NCE Campus
NCE Campus
NCE Campus
3 License Mode
2
Overall Architecture
NETCONF/YANG
Virtual network
Huawei support ESDP platform PKI platform SecCenter Huawei support website Device registration
(Device certificate) (DPI/antivirus signature (software versions & query center
system (License)
database) patches)
Service node clusters
Controller cluster
CampusInsight
ETCD cluster GaussDB cluster Distributed cache cluster KAFKA
(Infinispan cluster) cluster
Deployment Huawei public cloud Amazon cloud AWS Microsoft cloud Azure
environment VM Physical machine
Cloud managed
Firewall Switch Central Remote
devices and remote AR AP RU
O&M app
O&M app AP
Carrier network/
Enterprise Network
Firewall Firewall AR AR
Switch Firewall AR AP
Switch
Tenant
Switch
network AP Central AP
Switch Encrypted authentication
traffic and cloud-based
DC AP … AP
management traffic
iMaster NCE-Campus is an autonomous driving iMaster NCE-CampusInsight is an analysis Cybersecurity intelligence system (CIS) uses the
Management and network management and control system that component of iMaster NCE-Campus that latest big data analytics and machine learning
control platforms provides full-lifecycle network services covering provides experience visibility, minute-level fault technologies, and collaborates with devices on the
planning, construction, O&M, and optimization. locating, and intelligent network optimization. entire network to defend against APT attacks.
S12700E-12 CloudEngine S12700E: new core switches for campus networks in the Wi-Fi 6 era
8760-X1-PRO 6760-X1/X1E 5760-51 6760R-51/51E 8760R-X1/X1E AirEngine 5760-22W: Wi-Fi 6 wall plate APs
5760-22W
USG6700E
USG6600E AR6300
USG6500E AR6200
USG6300E
AR610 AR650 AR6100
3 License Mode
Firewall Firewall
Switch
AP AP
AP
Scenario 6: FW dual-machine in
Networking Modes of a Tenant Network (2) Mirror Mode
Cloud
management
Scenario 4: AR/FW dual link Scenario 5: Switch Stack
platform
FW
Cloud Hot standby in
management mirror mode
platform
Characteristics:
FW After dual-machine hot backup,of FW is set locally in
mirror mode , it support to be managed by the
platform
iStack
Scenario 7: WLAN AC Monitor
Cloud
management
platform
Characteristics:
1. AR/FW support dual uplink, the interface Characteristics:
includeDialer(pppoe), Cellular(4G/LTE), L3 1. Aggregation, access switch support cloud
Ethernet Interface
WLAN AC
management in stack mode. Up to 9 devices
2. Dialer/Cellular dail configuration is done can be stacked, and no more than 4 devices
directly on the device, not configure are recommended.
through NCE-Campus 2. Stacking cables are required for local automatic
stacking of devices. Devices that do not use
cables can be manually enabled for stacking. Characteristics:
Platform support to monitoring the WAC, the
configure is still go throuth the WAC
HUAWEI TECHNOLOGIES CO., LTD. HUAWEI Confidential Page 10
Deployment
Scenarios
Cloud
Cloud
management
management
platform
platform
Native AC
RADIUS Server
CSS
MPLS
Middle Branch AP
Internet
Large Campus
Characteristics: Small Branch
1. Frame switch support the cloud
management
Characteristics: Characteristics:
2. Frame switch with CSS, need to build 1. Build overlay turnnel based on EVPN 1. The platform support 802.1x, MAC,
2. All the branch need to deploy the AR Portal use authentication. It can work
the CSS and then register to the
platform that support EVPN as Radius server and Portal server.
3 License Mode
License
License Mode Application Scenario Role Operation
Redistribution
System administrator Import license files.
Global permanent Not supported On-Premises Scenario MSP administrator View the license information.
Tenant administrator View the license information.
a.When you log in to iMaster NCE-Campus for the first time, select Global
System administrator Subscription License, and set License Redistribution to No.
MSP-owned Cloud Scenario
b.Import license files.
Not supported (MSP administrators do not
need to centrally manage MSP administrator N/A
licenses.)
Tenant administrator N/A
Global subscription a.When you log in to iMaster NCE-Campus for the first time, select Global
Subscription License, and set License Redistribution to Yes.
System administrator b.Import license files.
MSP-owned Cloud Scenario
c.Configure license packages, and then distribute the packages to MSP
Supported (MSP administrators need to
administrators.
centrally manage licenses.)
MSP administrator Distribute licenses to tenant administrators.
Tenant administrator View the license information.
System administrator Disable the license split function when creating an MSP administrator.
Huawei Public Cloud Scenario
(MSP administrators do not MSP administrator Apply for license activation codes from the Electronic Software Delivery
Not supported Platform (ESDP).
need to centrally manage
tenant licenses.) Purchase license activation codes from MSPs, and import the codes to iMaster
Tenant administrator
Tenant subscription NCE-Campus.
Huawei Public Cloud Scenario System administrator Enable the license split function when creating an MSP administrator.
(MSP administrators need to Apply for license activation codes from the ESDP, and import the codes to
Supported MSP administrator
centrally manage tenant iMaster NCE-Campus.
licenses.)
Tenant administrator View the license information.
3 License Mode
15
Multiple Deployment Modes, Implementing ZTP
NCE-Campus NCE-Campus
NCE-Campus Registration
Firewall Enable DHCP Firewall
query center
(unique)
Application AR AR
scenario AP
LSW LSW
AP AP
Applicable to scenarios with APs Applicable to scenarios where Applicable to regions where a
only DHCP is enabled registration query center is available
16
Deployment Through Barcode Scanning Using a Mobile App
(Applicable to Scenarios with APs only)
① Pre-configuration
for network Before the deployment:
deployment NCE-Campus ① The tenant administrator imports device ESNs in batches
and plans offline configurations online.
Tenant
administrator
During the deployment:
Internet ② The installation engineer connects and powers on the
② Device connection devices.
and power-on ③ The installation engineer logs in to the CloudCampus app to
establish links between the APs and NCE-Campus through
Installation
engineer
barcode scanning, and then delivers configurations to the APs
through the local management SSID. After the operations are
complete, the NCE-Campus can detect and manage the APs.
③ App After the deployment:
deployment The devices retain persistent connections with the NCE-
Campus and periodically report performance data to the NCE-
Campus.
Operating
Android 4.4 and later
The device goes system
online.
19
Thank you
www.huawei.com