Documente Academic
Documente Profesional
Documente Cultură
Version 2.8.02.C
ZTE CORPORATION
ZTE Plaza, Keji Road South,
Hi-Tech Industrial Park,
Nanshan District, Shenzhen,
P. R. China
518057
Tel: (86) 755 26771900 800-9830-9830
Fax: (86) 755 26772236
URL: http://support.zte.com.cn
E-mail: doc@zte.com.cn
LEGAL INFORMATION
The contents of this document are protected by copyright laws and international treaties. Any reproduction or distribution of
this document or any portion of this document, in any form by any means, without the prior written consent of ZTE CORPO-
RATION is prohibited. Additionally, the contents of this document are protected by contractual confidentiality obligations.
All company, brand and product names are trade or service marks, or registered trade or service marks, of ZTE CORPORATION
or of their respective owners.
This document is provided as is, and all express, implied, or statutory warranties, representations or conditions are dis-
claimed, including without limitation any implied warranty of merchantability, fitness for a particular purpose, title or non-in-
fringement. ZTE CORPORATION and its licensors shall not be liable for damages resulting from the use of or reliance on the
information contained herein.
ZTE CORPORATION or its licensors may have current or pending intellectual property rights or applications covering the subject
matter of this document. Except as expressly provided in any written license between ZTE CORPORATION and its licensee,
the user of this document shall not acquire any license to the subject matter herein.
ZTE CORPORATION reserves the right to upgrade or make technical change to this product without further notice.
Users may visit ZTE technical support website http://ensupport.zte.com.cn to inquire related information.
Revision History
Manual Summary
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Hardware Installation installation preparation,
Manual 19-inch cabinet installation,
main device installation,
power cable connection, cable
connection and hardware
inspection.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Hardware Manual device functions, technical
characteristics and
parameters, working principle,
hardware structure, MCS, LIC,
power module and fan plug-in
box.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes using
Routing Switch User Manual (Basic and operation of device,
Configuration Volume) system management,
CLI privilege ranking
configuration, port
configuration, network
protocol configuration,
DHCP configuration,
VRRP configuration,
ACL configuration, QoS
configuration, DOTIX
configuration, cluster
management configuration,
network management
configuration, IPTV
configuration, VBAS
configuration, CPU guard,
URPF configuration and UDLD
configuration.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch User Manual (Ethernet device VLAN configuration,
Switching Volume) STP configuration, MAC
address table operation, link
aggregation configuration,
IGMP Snooping configuration,
link protection configuration,
Ethernet OAM configuration
and EPON OLT configuration.
Manual Summary
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch User Manual (IPv4 static routing configuration,
Routing Volume) RIP configuration, OSPF
configuration, IS-IS
configuration, BGP
configuration, load balancing
configuration, multicast
routing configuration, IP/LDP
FRR configuration and BFD
configuration.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes device
Routing Switch User Manual (MPLS MPLS configuration, MPLS
Volume) L3VPN configuration and MPLS
L2VPN configuration.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes device
Routing Switch User Manual (IPv6 IPv6 address configuration,
Volume) IPv6 neighbor discovery
protocol configuration, IPv6
tunnel configuration, IPv6
static routing configuration,
RIPng configuration, OSPFv3
configuration, IS-ISv6
configuration and BGP+
configuration.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes volume
Routing Switch Command Manual and section corresponding to
(Command Index Volume) each command in ZXR10 8900
series 10G routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Command Manual IPv6-related commands in
(IPv6 Volume) ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes RIP,
Routing Switch Command Manual (IP OSPF and IS-IS-related
Routing Volume I) commands in ZXR10 8900
series 10G routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes BGP,
Routing Switch Command Manual (IP route map and routing
Routing Volume II) policy-related commands
in ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Command Manual MPLS-related commands
(MPLS Volume) in ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Command Manual QoS-related commands in
(QoS Volume) ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Command Manual security configuration-related
(Security Volume) commands in ZXR10 8900
series 10G routing switch.
Manual Summary
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Command Manual system management, file
(Basic Configuration Volume I) management, user interface,
log statistics, FTP/TFTP server
and IPvr-related commands
in ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Command Manual interface configuration, DHCP
(Basic Configuration Volume II) and VRRP-related commands
in ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes NAT,
Routing Switch Command Manual Time Range, stack and
(Basic Configuration Volume III) DEBUG-related commands
in ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
Routing Switch Command Manual network management-related
(Network Management Volume) commands in ZXR10 8900
series 10G routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes MAC,
Routing Switch Command Manual VLAN, SuperVLAN, STP, link
(Ethernet Switching Volume) aggregation, VBAS, MAC PING
and UDLD-related commands
in ZXR10 8900 series 10G
routing switch.
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes VOIP
Routing Switch Command Manual and IPTV-related commands
(Voice and Video Volume) in ZXR10 8900 series 10G
ZXR10 8900 Series (V2.8.02.C) 10G This manual describes
routing switch.
Routing Switch Command Manual multicast protocol-related
(Multicast Volume) commands in ZXR10 8900
series 10G routing switch.
Commands supported by ZXR10 8900 series (V2.8.02.C) 10G
routing switch are based on uniform platform ZXROS V4.8.22.
ZXR10 8900 Series (V2.8.02.C) 10G Routing Switch User Manual
(DPI Volume) contains the following chapters:
Chapter Summary
Chapter 1 DPI This chapter describes basic concept and
Overview applications of DPI.
Chapter 2 Signature This chapter describes basic concept,
Entry Configuration configuration and configuration example of
DPI signature entry.
Chapter 3 Signature This chapter describes basic concept,
Symbol Configuration configuration and configuration example of
DPI signature symbol.
Chapter 4 Policy This chapter describes basic concept,
Configuration configuration and configuration example of
DPI policy.
Chapter 5 Sub Service This chapter describes basic concept,
Configuration configuration and configuration example of
DPI sub service.
Chapter Summary
Chapter 6 Service This chapter describes basic concept,
Configuration configuration and configuration example of
DPI service.
Chapter 7 DPI This chapter describes basic concept,
Template Configuration configuration and configuration example of
DPI template.
Glossary This part lists glossaries used in this manual.
What is DPI?
Table of Contents:
What is DPI?...................................................................... 1
DPI Applications ................................................................. 2
What is DPI?
DPI Overview DPIis also called Deep Packet Inspection. To say Deep, it is com-
pared with common packet resolution layers. Common Packet
Inspection only resolves items under layer 4 in IP packet, includ-
ing source address, destination address, source port, destination
port and protocol type. DPI resolves not only these layers, but
also application layer, identifying various applications and corre-
sponding items.
The key technology of DPI is to identify various applications in
network.
Common packet inspection identifies application type through port
id. For example, if port id is detected to be 80, this application is
believed to be a common network application. However, currently
some illegal applications in network will avoid inspection and mon-
itoring by way of hiding or impersonating port id and attack net-
work acting as data flow of legal packets. In this case, such illegal
applications fail to be detected with traditional L2-L4 inspection.
DPI technology is to inspect the content of packets in application
data flow so as to verify the actual application of these packets.
DPI Technology By deploying DPI technology in IP network, system can imple-
Applications ments service identification, service control and service statistics
functions in network operation.
Service Identification
Generally, there are two ways for service identification: one is
legal service fulfilled by carrier and the other is service moni-
tored by carrier.
The former type of service can be identified by five-elements of
service traffic. For example, the address of VOD service traffic
belongs to VOD server network segment and its port is a fixed
address. System adopts ACL to identify this type of service.
As for the latter service, resolve the details of IP packet with
the service identification method mentioned above and learn
the type of service traffic through searching of key word or
service behavior statistics.
Service Control
After identifying service traffic with DPI technology, control ser-
vice traffic according to combination conditions of network con-
figurations, such as user, timer, bandwidth, history, traffic and
so on. There are several control ways: normal forwarding,
blocking, limiting bandwidth, traffic shaping, re-marking prior-
ity and so on.
Taking operation of services into account, service control poli-
cies are mainly configured on policy server and distributed after
users get online.
traffic statistics
DPI service statistics function is used to view service traffic
distribution in network and using of various services intuition-
istically. In this way, factors promoting service development
and influencing network operation can be detected, which pro-
vides support to optimization of network and services. For ex-
ample, this function can be used to find what services attract
more users, check if provided service level meets requirement
of user SLA (Service-Level Agreement), conduct statistics to
percent of attack traffic in network, count the number of users
using one game service, and find what servers mostly consume
network bandwidths and which users use illegal VoIP and so on.
DPI Applications
DPI card can perform DPI inspection to L3 traffic redirected to DPI
card. Identify TCP connection or UDP connection established by
each traffic, scan packets based on each connection, and finally
identify connection-based applications (such as P2P VoIP, FTP and
so on). Implement different policies (supporting rate limit, modi-
fication to tos and pri of packet and so on) to different applications
according to user configurations so as to optimize network, pro-
vide meticulous services to users based on existing network, and
increase network benefits for carrier.
DPI card, with the help of NM system, has powerful capabilities in
data record, statistics and analysis. DPI card can conduct statistics
to upstream and downstream traffic per user based on tcp or udp
connection, and record the statistics in real time. After a certain
period (user can customize the interval), DPI card automatically
up-sends the recorded statistics to remote NM system through net-
work. NM system analyses these records and conducts statistics,
so that user can know traffic distribution in current network ex-
actly. Whats more, user can view changes of network traffic and
network applications of different periods (by day, week, month and
so on) and adopt different management modes according to these
changes, so that network can provide services normally.
Configuring Signature
Symbol
Table of Contents:
Signature Symbol Overview ................................................. 3
Configuring Signature Symbol .............................................. 3
Signature Symbol Configuration Example............................... 4
Configuring Signature
Symbol
Adding Signature Symbol
Command Function
ZXR10(config)#show signature-symbol <signature-sy This shows configuration of
mbol-id> designated signature symbol.
This shows id and details of a
signature entry bound under
signature symbol.
Signature Symbol
Configuration Example
The following part is a signature symbol configuration example:
ZXR10(config)#dpi ZXR10(config-dpi)#signature-symbol 2
ZXR10(config-dpi-signature-symbol-2)#add signature-entry 2
ZXR10(config-dpi-signature-symbol-2)# set hit-limit-num 10
protocol-type inherit ZXR10(config)# show signature-symbol 2
Configuring Signature
Entry
Table of Contents:
Signature Entry Overview .................................................... 5
Configuring Signature Entry ................................................. 5
Signature Entry Configuration Example.................................. 6
Command Function
ZXR10(config)#show signature-entry <signature-entr This shows configuration of a
y-id> signature entry.
Signature Entry
Configuration Example
The following part shows a signature entry configuration example:
ZXR10(config)#dpi ZXR10(config-dpi)#signature-entry 2
ZXR10(config-dpi-signature-entry-2)#set content
0xabcd(0xffffffff000000000000000000000000)+0x1234+0x5678
ZXR10(config)#show signature-entry 2
Configuring Policy
Table of Contents:
DPI Policy Overview ............................................................ 7
Configuring Flow Pool.......................................................... 7
Flow Pool Configuration Example .......................................... 8
Command Function
ZXR10(config)#show flow-pool <flow-pool-id> This shows configuration of flow
pool.
Table of Contents:
Subservice Overview........................................................... 9
Configuring Subservice........................................................ 9
Subservice Configuration Example .......................................11
Subservice Overview
Subservice describes one type of service contained in the service.
Each subservice contains one or more signature-symbol relations,
and each signature-symbol relation is made up of a signature-sym-
bol serial number (separated by slash, such as 1/2/3/4). Each
subservice is only bound with one flow-pool. Other policies can
also be bound. At present, policies action and aging-time are sup-
ported.
Configuring Subservice
Adding Signature Symbol Sequence
Command Function
ZXR10(config)#show subservice <subservice-id> This shows configuration of
designated subservice.
Subservice Configuration
Example
The following part shows a subservice configuration example:
ZXR10(config)#dpi ZXR10(config-dpi)#subservice 2
ZXR10(config-dpi-subservice-2)#add signature-symbol
1/2/3/4 XXXX
ZXR10(config-dpi-subservice-2)# add protocol HTTP
ZXR10(config-dpi-subservice-2)# bind flow-pool 2
ZXR10(config-dpi-subservice-2)# action permit
ZXR10(config-dpi-subservice-2)# aging-time 10
ZXR10(config)# show subservice 2
Configuring Service
Table of Contents:
Service Overview...............................................................13
Configuring Service............................................................13
Service Configuration Example ............................................14
Service Overview
Service represents the service level assigned by network adminis-
trator. One service is composed of a set of sub services. The same
one service can be bound on multiple interfaces and different ser-
vices can be bound with the same sub service. Import subservice
can be configured under service (that is add another subservice
into one subservice and the two must be in the same one service)
and each service can be bound with only one flow-pool.
Configuring Service
Adding One Subservice to Current
Service
Command Function
ZXR10(config)#show service <service-id> This shows service
configuration. It also shows
added subservices and bound
flowpool-id under this service.
Service Configuration
Example
The following part shows a service configuration example:
ZXR10(config)#dpi ZXR10(config-dpi)#service 2
ZXR10(config-dpi-service-2)#add subservice 2
ZXR10(config-dpi-service-2)# bind flow-pool 12
ZXR10(config)# show service 2
Configuring DPI
Template
Table of Contents:
DPI-Template Overview ......................................................17
Configuring DPI-Template ...................................................17
DPI-Template Configuration Example....................................19
DPI-Template Overview
Configure related rules under DPI-template node. Each sip (source
ip)/port/vlan can only be bound with one service and the same one
service can be bound to different sips/ports/vlans meanwhile.
Configuring DPI-Template
Binding Direction Rules to Data Flow
Showing Configuration of
DPI-Template
Command Function
ZXR10(config)#show dpi-template <template-id> This shows configuration of
dpi-template.
DPI-Template Configuration
Example
The following part shows a DPI-template configuration example:
ZXR10(config)#dpi ZXR10(config-dpi)# dpi-template 2
ZXR10(config-dpi-template-2)# bind slot 4
ZXR10(config-dpi-template-2)# bind service 2
ZXR10(config-dpi-template-2)# bind sip-addr 1.1.1.1
255.255.255.0 service 10
ZXR10(config-dpi-template-2)# bind switchport 1/12
service 20
ZXR10(config)# show dpi-template 2