Quidway NetEngine20/20E
Configuration Guide - Basic Configurations
1 Product Overview
Issue 05 (2010-01-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1-17
1.3.13 Security Features
The NE20/20E can do the following to ensure security:
z
Carry out Authentication, Authorization and Accounting (AAA) functions.
z
Build up distributed client/server secure access applications based on the ITU-T
RADIUS protocol specifications.
z
Provide AAA services for local, login and dialup users to prevent unauthorized access
based on the PAP and CHAP specification.
The NE20/20E supports protocol security authentication as follows:
z
PPP supports PAP and CHAP authentication modes.
z
Routing protocols including RIPv2, OSPF, IS-IS, and BGP support plain text
authentication and MD5 encrypted text authentication.
z
SNMP supports SNMPv3 encryption and authentication.
The NE20/20E supports the mirroring function. Mirroring indicates that the system sends a
copy of the packet on the current node to one specific packet analysis device from an
observing port without interrupting services. You can define the mirroring port number and
connect the port with the packet analysis device to monitor the traffic.
In compliance with the command levels, users are divided into four levels. A login user can
only use the commands with the levels no higher than the user's level.
Supporting the Network Address Translation (NAT) function, the NE20/20E relays the access
between private and public networks. It converts a private IP address to a public IP address or
changes the mix of internal IP address and port to the mix of external IP address and port.
This enables the hosts of internal network to access the Internet resources flexibly without
hazarding the "privacy" of the internal network.