
Electricity Networking
l
An AR500 can connect to downstream smart meters through RS485 lines.
l
AR500s can be connected through FE.
l
An AR500 can connect to upstream front end processors through FE/SFP lines.
OAM
An AR500 provides configuration management, terminal maintenance, broadcast timing, and
user management.
3.2.3 VPN
The AR500 provides an IP security (IPSec) mechanism to ensure high-quality, interoperable,
and cryptology-based security for communication processes. The two parties in communication
can encrypt data and authenticate the data source at the IP layer to ensure the confidentiality and
integrity of the data and prevent replay on the network.
IPSec implements these functions by using two security protocols: Authentication Header (AH)
and Encapsulating Security Payload (ESP). Internet Key Exchange (IKE) provides automatic
key negotiation, SA establishment, and SA maintenance functions to simplify IPSec use and
management.
The AR500 supports IPSec VPN and provides high reliability transmission tunnels. In addition,
the AR500 uses Generic Routing Encapsulation (GRE) and Layer 2 Tunneling Protocol (L2TP)
to support the following VPN services:
l
GRE VPN
l
IPSec VPN
l
SSL VPN
l
L2TP VPN
l
DSVPN
l
GRE over IPSec VPN
l
L2TP VPN over IPSec VPN
For details about VPN features, see
Feature Description - VPN
.
3.2.4 Security
ACL
An access control list (ACL) defines a series of filtering rules based on a certain policy, the ACL
permits or forbids the passage of data packets.
The AR500 can use ACL rules to filter packets.
Firewall
l
ACL-based packet filtering
ACL-based packet filtering is used to analyze the information of the packets to be
forwarded, including source/destination IP addresses, source/destination port numbers, and
Huawei AR500 Industrial Switch Routers
Product Description
3 Product Characteristics
Issue 01 (2013-5-10)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
14