.
Prerequisites
Before this operation, make sure that:
Networking Diagram
Figure 6-3 shows the CES service networking diagram.
6-9
The E1 user connects to the ONU E1 port. The ZXA10 C220 connects to theTDM network
through the E1 port on CE1B card.
Configuration Data
Table 6-2 describes configuration data of the CES service.
Item Data
Priority 7
Configuration Flow
Figure 6-4 shows the CES service configuration flow.
6-10
Steps
To configure the EPON CES service, perform the following steps:
1. Create the service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 1000
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
6-11
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
ZXAN(config)#
5. Enter the EPON-ONU interface mode. Enable the interface authentication protocol.
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#admin enable
Note:
You can use the show onu detail-info command to display the detailed information of the current
ONU.
6-12
Note:
In practical networking, it is recommended to use the default values of the OLT TDM interface.
This instance uses the default CES profile. To configure the CES property profile
of the OLT, refer to 6.7 Configuring the CES TDM Profile.
Note:
There is a default profile in the ZXA10 C220. It is recommended to use the default profile.
d. Create the PW link and configure the TDM properties of the PW link.
ZXAN(config)#ces
ZXAN(config-ces)#pw pw_0/13/1
ZXAN(config-ces-pw)#tdm-service type e1Satop rate 32 tdm_0/13/1 tdm-profile-name
default
Note:
l TDM service type of CE1B/CE1BB card is e1Satop.
l TDM service type of CT1BB card is t1Satop.
6-13
Note:
The OLT source/destination UDP port number must be consistent with the ONU source/des-
tination UDP port number. For convenience, they are generally configured same.
pw pw_0/13/1
PwType : e1Satop PsnType : ip
Admin-status : enable InboundLable :0x44D
OutboundLable :0x44D Destination IP Address 192.192.192.1.
Service prop:
Using tdm interface: tdm_0/13/1
TDM-prop profile: default
You can see detail profile info. by using
corresponding 'show' command.
Psn prop:
Destination Mac Address: 0015.EB72.000C
Vlan ID: 1000 priority: 7
Card prop:
Card interface : 13/1
Source Mac Address: 0015.EB72.001A
Source IP Address : 192.192.192.26
6-14
Note:
In practical networking, it is recommended to use the default ONU TDM interface configura-
tion.
Note:
The CES property profile parameters of two ends of the same PW must be consistent.
h. Configure the binding between the PW link and the TDM interface.
F429(config)#pw relation 1 rate 32 1 1 creat
11. Save the configuration data on the OLT and the ONU.
6-15
Result
The EPON CES service is configured successfully.
Context
The CL1A card provides a STM-1/OC3 interface for uplink. The CL1A card performs
multiplex E1 frames to STM-1 frames and sends STM-1 frames to the SDH/SONET
network through the STM-1 optical interface. The multiplexer at the remote end in SDH
network extracts E1 frames.
Networking Diagram
Figure 6-5 shows the CES service networking diagram.
6-16
The E1 user connects to the E1 interface of the ONU. The ZXA10 C220 accesses the
SDH/SONET network through the STM-1 interface on the CL1A card.
Configuration Data
Table 6-3 describes configuration data of the CES service.
Item Data
Priority 7
6-17
Item Data
Configuration Flow
Figure 6-6 shows the CES service configuration flow.
6-18
Steps:
1. Create the service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 1000
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
ZXAN(config)#
5. Enter the EPON-ONU interface mode. Enable the interface authentication protocol.
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#admin enable
6-19
Note:
You can use the show onu detail-info command to display the detailed information of the current
ONU.
Note:
In practical networking, it is recommended to use the default values for the OLT TDM interface
configuration.
6-20
Note:
There is a default profile in the ZXA10 C220. It is recommended to use the default profile.
d. Create the PW link and configure the TDM property of the PW link.
ZXAN(config)#ces
ZXAN(config-ces)#pw pw_0/14/1
ZXAN(config-ces-pw)#tdm-service type e1Satop rate 32 tdm_0/14/1.1/1/1/1/1
tdm-profile-name default
Note:
Note:
When the PSN network type is Ethernet, the in-ecid/out-ecid configured on the OLT must
correspond to those on the ONU. In this instance, the in-ecid/out-ecid value is 0x1102.
The in-ecid and out-ecid of the same PW can be different. For convenience, they are gener-
ally configured same.
pw pw_0/14/1
PwType : e1Satop PsnType : ethernet
Admin-status : enable InboundLable :0x1102
OutboundLable :0x1102
6-21
Service prop:
Using tdm interface: tdm_0/14/1.1/1/1/1/1
TDM-prop profile: default
You can see detail profile info. by using
corresponding 'show' command.
Psn prop:
Destination Mac Address: 0015.EB72.000C
Vlan ID: 1000 priority: 7
Card prop:
Card interface : 14/1
Source Mac Address: 0015.EB72.001C
Source IP Address : 192.192.192.28
6-22
Note:
In practical networking, it is recommended to use the default ONU TDM interface configura-
tion.
Note:
The CES property profile parameters of two ends of the same PW must be consistent.
h. Configure the binding between the PW link and the TDM interface.
F429(config)#pw relation 1 rate 32 1 1 creat
11. Save the configuration data on the OLT and the ONU.
Result
The EPON CES service is configured successfully.
Prerequisites
Before this operation, make sure that:
6-23
Networking Diagram
Figure 6-7 shows the CES service networking diagram.
The E1 user connects to the ONU E1 port. The ZXA10 C220 connects to the TDM network
through the E1 port on CE1B card.
Configuration Data
Table 6-4 describes configuration data of the CES service.
Item Data
Priority 7
6-24
Item Data
Bandwidth: 10 Mbit/s
Configuration Flow
Figure 6-8 shows the CES service configuration flow.
6-25
Steps
To configure the CES service, perform the following steps:
1. Create the service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 1000
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
6-26
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
4. Enter the GPON-OLT interface mode and authenticate the ONU by the SN.
ZXAN(config)#interface gpon-olt_0/10/1
ZXAN(config-if)#onu 1 type ZTE-F621 sn ZTEG00000002
ZXAN(config-if)#exit
ZXAN(config)#show gpon onu state gpon-olt_0/10/1
OnuIndex Admin State Omcc State O7 State Phase State
------------------------------------------------------------------
gpon-onu_0/10/1:1 enable enable operation working
6. Create a T-CONT.
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#tcont 2 name ces-tcont profile ces-tcont
Note:
6-27
Note:
In the practical networking, it is recommended to use the default values for the OLT TDM
interface configuration.
This instance uses the default CES profile. To configure the CES property profile
of the OLT, refer to 6.7 Configuring the CES TDM Profile.
Note:
There is a default profile in the ZXA10 C220. It is recommended to use the default profile.
d. Create the PW link and configure the TDM property of the PW link.
ZXAN(config)#ces
ZXAN(config-ces)#pw pw_0/13/1
ZXAN(config-ces-pw)#tdm-service type e1Satop rate 32 tdm_0/13/1 tdm-profile-name
default
Note:
l TDM service type of CE1B/CE1BB card is e1Satop.
l TDM service type of CT1BB card is t1Satop.
6-28
Note:
When PSN network type is Ethernet, the in-ecid/out-ecid configured on OLT must correspond
to those on ONU. In this instance, the in-ecid/out-ecid value is 0x1102.
The in-ecid and out-ecid of the same PW can be different. For convenience, they are gener-
ally configured same.
pw pw_0/13/1
PwType : e1Satop PsnType : ethernet
Admin-status : enable InboundLable :0x1102
OutboundLable :0x1102
Service prop:
Using tdm interface: tdm_0/13/1
TDM-prop profile: default
You can see detail profile info. by using
corresponding 'show' command.
Psn prop:
Destination Mac Address: 0015.EB72.000C
Vlan ID: 1000 priority: 7
Card prop:
Card interface : 13/1
Source Mac Address: 0015.EB72.001A
Source IP Address : 192.192.192.26
This instance uses the default values. To configure the OLT TDM interface, use
the following command.
ZXAN(gpon-onu-mng)#interface ces ces_0/1 state disable
6-29
Note:
In practical networking, it is recommended to use the default ONU TDM interface configura-
tion.
Note:
There is a default profile in the ZXA10 C220 system. It is recommended to use the default
profile.
Result
The GPON CES MEF8 service is configured successfully.
6-30
Context
The CL1A card provides a STM-1/OC3 interface for uplink. The CL1A card performs
multiplex E1 frames to STM-1 frames and sends STM-1 frames to the SDH/SONET
network through the STM-1 optical interface. The multiplexer at the remote end in SDH
network extracts E1 frames.
Networking Diagram
Figure 6-9 shows the CES service networking diagram.
6-31
The E1 user connects to the E1 interface of the ONU. The ZXA10 C220 accesses the
SDH/SONET network through the STM-1 interface on the CL1A card.
Configuration Data
Table 6-5 describes configuration data of the CES service.
Item Data
Priority 7
Bandwidth: 10 Mbit/s
6-32
Configuration Flow
Figure 6-10 shows the CES service configuration flow.
Steps
To configure the CES service, perform the following steps:
1. Create the service VLAN.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 1000
ZXAN(config-vlan)#exit
ZXAN(config)#
Note:
You can use the show vlan summary command to display the created VLAN information.
6-33
Note:
When you use the switchport vlan command to configure a port VLAN, the system adds the VLAN
automatically.
4. Enter the GPON-OLT interface mode and authenticate the ONU by the SN.
ZXAN(config)#interface gpon-olt_0/10/1
ZXAN(config-if)#onu 1 type ZTE-F621 sn ZTEG00000002
ZXAN(config-if)#exit
ZXAN(config)#show gpon onu state gpon-olt_0/10/1
OnuIndex Admin State Omcc State O7 State Phase State
------------------------------------------------------------------
gpon-onu_0/10/1:1 enable enable operation working
6. Create a T-CONT.
ZXAN(config)#interface gpon-onu_0/10/1:1
ZXAN(config-if)#tcont 2 name ces-tcont profile ces-tcont
Note:
6-34
A CL1A card supports 63 E1 channels. The first MAC address is for the first 32
channels, while the second MAC address for the other 31 channels.
ZXAN(config)#show ces global-prop 14/1
Slot/Port SourceMAC Source IP
-----------------------------------------------------
14/1 0015.EB72.001C 192.192.192.28
Note:
In practical networking, it is recommended to use the default values for the OLT TDM interface
configuration.
Note:
There is a default profile in the ZXA10 C220. It is recommended to use the default profile.
d. Create the PW link and configure the TDM property of the PW link.
ZXAN(config)#ces
ZXAN(config-ces)#pw pw_0/14/1
ZXAN(config-ces-pw)#tdm-service type e1Satop rate 32 tdm_0/14/1.1/1/1/1/1
tdm-profile-name default
6-35
Note:
Note:
When the PSN network type is Ethernet, the in-ecid/out-ecid configured on the OLT must
correspond to those on the ONU. In this instance, the in-ecid/out-ecid value is 0x1102.
The in-ecid and out-ecid of the same PW can be different. For convenience, they are gener-
ally configured same.
pw pw_0/14/1
PwType : e1Satop PsnType : ethernet
Admin-status : enable InboundLable :0x1102
OutboundLable :0x1102
Service prop:
Using tdm interface: tdm_0/14/1.1/1/1/1/1
TDM-prop profile: default
You can see detail profile info. by using
corresponding 'show' command.
Psn prop:
Destination Mac Address: 0015.EB72.000C
Vlan ID: 1000 priority: 7
Card prop:
Card interface : 14/1
Source Mac Address: 0015.EB72.001C
Source IP Address : 192.192.192.28
6-36
ZXAN(config)#pon-onu-mng gpon-onu_0/10/1:1
ZXAN(gpon-onu-mng)#service tdmservice type hybrid gemport 1 cos 7 vlan 1000
Note:
In practical networking, it is recommended to use the default ONU TDM interface configura-
tion.
Note:
There is a default profile in the ZXA10 C220 system. It is recommended to use the default
profile.
6-37
Result
The GPON CES dedicated line service is configured successfully.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The CES service card status is proper.
Context
Table 6-6 describes the TDM profile parameters.
6-38
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the ces command to enter CES configuration mode.
3. Use the tdm-profile command to configure the TDM profile.
Note:
l Configure this profile before relating it to PW link.
l If a profile is applied to a PW link, it is not allowed to modify or delete this profile.
l The RTP value of each profile related to the same slot must be the same.
4. Use the show ces tdm-profile command to query TDM profile configuration information.
– End of Steps –
Result
The CES TDM profile is configured successfully.
Example
Configure the TDM profile and view configuration information.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#ces
6-39
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The CES service card status is proper.
Context
In practical networking, it is recommended to us the default values for CES TDM interface
configuration.
To configure the CES TDM interface, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the interface command to enter the TDM interface configuration mode.
3. Use the admin-status command to configure the TDM interface management status.
4. Use the clock-source command to configure the transmission clock source of the TDM
interface.
5. Use the framing command to configure the SONET/SDH interface frame format. Only
SDH is supported now.
6. Use the line-coding command to configure the TDM interface coding type. The default
type is HDB3.
6-40
7. Use the line-type command to configure the TDM interface line type (whether it is
framed and the framing type). The default type is e1.
8. Use the loopback command to configure the TDM interface loopback mode.
9. Configure the T1/E1 line properties of the SDH interface.
a. Enter the line configuration mode.
l Use the au-3 command to enter the au-3 configuration mode.
l Use the au-4 tug-3 command to enter the au-4 tug-3 configuration mode.
b. Use the tug-2 command to configure the T1/E1 line properties.
– End of Steps –
Result
The CES TDM interface is configured successfully.
Example
Configure the transmission clock source mode of the TDM interface on port 1 slot 13 to
differential.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#interface tdm_0/13/1
ZXAN(config-if)#clock-source differential
6-41
6-42
7.1 Overview
Service Description
A VLAN is a group of hosts that communicate as if they were in the same broadcast domain,
regardless of their physical location. A VLAN has the same attributes as a physical LAN,
but it allows for end stations to be grouped together even if they are not located on the
same network switch. IEEE issued the IEEE 802.1q standard draft in 1999 to standardize
the VLAN implementation plan.
Service Specifications
The ZXA10 C220 supports up to 4094 VLANs.
Table 7-1 describes VLAN specifications.
TLS VLAN Add an outer-layer SVLAN whatever the user access mode is, or whether the
uplink packet has a VLAN tag, or whatever the VLAN tag is.
1:1 VLAN Set the special channel for the user port and uplink port. The packets are
exchanged in 1:1 mode according to the VLAN ID.
7-1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The uplink port and service port are proper.
Context
When TLS is enabled on a PON-ONU interface, the upstream frames from the user port
are added with the TLS VLAN ID before the four-byte 802.1q. This configuration is used
for VLAN transparent transmission between enterprises.
To configure the TLS VLAN, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the vlan command to add a VLAN.
3. Use the interface command to enter the interface configuration mode.
4. Use the switchport mode command to configure the port VLAN mode.
Note:
When the port mode is access or transparent, the TLS properties cannot be configured.
5. Use the switchport tls enable command to enable port VLAN TLS.
Note:
In trunk or hybrid mode, when the TLS function is disabled, TLS VLAN ID automatically changes
to 0.
6. Use the switchport tls vlan command to configure the port TLS VLAN.
7. Use the show vlan port command to query the port VLAN configuration.
– End of Steps –
Result
The TLS VLAN is configured successfully.
7-2
Example
The user frames have a VLAN tag 100. The ZXA10 C220 adds VLAN tag 101 to the
frames.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 101
ZXAN(config-vlan)#exit
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#switchport mode trunk
ZXAN(config-if)#switchport vlan 101 tag
ZXAN(config-if)#exit
ZXAN(config)#interface epon-onu_0/6/4:1
ZXAN(config-if)#switchport mode trunk
ZXAN(config-if)#switchport tls enable
ZXAN(config-if)#switchport tls vlan 101
ZXAN(config-if)#show vlan port epon-onu_0/6/4:1
Mode Pvid CPvid Tpid ProtEn PrioEn TLSEn TLSVlan UntagVlan TagVlan
---------------------------------------------------------------------
trunk 1 0 0x8100 disable disable enable 101 1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The VLAN of the upper-layer device interface corresponds to the VLAN configured on
the uplink interface.
l The xPON service card status is proper.
l The xPON service is configured.
Context
The ZXA10 C220 supports VLAN smart QinQ at two levels:
l ONU-level
Use the service-port command to configure VLAN smart QinQ based on ONUs.
l PON-level
Use the vlan-smart-qinq command to VLAN smart QinQ based on PON ports.
This topic takes PON-level VLAN smart QinQ as an example.
7-3
The xPON OLT is connected by multiple ONUs in the downlink direction. The xPON
OLT connects the DSLAM through the ONU to achieve the function of MAN convergence
switches. The packets are added with different external VLAN tags according to different
data streams to achieve service identification.
The ZXA10 C220 supports the following smart QinQ modes:
l Based on a single CVLAN
l Based on a CVLAN segment
l Based on CoS
l Based on the Ethernet type
l Based on single CVLAN + CoS
l Based on single CVLAN + Ethernet type
When entries on the same port conflict, the item configured earliest takes effect.
Configuration Data
Table 7-2lists the smart QinQ configuration data.
Item Data
ONU ID 1
Configuration Flow
Figure 7-1 shows the configuration flow of VLAN smart QinQ.
7-4
Steps
1. Configure the transparent transmission service VLAN and external SVLAN.
ZXAN#config terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan database
ZXAN(vlan)#vlan 60,200-500,1024,2048
ZXAN(vlan)#exit
7-5
Note:
Port VLAN Smart QinQ can be enabled only after global VLAN Smart QinQ is enabled.
6. Configure the uplink port of the transparent transmission VLAN and the external
SVLAN.
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#switchport mode hybrid
ZXAN(config-if)#switchport vlan 200-500 tag
ZXAN(config-if)#switchport vlan 60 tag
ZXAN(config-if)#switchport vlan 1024 tag
ZXAN(config-if)#switchport vlan 2048 tag
ZXAN(config-if)#end
Result
The VLAN smart QinQ is configured successfully.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
7-6
l The VLAN of the upper-layer device interface corresponds to the VLAN configured on
the uplink interface.
l The xPON service card status is proper.
l The xPON basic service is configured.
Context
In the 1:1 VLAN mode, there is only one service port and one uplink in a VLAN, thus frames
are forwarded according to SVLAN ID or CVLAN ID + SVLAN ID, but not MAC address +
VLAN ID.
To configure the 1:1 VLAN, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the vlan command to enter the VLAN configuration mode.
3. Use the xconnect command to configure cross connection in the 1:1 VLAN.
Note:
In a 1:1 VLAN, only when the cross connection is configured, the VLAN configuration on corre-
sponding uplink port and service port are permitted, which includes:
4. Use the vlan-xconnect command to add 1:1 VLAN connection configuration items.
5. Use the interface command to enter the PON-ONU interface configuration mode.
6. Use the switchport vlan command to configure the VLAN properties of the PON-ONU
interface.
Note:
l Default VLAN
l 1:1 VLAN
l VLAN translation
l VLAN QinQ
As long as the frames on the PON-ONU interfacet match the SVLAN or CVLAN + SVLAN, the 1:1
VLAN forwarding is implemented.
7. Use the interface command to enter the uplink port configuration mode.
7-7
8. Use the switchport vlan command to configure the VLAN properties of the uplink port.
Note:
9. Use the show vlan-xconnect summary command to query the configured 1:1 VLAN.
10. Use the show vlan-xconnect detail command to query the detailed configuration rules
of the 1:1 VLAN.
– End of Steps –
Result
The 1:1 VLAN is configured successfully.
Example
Configure the special channel for service port epon-onu_0/5/2:1 and uplink port gei_0/6/1
in VLAN 600. When the user frames match SVLAN 600, the 1:1 VLAN forwarding is
implemented.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan 600
ZXAN(config-vlan)#xconnect enable
ZXAN(config-vlan)#exit
ZXAN(config)#vlan-xconnect user-port epon-onu_0/5/1:1 vport 1 uplink-port
gei_0/6/1 svlan 600
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#switchport mode trunk
ZXAN(config-if)#switchport vlan 600 tag
ZXAN(config-if)#exit
ZXAN(config)#interface gei_0/6/1
ZXAN(config-if)#switchportvlan 600 tag
ZXAN(config-if)#exit
ZXAN(config)#show vlan-xconnect summary
All xconnect-vlan num: 1
Details are following:
600
ZXAN(config)#show vlan-xconnect detail
xconnect vlan rule num: 1
User-Port Vport Uplink-Port Svlan Cvlan
-------------------------------------------------------
epon-onu_0/5/1:1 vport 1 gei_0/6/1 600 0
vport 1
7-8
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The VLAN of the upper-layer device interface corresponds to the VLAN configured on
the uplink interface.
l The xPON service card status is proper.
l The xPON service is configured.
Context
The ZXA10 C220 supports the following VLAN translations on service ports.
Untagged Single–tag
Untagged Dual–tag
Tagged Single–tag
Tagged Dual–tag
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the interface command to enter the EPON-ONU interface configuration mode.
3. Use the service-port command to create a service port under the EPON ONU port.
Note:
After the ONU is configured with the service port rules, the PON-level VLAN configuration (such
as smart QinQ) on the PON port is ineffective for the ONU and the configured service port rules
take effect.
7-9
4. Use the show service-port command to view the configured service port items.
– End of Steps –
Result
The service port VLAN is configured successfully.
Example
Configure the service port under epon-onu_0/5/1:1.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#service-port 1 user-vlan 10 user-etype PPPOE vlan 20 svlan 100
ZXAN(config-if)#service-port 2 user-vlan untagged vlan 21 svlan 31
7-10
8.1 Overview
The STP is used to ensure a loop-free topology in a bridged network. It prevents redundant
paths by using specific algorithms, to prune the network loops by viewing the network
logically as a tree structure. This prevents packet circulation in the network loops.
The STP exchanges BPDUs between all the switches of STP in an expanded LAN. BPDUs
exchange implement the following functions:
l Selecting a root bridge from a stable spanning tree topology
l Selecting a specified switch from each switch network segment
l Preventing loop from the topology network by setting the redundant switch port to
Discard
The ZXA10 C220 supports SSTP, RSTP, and MSTP, which follow the IEEE802.1d,
IEEE802.1w, and IEEE802.1s standards respectively.
8-1
RSTP provides faster convergence than SSTP. When the network topology changes, the
port state of the redundant switch port can be quickly changed from Discard to Forward
in a point-to-point connection condition.
RSTP complies with the IEEE 802.1w standard.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The xPON service is configured.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
The MSTP is applied in the redundancy network. It provides fast convergence, and
enables different VLAN traffics to be dispatched in the corresponding paths, and thus
provides load sharing mechanism for the redundancy links.
The MSTP trims the loopback network to a tree network that has no loops, which prevents
packets from increasing and loop in the network. It also provides multiple redundancy
paths for data forwarding, in which process realizing VLAN data load balance.
The ZXA10 C220 supports the MSTP and is compatible with the STP and RSTP. It also
supports MSTP ring network.
To configure the MSTP, perform the following steps:
Steps
1. Enable the STP protocol.
8-2
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#spanning-tree enable
3. Set the maximum valid time for the packet of the local bridge.
By default, the maximum valid time for the STP BPDU packet of the specific bridge is
20 seconds.
The device determines whether it times out for the port to receive the configuration
information according to the maximum valid time. If it times out, the snapping tree
instance needs to be recalculated.
If the current device is the root bridge device, it determines the timeout according to
the maximum valid time of the root bridge device. If the current device is a non-root
bridge device, it determines the timeout also according to the maximum valid time of
the root bridge device.
ZXAN(config)#spanning-tree max-age 21
4. Set the time interval for the current bridge to send packets.
By default, the time interval for the specific bridge to send the STP BPDU packets is
2 seconds.
This time interval ensures that the configuration information is sent periodically and
keeps the spanning tree stable. If the device does not receive any configuration
information, it regards the information timing out and recalculates the spanning tree.
If the current device is the root bridge device, it sends packets according to the time
interval of the root bridge device. If the current device is a non-root bridge device, it
sends packets also according to the time interval of the root bridge device.
ZXAN(config)#spanning-tree hello-time 3
5. Set the STP forwarding delay time interval of the current bridge.
To prevent temporary loop, when the port state switches from Discarding to
Forwarding and the requirements on port status fast switching are not met, the
intermediate state Learning is set and the status switching process needs certain
time to keep synchronization with the status switching of the remote switch.
8-3
If the current device is the root bridge device, it uses the forwarding delay time interval
of the root bridge device. If the current device is a non-root bridge device, it also uses
the forwarding delay time interval of the root bridge device.
ZXAN(config)#spanning-tree forward-delay 16
Note:
To ensure MSTP to work normally in the network, the maximum valid time for the packet of the
local bridge, the time interval for the current bridge to send packets, and the STP forwarding delay
time interval of the current bridge should meet the following formula:
2 × (forwarding delay time – 1.0 second) ≥ maximum valid time ≥ 2 × (sending time interval + 1.0
second)
To set the version number in mst_config_id, the STP protocol must be enabled. If the
switches need to be configured in one domain, this parameters is mandatory. Keep
the configuration of all switches consistent. The default value is 0.
ZXAN(config)#spanning-tree mst configuration
ZXAN(config-mstp)#revision 10
8-4
Note:
In SSTP and RSTP modes, the ZXA10 C220 only has instance 0, that is CIST. In MSTP mode,
instance 0 exists by default and cannot be deleted.
The devices in one domain should meet all the following requirements:
8-5
If the priorities of the devices are the same, the device with the smallest MAC address
is the root bridge.
ZXAN(config)#spanning-tree mst instance 1 priority 4096
13. Set the maximum hops of the local bridge BPDU packets.
The maximum hops of the BPDU packets in the MST domain ranges from 1 to 40, and
the default value is 20.
In the MST domain, when a BPDU packet is forwarded from the root device of the
spanning tree to other devices, the hop number decreases by one when the packet
passes a device. The device discards the configuration information with the hop
number of 0 to limit the network scale in the domain.
ZXAN(config)#spanning-tree mst max-hops 40
– End of Steps –
Result
The MSTP is configured successfully.
8-6
9.1 Overview
DHCP enables a host on the network to obtain an IP address that ensures its normal
communication and the relevant configuration information from a DHCP server.
DHCP uses UDP as the transmission protocol. The host sends a message to port 67 of
the DHCP server and the DHCP server returns the message to port 68 of the host. The
DHCP working process is as follows:
1. The host sends a broadcast packet DHCPDiscover including the request of the IP
address and other configuration parameters.
2. The DHCP server returns a unicast packet DHCPOffer including the valid IP address
and configuration.
3. The host selects the server which returns the first DHCPOffer and sends a broadcast
packet DHCPRequest to the server, indicating to accept relevant configuration.
4. The selected DHCP server returns a unicast packet DHCPAck for acknowledgement.
At this point, the host can use the IP address and relevant configuration obtained from the
DHCP server for communication.
The ZXA10 C220 supports the following DHCP applications:
l DHCP snooping
On the ZXA10 C220, monitor the DHCP communication process of the specified ONU
in the specified VLAN to record the user IP/MAC relationship of the specified ONU.
Through DHCP snooping, the administrator can locate the access users by the IP
addresses to implement IP address anti-snooping.
l DHCP server
The ZXA10 C220 works as the DHCP server to allocate IP addresses for users.
l DHCP relay
The ZXA10 C220 works in layer-3 switching state as the DHCP relay. It forwards the
user DHCP request to the specified DHCP server.
9-1
The ZXA10 C220 can either work as the DHCP server or DHCP relay. Both of the
applications, however, cannot be used simultaneously on the same VLAN interface.
The ZXA10 C220 uses DHCP snooping to prevent unauthorized DHCP server from
accessing the network. A trusted port needs to be configured for the proper DHCP server.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The xPON service card status is proper.
l The xPON service is configured.
Context
To configure DHCP snooping, perform the following steps:
Steps
1. Use the ip dhcp snooping enable command to enable global DHCP snooping.
2. Use the ip dhcp snooping vlan command to enable DHCP snooping in the VLAN.
3. Use the ip dhcp snooping trust command to set the DHCP server port to the trusted
interface.
4. Use the dhcp-option82 enable command to enable the DHCP Option 82 process
globally.
5. Use the interface command to enter the EPON-ONU interface configuration mode.
6. Use the ip dhcp snooping enable command to enable DHCP snooping in ONU interface
mode.
7. Use the ip dhcp snooping quota command to set the DHCP session count under the
user port.
– End of Steps –
Result
DHCP snooping is configured successfully.
Example
Configure DHCP snooping function with the following parameters:
l Uplink port : gei_0/14/1 (connects to legal DHCP server)
9-2
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The xPON service card status is proper.
l The xPON service is configured.
Context
To configure the DHCP server, perform the following steps:
Steps
1. Use the ip dhcp enable command to enable the global DHCP function.
2. Use the ip local pool command to configure the IP address pool of the DHCP server.
3. Use the ip dhcp server leasetime command to configure the lease time of the DHCP
server IP address.
4. Use the ip dhcp server dns command to configure the DNS address that the DHCP
server returns to the user.
9-3
Note:
When the DHCP server is directly connected with the client subnet, the default gateway address
should be set to the IP address of the interface VLAN.
10. Use the peer default ip pool command to configure the IP address pool of the layer-3
interface.
11. Use the show ip dhcp server user vlan command to query the user information on the
DHCP server.
– End of Steps –
Result
The DHCP server is configured successfully.
Example
The ZXA10 C220 works as the DHCP server and the default gateway. The host obtains
the IP address dynamically through the ZXA10 C220.
l Server interface IP address: 10.10.1.1
l VLAN ID: 10
l IP address pool: 10.10.1.3 – 10.10.1.254
l DNS IP address: 10.10.1.2
l IP address lease period: 90 seconds
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#ip dhcp enable
ZXAN(config)#ip local pool zte 10.10.1.3 10.10.1.254 255.255.255.0
ZXAN(config)#ip dhcp server dns 10.10.1.2
ZXAN(config)#ip dhcp server leasetime 90
ZXAN(config)#vlan 10
ZXAN(config-vlan)#exit
ZXAN(config)#interface vlan 10
ZXAN(config-if)#ip address 10.10.1.1 255.255.255.0
ZXAN(config-if)#ip dhcp mode server
9-4
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The xPON service card status is proper.
l The xPON service is configured.
Context
To configure DHCP relay, perform the following steps:
Steps
1. Use the ip dhcp enable command to enable the global DHCP function.
2. Use the interface vlan command to enter the layer-3 VLAN interface mode.
3. Use the ip address command to configure the IP address of the layer-3 interface.
4. Use the ip dhcp mode command to enable DHCP relay or DHCP proxy on the VLAN
interface.
The DHCP proxy mode is the extension of the DHCP relay mode. The DHCP proxy
mode is used to detect subscriber offline quickly by maintaining different lease periods:
l T1: short-term lease period between the DHCP client and the DHCP relay
l T2: long-term lease period between the DHCP relay and DHCP server
When the subscriber is offline, the DHCP relay detects it during the T1 period, and
then sends a Release packet to the DHCP server to release the server resource.
5. Use the ip dhcp relay agent command to configure the DHCP relay agent address of
the VLAN interface.
Note:
The DHCP relay agent address should be consistent with the IP address configured on the layer-3
interface.
9-5
b. Use the interface vlan command to enter the layer-3 VLAN interface mode.
c. Use the ip dhcp helper-address policy vclass-id command to set the DHCP
packets to be forwarded according to the DHCP Option 60 character strings
in DHCP relay and DHCP proxy modes.
7. Use the show ip dhcp relay user vlan command to query the user information on the
DHCP relay.
– End of Steps –
Result
DHCP relay is configured successfully.
Example
The ZXA10 C220 enables the DHCP relay function. The networking is as shown in Figure
9-1.
9-6
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#ip dhcp enable
ZXAN(config)#interface vlan 200
ZXAN(config-if)#ip address 136.136.136.1 255.255.255.0
ZXAN(config-if)#exit
ZXAN(config)#interface vlan 300
ZXAN(config-if)#ip address 135.135.135.1 255.255.255.0
ZXAN(config-if)#exit
ZXAN(config)#interface vlan 200
ZXAN(config-if)#ip dhcp mode relay
ZXAN(config-if)#ip dhcp relay agent 136.136.136.1
ZXAN(config-if)#exit
ZXAN(config)#ip dhcp relay server vclass-id zte 135.135.135.118 standard
ZXAN(config)#interface vlan 200
ZXAN(config-if)#ip dhcp helper-address policy vclass-id
ZXAN(config-if)#exit
9-7
9-8
10.1 Overview
ACL is used to identify and restrict traffic. A series of matching rules are used to identify
and filter the packets. Packets are identified (according to a predefined policy) before
being permitted or denied
The ZXA10 C220 supports four types of ACL.
l Standard ACL
l Extended ACL
l Link layer ACL
l Hybrid ACL
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The Ethernet port status is proper.
Context
In a standard ACL, rules are defined according to source IP address only.
To configure the standard ACL, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
10-1
Note:
The standard ACL number ranges from 1 to 99. It is applied to the Ethernet port only.
Note:
l Each standard ACL supports up to 127 rules.
l The time range must be configured before it is applied to a rule. If the time range is not
configured, the rule is always effective.
Result
The standard ACL is configured successfully.
Example
Configure a standard ACL on port gei_0/14/1 to deny the packets from the source IP
address 168.1.1.1/24 to access the port during 9:00 – 17:00 on week days.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#time-range worktime 09:00:00 to 17:00:00 working-day
ZXAN(config)#acl standard number 3
ZXAN(config-std-acl)#rule 1 deny 168.1.1.1 0.0.0.255 time-range worktime
ZXAN(config-std-acl)#rule 2 permit any
ZXAN(config-std-acl)#show acl 3
standard acl 3
rule 1 deny 168.1.1.0 0.0.0.255 time-range worktime
rule 2 permit any
ZXAN(config-std-acl)#exit
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#ip access-group 3 in
10-2
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The uplink port status is proper.
l The xPON service card status is proper.
Context
In an extended ACL, rules are defined on the basis of the following:
l Source/destination IP address
l IP protocol type
l Source/destination TCP port number
l Source/destination UDP port number
l ICMP
l IGMP
l DSCP
l ToS
l IP precedence
To configure the extended ACL, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the time-range command to configure the ACL time range.
3. Use the acl extend command to enter the extended ACL configuration mode.
Note:
The extended ACL number ranges from 100 to 199. It can be applied to the Ethernet port and
EPON OLT port.
Note:
l Each extended ACL supports up to 127 rules.
l The time range must be configured before it is applied to a rule. If the time range is not
configured, the rule is always effective.
10-3
Result
The extended ACL is configured successfully.
Example
Configure an extended ACL on port gei_0/14/1 to deny the TCP packets from the source
IP address 192.168.1.0/24 and source port 23 (Telnet).
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl extend number 101
ZXAN(config-ext-acl)#rule 1 deny tcp 192.168.1.0 0.0.0.255 eq telnet any
ZXAN(config-ext-acl)#rule 2 permit tcp any eq telnet any
ZXAN(config-ext-acl)#show acl 101
extended acl 101
rule 1 deny tcp 192.168.1.0 0.0.0.255 eq telnet any
rule 2 permit tcp any eq telnet any
ZXAN(config-ext-acl)#exit
XAN(config)#interface gei_0/14/1
ZXAN(config-if)#ip access-group 101 in
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The Ethernet port status is proper.
l The xPON service card status is proper.
Context
In a link layer ACL, rules are defined on the basis of the following:
l Source/destination MAC address
l Source VLAN ID
10-4
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the time-range command to configure the ACL time range.
3. Use the acl link command to enter the layer-2 ACL configuration mode.
Note:
The layer-2 ACL number ranges from 200 to 299. It can be applied to the Ethernet port and EPON
OLT port.
Note:
l Each layer-2 ACL supports up to 127 rules.
l The time range must be configured before it is applied to a rule. If the time range is not
configured, the rule is always effective.
Result
The layer-2 ACL is configured successfully.
Example
Configure a layer-2 ACL on port gei_0/14/1 to deny the packets from the source MAC
address 0000.0000.0001.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl link number 200
ZXAN(config-link-acl)#rule 1 deny any ingress
0000.0000.0001 0000.0000.0000 egress any
ZXAN(config-link-acl)#rule 2 permit any
ZXAN(config-link-acl)#show acl 200
10-5
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The Ethernet port status is proper.
l The xPON service card status is proper.
Context
In a hybrid ACL, rules are defined according to criteria mentioned in pervious three ACL
types, which include:
l Source/destination MAC address
l Source VLAN ID
l Source/destination IP address
l Source/destination TCP port number
l Source/destination UDP port number
To configure the hybrid ACL, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the time-range command to configure the ACL time range.
3. Use the acl hybrid command to enter the hybrid ACL configuration mode.
Note:
The hybrid ACL number ranges from 300 to 399. It can be applied to the Ethernet port, EPON
OLT port, EPON ONU port, and GPON ONU port.
10-6
Note:
l Each hybrid ACL supports up to 127 rules.
l The time range must be configured before it is applied to a rule. If the time range is not
configured, the rule is always effective.
– End of Steps –
Result
The hybrid ACL is configured successfully.
Example
Configure a hybrid ACL on port gei_0/14/1:
l Deny ARP packets.
l Deny IP packets of the destination IP address 192.168.1.0/24 and source MAC
address 0000.0000.0001.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl hybrid number 300
ZXAN(config-hybd-acl)#rule 1 deny any any any arp
ZXAN(config-hybd-acl)#rule 2 deny any any 192.168.1.0 0.0.0.255
ip ingress 0000.0000.0001 0000.0000.0000 egress any
ZXAN(config-hybd-acl)#rule 3 permit any any any any
ZXAN(config-hybd-acl)#show acl 300
acl hybrid number 300
rule 1 deny any any any arp ingress any egress any
rule 2 deny any any 192.168.1.0 0.0.0.255 ip ingress
0000.0000.0001 0000.0000. 0000 egress any
rule 3 permit any any any any ingress any egress any
ZXAN(config-hybd-acl)#exit
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#ip access-group 300 in
10-7
10-8
11.1 Overview
Service Description
PON supports PON port protection mechanism, which improves the transmission reliability.
When the optical link between the active PON and ONUs is faulty, services are switched
to the backup PON port.
Service Specifications
The ZXA10 C220 provides the protection switchover function in the following ways with
the priorities from high to low:
l Force switchover
l Alarm triggering
l Manual switchover
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The interface VLAN of the upper-layer device is consistent with the VLAN configured
on the uplink port.
l The EPON service card status is proper.
l The EPON service is configured.
11-1
Context
The ZXA10 C220 supports four types of PON port protection:
l Type A
Type A is the OLT-side redundancy protection. The two PON ports of the OLT use one
PON MAC chip and are connected to the two optical modules through the 1:2 electrical
switch to achieve protection on the two PON ports. The OLT side of the splitter has
two input ports and multiple output ports, which are applicable for protection between
the PON ports on the same PON card. This type of protection can only recover the
OLT-side service.
l Type B
Type B is the OLT-side redundancy protection. The two PON ports of the OLT use
independent PON MAC chips and optical modules to achieve protection on the two
PON ports. The OLT side of the splitter has two input ports and multiple output ports,
which are applicable for protection between the PON ports on the same PON card
and among different PON cards. This type of protection can only recover the OLT-side
service.
l Type C
Type C is the OLT-side and ONU-side full redundancy protection, also known as full
duplex protection. The two PON ports on the OLT, two optical modules on the ONU,
backbone fiber, splitter, and distribution fiber all use dual-route redundancy. This type
of protection is implemented in the following modes:
à On the same PON MAC chip on the same PON card
à On different PON MAC chips on the same PON card
à Among different PON cards
The ONU uses one PON MAC chip and different optical modules, and the standby
optical module is in cold standby state. In this configuration mode, the system can
switch to the standby device to recover the service at any time.
l Type D
Type D is the OLT-side and ONU-side full redundancy protection, also known as full
duplex protection. The two PON ports on the OLT, two PON ports on the ONU,
backbone fiber, splitter, and distribution fiber all use dual-route redundancy. This type
of protection is implemented in the following modes:
The ONU uses different PON MAC chips and different optical modules. In this
configuration mode, the system can switch to the standby device to recover the
service at any time.
This topic describes configuration of type B PON port protection.
11-2
Networking Diagram
Figure 11-1 shows the networking diagram of the EPON PON port protection.
The ONU connects two EPON ports of the ZXA10 C220 through a splitter to achieve PON
port protection.
Configuration Data
Table 11-1 lists the configuration data for the EPON PON port protection.
Item Data
Configuration Flow
Figure 11-2 shows the configuration flow of the EPON PON port protection.
11-3
To configure the EPON PON port protection, perform the following steps:
Steps
1. Enter the PON configuration mode. Clear configuration on the protecting PON port
(optional).
In PON mode, use the clear command to clear configuration on the protecting PON
port. If there is no configuration on the protecting PON port, you may skip the step.
ZXAN(config)#pon
ZXAN(config-pon)#clear epon-olt_0/5/2
[Successful]
11-4
Name : zte
Work channel interface : epon-olt_0/5/1
Protect channel interface: epon-olt_0/5/2
Protection type : typeB
Protection mode: revertive
Time to restore(s): 120
Active channel: work-channel
Alarm request:
Work channel: OLTSF CardOff
Protect channel: OLTSF CardOff
Externel request: no-request
The parameters for the PON protection group properties are as follows:
Use the no protection switch-command command to clear all the external switchover
commands, that is, to delete the force command, manual command, or lock command.
11-5
Note:
l Clear all
l Lock protection
l Switch over the working port to protecting port by force
l Switch over the protecting port to working port by force
l Switch over the working port to protecting port manually
l Switch over the protecting port to working port manually
If a lower priority is configured after a higher priority is configured, the lower one does not take
effect. It is necessary to clear the previous mode and then configure the lower priority.
Result
The EPON PON port protection is configured successfully.
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The interface VLAN of the upper-layer device is consistent with the VLAN configured
on the uplink port.
l The GPON service card status is proper.
l The GPON service is configured.
Context
The ZXA10 C220 supports two types of PON port protection:
l Type B
Type B is the OLT-side redundancy protection. The two PON ports of the OLT use
independent PON MAC chips and optical modules to achieve protection on the two
PON ports. The OLT side of the splitter has two input ports and multiple output ports,
11-6
which are applicable for protection between the PON ports on the same PON card
and among different PON cards. This type of protection can only recover the OLT-side
service.
l Type C
Type C is the OLT-side and ONU-side full redundancy protection, also known as full
duplex protection. The two PON ports on the OLT, two optical modules on the ONU,
backbone fiber, splitter, and distribution fiber all use dual-route redundancy. This type
of protection is implemented in the following modes:
This topic describes configuration of type B PON port protection.
Networking Diagram
Figure 11-3 shows the networking diagram of the GPON PON port protection.
The ONU connects two GPON ports of the ZXA10 C220 through a splitter to achieve PON
port protection.
Configuration Data
Table 11-2 lists the data scheme for the GPON PON port protection.
11-7
Item Data
Configuration Flow
Figure 11-4 shows the configuration flow of the GPON PON port protection.
Steps
1. Enter the PON configuration mode. Clear configuration on the protecting PON port
(optional).
In PON mode, use the clear command to clear configuration on the protecting PON
port. If there is no configuration on the protecting PON port, you may skip the step.
ZXAN(config)#pon
ZXAN(config-pon)#clear gpon-olt_0/10/2
11-8
[Successful]
2. Enter the PON mode and configure the PON protection group.
In PON mode, use the protection group command to create the PON protection group.
ZXAN(config)#pon
ZXAN(config-pon)#protection group zte workpon gpon-olt_0/10/1 protectpon
gpon-olt_0/10/2 typeB
.[Successful]
ZXAN(config-pon)#show protection group list
zte
Name : zte
Work channel interface : gpon-olt_0/10/1
Protect channel interface: gpon-olt_0/10/2
Protection type : typeB
Protection mode: revertive
Time to restore(s): 120
Active channel: work-channel
Alarm request:
Work channel: No alarm request!
Protect channel: OLTSF
Externel request: no-request
The parameters for the PON protection group properties are as follows:
l Switchover mode: Revertive mode and non-revertive mode. By default, it is
non-revertive mode.
l Time to restore: The time to wait for restoration. When the protection mode is
non-revertive, the time interval is 0. When the mode is revertive, the time interval
is greater than 30 seconds in general.
4. (Optional) Configure the switchover mode between the working port and protecting
port of the protection group.
Use the protection switch-command command to configure the switchover mode
between the working port and protecting port of the protection group. This instance
uses the default mode (no switchover mode). To configure the mode, use the
following command:
ZXAN(config-pon)#protection switch-command group zte force p2w
11-9
l Force: Work on this port regardless the status. You can switch over between the
protecting port and working port by force.
l Manual: Switch over to a port manually. You can switch over between the pro-
tecting port and working port manually.
l Lockoutprotect: Disable protection.
Use the no protection switch-command command to clear all the external switchover
commands, that is, to delete the force command, manual command, or lock command.
Note:
l Clear all
l Lock protection
l Switch over the working port to protecting port by force
l Switch over the protecting port to working port by force
l Switch over the working port to protecting port manually
l Switch over the protecting port to working port manually
If a lower priority is configured after a higher priority is configured, the lower one does not take
effect. It is necessary to clear the previous mode and then configure the lower priority.
Result
The GPON PON port protection is configured successfully.
11-10
12.1 Overview
The ZXA10 C220 provides uplink port service protection to enhance the service
transmission stability.
The ZXA10 C220 supports the following uplink protection features:
l UAPS
l CTLA 1+1
l Link aggregation
l ZTE Ethernet Switch Ring
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The uplink port status is proper.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
The ZXA10 C220 supports the UAPS. The system periodically checks the working status
of the uplink port. When the system detects that the working port state is link down or the
link is disconnected, it switches the services to the standby port automatically and without
12-1
interrupting the services. Then, the original working port is switched to the standby port
and the original standby port is switched to the working port.
The working port transmits data while the standby port does not.
To configure the UAPS, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
The detection period takes effect only when the next-hop IP address is configured.
10. Use the port-optical-tx-control command to enable/disable the optical function on the
standby port by force.
12-2
Note:
If this function is enabled, the UAPS optical port of the local NE and the peer device should disable
the auto-negotiation mode and enable force mode.
ZXAN(config)#interface xgei_0/2/1
ZXAN(config-if)#no negotiation auto
11. Use the swap command to switch the UAPS group ports by force.
The active and standby ports in the UAPS group can be switched only when the
standby port is up.
12. Use the show uaps groupid command to view the UAPS group status.
– End of Steps –
Result
The UAPS is configured successfully.
Example
Configure a UAPS group:
l Group ID: 1
l Active port: gei_0/6/1
l Standby port: gei_0/6/2
l Protection time: 400 s
l Switch-type: common port
l Revertive control: enabled
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#uaps-group 1
ZXAN(cfg-uaps-1)#port master-portlist gei_0/6/1
slave-portlist gei_0/6/2
ZXAN(cfg-uaps-1)#protect-time 400
ZXAN(cfg-uaps-1)#switch-type common-port
ZXAN(cfg-uaps-1)#revertive enable
ZXAN(cfg-uaps-1)#show uaps groupid 1
Revertive control : enable
PortLight control : disable
Protect-time : 400s
Next-hop : 0.0.0.0
Bfd next_hop : 0.0.0.0
Link-type : normal
Link-detect-retry : 5
Link-detect-interval : 3
12-3
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The CES service card status is proper.
l The user service is configured.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
The CL1A 1+1 protection means two CL1A cards to protect each other. One CL1A card
is the working card, connecting to the SDH of the opposite end, as the working channel.
The other CL1A card is the protecting card, connection to the SDH of the opposite end, as
the protecting channel.
1+1 protection works in concurrently transmitting and preferably receiving mode.
l On the CL1A->SDH transmitting direction, the working CL1A and protection CL1A
transmit the data simultaneously. And the SDH of the opposite end receives the data
from one channel.
l On the SDH->CL1A direction, the working channel and protection channel receive
the data simultaneously. The main control card receives data from one channel,
discarding data from the other channel.
To create the protection group, the CES source MAC address of the working card must
keep consistent with that of the protection card. No service is allowed when the address
is configured.
If both CL1A cards use STM-1 interface for the uplink service, two MAC addresses must
be configured:
12-4
Note:
When the protection group is created, the inner ports of the working card and protection
card need to be added to the corresponding service VLAN at the same time.
ZXAN(config)#interface tdm-gei_0/14/1-2
ZXAN(config-if-range)#switchport vlan 4000 tag
ZXAN(config-if-range)#exit
ZXAN(config)#interface tdm-gei_0/13/1-2
ZXAN(config-if-range)#switchport vlan 4000 tag
Steps
1. Use the configure terminal command to enter the global configuration mode.
If manual switch-over is selected, the working card can receive other switch-over
commands. When there is a switch-over alarm , the working card is switched
over to the protection card. When the alarm disappears, the protection card is
automatically switched back to the working card.
12-5
6. Use the show ces sdhprot group count command to query the quantity of protection
groups.
7. Use the show ces sdhprot group prop command to query the detailed properties of the
protection groups.
8. Use the show ces sdhprot switch-command command to query the external switchover
commands used by the specified protection group.
9. Use the show ces sdhprot request command to query all the requested messages of
the specified protection group, including the alarm request and external switchover
request.
10. Use the show ces sdhprot sync-data progress-bar command to query the data
synchronization process between the working card and the protection card.
After the protection group is created, the service configuration is disabled on the
protection card while the service is configured on the working card. The service on
the working card is synchronized to the protection card automatically.
The protection group can also be created after the service is configured on the working
card to implement the 1+1 protection.
– End of Steps –
Result
The CL1A 1+1 protection is configured successfully.
Example
Configure the CL1A 1+1 protection.
l Protection group name: aaa
l Working optical port: tdm_0/14/1
l Protection optical port: tdm_0/13/1
l Mode: non-revertive
l Switchover by force: from the working port to the protection port
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#ces
ZXAN(config-ces)#sdhprot group aaa worksdhport tdm_0/14/1
protectsdhport tdm_0/13/1 1plus1
ZXAN(config-ces)#sdhprot switch-command group aaa force w2p
ZXAN(config-ces)#show ces sdhprot group prop aaa
Name : aaa
Protect interface: tdm_0/13/1
Work interface : tdm_0/14/1
Active interface: protect-channel
Type : 1+1
12-6
Mode: non-revertive
Holdoff: 0
Wtr: 0
Prerequisites
Before this operation, make sure that:
Context
The ZXA10 C220 supports two types of link aggregation:
l Static trunk
Static trunk directly adds multiple physical ports to a trunk group, thus forming a logical
port. In this mode, users cannot observe the status of the link aggregated ports.
l LACP
LACP converges multiple physical ports into a trunk group to form a logical port and
automatically generates aggregation to obtain the maximum bandwidth.
The following are rules for link aggregation configuration on the ZXA10 C220:
l Supports maximum eight trunk groups, with maximum eight ports in each trunk group.
l Member ports must in full duplex mode.
l VLAN Mode of the member port must be consistent, such as access, trunk, or hybrid.
The logical port formed by link aggregation on the ZXA10 C220 is called smartgroup. A
smartgroup can be used as a common port, and has the same default VLAN properties as
common Ethernet ports.
To configure the link aggregation, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
12-7
Note:
The default mode is based on the source and destination MAC addresses.
Note:
l On: The port runs static trunk. Both end of the aggregated link should be set to the on mode.
l Passive: The port runs LACP in passive negotiation mode.
It is recommended to set one end to active mode and the other end to passive, or set both
ends to active.
The VLAN properties of a member port should be consistent with that of the smartgroup. Other-
wise, the port cannot be added to the trunk group.
– End of Steps –
Result
The link aggregation is configured successfully.
Example
The ZXA10 C220 connects to switch B through the smartgroup port, which is aggregated
by four physical ports: gei_0/14/1 – gei_0/14/4. The port mode of smartgroup is trunk. The
port bears VLAN 10 and VLAN 20. It uses the load-balance mode based on the source IP
address.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#interface smartgroup1
ZXAN(config-if)#switchport mode trunk
12-8
Prerequisites
Before this operation, make sure that:
Context
The ZESR provides protection to the ring that is composed of uplink ports of multiple
ZXA10 C220s. When one or multiple uplink ports are faulty, the services are switched
to the secondary port.
l ZESR domain
A ZESR domain, where the ZESR protocol is valid, consists of a master node, multiple
transit nodes, the corresponding control VLAN, and protected VLANs. A typical ZESR
domain equals to a physical ring topology.
12-9
l Master node
There is only one master node in each ZESR domain. The master node sends
health-check control messages to detect status of the ring, and blocks/unblocks
ports.
l Transit node
Transit nodes are the other nodes in a ZESR domain which receive and froward
health-check control messages. Transit nodes detects status of their ports in the ring.
If there is a link disconnection, the transit node informs the master node.
l Primary port
The primary port in the master node sends health-check control messages in the
control VLAN. Primary ports in transit nodes only forward messages.
l Secondary port
The secondary port in the master node receives and detects health-check control
messages. When the ring is in proper state, the port status is block, which means the
port blocks all packets in protected VLANs. When the ring is invalid, the secondary
port status changes to forward.
l Control VLAN
There is only one control VLAN in each ZESR. Health-check control messages are
transited in the control VLAN. On each node, there are only two ports in the control
VLAN. When the secondary port on the master node is in block status, it still receives
data messages in the control VLAN.
l Protected VLAN
Protected VLANs are service VLANs which carry user data. When a ZESR is in the
proper ‘complete’ status, the secondary port in the master node blocks all packets in
protected VLAN to avoid packets storm.
To configure the ZESR, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the vlan command to configure the control VLAN and protected VLAN.
3. Use the spanning-tree enable command to enable STP.
4. Use the spanning-tree mst configuration command to enter the STP configuration
mode.
5. Use the instance command to configure STP instance and VLAN mapping.
6. Use the interface command to enter the uplink port configuration mode.
7. Use the switchport vlan command to configure uplink port of the control VLAN and
protected VLAN.
8. Use the zesr command to configure ZESR domain.
12-10
Result
The ZESR is configured successfully.
Example
A typical ZESR networking diagram is shown in Figure 12-1.
12-11
ZXAN(vlan)#vlan 500-600,1000
ZXAN(vlan)#exit
ZXAN(config)#spanning-tree enable
ZXAN(config)#spanning-tree mst configuration
ZXAN(config-mstp)#instance 1 vlans 1000
ZXAN(config-mstp)#instance 2 vlans 500-600
ZXAN(config-mstp)#exit
ZXAN(config)#interface gei_0/12/1-2
ZXAN(config-if-range)#switchport vlan 1000 tag
ZXAN(config-if-range)#switchport vlan 500-600 tag
ZXAN(config-if-range)#exit
ZXAN(config)#zesr ctrlvlan 1000 master 0 primaryport gei_0/12/1 secondport
gei_0/12/2 protectInstance 2 ctrlInstance 1 //master 1 means the master node
ZXAN(config-if)#show zesr ctrlvlan 1000
zesr domain:
ctrlvlan : 1000
state : complete
node type : Master
healthtime : 1000ms
failtime : 3000ms
preforwardtime : 3000ms
protectInstance : 2
ctrlvlanInstance : 1
primaryport status : forward
gei_0/12/1 : up
secondport status : block
gei_0/12/2 : up
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#vlan database
ZXAN(vlan)#vlan 500-600,1000
ZXAN(vlan)#exit
ZXAN(config)#spanning-tree enable
ZXAN(config)#spanning-tree mst configuration
ZXAN(config-mstp)#instance 1 vlans 1000
ZXAN(config-mstp)#instance 2 vlans 500-600
ZXAN(config-mstp)#exit
ZXAN(config)#interface gei_0/12/1-2
ZXAN(config-if-range)#switchport vlan 1000 tag
ZXAN(config-if-range)#switchport vlan 500-600 tag
ZXAN(config-if-range)#exit
ZXAN(config)#zesr ctrlvlan 1000 master 1 primaryport gei_0/12/1 secondport
gei_0/12/2 protectInstance 2 ctrlInstance 1 //master 1 means the transit node
12-12
12-13
12-14
13.1 Overview
Service Description
QoS indicates the performance of data flows when they pass the network. QoS provides
the peer-to-peer quality assurance through a series of metrics such as the service
availability, throughput, delay/jitter, and packet loss ratio.
Service Specification
The ZXA10 C220 support various QoS operations, including traffic classification and mark,
congestion management, traffic monitoring and shaping.
l It uses ACL to classify packets according to the physical interface, MAC address, IP
address, protocol type, or application port number. Meanwhile, it marks the 802.1q
priority or ToS/DSCP priority of the packets.
l It supports traffic shaping based on the port, queue, or policy, and is applicable for
multiple service models.
l It supports priority marking based on the packet classification result or physical port.
l Both the user side and network side support eight CoS queues. The network side
supports FQ, SP, and WRR scheduling. The user side supports SP, WRR, and
SP+WRR scheduling.
13-1
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The port for traffic limit works normally.
Context
Traffic limit restrains the bandwidth of certain service traffic. When the service bandwidth
exceeds the limit, the optional actions are as follows:
l Discard or forward the packets.
l Modify DSCP.
l Modify the drop precedence.
To configure the traffic limit, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the acl command to configure the ACL.
3. Use the rule command to configure the ACL rules.
4. Use the traffic-limit in command to configure the traffic limit.
5. In Ethernet interface mode, use the ip access-group acl in command to apply the ACL
to the uplink port.
6. In EPON-OLT interface mode, use the ip access-group acl in command to apply the
ACL to the EPON-OLT port.
7. In EPON-ONU interface mode, use the ip access-group acl{ in | out} [ vport vport]
command to apply the ACL to the EPON-ONU interface.
– End of Steps –
Result
The traffic limit is configured successfully.
Example
Limit the traffic of the packets whose source IP address is 168.2.5.5 on ports gei_0/14/1
and epon-onu_0/6/4:1.
13-2
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl hybrid number 300
ZXAN(config-hybd-acl)#rule 1 permit any 168.2.5.5 0.0.0.0 any any
ZXAN(config-hybd-acl)#rule 2 permit any any any any
ZXAN(config-hybd-acl)#exit
ZXAN(config)#show acl 300
acl hybrid number 300
rule 1 permit any 168.2.5.5 0.0.0.0 any any ingress any egress any
rule 2 permit any any any any ingress any egress any
ZXAN(config)#traffic-limit in 300 rule-id 1 cir 5000 cbs 2000
pir 10000 pbs 2000 mode blind
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#ip access-group 300 in
ZXAN(config-if)#exit
ZXAN(config)#interface epon-onu_0/6/4:1
ZXAN(config-if)#ip access-group 300 in
ZXAN(config-if)#exit
Prerequisites
Before this operation, make sure that:
Context
Priority mark is used to assign priorities to certain packets according to ACL rules. It
supports the following operations:
Note:
The ToS priority and DSCP priority are mutually exclusive and cannot be configured at the same time.
13-3
The ZXA10 C220 supports ACL configuration on the uplink port, OLT port, and ONU bridge
port.
To configure the priority mark, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the acl command to configure the ACL.
Result
Priority mark is configured successfully.
Example
Configure the priority mark on the traffic that matches ACL rules and is received on ports
gei_0/14/1 and epon-onu_0/6/4:1. The DSCP priority is 10, the local priority is 0, and the
drop precedence is low.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl hybrid number 300
ZXAN(config-hybd-acl)#rule 1 permit any 168.2.5.5 0.0.0.0 any any
ZXAN(config-hybd-acl)#rule 2 permit any any any any
ZXAN(config-std-acl)#exit
ZXAN(config)#priority-mark in 300 rule-id 1 dscp 10 local-precedence 0
drop-precedence low
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#ip access-group 300 in
ZXAN(config-if)#exit
ZXAN(config)#interface epon-onu_0/6/4:1
ZXAN(config-if)#ip access-group 300 in
13-4
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The source port and destination port for traffic mirroring work normally.
Context
The ZXA10 C220 supports ACL configuration on the uplink port, OLT port, and PON-ONU)
interface .
l The system supports only one mirroring destination port.
l Multiple ports can be mirrored to one destination port.
l The mirroring destination port cannot be the aggregation port.
To configure the traffic mirroring, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the acl command to configure the ACL.
3. Use the rule command to configure the ACL rules.
4. Use the traffic-mirror in command to configure traffic mirroring.
5. In Ethernet interface mode, use the ip access-group acl in command to apply the ACL
to the uplink port.
6. In EPON-OLT interface mode, use the ip access-group acl in command to apply the
ACL to the EPON-OLT port.
7. In xPON-ONU interface mode, use the ip access-group acl in [ vport vport] command
to apply the ACL to the xPON-ONU interface.
– End of Steps –
Result
The traffic mirroring is configured successfully.
Example
Mirror the traffic that matches ACL rule 10 received from port gei_0/14/1 to port gei_0/14/2.
ZXAN(config)#acl standard number 10
ZXAN(config-std-acl)#rule 1 permit 168.2.5.5
ZXAN(config-std-acl)#rule 2 permit any
13-5
ZXAN(config-std-acl)#exit
ZXAN(config)#traffic-mirror in 10 rule-id 1 interface gei_0/14/2
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#ip access-group 10 in
Prerequisites
Before this operation, make sure that:
Context
Redirection modifies the egress direction of packets according to traffic classification. The
direction may be modified to a specified port, CPU, or next-hop IP address.
To configure the redirection, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the acl command to configure the ACL.
3. Use the rule command to configure the ACL rules.
4. Use the redirect in command to redirect the traffic that matches the ACL rules.
5. In Ethernet interface mode, use the ip access-group acl in command to apply the ACL
to the uplink port.
6. In EPON-OLT interface mode, use the ip access-group acl in command to apply the
ACL to the EPON-OLT port.
7. In xPON-ONU interface mode, use the ip access-group acl in [ vport vport] command
to apply the ACL to the xPON-ONU interface.
– End of Steps –
Result
The redirection is configured successfully.
13-6
Example
Redirect the packets whose source IP address is 168.2.5.5 from port gei_0/14/4 to port
gei_0/14/3. Configure policy routing on the packets whose destination IP address is
166.100.5.6. Specify the next-hop IP address 166.88.96.56.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl extend number 100
ZXAN(config-ext-acl)#rule 1 permit ip 168.2.5.5 0.0.0.0 any
ZXAN(config-ext-acl)#rule 2 permit ip any 66.100.5.6 0.0.0.0
ZXAN(config-ext-acl)#rule 3 permit ip any any
ZXAN(config-ext-acl)#exit
ZXAN(config)#redirect in 100 rule-id 1 interface gei_0/14/3
ZXAN(config)#redirect in 100 rule-id 2 next-hop 166.88.96.56
ZXAN(config)#interface gei_0/14/4
ZXAN(config-if)#ip access-group 100 in
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The port for traffic statistics works normally.
Context
Traffic statistics is used to collect statistics on the packets of specific service flows. It
counts quality and bytes of the packets arrived at the ingress port.
To configure the traffic statistics, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the acl command to configure the ACL.
5. In Ethernet interface mode, use the ip access-group acl in command to apply the ACL
to the uplink port.
13-7
6. In EPON-OLT interface mode, use the ip access-group acl in command to apply the
ACL to the EPON-OLT port.
7. In xPON-ONU interface mode, use the ip access-group acl in [ vport vport] command
to apply the ACL to the xPON-ONU interface.
8. Use the show traffic-statistics command to query the traffic statistics information.
9. In privilege mode, use the clear traffic-statistics command to clear traffic statistics.
– End of Steps –
Result
The traffic statistics is configured successfully.
Example
Collect statistics on the traffic that matches ACL rule 300 received on ports gei_0/14/2 and
epon-onu_0/6/4:1.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl hybrid number 300
ZXAN(config-hybd-acl)#rule 1 permit any 168.2.5.5 0.0.0.0 any any
ZXAN(config-hybd-acl)#rule 2 permit any 67.100.88.0 0.0.0.255 any any
ZXAN(config-hybd-acl)#rule 3 permit any any any any
ZXAN(config-ext-acl)#exit
ZXAN(config)#traffic-statistics in 300 rule-id 1 pkt-type
all statistics-type byte
ZXAN(config)#traffic-statistics in 300 rule-id 2 pkt-type
all statistics-type packet
ZXAN(config)#interface gei_0/14/2
ZXAN(config-if)#ip access-group 300 in
ZXAN(config-if)#exit
ZXAN(config)#interface epon-onu_0/6/4:1
ZXAN(config-if)#ip access-group 300 in
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The uplink port works normally.
13-8
Context
Traffic shaping controls the speed rate of the output packets so that the packets are sent
at a constant speed. Traffic shaping is used to set the packet speed rate to match that of
the receiving device, to avoid congestion or packet discarding.
By default, the output traffic shaping function is disabled.
To configure the traffic shaping, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the qos traffic-shape command to configure traffic shaping on the uplink port.
3. In EPON-OLT interface mode, use the qos traffic-shape command to configure traffic
shaping on the PON port.
– End of Steps –
Result
The traffic shaping is configured successfully.
Example
Configure the traffic shaping on uplink port gei_0/14/1.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#qos traffic-shape rate-limit 1024 bucket-size 2048
l The ZXA10 C220 supports eight queues and schedules the queues according to the
queue priorities. The queue with larger queue ID has higher priority.
l The mapping relations between the queues and the 802.1p priorities can be
configured.
l The queue depth can be configured.
l The ZXA10 C220 supports three queue scheduling modes:
à SP (default)
à WRR
13-9
à SP + WRR
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
Each physical port of the ZXA10 C220 supports eight (0 – 7) output queues, which are
called CoS queues. The device performs operations on the output queues on the entry
port according to the CoS queues corresponding to the packet 802.1p. When congestion
occurs on the network, multiple packets may compete for one resource. Queue scheduling
can solve this problem.
The ZXA10 C220 supports three queue scheduling modes:
l SP
Queue scheduling follows the priorities strictly. The packets of the queue with higher
priority are sent first. By default, this mode is used.
l WRR
The eight queues have weights from high to low (w7 – w0). The weight indicates
the proportion of obtaining resources. WRR implements round scheduling between
queues to ensure that each queue has certain service time.
l SP + WRR
This mode is the combination of the previous modes. Some queues use SP
scheduling and some use WRR scheduling. When the WRR value is specified to 0,
the queue uses the SP scheduling.
On the network side, the ZXA10 C220 supports three queue scheduling modes:
l Fair-queue
l SP
l WRR
Note:
13-10
The ZXA10 C220 PON port supports three types of queue scheduling modes:
l SP
l WRR
l SP+WRR
To configure the queue scheduling, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. In Ethernet mode, use the qos queue-mode command to configure the queue
scheduling mode on the network-side port.
Note:
Note:
The system supports five profiles. The default QoS queue block profile is _DFT_QUEUE_BLOC
K_PRF, which cannot be modified or deleted. The user can create and configure the other four
profiles as required.
4. Use the queue-block command to configure the queue scheduling profile parameters
of the PON port.
Note:
The queue depth of each default PON port is 48, which cannot be configured arbitrarily.
5. In xPON-OLT interface mode, use the qos queue-block-profile command to apply the
queue scheduling profile to the specified OLT port.
– End of Steps –
Result
The queue scheduling is configured successfully.
Example
Configure SP queue scheduling on port gei_0/14/1.
13-11
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#interface gei_0/14/1
ZXAN(config-if)#qos queue-mode strict-priority
Configure WRR queue scheduling on port epon-olt_0/5/1, with the weights of 10, 10, 20,
20, 10, 10, 10, and 10 and the queue depth of 48.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#qos-user-side queue-block-profile test
ZXAN(cfg-queue-prf)#queue-block queue0 10 48 queue1 10 48
queue2 20 48 queue3 20 48 queue4 10 48 queue5 10 48
queue6 10 48 queue7 10 48
ZXAN(cfg-queue-prf)#exit
ZXAN(config)#show qos-user-side queue-block-profile test
---------------------------------------------------------
profile name : TEST
profile detail :
queue-block ---- queue_number : 0 1 2 3 4 5 6 7
---- queue_weight : 10 10 20 20 10 10 10 10
---- queue_depth : 48 48 48 48 48 48 48 48
profile used by :
ZXAN(config)#interface epon-olt_0/5/1
ZXAN(config-if)#qos queue-block-profile test
Prerequisites
Before this operation, make sure that:
Context
Table 13-1 lists the default mapping between queues and 802.1p priorities.
13-12
0 0 0 1
1 1 0 1
2 2 0 1
3 3 0 1
4 4 0 1
5 5 0 1
6 6 0 1
7 7 0 1
To configure the mapping between queues and 802.1p priorities, perform the following
steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the qos-network-side cos-local-map command to configure the mapping table
between the network-side 802.1p user priorities and the local queues.
3. Use the qos-network-side cos-drop-map command to configure the mapping table
between network-side 802.1p user priorities and the local drop precedences.
4. Use the qos-network-side trust-cos enable command to enable mapping between
network-side 802.1p priorities and queues.
Note:
If mapping is enabled, the incoming data is mapped from CoS to queues according to the cos-
local-map table.
Note:
The system supports five mapping profiles. The default profile name is _DFT_COS_QUEUE_MA
P_PRF, which cannot be modified or deleted. The user can create and configure the other four
mapping profiles as required.
6. Use the cos-queue-map command to configure the mapping between the 802.1p user
priorities to the local queues.
13-13
7. In OLT interface mode, use the qos cos-queue-map-profile command to apply the
mapping profile on the OLT interface.
8. Use the show qos-network-side cos-local-map command to query the mapping between
the network-side port 802.1p priorities and queues.
9. Use the show qos-network-side cos-drop-map command to query the mapping between
the network-side port 802.1p user priorities to the local drop precedence.
10. Use the show qos-network-side trust-cos command to query the mapping function on
the network-side port
11. Use the show qos-user-side cos-queue-map-profile command to query the information
on the mapping profile from the user-side port 802.1p priorities to queues.
– End of Steps –
Result
The mapping between queues and 802.1p priorities is configured successfully.
Example
Configure the mapping on the network-side port.
l 802.1p priority 0 to queue 0
l 802.1p priority 1 to queue 2
l Other priorities to queue 6
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#qos-network-side cos-local-map cos0 0 cos1 2 cos2 6 cos3 6 cos4 6
cos5 6 cos6 6 cos7 6
ZXAN(config)#qos-network-side trust-cos enable
13-14
---- queue : 0 2 6 6 6 6 6 6
---- drop : 0 0 0 0 0 0 0 0
profile used by :
ZXAN(config)#interface epon-olt_0/5/1
ZXAN(config-if)#qos cos-queue-map-profile test
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
By default, the mapping between the CoS (802.1p) priorities and DSCP priorities on the
ZXA10 C220 are as follows:
l Table 13-2 lists the mapping relationship between the DSCP priority and CoS priority
in qos-network-side conform-dscp. The default drop precedence is 0.
Table 13-2 Mapping Between DSCP Priority and CoS (802.1p) Priority
0-7 0
8 - 15 1
16 - 23 2
24 - 31 3
32 - 39 4
40 - 47 5
48 - 55 6
56 - 63 7
13-15
To configure the mapping between the CoS (802.1p) priorities and DSCP priorities, perform
the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the qos-network-side conform-dscp command to configure the DSCP value to
service priority mapping on the network-side port.
Note:
3. Use the qos-network-side trust-dscp enable command to enable DSCP mapping on the
network-side port.
4. Use the qos-user-side cos-dscp-map command to configure the mapping relations
between the user-side port CoS (802.1p) values and the DSCP values and modify
the DSCP priority according to the 802.1p priority.
Note:
This mapping table is used when the DSCP mode is trust-cos-map on the port or virtual port.
5. Use the qos-user-side dscp-cos-map command to configure the mapping between the
user-side port DSCP values and the CoS (802.1p) values and modify the 802.1p
priority according to the DSCP priority.
Note:
This mapping is used when the mode of CoS or CTAG-CoS is trust-dscp-map on the port or virtual
port.
6. Use the show qos-network-side conform-dscp command to query the mapping between
the network-side port CoS (802.1p) priorities and DSCP priorities.
7. Use the show qos-network-side trust-dscp command to query the DSCP mapping status
on the network-side port.
8. Use the show qos-user-side cos-dscp-map command to query the mapping between the
user-side port CoS (802.1p) values and DSCP values.
9. Use the show qos-user-side dscp-cos-map command to query the mapping between the
user-side port DSCP values and CoS (802.1p) values.
– End of Steps –
13-16
Result
The mapping between CoS and DSCP is configured successfully.
Example
Configure the priority mapping table on the network-side port:
l DSCP of the received packet: 0
l Modify the DSCP value to 61
l CoS: 0
l Drop precedence: 2
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#qos-network-side conform-dscp 0 61 0 2
ZXAN(config)#qos-network-side trust-dscp enable
ZXAN(config)#show qos-network-side conform-dscp
--------------------------------------------------------------------
dscp list 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
dscp value 61 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
cos value 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
drop priority 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
------------------------------------------------------------------
dscp list 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
dscp value 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31
cos value 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
drop priority 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
---------------------------------------------------------------
dscp list 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47
dscp value 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47
cos value 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
drop priority 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
--------------------------------------------------------------
dscp list 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63
dscp value 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63
cos value 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
drop priority 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
ZXAN(config)#show qos-network-side trust-dscp
-----------------------------------
trust-dscp: Enable
13-17
Prerequisites
Before this operation, make sure that:
Context
By default, the system uses the default QoS profile _DFT_VIRTUAL_PORT_PRF on all the
bridge ports. The detailed parameters are as follows:
ZXAN(config)#show qos-user-side virtual-port-profile
_DFT_VIRTUAL_PORT_PRF
-------------------------------------------------------
profile name : _DFT_VIRTUAL_PORT_PRF
profile detail :
cos-filter ---- : disable
def-scos ---- : 0
cos-remark-profile ---- : _DFT_COS_REMARK_PRF
ingress-cos-set-mode ---- : trust
egress-cos-set-mode ---- : trust
ingress-dscp-set-mode ---- : trust
profile used by :
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the qos-user-side virtual-port-profile command to create a bridge port QoS profile.
Note:
The system supports five profiles. The system default profile is _DFT_VIRTUAL_PORT_PRF,
which cannot be modified or deleted. The user can create and configure the other four map-
ping profiles as required.
When this function is enabled and the CoS value in the ingress packet is inconsistent
with the default CoS value of the virtual port, this packet is discarded.
5. Use the ingress-cos-set-mode command to configure the upstream CoS priority setting
mode on the PON port.
13-18
Note:
l trust: Keep the CoS value of the upstream data stream the same.
l scos-override: Change the CoS field of the external tag according to the def-scos value.
l scos-remark: Change the CoS field of the external tag according to the CoS remark profile.
l ccos-scos-remark: Change the CoS field of both the external and internal tags according
to the CoS remark profile.
Note:
l trust: Set the CoS field according to the CoS value of the ingress packet.
l trust-dscp-map: Implement mapping according to the mapping table from the DSCP values
to the CoS (802.1p) values.
l remark: Change the CoS field according to the CoS remark profile.
7. Use the ingress-dscp-set-mode command to configure the upstream DSCP value setting
mode on the PON port.
Note:
l trust: Keep the DSCP value of the upstream data stream the same.
l trust-cos-map: Implement mapping according to the mapping table from the CoS (802.1p)
values to the DSCP values.
8. Use the cos-remark-profile command to configure the CoS remark profile correlated
to the virtual port.
Before carrying out this command, use the qos-user-side cos-remark-profile command
in global configuration mode to create the CoS remark profile.
ZXAN(config)#qos-user-side cos-remark-profile test
ZXAN(cfg-cos-remark-prf)#cos-remark cos0 2
cos1 6 cos2 7 cos3 3 cos4 4 cos5 5
cos6 0 cos7 1
ZXAN(cfg-cos-remark-prf)#exit
By default, all the virtual ports is correlated to CoS profile _DFT_COS_REMA RK_PRF.
13-19
11. Use the show qos-user-side virtual-port-profile command to query the QoS profile
configuration on the bridge port.
– End of Steps –
Result
Bridge port QoS is configured.
Example
Create bridge port QoS profile: test.
l Default bridge port CoS value: 2
l Upstream CoS value mode: override
l Apply the profile to VPORT1 of port epon-onu_0/5/1:1
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#qos-user-side virtual-port-profile test
ZXAN(cfg-qos-vport-prf)#def-scos 2
ZXAN(cfg-qos-vport-prf)#ingress-cos-set-mode override
ZXAN(cfg-qos-vport-prf)#exit
ZXAN(config)#show qos-user-side virtual-port-profile test
---------------------------------------------------------
profile name : TEST
profile detail :
cos-filter ---- : disable
def-scos ---- : 2
cos-remark-profile ---- : _DFT_COS_REMARK_PRF
ingress-cos-set-mode ---- : scos-override
egress-cos-set-mode ---- : trust
ingress-dscp-set-mode ---- : trust
profile used by :
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#qos virtual-port-profile test vport 1
ZXAN(config-if)#exit
13-20
14.1 Overview
The ZXA10 C220 supports the following user security features:
l Port location
l ARP anti-spoofing
l ARP agent
l PON port loopback detection
l Dual-layer VLAN interconnection
14.2.1 Overview
The ZXA10 C220 provides the port location mechanism to improve network security
and prevent user accounts from being stolen. Port location can be implemented by the
following methods:
l DHCP Option 82
l PPPoE+
14-1
Prerequisites
Before this operation, make sure that:
Context
l The Option 82 field includes CID (Circuit ID), RID (Remote ID), and sub-option90
(optional), and provides the information, such as the shelf number, slot number, port
number, VPI, and VCI.
l Only when DHCP Option 82 is enabled, the Option 82 field can be added/stripped
to/from the DHCP packets.
l When DHCP Option 82 is disabled, the system transparently transmits or directly
forwards the DHCP packets without any processing.
To configure the DHCP Option 82 function, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the dhcp-option82 enable command to enable global DHCP Option 82.
3. Use the port-location access-node-identifier command to configure access node ID in
the user ID.
4. Use the port-location hostname command to configure the host name for port location.
This command is mandatory when port-location access-node-identifier is set to the host
name.
5. Use the interface command to enter the xPON-ONU interface mode.
6. Use the port-location format command to configure the Agent Circuit ID format.
7. Use the port-location sub-option remote-id command to enable or disable the DHCP
Option 82 Remote ID field.
8. Use the port-location sub-option remote-id name command to configure the remote ID
of port DHCP Option 82.
9. Use the dhcp-option82 enable command to enable the port DHCP Option 82 function.
10. Use the dhcp-option82 trust command to configure the port to trust/untrust port and
configure the processing policy.
14-2
Note:
If it is a Trust port, the user can select the Keep or Replace policy. If it is an Untrust port, the user
can select the Discard or Add policy.
11. Use the show port-location global command to query the global configuration of port
location.
12. Use the show port-location port command to query the port-level configuration of port
location.
13. Use the show dhcp-option82 global command to query the global configuration of DHCP
Option 82.
14. Use the show dhcp-option82 port command to query the port-level configuration of
DHCP Option 82.
– End of Steps –
Result
The DHCP Option 82 function is configured successfully.
Example
Configure the DHCP Option 82 function.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#dhcp-option82 enable
ZXAN(config)#port-location access-node-identifier inband-mac
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#port-location format china-telecom vport 1
ZXAN(config-if)#port-location sub-option remote-id enable vport 1
ZXAN(config-if)#port-location sub-option remote-id name ZTE123 vport 1
ZXAN(config-if)#dhcp-option82 enable vport 1
ZXAN(config-if)#dhcp-option82 trust true keep vport 1
ZXAN(config-if)#exit
ZXAN(config)#show port-location global
identifier : inband-mac
rackno : 0
frameno : 0
hostname : ZXAN
ZZXAN(config)#show port-location port epon-onu_0/5/1:1 vport 1
14-3
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l All the cards work normally.
l The xPON service and VLAN are configured.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
When users access the Internet in PPPoE+ mode, the system uses PPPoE+ Intermediate
Agent to locate port. The system carries the user information in the PPPoE+ discovery
packets to report to the BRAS for user authentication, and thus binding the user account
and circuit.
To configure the PPPoE+ function, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the pppoe-plus enable command to enable the global PPPoE+ functions
6. Use the port-location format command to configure the Agent Circuit ID format.
7. Use the port-location sub-option remote-id command to enable or disable the DHCP
Option 82 Remote ID field.
14-4
8. Use the port-location sub-option remote-id name command to configure the port remote
ID name.
9. Use the pppoe-plus enable command to enable the port PPPoE+ function.
10. Use the pppoe-plus trust command to configure the port to trust/untrust port and
configure the processing policy.
Note:
If it is a Trust port, the user can select the Keep or Replace policy. If it is a Untrust port, the user
can select the Discard or Add policy.
By default, the port is a Untrust port and the processing policy is Add.
11. Use the show port-location global command to query the global configuration of port
location.
12. Use the show port-location port command to query the port-level configuration of port
location.
13. Use the show pppoe-plus global command to query the global configuration of PPPoE+.
14. Use the show pppoe-plus port command to query the port-level configuration of
PPPoE+.
– End of Steps –
Result
The PPPoE+ function is configured successfully.
Example
Configure the PPPoE+ function.
ZXAN(config)#pppoe-plus enable
ZXAN(config)#port-location access-node-identifier inband-mac
ZXAN(config)#interface epon-onu_0/5/1:1
ZXAN(config-if)#port-location format china-telecom vport 1
ZXAN(config-if)#port-location sub-option remote-id enable vport 1
ZXAN(config-if)#port-location sub-option remote-id name ZTE123 vport 1
ZXAN(config-if)#pppoe-plus enable vport 1
ZXAN(config-if)#exit
ZZXAN(config)#show port-location global
identifier : inband-mac
rackno : 0
14-5
frameno : 0
hostname : ZXAN
ZXAN(config)#show port-location port epon-onu_0/5/1:1 vport 1
Onu Vport CircuitId Format RemoteId status RemoteId name
epon-onu_0/5/1:1 1 china-telecom enable ZTE123
ZXAN(config)#show pppoe-plus global
pppoe-plus status : enable
ZXAN(config)#show pppoe-plus port epon-onu_0/5/1:1 vport 1
Onu Vport Pppoe-plus status Trust Policy
epon-onu_0/5/1:1 1 enable false add
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The xPON service card status is proper.
Context
At the user side, the ARP anti-spoofing function is based on the ARP entries created by
the DHCP module, and the ARP entries of the fixed user configured by the IP access user
management module.
When the ARP anti-spoofing function is enabled, if the source IP address and VLAN of
the received ARP packet exist in the ARP table, the system checks whether the MAC
addresses are the same. If they are different, the system considers the packet as an ARP
spoofing behavior and discards it.
At the network side, the ARP anti-spoofing function is based on the statica gateway MAC
address of the VLAN.
The ARP anti-spoofing function can be configured with up to eight VLANs.
To configure the ARP anti-spoofing function, perform the following steps:
Steps
1. Use the ip-service arp-anti-spoofing command to enable or disable ARP anti-spoofing.
2. Use the ip-service arp-anti-spoofing vlan command to configure ARP anti-spoofing in
the specified VLAN.
3. Use the show ip-service arp command to show the ARP mapping table information.
4. Use the show ip-service arp-anti-spoofing command to show the related configuration
on ARP anti-spoofing.
14-6
Result
The ARP anti-spoofing function is configured successfully.
Example
Configure and query the ARP anti-spoofing funtion.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#ip-service arp-anti-spoofing enable
ZXAN(config)#ip-service arp-anti-spoofing vlan 217
direction uplink-port
ZXAN(config)#show ip-service arp-anti-spoofing
Arp Anti-Spoofing status:Enabled.
vlan direction
----------------------
217 uplink-port
Prerequisites
l The network devices and lines are proper.
l The xPON card status is proper.
Context
When the ARP agent function is configured, the ZXA10 C220 responds to ARP requests
for IPoA subscribers and implements DHCP ARP security control.
To configure the ARP agent function, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the arp-agent gateway vlan command to configure ARP agent gateway.
3. Use the show arp-agent gateway command to query ARP agent gateway.
– End of Steps –
Result
The ARP agent function is configured successfully.
14-7
Example
Set the ARP agent gateway of the interconnection VLAN 2 to 172.168.1.1.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#arp-agent gateway vlan 2 172.168.1.1
ZXAN(config)#show arp-agent gateway
Prerequisites
l The network devices and lines are proper.
l The xPON card status is proper.
Context
To configure the loopback detection, perform the following steps:
Steps
1. Use the configure terminal command to command to enter the global configuration
mode.
2. Use the pon-loopback-detection enable command to enable global loopback detection
on a PON port.
3. Use the pon-loopback-auto-shutdown enable command to enable loopback port
auto-shutdown function.
Note:
You need to enable loopback port auto-shutdown function before enabling loopback detection on
a PON port.
4. Use the interface command to enter the PON-OLT interface configuration mode.
5. Use the loopback-detection command to enable loopback detection on a PON port.
14-8
Result
The PON port loopback detection is configured successfully.
Example
Configure the loopback detection on epon-olt_0/3/1.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#pon-loopback-detection enable
ZXAN(config)#pon-loopback-auto-shutdown enable
ZXAN(config)#interface epon-olt_0/3/1
ZXAN(config-if)#loopback-detection enable
Prerequisites
l The network devices and lines are proper.
l The xPON card status is proper.
Context
When the dual-layer VLAN interconnection is configured, subscribers in the same SVLAN
and CVLAN but different PON ports can access each other.
l ZXA10 C220 supports maximum 50 interconnection VLANs.
l The dual-layer VLAN interconnection conflicts with global port protection. Before
configuring VLAN interconnection, use the security port-protect disable command to
disable global port protection.
To configure the dual-layer VLAN interconnection, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the security userswitch command to enable dual-layer VLAN interconnection.
3. Use the security usercommunication command to configure VLAN interconnection
entry.
14-9
4. Use the show security user-switch command to query global VLAN interconnection
status.
5. Use the show security vlan-communication command to query VLAN interconnection
entry.
– End of Steps –
Result
The dual-layer VLAN interconnection is configured successfully.
Example
Configure dual-layer VLAN interconnection for SVLAN 100 and CVLAN 200.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#security userswitch enable
ZXAN(config)#security usercommunication svlan 100 cvlan 200
ZXAN(config)#show security user-switch
Security userswitch enable
ZXAN(config)#show security vlan-communication
vlan-communication item:
Svlan Cvlan
-------------
100 200
14-10
15.1 Overview
The ZXA10 C220 supports the following system security features:
l SSH
l TACACS+
l RADIUS authentication
l Management ACL
l Anti-DoS attack
l Ethernet OAM
Prerequisites
Before this operation, make sure that:
Context
The SSH can replace the Telnet to implement secure remote login. The user can use SSH
to encrypt data during transmission to prevent attack. In addition, the data transmitted
15-1
through SSH are compressed, which enhances the transmission speed. When the SSH
client communicates with the server, the user name and password are encrypted for
security purposes.
The ZXA10 C220 works as an SSH server.
To configure the SSH, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the ssh server enable command to enable the SSH function.
3. Use the ssh server version command to configure the SSH version.
4. Use the ssh server generate-key command to generate the RSA key.
Note:
If the protocol version is v2, the client and the server interworks with each other to generate the
key automatically and the user can skip this command.
5. Use the ssh server authentication mode command to configure the SSH authentication
mode.
6. Use the ssh server authentication type command to configure the SSH authentication
type.
Note:
If the authentication mode is local, the user can skip this command.
7. Use the ssh server authentication ispgroup command to configure the SSH
authentication RADIUS group.
Note:
If the authentication mode is local, the user can skip this command.
10. Use the ssh server only command to permit the SSH only.
11. Use the show ssh command to query the SSH configuration.
– End of Steps –
15-2
Result
The SSH is configured.
Example
Configure the SSH:
l SSH version: 2
l Authentication mode: RADIUS
l Authentication type: PAP
l SSH only: Enable
l RADIUS server: 192.168.1.1
l RADIUS key: zte
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#ssh server enable
ZXAN(config)#ssh server only
ZXAN(config)#ssh server authentication mode radius
ZXAN(config)#ssh server authentication type pap
ZXAN(config)#ssh server version 2
ZXAN(config)#ssh server authentication ispgroup 2
ZXAN(config)#radius authentication-group 2
ZXAN(config-authgrp-2)#server 1 192.168.1.1 key zte
ZXAN(config-authgrp-2)#exit
ZXAN(config)#show ssh
SSH configuration:
SSH enable-flag configuration : enable
SSH version : ver2.0
SSH only configuration : enable
SSH init server key : disable
SSH auth radius isp-groupid : 2
SSH auth mode : radius
SSH auth type : pap
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The ZXA10 C220 device runs normally.
15-3
Context
The TACACS+ provides the access control service for routers, network access servers,
and other network processing devices through one or multiple central servers. TACACS+
supports independent AAA functions, allowing different TACACS+ security servers to work
as the authentication, authorization, and accounting servers.
TACACS+ and RADIUS are widely used at present. TACACS+ uses TCP while RADIUS
uses UDP. TACACS has three versions. The third version TACACS+ is incompatible with
the previous two versions.
TACACS allows the client to have its own user name and password and send the query
request to the TACACS authentication server (also known as TACACS Daemon or
TACACSD). Generally, this server runs on the host. The host returns a permit/deny packet
to respond to the request, and then determines whether TIP is permitted. This process is
Opened Up, and the related algorithm and data are determined by the TACACS server.
In addition, the TACACS extended protocol supports more authentication requests and
response codes.
To configure the TACACS+, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the login-authorization-type command to configure the login authentication mode.
3. Use the login-authentication-type configure the login authentication type.
4. Use the ssh server authentication mode command to configure the SSH server
authentication mode.
5. Use the tacacs-server host command to configure the TACACS+.
6. Use the aaa group-server tacacs+ command to create an AAA server group.
7. Use the server command to configure the IP address of the server group.
8. Use the aaa authorization exec default command to configure the authorization
information.
9. Use the aaa authentication login default command to configure the authentication
information.
10. Use the aaa accounting commands command to configure the accounting information.
– End of Steps –
Result
The TACACS+ is configured successfully.
Example
Configure the TACACS+ function on the ZXA10 C220. Set the IP address of the TACACS+
server to 10.63.79.79.
15-4
ZXAN(config)#login-authorization-type tacacs+
ZXAN(config)#login-authentication-type tacacs+
ZXAN(config)#ssh server authentication mode tacacs+
ZXAN(config)#tacacs-server host 10.63.79.79
ZXAN(config)#aaa group-server tacacs+ zte
ZXAN(config-sg)#server 10.63.79.79
ZXAN(config-sg)#exit
ZXAN(config)#aaa authorization exec default group zte
ZXAN(config)#aaa authentication login default group zte
ZXAN(config)#aaa accounting commands 10 default stop-only group zte
ZXAN(config)#exit
ZXAN#write
Prerequisites
Before this operation, make sure that:
Context
The RADIUS is a standard AAA protocol. AAA can authenticate the users who access the
route switch, preventing illegal users, and thus improving the device security.
To configure the RADIUS, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the radius authentication-group command to configure the RADIUS authentication
group.
– End of Steps –
15-5
Result
The RADIUS is configured successfully.
Example
Configure the RADIUS:
l Authentication group: 1
l Server IP address: 10.61.225.14
l Key: zte
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#radius authentication-group 1
ZXAN(config-authgrp-1)#server 1 10.61.225.14 key zte
ZXAN(config-authgrp-1)#timeout 120
ZXAN(config-authgrp-1)#algorithm round-robin
ZXAN(config-authgrp-1)#deadtime 60
ZXAN(config-authgrp-1)#max-retries 3
Prerequisites
Before this operation, make sure that:
Context
In the actual networking, the device is generally configured with an in-band NM IP address
and is connected to the public network or maintenance dedicated network through the
uplink port. All the users in the network can access the device. For security purposes,
only a few users have the right to configure the device. In this case, the ACL function is
used.
Management ACL is used to control the external devices to access the device, that is,
control the source IP addresses of the received IP packets.
When ACL is enabled on the device, the IP packets whose resource IP addresses cannot
be found in the ACL table are discarded. In addition, the device does not respond to the
ARP request packet and ICMP packet from these source IP addresses. This enhances
system security.
15-6
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the acl standard command to configure the standard ACL.
3. Use the rule command to configure the ACL rules.
4. Use the line telnet access-class command to apply the ACL to the Telnet access.
5. Use the snmp-server access-list command to apply the ACL to SNMP access.
6. Use the show acl command to query the ACL rule configuration information.
– End of Steps –
Result
The management ACL is configured successfully.
Example
Configure the management ACL, permitting the devices whose IP addresses are in the
network segment 192.168.1.0/24 to access the device, but deny the device whose IP
address is 192.168.1.100.
ZXAN#configure terminal
Enter configuration commands, one per line. End with CTRL/Z.
ZXAN(config)#acl standard number 10
ZXAN(config-std-acl)#rule 1 deny 192.168.1.100 0.0.0.0
ZXAN(config-std-acl)#rule 2 permit 192.168.1.0 0.0.0.255
ZXAN(config-std-acl)#exit
ZXAN(config)#line telnet access-class 10
Prerequisite
Before this operation, make sure that:
l The network devices and lines are proper.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
The ZXA10 C220 uses the following methods to prevent itself from huge traffic attack:
15-7
l For out-of-band traffic, the ZXA10 C220 limits packets rate on the CPU, including total
packet rate and certain protocol packet rate.
l For in-band traffic, besides rate limit, the ZXA10 C220 uses anti-DoS attack module to
record packet MAC addresses and drop packets whose rate exceeds the threshold.
With the anti-DoS attack function, the CPU of the ZXA10 C220 is free from excessive
packets from certain user MAC address.
To configure the anti-DoS attack function, perform the following steps:
Steps
To configure control panel security, perform the following steps:
1. Use the configure terminal command to enter the global configuration mode.
2. Use the control-panel command to enter the security control configuration mode.
3. Use the anti-dos command to enable or disable anti-DOS attack.
4. Use the anti-dos limit-num command to set the limit of the anti-DOS black list.
When the system detects that the user packets (identified by MAC addresses) sent to
the main control card exceed five times of the threshold, the system considers itself to
be attacked and adds the MAC address to the black list. By default, the threshold is
100 pps.
5. Use the anti-dos drop command to enable or disable anti-DOS packet drop.
When this function is enabled and a MAC address is added to a black list, the system
discards packets from this MAC address.
6. Use the anti-dos drv-limit command to configure drive limit.
7. Use the anti-dos blocking-time command to configure the anti-DOS polling time.
8. Use the packet-limit command to set speed limit of the specific type of packets.
The ZXA10 C220 supports rate limit of the
ARP/BPDU/DHCP/ICMP/IGMP/PPPoE/SNMP/VBAS packets. The unit is pps.
When the parameter is all, the total drive speed on the CPU entrance is limited.
9. Use the cpu queue command to configure the CPU entry list limit.
10. Use the show control-panel anti-dos black-table command to query the black list
information.
11. Use the show control-panel packet-limit statistics command to query statistics
information of the specified packets.
Result
The anti-DoS attack function is configured successfully.
Example
Configure the anti-DoS attack function.
l Anti-DoS polling time: 300 seconds
l Anti-DoS black list limit: 20 pps
15-8
Prerequisites
Before this operation, make sure that:
l The network devices and lines are proper.
l The uplink port status is proper.
l The user has logged in to the ZXA10 C220 through HyperTerminal or Telnet.
Context
The ZXA10 C220 support service layer OAM function, which includes link continuity check,
port loopback detection, link trace, and alarm notification.
To configure the Ethernet OAM function, perform the following steps:
Steps
1. Use the configure terminal command to enter the global configuration mode.
2. Use the cfm create md command to create the Ethernet OAM MD.
3. Use the ma create command to create the Ethernet OAM MA.
4. Use the primary vlan command to configure the MA primary VLAN.
Note:
In the Ethernet OAM MDs of the same level, primary VLAN of MAs is unique.
5. Use the protect command to configure the MA protection mode. Only VLAN protection
mode is valid.
15-9
6. Use the create mep command to create the local Ethernet OAM MEP.
7. Use the assign mep command to assign the local MEP to uplink port.
8. Use the create rmep command to create the remote Ethernet OAM MEP.
9. Use the mep mepid command to enter the MEP configuration mode.
10. Use the ccm-check enable command to enable the MEP CCM check.
11. Use the ccm-send enable command to enable the MEP CCM message sending.
12. Use the state enable command to enable MEP 802.1ag function.
13. Use the show cfm mp all command to query information about the CFM test.
14. In the administrator mode, use the cfm lbm md command to carry out the loopback
test.
15. n the administrator mode, use the cfm ltm md command to carry out the link trace test.
– End of Steps –
Result
The Ethernet OAM function is configured successfully.
Example
An local ZXA10 C220 is connected to an opposite ZXA10 C220 through an MIP. ZXA10
C220s on both ends work as MEPs, on which the 802.1ag function are enabled, and
monitor and manage the service links in VLAN 200.
The networking diagram is shown in Figure 15-1.
15-10
Carry out the following commands to test link on the local MEP. On the remote MEP, carry
out the same commands. .
ZXAN#cfm lbm md 1 ma 1 smep-id 111 dmep-id 222 //local loopback test
Sending 5 loopback messages to 00d0.d006.f4cc ,timeout is 3 seconds.
ZXAN#cfm ltm md 1 ma 1 smep-id 111 dmep-id 222 //link trace test
Linktrace to 00d0.d006.f4cc: timeout 5 seconds, 64 hops, trans-id 1.
Please wait 5 seconds to print the result.
------------------------------------------------------------------------------
Hops MAC ADDRESS Ingress Action Egress Action Relay Action
------------------------------------------------------------------------------
1 00d0.d006.f4cc IngOK RlyHit
Destination 00d0.d006.f4cc reached.
15-11
15-12
I
ZXA10 C220 Configuration Manual (CLI)
II
Tables
Table 1-1 In-Band NM Configuration Data................................................................. 1-6
Table 1-2 Out-Of-Band NM Configuration Data ....................................................... 1-10
Table 1-3 Clock Synchronization Methods............................................................... 1-20
Table 1-4 System Clock Configuration Configuration Data ...................................... 1-22
Table 1-5 External Input Clock Parameters ............................................................. 1-23
Table 1-6 External Output Clock Parameters .......................................................... 1-24
Table 2-1 Configuration Data of EPON Data Service................................................. 2-3
Table 2-2 Parameters for Configuring the ONU Bandwidth...................................... 2-10
Table 2-3 ONU Bandwidth Configuration Data ........................................................ 2-10
Table 2-4 Default Bandwidth Profile Parameters ..................................................... 2-12
Table 2-5 ONU Bandwidth Profile Configuration Data ............................................. 2-13
Table 2-6 VLAN Modes ........................................................................................... 2-16
Table 2-7 Configuration Data of 9806H ADSL Data Service .................................... 2-21
Table 2-8 Configuration Data of 10G EPON Data Service ....................................... 2-31
Table 3-1 Configuration Data of GPON Data Service ............................................... 3-3
Table 3-2 ONU Phase State...................................................................................... 3-8
Table 3-3 RELATIONSHIP BETWEEN UPSTREAM BANDWIDTH AND T-CONT
BANDWIDTH ......................................................................................... 3-10
Table 4-1 Configuration Data of IGMP Snooping Multicast Service (EPON) .............. 4-2
Table 4-2 IGMP Snooping Multicast Service Configuration Data (GPON).................. 4-8
Table 4-3 MVLAN Configuration Data ..................................................................... 4-16
Table 4-4 IGMP Global Parameters Description ...................................................... 4-17
Table 4-5 IGMP Port Parameters ............................................................................ 4-21
Table 4-6 Multicast Preview Profile Configuration Parameters................................. 4-24
Table 4-7 CDR Configuration Parameters ............................................................... 4-26
Table 5-1 VoIP Service Configuration Data ............................................................... 5-2
Table 5-2 VoIP Service Configuration Data ............................................................... 5-7
Table 5-3 Configuration Data of VoIP Service......................................................... 5-12
Table 5-4 Configuration Data of VoIP Service.......................................................... 5-17
Table 5-5 Parameters Description for VoIP IP Profile .............................................. 5-23
Table 5-6 Parameters Description for VoIP VLAN Profile......................................... 5-24
Table 5-7 Parameters Description for H.248 Protocol Profile ................................... 5-25
III
ZXA10 C220 Configuration Manual (CLI)
IV
Index
10G EPON Service ............................ 2-30 Configuring System Clock .................. 1-21
Configuring TACACS+........................ 15-3
A Configuring the 1:1 VLAN..................... 7-6
Configuring the 10G EPON
Adding a Card .................................... 1-15
Service ............................................. 2-30
Adding a Rack.................................... 1-13
Configuring the 9806H ADSL Access
Adding a Shelf.................................... 1-14
Service ............................................. 2-20
Anti-DoS attack .................................. 15-7
Configuring the Bandwidth
Anti-DoS Attack.................................. 15-7
Profile................................................2-11
ARP Anti-Spoofing ............................. 14-6
Configuring the D-Series/F-Series
Authenticating an ONU (EPON) ........... 2-7
ONU Access Service ........................ 2-16
Authenticating an ONU (GPON) ........... 3-7
Configuring the Extended ACL ........... 10-3
Configuring the GPON Service............. 3-2
C
Configuring the Hybrid ACL ................ 10-6
Clock.................................................. 1-20 Configuring the IGMP Global
Configuring CAC ................................ 4-25 Parameters....................................... 4-17
Configuring CDR ................................ 4-26 Configuring the IGMP Port
Configuring CES TDM Interface ......... 6-40 Parameters....................................... 4-21
Configuring CES TDM Profile ............. 6-38 Configuring the IPTV Package ........... 4-23
Configuring CL1A 1+1 Configuring the Layer-2 ACL .............. 10-4
Protection ......................................... 12-4 Configuring the MVLAN
Configuring CL1A Uplink CES Service Parameters....................................... 4-14
(EPON)............................................. 6-16 Configuring the OLT Port
Configuring DHCP Relay...................... 9-5 (EPON)............................................. 2-27
Configuring DHCP Server .................... 9-3 Configuring the OLT Port
Configuring DHCP Snooping ................ 9-2 (GPON) ............................................ 3-20
Configuring EPON Protection ..............11-1 Configuring the ONU Bandwidth........... 2-9
Configuring External Input Configuring the ONU In-Band IP
Clock ......................................... 1-231-24 Address (EPON)............................... 2-14
Configuring GPON Protection..............11-6 Configuring the ONU In-Band IP
Configuring Link Aggregation ............. 12-7 Address (GPON) .............................. 3-17
Configuring Management ACL ........... 15-6 Configuring the ONU Type Profile
Configuring Mapping Relations (EPON)............................................... 2-6
between Queues and 802.1p Configuring the ONU Type Profile
Priorities ......................................... 13-12 (GPON) .............................................. 3-6
Configuring MSTP ................................ 8-2 Configuring the Service Port
Configuring Priority Mark .................... 13-3 VLAN.................................................. 7-9
Configuring Queue Scheduling ......... 13-10 Configuring the Standard ACL............ 10-1
Configuring RADIUS .......................... 15-5 Configuring the T-CONT
Configuring Redirection ...................... 13-6 Profile.........................................3-9, 3-11
Configuring SSH ................................ 15-1
V
ZXA10 C220 Configuration Manual (CLI)
Configuring the TLS VLAN ................... 7-2 Multicast Service .................................. 4-1
Configuring Traffic Limit...................... 13-2
Configuring Traffic Mirroring ............... 13-5 O
Configuring Traffic Shaping ................ 13-8 ONU Configuration ............................. 2-16
Configuring Traffic Statistics ............... 13-7 Out-Of-Band NM .................................. 1-9
Configuring Virtual Port QoS ............ 13-18
Configuring VLAN Smart QinQ ............. 7-3 P
PON Protection ...................................11-1
D
Port Location ...................................... 14-1
Deleting a Card .................................. 1-17 PPPoE+ ............................................. 14-4
DHCP................................................... 9-1
DHCP Option 82 ................................ 14-2 Q
QoS ................................................... 13-1
E Queue Scheduling.............................. 13-9
EPON CES Service....................... 6-2, 6-9
EPON Data Service.............................. 2-2 R
EPON Service ...................................... 2-1
Resetting a Card ................................ 1-18
Ethernet OAM .................................... 15-9
RSTP ................................................... 8-1
F S
Flow VLAN Parameters ...................... 3-15 Service Connection ............................ 3-12
Showing the Card Information ............ 1-16
G SSTP ................................................... 8-1
GPON CES Service .................. 6-23, 6-31 STP...................................................... 8-1
GPON Service...................................... 3-1 Swapping the Control and Switching
Cards ............................................... 1-19
I System Security ................................. 15-1
IGMP Proxy Multicast Service ............ 4-13
IGMP Snooping Multicast
T
Service ........................................ 4-2, 4-7 Traffic Management Based On ACL
In-Band NM.......................................... 1-6 Rules................................................ 13-1
L U
Login Through HyperTerminal .............. 1-1 UAPS ................................................. 12-1
Login Through NetNumen N31 Unified UNI VLAN Parameters ....................... 3-16
Management System.......................... 1-5 Uplink Port Protection......................... 12-1
Login Through Telnet............................ 1-4
V
M VoIP ..................................................... 5-1
Managing the ONU Remotely............. 2-23 VoIP Service ................5-1, 5-6, 5-11, 5-16
Mapping between CoS and
DSCP ............................................. 13-15 Z
MSTP................................................... 8-2 ZTE Ethernet Switch Ring .................. 12-9
VI
Glossary
AAA
- Authentication, Authorization and Accounting
ACL
- Access Control List
ADSL
- Asymmetric Digital Subscriber Line
AES
- Advanced Encryption Standard
AIS
- Alarm Indication Signal
ARP
- Address Resolution Protocol
BGP
- Border Gateway Protocol
BPDU
- Bridge Protocol Data Unit
BRAS
- Broadband Remote Access Server
CAC
- Channel Access Control
CBS
- Committed Burst Size
CCM
- Continuity Check Message
CDR
- Call Detail Record
CES
- Circuit Emulation Services
CFM
- Connectivity Fault Management
CIR
- Committed Information Rate
CIST
- Common and Internal Spanning Tree
VII
ZXA10 C220 Configuration Manual (CLI)
CLI
- Command Line Interface
CPU
- Central Processing Unit
CVLAN
- Customer Virtual Local Area Network
CoS
- Class of Service
DBA
- Dynamic Bandwidth Allocation
DHCP
- Dynamic Host Configuration Protocol
DNS
- Domain Name Server
DSCP
- Differentiated Services Code Point
DSLAM
- Digital Subscriber Line Access Multiplexer
DoS
- Denial of Service
EBS
- Excess Burst Size
EPON
- Ethernet Passive Optical Network
ES
- Errored Second
FE
- Fast Ethernet
FEC
- Forward Error Correction
FQ
- Fair Queuing
FTTB
- Fiber to the Building
FTTC
- Fiber to the Curb
FTTH
- Fiber to the Home
VIII
Glossary
GEM
- GPON Encapsulation Method
GPON
- Gigabit Passive Optical Network
ICMP
- Internet Control Message Protocol
ID
- Identification/Identity/Identifier
IEEE
- Institute of Electrical and Electronics Engineers
IETF
- Internet Engineering Task Force
IGMP
- Internet Group Management Protocol
IP
- Internet Protocol
IPTV
- Internet Protocol Television
IPoA
- IP over ATM
LACP
- Link Aggregation Control Protocol
LAN
- Local Area Network
LLID
- Logical Link Identifier
MA
- Maintenance Association
MAC
- Medium Access Control
MAN
- Metropolitan Area Network
MD
- Maintenance Domain
MEF
- Metro Ethernet Forum
MEP
- MEG End Point
IX
ZXA10 C220 Configuration Manual (CLI)
MG
- Media Gateway
MGC
- Media Gateway Controller
MGCP
- Media Gateway Control Protocol
MIP
- MEG Intermediate Point
MST
- Multiplex Section Termination
MSTP
- Multiple Spanning Tree Protocol
MVLAN
- Multicast Virtual Local Area Network
NE
- Network Element
NM
- Network Management
NMS
- Network Management System
OAM
- Operation, Administration and Maintenance
OC
- Optical Carrier
OLT
- Optical Line Terminal
OMCI
- ONT Management Control Interface
ONU
- Optical Network Unit
OSPF
- Open Shortest Path First
PAP
- Password Authentication Protocol
PON
- Passive Optical Network
POTS
- Plain Old Telephone Service
X
Glossary
PPPoE
- Point to Point Protocol over Ethernet
PSN
- Packet Switched Network
PVC
- Permanent Virtual Channel
PVID
- Port VLAN ID
PW
- Pseudo Wire
QoS
- Quality of Service
RADIUS
- Remote Authentication Dial In User Service
RMON
- Remote Monitoring
RSTP
- Rapid Spanning Tree Protocol
RTP
- Real-time Transport Protocol
SDH
- Synchronous Digital Hierarchy
SEC
- SDH Equipment Clock
SFU
- Single Family Unit
SIP
- Session Initiation Protocol
SLC
- Subscriber Line Circuit
SMS
SN
- Serial Number
SNMP
- Simple Network Management Protocol
SONET
- Synchronous Optical NETwork
XI
ZXA10 C220 Configuration Manual (CLI)
SP
- Strict Priority
SS
- Soft Switch
SSH
- Secure Shell
SSM
- Synchronization Status Message
SSTP
- Single Spanning Tree Protocol
STM
- Synchronous Transport Module
STP
- Spanning Tree Protocol
SVLAN
- Selective VLAN
SVLAN
- Service Virtual Local Area Network
TACACS+
- Terminal Access Controller Access-Control System Plus
TCP
- Transfer Control Protocol
TDM
- Time Division Multiplexing
TID
- Terminal Identification
TLS
- Transport Layer Security
ToS
- Type Of Service
UAPS
- Uplink Auto Protection Switching
UDP
- User Datagram Protocol
UNI
- User Network Interface
VBAS
- Virtual Broadband Access Server
XII
Glossary
VCI
- Virtual Channel Identifier
VID
- VLAN Identifier
VLAN
- Virtual Local Area Network
VPI
- Virtual Path Identifier
VPN
- Virtual Private Network
VoIP
- Voice over Internet Protocol
WAN
- Wide Area Network
WRR
- Weighted Round Robin
XIII