Showing posts with label S5720S-28X-LI-24S-AC. Show all posts
Showing posts with label S5720S-28X-LI-24S-AC. Show all posts

Tuesday, November 6, 2018

Why testing a traffic-policy applied on Huawei S5720 fails?

Device: S5720S-28X-LI-24S-AC

Issue Description
Customer claims that traffic-policy configured on Huawei S5720 switch does not take effect.
When customer pings a public IP address (e.g 8.8.8.8) using as a source local interface of S5720(e.g. 10.10.10.1), he receives a reply even if acl 3002 is configured to deny it.

acl number 3002
rule 10 permit ip destination 10.10.10.0  0.0.0.255 logging
rule 20 permit ip destination 10.20.10.0 0.0.0.255 logging
rule 30 deny ip logging
#
traffic classifier c1 operator and
if-match acl 3002
#
traffic behavior b1
permit
#
traffic policy p1
classifier c1 behavior b1
#
vlan 50
traffic-policy p1 inbound
transparent.gif Handling Process
When the peer device replies an ICMP reply packet, the destination IP will be 10.10.10.1.
10.10.10.1 will match ACL 3002(rule 30), but the traffic policy will not take effect because the packet destination IP is interface address of the switch.
There is a default ACL which is used to “catch” ICMP packets (whose destination IP is the IP address of the switch) to CPU.
The priority of the default ACL is higher than the configured traffic-policy. So the packets will not be dropped by traffic policy.
Note that the default ACL mentioned above only takes effect for ICMP packets whose final destination is the switch. For pass-by packets, the configured traffic-policy will take effect.
transparent.gif Solution
When we want to test a traffic-policy, we need to use a device connected behind the switch configured with the traffic-policy.

Monday, October 15, 2018

Block all DHCP packets to exit an interface S5720S-28X-LI-24S-AC

Issue Description
For some specific scenarios, we need to block DHCP broadcast packets (Discovery, Request) to exit a specific interface.
b43ae64853dc466c83083ba6cc9eb7a5
In this specific scenario, PC1 gets dynamic IP from DHCP server located on LSW2. LSW1 just forwards the discovery and request packets towards LSW2.
The requirement is to block these packets to exit GE0/0/3 on LSW1.
Solution
Solution: configure a traffic policy and apply it in outbound direction on S5720S-28X-LI-24S-AC interface where you want to block the packets (in this case GE0/0/3 of LSW1)
The traffic classifier will use an advanced ACL to match the DHCP traffic, which is UDP traffic for ports 67 and 68.
The traffic behavior will be set to "deny" and, optionally to "statistic enable" to check afterwards if packets are dropped.
Configuration is as bellow:
acl number 3000
rule 5 permit udp destination-port eq bootps
rule 10 permit udp destination-port eq bootpc
#
traffic classifier c1 operator and
if-match acl 3000
#
traffic behavior b1
deny
statistic enable
#
traffic policy p1
classifier c1 behavior b1
#
interface GigabitEthernet0/0/3
port link-type trunk
port trunk allow-pass vlan 2 to 4094
traffic-policy p1 outbound
dhcp snooping enable

if you have some other questions about Huawei Switch, you can contact for supports@thunder-link.com.