华为

system-view

to enter configuration mode:

system-view

Exit current view:

quit

exit configuration mode with:

return

Commands

save (not in system-view ! must ‘return’ before)

save

clock

dis clock
clock datetime 14:11:30 2025-09-09

logbuffer

dis logbuffer brief

web-manager

web-manager

hotkey

[HUAWEI]dis hotkey
----------------- HOTKEY -----------------

            =Defined hotkeys=
Hotkeys Command
CTRL_G  display current-configuration
CTRL_L  display ip routing-table
CTRL_O  undo debugging all

           =Undefined hotkeys=
Hotkeys Command
CTRL_U  NULL

            =System hotkeys=
Hotkeys Function
CTRL_A  Move the cursor to the beginning of the current line.
CTRL_B  Move the cursor one character left.
CTRL_C  Stop current command function.
CTRL_D  Erase current character.
CTRL_E  Move the cursor to the end of the current line.
CTRL_F  Move the cursor one character right.
CTRL_H  Erase the character left of the cursor.
CTRL_K  Kill outgoing connection when connecting.
CTRL_N  Display the next command from the history buffer.
CTRL_P  Display the previous command from the history buffer.
CTRL_R  Redisplay the current line.
CTRL_T  Kill outgoing connection.
CTRL_V  Paste text from the clipboard.
CTRL_W  Delete the word left of the cursor.
CTRL_X  Delete all characters up to the cursor.
CTRL_Y  Delete all characters after the cursor.
CTRL_Z  Return to the user view.
CTRL_]  Kill incoming connection or redirect connection.
ESC_B   Move the cursor one word back.
ESC_D   Delete remainder of word.
ESC_F   Move the cursor forward one word.
ESC_N   Move the cursor down a line.
ESC_P   Move the cursor up a line.
ESC_<   Specify the beginning of clipboard.
ESC_>   Specify the end of clipboard.

mac-access-profile

dis mac-access-profile configuration
mac-access-profile name pf-mac-access
[HUAWEI-mac-access-profile-pf-mac-access]?
Current view commands:
  authentication  MAC authenticate configure information
  commit          Commit the configuration to the system
  configuration   Configuration
  display         Display current system information
  mac-authen      MAC authenticate configure information
  monitor         Monitor
  ping            Ping function
  pki             Configure Public Key Infrastructure (PKI) module information
  quit            Exit from the current command view
  reset           Reset operation
  return          Exit to user view
  run             Execute command of user view
  stack           Stack
  test-aaa        Accounts test
  tracert         Trace route to host
  undo            Cancel current setting
[HUAWEI]dis mac-access-profile configuration name pf-mac-access

authentication-profile

[HUAWEI]authentication-profile name pf-mac
[HUAWEI-authen-profile-pf-mac]?
Current view commands:
  access-domain         Access Domain
  authentication        Authentication
  commit                Commit the configuration to the system
  configuration         Configuration
  display               Display current system information
  dot1x-access-profile  Dot1x access profile
  link-down             Link down cause user offline
  mac-access-profile    Mac access profile
  monitor               Monitor
  ping                  Ping function
  pki                   Configure Public Key Infrastructure (PKI) module
                        information
  quit                  Exit from the current command view
  reset                 Reset operation
  return                Exit to user view
  run                   Execute command of user view
  stack                 Stack
  test-aaa              Accounts test
  tracert               Trace route to host
  undo                  Cancel current setting
[HUAWEI]display authentication-profile configuration
[HUAWEI]display authentication-profile configuration name pf-mac

dot1x-access-profile

[HUAWEI]dot1x-access-profile name test
[HUAWEI-dot1x-access-profile-test]?
Current view commands:
  authentication  Authentication
  commit          Commit the configuration to the system
  configuration   Configuration
  display         Display current system information
  dot1x           802.1x configuration information
  monitor         Monitor
  ping            Ping function
  pki             Configure Public Key Infrastructure (PKI) module information
  quit            Exit from the current command view
  reset           Reset operation
  return          Exit to user view
  run             Execute command of user view
  stack           Stack
  test-aaa        Accounts test
  tracert         Trace route to host
  undo            Cancel current setting
[HUAWEI]dis dot1x-access-profile configuration name test

IP

[HUAWEI]ip ?
  address                 Specify IP configurations for the system
  anti-attack             Specify host anti-attack configurations
  as-path-filter          Specify a regular expression access list number
  community-filter        Add a community filter entry
  community-list          Community list
  direct-routing-table    Direct routes
  domain-name             Specify domain name
  extcommunity-filter     Match BGP/VPN extended community filter
  extcommunity-list       Extcommunity-list
  frr                     Fast reroute
  host                    Host
  icmp                    ICMP protocol
  import-rib              Import route information from another routing protocol
  ip-prefix               Specify an address prefix list
  ipv6-prefix             Specify an IPv6 address prefix list
  large-community-filter  Match BGP/VPN large community filter
  large-community-list    Large community list
  option                  IP option
  pool                    Configure an IP pool or enter the IP pool view
  prefix-limit            IP address prefix limit
  rd-filter               Route distinguisher filter
  relay                   DHCP relay
  route                   DHCP client
  route-static            IPv4 static routes
  rpf-route-static        Establish a multicast static route
  vpn-instance            VPN Instance
display ip interface brief
display ip routing-table

route-static

[HUAWEI]ip route-static ?
  X.X.X.X             Destination IP address
  bfd                 BFD configuration information
  default-bfd         Default BFD parameter
  default-preference  Preference value for IPv4 static routes
  frr                 Fast reroute
  selection-rule      Selection rule
  track               Specify a track object
  vpn-instance        VPN instance route information

Interface

display interface GE 1/0/1
dis int brief
display interface 10GE1/0/2 transceiver

Interfaces group:

interface range GE 1/0/17 to GE 1/0/24

Trunk interfaces (multiple physical Ethernet links together to increase bandwidth and reliability, NOT a link-type of type ‘trunk’):

[HUAWEI]interface Eth-Trunk ?
  <0-127>  Eth-Trunk interface number

Enter configuration of a specific interface:

interface GE1/0/3
[HUAWEI-GE1/0/3]?
Current view commands:
  am                      Port isolate
  arp                     Specify ARP configuration information
  authentication-profile  Authentication profile
  bandwidth               Specify mib-referenced bandwidth of the interface
  bfd                     Specify Bidirectional Forwarding Detection (BFD)
  bpdu                    BPDU message
  carrier                 Set carrier time
  commit                  Commit the configuration to the system
  configuration           Configuration
  dei                     Specify dei as drop precedence
  description             Specify interface description
  dhcp                    Dynamic host configure protocol
  dhcpv6                  Dynamic host configure protocol for IPv6
  display                 Display current system information
  dual-active             Dual-active detection
  duplex                  Set duplex mode
  eee                     Energy-efficient-ethernet
  enable                  Enable function
  erps                    Ethernet ring protection switching
  eth-trunk               Add the interface into an Eth-Trunk
  flow-control            Configure flow-control operation mode
  identity                Identity
  ifg                     Interval frame gap
  igmp                    Specify IGMP parameters
  ip                      IP packet
  ip-subnet-vlan          VLAN assignment based on IP subnet
  ipv4                    IPV4 address
  ipv6                    IPv6 status and configuration information
  jumboframe              Set jumbo frame
  l2protocol-tunnel       Layer 2 protocol tunnel
  lacp                    Link aggregation control protocol
  lldp                    Link Layer Discovery Protocol
  loopback                Configure port loopback
  mac-address             MAC address
  mac-vlan                MAC-based VLAN
  monitor                 Monitor
  multicast               Multicast configuration
  nd                      Neighbor discovery
  negotiation             Set negotiation mode
  ping                    Ping function
  pki                     Configure Public Key Infrastructure (PKI) module
                          information
  pnp                     Plug and play function
  poe                     Power over Ethernet
  port                    Switch port
  port-auto-sleep         Port auto-power-down function
  port-isolate            Port isolate
  port-mirroring          Mirror feature
  port-security           Port security
  protocol-vlan           Protocol-based VLAN
  qinq                    802.1Q in 802.1Q
  qos                     Quality of service
  quit                    Exit from the current command view
  reset                   Reset
  restart                 Restart the specified interface
  return                  Exit to user view
  rmon                    Specify RMON configuration
  rmon-statistics         Specify RMON statistics
  run                     Execute command of user view
  set                     Set configuration
  shutdown                Shutdown the specified interface
  smart-link              Smart link configuration information
  speed                   Configure port speed mode
  stack                   Stack
  stack-port              Stack-Port interface
  statistics              Statistics information
  storm                   Storm
  stp                     Specify Spanning Tree Protocol (STP) configuration
                          information
  test-aaa                Accounts test
  tracert                 Trace route to host
  traffic-policy          Apply specific traffic policy
  trap-threshold          Set trap threshold
  trust                   Specify trust parameters
  undo                    Cancel the current setting
  virtual-cable-test      Virtual Cable Test
  vlan                    Set VLAN precedence
  voice-vlan              Voice VLAN
  xldp                    X-Lean discovery protocol

poe

[HUAWEI-GE1/0/3]poe ?
  af-inrush     Support IEEE802.3af
  at-inrush     Support IEEE802.3at
  enable        Enable
  fast-on       Fast power-on
  legacy        Legacy
  power         Power
  power-off     Power off
  power-on      Power On
  priority      Priority
  single-class  Single classification
dis poe power-state
undo poe enable

port

[HUAWEI-GE1/0/1]port ?
  bridge          Bridge
  crc-statistics  Crc-statistics
  default         Specify the current port's PVID VLAN characteristics (ONLY ACCESS)
  discard         Discard
  hybrid          Hybrid port (ONLY HYBRID)
  identity        Peer device identity
  link-flap       Link flapping
  link-type       Switch port link type
  mux-vlan        Multiplex VLAN
  priority        Specify current port's priority
  trunk           Trunk port (ONLY TRUNK)
  vlan-stacking   VLAN Stacking (ONLY TRUNK and HYBRID)
[HUAWEI-GE1/0/1]port link-type ?
  access        Access port
  dot1q-tunnel  QinQ port
  hybrid        Hybrid port
  trunk         Trunk port
port link-type access
access
[HUAWEI-GE1/0/17]port default ?
  vlan  Virtual LAN
trunk
[HUAWEI-GE1/0/17]port trunk ?
  allow-pass  Allowed VLAN
  pvid        Specify the current port's PVID VLAN characteristics
port trunk allow-pass vlan 101 102 254
[HUAWEI-GE1/0/17]port vlan-stacking ?
  8021p     Outside 802.1p ID
  untagged  Untagged
  vlan      Outer VLAN ID of the received frame before being translated
hybrid
[HUAWEI-GE1/0/17]port hybrid ?
  pvid      Specify the current port's PVID VLAN characteristics
  tagged    Tagged
  untagged  Untagged

default

[HUAWEI-GE1/0/9]port default vlan 254
port trunk allow-pass vlan all

VLAN Interface

interface Vlanif 1
[HUAWEI-Vlanif1]ip ?
  address  Set the IP address of an interface
  binding  Enable binding of an interface with a VPN Instance
  option   IP option
  urpf     Unicast reverse path forwarding check
  verify   IP verification
[HUAWEI-Vlanif1]ip address ?
  X.X.X.X      IP address
  bootp-alloc  IP address allocated by BOOTP
  dhcp-alloc   IP address allocated by DHCP
  unnumbered   Share an address with another interface
ip address 192.168.1.100 24

Name the vlan:

name Mgmt
display port vlan

Authentication, Authorization, and Accounting (AAA)

[HUAWEI-aaa]?
Current view commands:
  aaa-author                  AAA authorization
  aaa-bind                    Configure aaa-bind
  aaa-quiet                   AAA quiet
  access-user                 Remote access user
  accounting-scheme           Configure accounting scheme
  administrator               Remote administrator user
  authentication-scheme       Configure authentication scheme
  authorization-modify        Authorization modify
  authorization-scheme        Set authorization scheme
  cmd                         Set command type recording scheme
  commit                      Commit the configuration to the system
  configuration               Configuration
  cut                         Cut connection
  display                     Display current system information
  domain                      Domain
  domain-location             Configure the position of domain name
  domain-name-delimiter       Configure delimiter of username
  domainname-parse-direction  Configure the direction of domainname parsing
  local-aaa-user              Set user policy
  local-access-user           Add/Delete/Set access user(s)
  local-user                  Add/Delete/Set user(s)
  monitor                     Monitor
  outbound                    Set outbound type recording scheme
  ping                        Ping function
  pki                         Configure Public Key Infrastructure (PKI) module
                              information
  quit                        Exit from the current command view
  recording-scheme            Set recording scheme
  remote-user                 Remote authentication user
  reset                       Set password
  return                      Exit to user view
  run                         Execute command of user view
  service-scheme              Configure service scheme
  stack                       Stack
  system                      Set system type recording scheme
  task-group                  Configure a task group
  test-aaa                    Accounts test
  tracert                     Trace route to host
  undo                        Cancel current setting
  user-group                  Configue user group

local-user

[HUAWEI-aaa]local-user webuser password irreversible-cipher test1234
Error: The password is composed of digit, lowercase letter, uppercase letter or other characters, and it must meet 4 of them at least.
display local-user
[HUAWEI-aaa]local-user webuser service-type ?
  ftp       FTP user
  http      HTTP user
  none      No service-type
  ssh       SSH user
  telnet    Telnet user
  terminal  Terminal user
[HUAWEI-aaa]local-user webuser privilege level ?
  INTEGER<0-3>  Level value

https://support.huawei.com/enterprise/en/doc/EDOC1100248032/7156fd7e/overview-of-authentication-modes-and-user-privilege-levels

authentication-scheme

[HUAWEI-aaa]authentication-scheme pf-auth
[HUAWEI-aaa-authen-pf-auth]?
Current view commands:
  authentication-mode  Configure authentication method
  authentication-type  Authentication Type
  commit               Commit the configuration to the system
  configuration        Configuration
  display              Display current system information
  monitor              Monitor
  ping                 Ping function
  pki                  Configure Public Key Infrastructure (PKI) module
                       information
  quit                 Exit from the current command view
  radius-reject        Configure radius-reject action
  reset                Reset operation
  return               Exit to user view
  run                  Execute command of user view
  server               Server
  stack                Stack
  test-aaa             Accounts test
  tracert              Trace route to host
  undo                 Cancel current setting
authentication-mode
[HUAWEI-aaa-authen-pf-auth]authentication-mode ?
  ad          AD
  hwtacacs    HWTACACS
  ldap        LDAP
  local       Local
  local-case  Local case-sensitive
  none        None
  radius      RADIUS

HTTP

[HUAWEI-http]?
Current view commands:
  client         HTTP client
  commit         Commit the configuration to the system
  configuration  Configuration
  display        Display current system information
  monitor        Monitor
  ping           Ping function
  pki            Configure Public Key Infrastructure (PKI) module information
  quit           Exit from the current command view
  reset          Reset operation
  return         Exit to user view
  run            Execute command of user view
  service        Specify current server attribute
  stack          Stack
  test-aaa       Accounts test
  tracert        Trace route to host
  undo           Cancel current configuration

web-manager

dis web-manager configuration
[HUAWEI]web-manager ?
  captcha          Configure captcha
  enable           Enable Web server
  http             Configure http forward
  ipv4             IPv4 protocol
  ipv6             IPv6 protocol
  lock-ip          Configure Lock Ip
  max-user-number  Max user number
  security         Indicate HTTP running over SSL
  server-source    Set the server source
  slow-attack      Slow attack
  timeout          Specify web server time out value
  warning-banner   Specify the warning banner
undo web-manager captcha enable
web-manager server-source all-interface

SSH

[HUAWEI]dis ssh server status
SSH Version                                : 2.0
SSH authentication timeout (Seconds)       : 60
SSH authentication retries (Times)         : 3
SSH server key generating interval (Hours) : 0
SSH version 1.x compatibility              : Disable
SSH server keepalive                       : Enable
SFTP IPv4 server                           : Disable
SFTP IPv6 server                           : Disable
STELNET IPv4 server                        : Disable
STELNET IPv6 server                        : Disable
SNETCONF IPv4 server                       : Disable
SNETCONF IPv6 server                       : Disable
SNETCONF IPv4 server port(830)             : Disable
SNETCONF IPv6 server port(830)             : Disable
SCP IPv4 server                            : Disable
SCP IPv6 server                            : Disable
SSH port forwarding                        : Disable
SSH IPv4 server port                       : 22
SSH IPv6 server port                       : 22
ACL name                                   : --
ACL number                                 : --
ACL6 name                                  : --
ACL6 number                                : --
SSH server ip-block                        : Enable
ecc local-key-pair create
dis ecc local-key-pair public
ssh server publickey ecc
stelnet ipv4 server enable
undo ssh server keepalive disable
ssh server-source -i Vlanif 1

Radius

radius-server

dis radius-server configuration
[HUAWEI]radius-server ?
  authorization              RADIUS authorization server
  dead-count                 RADIUS server down detected times
  dead-interval              RADIUS server down detected duration
  detect-cycle               RADIUS server down detected cycles
  max-unresponsive-interval  RADIUS server max non-response time interval
  session-manage             Configure the session manage server
  template                   Add or delete RADIUS server template
authorization
dis radius-server authorization configuration
[HUAWEI]radius-server authorization ?
  X.X.X.X     IP address of the server
  match-type  Configure the match type of the user information
  port        Configure the port of the authorization server
template
[HUAWEI]radius-server template packetfence
[HUAWEI-radius-packetfence]?
Current view commands:
  called-station-id   Modify format of called-station-id
  calling-station-id  Modify MAC format of calling-station-id
  commit              Commit the configuration to the system
  configuration       Configuration
  display             Display current system information
  monitor             Monitor
  ping                Ping function
  pki                 Configure Public Key Infrastructure (PKI) module
                      information
  quit                Exit from the current command view
  radius-attribute    Attribute config
  radius-server       Configure RADIUS server template
  reset               Reset operation
  return              Exit to user view
  run                 Execute command of user view
  stack               Stack
  test-aaa            Accounts test
  tracert             Trace route to host
  undo                Undo command
[HUAWEI-radius-packetfence]radius-server ?
  accounting              Configure accounting server
  accounting-stop-packet  Configure the resending value of
                          accounting-stop-packet
  algorithm               Packet send algorithm
  attribute               Configure the function of attribute translation
  authentication          Configure authentication server
  dead-time               Configure dead time
  detect-server           Detect-server
  format-attribute        Configure RADIUS attribute's format
  hw-dhcp-option-format   Huawei dhcp option format
  nas-identifier-format   Configure NAS-Identifier format
  nas-port-format         Configure NAS-Port format
  nas-port-id-format      Configure NAS-Port-Id format
  retransmit              Configure server retransmission
  shared-key              Configure server shared-key
  source                  Set source IP address
  support                 Support
  testuser                Testuser
  timeout                 Configure server timeout
  traffic-unit            Configure the octets of format
  user-name               Configure the format of username

UI Console

[HUAWEI]user-interface console 0
[HUAWEI-ui-console0]?
Current view commands:
  acl                  ACL-based connection
  authentication-mode  Configure the authentication mode for a user terminal
                       interface
  commit               Commit the configuration to the system
  configuration        Configuration
  databits             Set the databits of a user terminal interface
  display              Display current system information
  flow-control         Set the flow control mode of the user terminal
  history-command      Record history commands
  idle-timeout         Set the timeout period for a terminal user
  monitor              Monitor
  parity               Set the parity mode of user terminal
  ping                 Ping function
  pki                  Configure Public Key Infrastructure (PKI) module
                       information
  protocol             Set the user interface protocol
  quit                 Exit from the current command view
  reset                Reset operation
  return               Exit to user view
  run                  Execute command of user view
  screen-length        Set the number of lines displayed on a screen
  set                  Set the parameters for a user terminal interface
  shell                Enable terminal user service
  shutdown             Shutdown the specified user-interface(s)
  speed                Set the TX/RX rate of a user terminal
  stack                Stack
  stopbits             Set the stop bit of the user terminal
  test-aaa             Accounts test
  tracert              Trace route to host
  undo                 Cancel the current setting
  user                 Set the parameters of a login user

idle-timeout

[HUAWEI-ui-console0]idle-timeout ?
  INTEGER<1-1440>  Set the number of minutes before a terminal user times
                   out(default: 5minutes)

[HUAWEI-ui-console0]idle-timeout 10

Infos

display version
display software info
display current-configuration
dis this
dis vlan

Switch variants (S, V, R)

S Series:
These are primarily designed for enterprise networks, data centers, and campus environments. They offer a broad range of functionalities, from basic Layer 2 switching to advanced Layer 3 routing and security features. Examples include the S3700, S5700, and S6700 series.

V Series:
This designation points to a focus on video conferencing and telecommunications. Switches in the V series might have specialized ports or features to handle the quality of service (QoS) requirements of real-time voice and video traffic, common in unified communications solutions.

R Series:
The ‘R’ series represents Huawei’s routers. These devices are built for wide-area networks (WANs) and connect different networks, handling packet forwarding based on IP addresses rather than MAC addresses, which is the primary function of a switch.