Quidway NetEngine20/20E
Configuration Guide - Basic Configurations
1 Product Overview
Issue 05 (2010-01-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1-11
1.3.3 Terminal Services
Telnet Service
The NE20/20E supports the versatile Telnet Server and the Telnet Client services. They enable
you to log in to a specified port of a router from your PC by running Telnet client and then to
initiate communication with the device connecting to the asynchronous serial port of the
router. In this way, you realize remote configuration and maintenance for the device.
SSH Terminal Service
Network attacks are usually triggered by the Telnet service that is provided by the server. As
the Telnet protocol does not provide a secure authentication mode and the data transmitted
over the TCP is in plain text, this challenges the security of the network.
The NE20/20E provides Secure Shell (SSH) service and supports PASSWORD, RSA
authentication, DES and 3DES encryption:
z
The user name and password used for the communication between the SSH client and
server are encrypted, which effectively prevents the password from being intercepted.
z
Meanwhile, the SSH service encrypts the data in transmission to ensure the security and
reliability of the data.
z
All of these make it possible for secure remote access to be implemented over insecure
networks.
z
The RSA authentication, in particular, realizes secure key exchange and final secure
session by generating a public key and a private key according to the encryption
principal for asymmetric encryption system.
1.3.4 High Reliability
The NE20/20E effectively ensures the network availability through redundancy of key
modules, high availability of Line Processing Units (LPUs), Fast Reroute (FRR) and Graceful
Restart (GR).
Redundancy of Key Modules
The NE20/20E can work with a single Routing Process Unit (RPU) or two RPUs in
redundancy. The RPU of the NE20/20E supports hot backup.
The NE20/20E supports the following two switchover methods:
z
Automatic switchover
z
Forcible switchover
The NE20/20E supports backup of management bus and 1+1 backup for the power module.
The LPU, the power module and the fan modules are hot swappable.
IP/MPLS Fast Reroute
The Fast Reroute (FRR) can minimize data loss due to network faults. The switch time can
achieve less than 50 ms
The NE20/20E provides the following FR functions:
z
IP fast reroute