Huawei IP Presentation WWT
Huawei IP Presentation WWT
accelerate intelligence
Blaise POUOKAM
IP product and solution Manager
Data communication networks are vital for the intelligent world
Beijing
IP Router, WAN Network
Nanjing
Ethernet Switch, Campus
Suzhou
Wi-Fi AP and WLAN
Hangzhou
Firewall and Network
13
Solutions Network Solutions Network Solutions Security Solutions research centers worldwide
11,000+
R&D staff
>20%
of annual revenue reinvested into R&D
100+
scientists and top experts
Germany France Ireland Canada
TSN, Cyber Security, Network Calculus, Network Open Programmable, Graph DB, Network
Short Distance Optical Measurement Intent Assurance AI & Digital map
Continuous contribution to industry standards including IETF and IEEE
12+
Industry standards bodies and open
600+ 11,000+ 50+ Wu Qin
IETF IAB member
Huawei's contributions Total patents licensed Working groups that Huawei (China)
source organizations that Huawei has
to IETF RFCs by the end of 2023 participates in as chair or higher
joined
Osama Aboul-
Magd
Chair of the IEEE
802.11ac/ax WG
(Canada)
Wireless
office Enterprise DC
Network Security
Huawei Datacom network solutions & products
Insufficient
200k 96k+ 170+ Wireless terminal surge wireless performance
employees R&D country/region
1→ 3~4 terminals/user 200,000+ employees
Difficult to
Manager's office The office Meeting room Video conferencing surge guarantee app. experience
20%↑ for number of video conferences 2.8+ million emails/day
600k video conferences/month
80% of campus traffic are video conference traffic
1994 2003 2015 2018 Complex networking, 3000+ app., 15 O&M engineers
Cause fault locating > 120 minutes 160k switches and APs
Three SSIDs cover global services.
Huawei High-Quality 10 Gbps CloudCampus: The Preferred Choice for Your Digital
and Intelligent Journey
Gartner® Magic Quadrant™ Leader
Upgrade to Wi-Fi 7
AE 6776-56TP AE 8771-X1T AE 6776I-X7TH AE 5776-26 AE 5773-23HW
Access layer
GE 2.5GE
2.5/10GE
2.5/10GE Upgrade without replacing cables
Collaborative office Wireless office 10M 100M 1GE 2.5GE 10GE
Computer/Laptop Upgrade to Wi-Fi 7
Wide adoption of 2.5GE NICs 2.5GE as a start rate 197 199 200 2024 20X
6 4 9 X
Wi-Fi 7 AP Remote RU
CloudEngine S-Series Switches, Building a High-Quality 10 Gbps Campus Network
CloudEngine
S5735I-H/S-V2
S5731I-L
CloudEngine
S16700
CloudEngine
S12700E
CloudEngine
S8700
CloudEngine
CloudEngine S6780-H (2 U) CloudEngine
CloudEngine S5732-H S6750-H/S S7700 CloudEngine
S5735-S/L S5732-H-V2 S6730-H/-H-V2 S5731-H
S5735-S/L-V2 S5755-H S5731-S CloudEngine
S5735R-L-V2 S5731-L-RUA
S5751-L-RU
High-speed access:
• 2.5GE, backward compatible with 10M/100M/1000M, paving
24/48 x 10M/100M/1000M/2.5GE 4 x 1/10GE
the way for future upgrade and evolution
electrical ports optical ports
New
2 x 12GE Ultra-high-speed uplink:
dedicated
stack ports • 4 x 10GE uplinks, 2 x 12GE dedicated stack ports
Easy maintenance:
• Dying gasp (timely alarm upon a power failure) and one PNP
button (which can reset the switch and restore factory settings)
Built-in fans
AP1
AP3
11
11
AP2
6
VIP
Dedicated lane
for VIP users
Preferential access
• Exclusive super frame tech. < 50 ms vs. > 200 ms
anytime, anywhere
• Dedicated slices for VIP users (industry average)
+
Resource reservation VIP-targeted
for VIP users optimization
Common
user
Signal enhancement VIP user
Poor office experience for executives, for VIP users
complicating compliant handling • per-packet power control Huawei-only
• Signal enhance for VIP users
+
Proactive care
POS PDA for image Conferencing
machine
AGV
reading terminal
for VIP
VIP
Common user
VIP user: E2E full- Real-time VIP experience
Hard to achieve key service assurance on terminals user
journey visualization evaluation and proactive care
Fault warning
Wireless Experience Upgrade: Green Fully-Wireless Campus with 30% Less
Power Consumption
30%
Invisible energy saving Energy saving policy Policy Policy self-
Network-wide/Site/Building Dependence on manual experience implementation recommendation AI-powered energy
Energy saving visualization, AI- saving: 8 hours/day
CloudEngine S16700/S8700
powered policy recommendation
10GE/25GE/40GE/100GE
19%
Power consumption per AP
PCB + antenna
PCB
Smaller size, saving logistics and warehousing costs Lower power consumption and significant power savings Light weight, easy to install, saving transportation costs
No. 1 Wi-Fi 7
2024
Huawei strengths
Admission is to authenticate and authorize users attempting to access the network for the purpose of network
security. This ensures that only authorized and qualified users can access the network.
Determine
Check user
accessible
identity.
resources.
Access Identity
request validity
Identity Enterprise
Authorization
authentication network
5W1H-based user
Denial of access requests
authorization
from unauthorized users
Campus Networks, Requiring Unified Policy Management and Control
Wired access to the Various service applications such as emails, voice over IP
headquarters (VoIP), video conferences, and e-flows
External Wi-Fi access Intensified security threats
Wired/Wireless access to System vulnerabilities, terminal viruses, and malware
enterprise branches
Intelligent Policy Engine, Achieving Refined Permission Control
Access location
Site, region, device group, device type,
Where
device, SSID, and IP address
Bandwidth Uplink/Downlink bandwidth and DSCP
Access time
By week/time point When High/Medium/Low
Traffic and online duration control
QoS
Terminal type (supported only in Portal
PC/iOS/Android What authentication mode)
Intelligent
Device attribute policy engine Application Application group/Application
Company-provided/BYOD
Whose
terminal
Scenario
description A student connected the router to the switch of the school without permission to access the Internet. As a result, the network was abnormal.
iMaster NCE-Campus:
• Unauthorized access
identification Rule Type Description Result
• Alarms and blocking Only the whitelisted terminals are authorized. Other terminals including All non-whitelisted terminals are
Whitelist
Definition unidentified terminals are unauthorized. unauthorized.
Blacklisted terminals are unauthorized. Other terminals including All blacklisted terminals are unauthorized and
Blacklist
unidentified terminals are authorized. other terminals are authorized.
Information Proactive
reporting scanning Identification Method Application Scope Details Scheduled Scanning
Network
resources
Network Network
Silicon Valley
resources resources
1. Policy: permission
2. Policy: security
Shenzhen 3. Experience:
priority/bandwidth
Douala
Users can access the network anytime and anywhere, ensuring consistent service policies and network experience.
Huawei SD-WAN Intelligent
solution
Challenges Faced by WAN Network Reconstruction
High private lines Difficult to guarantee Multi-cloud poses Low network O&M
bandwidth cost application experience security risks efficiency
Private
SaaS
Explore 5G, private line, Differentiated network Local security + Centralized Unified management and
and Internet technologies service capabilities cloud security services control, intelligent O&M
Huawei SD-WAN Solution for Enterprise
Salesforce
SOHO Dropbox Intelligent O&M, reducing OPEX
NetEngine AR600 5G/LTE SaaS
Device plug-and-play, implementing ZTP
Intelligent policy recommendation and simulation
verification, providing optimal global policies
Hub and Spoke Network architecture
Multiple ZTP Methods: Implementing Device Plug-and-Playar
Network Registration
DHCP USB Email
center
Register with iMaster NCE
for provisioning
5G
5G/Internet/MPLS
4 3 2 1 4 3 2 1 Flow P1
MPLS 2 1
4 3 2 1 Flow P2
Application
4 3 2 1 Flow P3 4 3 2 1
identification
Link switchover is triggered if the 4 3 2 1
quality is lower than the SLA MPLS
threshold.
HQ Application
Branch identification (100 Mbit/s)
Internet HQ
4 3
Branch
MPLS
4 3 2 1 (50 Mbit/s)
Application
identification
MPLS Application
identification
MPLS 50%
Branch HQ
Branch HQ
Lower-priority applications Internet
Lower-priority applications Internet
4 3 2 1
4 3 2 1 4 3 2 1 2 1
If the bandwidth utilization is greater than 70% (configurable), traffic of If the bandwidth utilization is less than 50% (configurable), traffic of
higher-priority applications is preferentially processed. lower-priority applications is switched back.
Intelligent A-FEC : Ensuring No Frame Freezing Even at 30% Packet Loss of Links
8 7 6 X 5 4 3 2 1
5 4 3 2 1
8 7 6
NetEngine AR HQ
Internet
Non-key application traffic Branch
Intelligent A-FEC: ensuring NO Frame Freezing even at 30% Packet loss of links
Service experience
optimized
Traditional solution: frame freezing and artifacts at Huawei: no frame freezing or artifact even at 30%
Branch A Enterprise DC
IPsec DSVPN
Branch B Internet
Branch C
Enterprise HQ
Mobile employee
Branch D
Internet
Internet Internet
HQ
HQ HQ
AR631I-LTE4EA
LTE-1
‘[[[[ LTE-2
-40°C to +70°C
GPS/BeiDou
Dual LTE links for high reliability Always-on ATM services Easy to find ATMs
at extreme temperatures
Flexible Built-in 6 Enterprise-level Security Capabilities
*Default forwarding performance: NAT, ACL, and QoS services plus forwarding bandwidth (bps, IMIX packets)
Medium and large branches: Switch, router, and firewall are all in one device
Too many devices, difficult O&M, and high costs Huawei Solution and Customer Benefits
Topology diagram
Head/Branch office
Internet
• Access device: router LTE/5G
• Router, switch, and firewall are integrated to reduce the number of NEs, simplify O&M, and
save equipment room space.
• Hybrid operation, and low forwarding latency in securities trading
+
area
area
Waiti
ng
Guide area
Closure rate of
occasional faults < Intelligent policy
50% NCE-Campus/NCE-CampusInsight recommendation,
Numerous tickets,
several days to Wi-Fi 100% closed-loop
LAN
handle, difficult to trace LAN
Wi-Fi
historical faults
SD-WAN
Dashboard Monitoring: Global Insights into Networks and Ultimate O&M
Experience
Network resource
statistics
GIS map
Alarm statistics
Application Network
statistics performance
statistics
Cloud Ready WAN Centralized Management and Visibility Reduced Network Downtime
Opex Cost Reduction Real-time Network & Application High Level of WAN Visibility
Visibility
Higher Link Utilization Secure End to End Encryption
Visibility, Scalability, Performance and across the entire WAN
Overhead Reduction control are Enhanced
Fully Authenticated WAN devices
Zero Touch Deployment of remote
sites
Thank you. 把数字世界带入每个人、每个家庭、
每个组织,构建万物互联的智能世界。
Bring digital to every person, home, and
organization for a fully connected,
intelligent world.