Switch Highlights
Leading Architecture Built for Next-Generation Networks
⚫ CloudEngine S8700 uses fully programmable chips that adapt to the changing service forwarding processes driven by protocol evolution and technology advances. It enables fast and flexible provisioning of new services simply by upgrading software, without having to replace hardware, thereby protecting customers' investments. In contrast, traditional Application Specific Integrated Circuit (ASIC) chips use a fixed forwarding architecture and follow a fixed forwarding process. For this reason, new services cannot be provisioned until new hardware is developed to support the services, which can take one to three years.
⚫ In addition to having capabilities of traditional switches, CloudEngine S8700 offers fully programmable open interfaces and supports user-defined forwarding processes to meet service customization requirements of enterprises. Enterprises can use the multi-layered open interfaces to develop new protocols and functions independently or jointly with equipment vendors to build campus networks meeting their own needs.
Wired and Wireless Convergence
⚫ By integrating WLAN AC capabilities, CloudEngine S8700 eliminates the need to purchase additional WLAN AC hardware.Each CloudEngine S8700 can manage up to 5K APs (CloudEngine S8700-4 can manage up to 1K APs).
⚫ CloudEngine S8700 supports the unified user management function that authenticates both wired and wireless users,ensuring a consistent user experience no matter whether they are connected to the network through wired or wireless access devices. CloudEngine S8700 supports various authentication methods, including 802.1X, MAC address, Portal authentication,and is capable of managing users based on user groups, domains, and time ranges. These functions intuitively control user and service management and enable the transformation from data switching-centered management to service experience-centered management.
Note: The CloudEngine S8700 series switches can manage 16 APs by default . You can purchase licenses for more AP management on demand.
Powerful Service Processing Capability and Flexible Network Scalability
⚫ CloudEngine S8700 is highly scalable to seamlessly evolve to higher bandwidth and easily upgrade port speeds, and is also compatible with currently used cards, protecting investments.
⚫ Ultra-high densities of GE, 10GE, and multi-GE ports help to build an all-10GE core in enterprise campuses and data centers.
⚫ With a multi-service routing and switching platform, CloudEngine S8700 meets service transmission requirements at the access, aggregation, and core layers of enterprise networks, and provides wireless, voice, video, and data services, helping to build an all-service network with high availability and low latency.
⚫ CloudEngine S8700 supports a broad set of Layer 2 and Layer 3 multicast protocols, such as Protocol-Independent Multicast (PIM) Sparse Mode (SM), PIM Dense Mode (DM), PIM Source-Specific Multicast (SSM), and Internet Group Management Protocol (IGMP) snooping. This capability greatly facilitates high-definition video surveillance and videoconferencing access for multiple terminals.
Carrier-Grade Reliability for Worry-free Service Running
⚫ CloudEngine S8700 provides redundant backup for key components, including main control boards, power modules, and fan modules, all of which are hot swappable.
⚫ The main control boards work in 1:1 forwarding backup mode and offer dual data forwarding planes to implement fast service switchover. This design ensures hitless performance of the entire system when a single main control board is faulty,maximizing user experience.
⚫ Innovative high-density miniaturized power modules adopt the pooling design and support N+N backup, N+1 backup, and N+0 non backup. With such designs, a power failure does not affect the running of the entire system.
⚫ The modular dual-fan box is designed. When one fan in the module is faulty, other fans can adjust the speed intelligently to ensure heat dissipation of the system.
⚫ CloudEngine S8700 supports BFD functionality with a 3.3ms packet transmission interval and high-precision hardware-level BFD OAM capabilities.
Innovative Energy-Saving Design for Intelligent Power Consumption Control
⚫ CloudEngine S8700 uses innovative energy-saving chips capable of dynamically adjusting power on all ports based on traffic volume, with idle ports entering sleep mode to reduce power consumption.
⚫ CloudEngine S8700 supports intelligent Power over Ethernet (PoE) and uses different energy management modes depending on the powered device (PD) type, providing flexible energy management.
⚫ CloudEngine S8700 also supports Energy Efficient Ethernet (IEEE 802.3az), whereby transceivers on line cards can quickly transition to the lower power idle state to reduce power consumption when no traffic is being transmitted.
⚫ The fan module automatically adjusts the fan speed based on the ambient temperature to reduce power consumption.
⚫ The front-to-back airflow meets the airflow requirements of the equipment room to avoid cascading heating.
Super PoE Capability Ideal for Connectivity of Everything on a Next-Generation Campus ⚫ CloudEngine S8700 is also equipped with a high-density multi-GE line card (10GE capable), which supports up to 90 W PoE++ on a single port, supplying power to Wi-Fi 6/7 access points (APs), HD cameras, and videoconferencing endpoints.
⚫ CloudEngine S8700 also provides the perpetual PoE capability. When CloudEngine S8700 reboots (for example, when the software version is upgraded), the power supply to PDs connected to CloudEngine S8700 is not interrupted. This ensures uninterrupted power supply to PDs during the switch restart.
Innovative hybrid optical-electrical access drives campus network media transformation and accelerates enterprise green and low-carbon transformation.
⚫ The S8700 provides 48 x 10GE combo ports, meeting requirements for 10GE optical port interconnection and PoE++ power supply. For example, the ports can be connected to downstream switches, Wi-Fi 6/7 APs, or other wired terminals.
⚫ Using hybrid cables 2.0, the switch can provide PoE++ for devices (such as Wi-Fi 6/7 APs) over a distance of up to 300 m,far exceeding the PoE limitation of 100 m.
⚫ With optical data transmission, the switch can provide up to 10 Gbit/s access for connected devices, reaching ultra-fast upstream transmission.
⚫ The switch can be easily upgraded through optical module replacement to provide higher bandwidth (for example, from 10 Gbit/s to 25 Gbit/s, 40 Gbit/s, or even 100 Gbit/s) without additional cabling, maximizing customers' return on investment (ROI).
Comprehensive Security Protection to Fend Off Security Threats In and Outside of Enterprises
⚫ The S8700 supports MACsec that provides hop-by-hop secure data transmission. MACsec is suitable for meeting high requirements on data confidentiality in scenarios such as governments and financial institutions.
⚫ Comprehensive Network Admission Control (NAC) solutions for enterprise networks: The S8700 supports MAC address authentication, 802.1X authentication, policy association, and free mobility to ensure the security of various access modes, such as dumb terminal access, mobile access, and centralized IP address allocation.
⚫ Two-level CPU protection mechanism: The S8700 supports CPU hardware queues and separates the data plane from the control plane, which helps to defend against DoS attacks and unauthorized access while preventing control plane overloading.
Virtualization for a Multi-Purpose Network
⚫ CloudEngine S8700 is designed with abundant Virtual Extensible LAN (VXLAN) features. Specifically, it supports centralized and distributed VXLAN gateway deployment modes, dynamically establishes VXLAN tunnels through Border Gateway Protocol Ethernet Virtual Private Network (BGP EVPN), and allows configuration through NETCONF/YANG. ⚫ By using VXLAN, CloudEngine S8700 constructs a Unified Virtual Fabric (UVF). As such, multiple service networks or tenant networks can be deployed on the same physical network while being isolated from each other. This capability truly achieves 'one network for multiple purposes'. The resulting benefits include enabling data transmission of different services or customers, reducing network construction costs, and improving network resource utilization.
High Performance IPv6 Service Processing Allows Seamless Transition from IPv4 to IPv6
⚫ CloudEngine S8700 software and hardware platforms support the IPv4/IPv6 dual stack, various tunneling technologies,IPv6 static routing, RIPng, OSPFv3, BGP+, and IPv6 IS-IS, allowing for pure IPv6 networking and combined IPv4 and IPv6 networking.
Comprehensive Network Slicing Functions
⚫ CloudEngine S8700 provides a comprehensive range of network slicing functions to meet diversified SLA requirements of different services and customers. Service isolation and bandwidth guarantee are implemented based on QoS. Slices can be completely isolated from each other without affecting each other. Traffic is isolated at the physical layer, and network slicing is performed for services on the same physical network. The Network Slicing technology can be used at the access, aggregation, and core layers to meet differentiated SLA requirements of new services on campus networks.
Fine-Grained Network Management and Visualized Fault Diagnosis
⚫ In-situ Flow Information Telemetry (IFIT) is an in-band Operations, Administration, and Maintenance (OAM) measurement technology that uses service packets to measure real performance indicators of an IP network, such as the packet loss rate and delay. IFIT can significantly improve the timeliness and effectiveness of network O&M, thereby promoting the development of intelligent O&M.
⚫ IFIT supports application-level quality measurement, tunnel-level quality measurement, and native-IP IFIT measurement. Currently, the device supports only native-IP IFIT measurement. Unless otherwise specified, IFIT in the following sections refers to native-IP IFIT measurement.
⚫ IFIT provides in-band measurement capabilities to monitor indicators such as the delay and packet loss rate of service flows in real time.
⚫ IFIT provides visualized O&M capabilities to centrally manage and control networks and graphically display performance data.
⚫ IFIT has high measurement precision and is easy to deploy. It helps construct an intelligent O&M system and has future- oriented scalability.
Openness and Programmability
⚫ CloudEngine S8700 supports the Open Programmability System (OPS), an open programmable system based on the Python language. IT administrators can program the O&M functions of CloudEngine S8700 through Python scripts to quickly innovate functions and implement intelligent O&M.
Service Configuration Rollback for More Stable Network Running
⚫ CloudEngine S8700 supports configuration rollback. When an exception, such as a configuration error or fault, occurs,configurations can be rolled back to those at the specified time. This ensures stable service running.
Solution Benifits
Simplified Management
⚫ Deployment automation: CloudEngine S8700 supports VXLAN and BGP EVPN, and builds an Unified Virtual Fabric (UVF) to automate deployment of up to 512 Virtual Networks (VNs). In this way, multiple service networks or tenant networks can be deployed and isolated from each other on the same physical network, truly achieving one network for multiple purposes.
⚫ Policy automation: CloudEngine S8700 uses SDN to automate deployment of wired and wireless user policies and implement refined management and control, achieving free mobility.
Audio and video assurance
⚫ High compatibility: centralized application identification
Traditionally, many high-end fixed access switches have to be deployed at the access layer to enable application identification.Hua wei's solution achieves this with the high-quality experience assurance card. Specifically, application identification can be supported at the core/aggregation layer, and DSCP and 802.1p priorities of service packets can be modified and carried on the entire network. This solution is compatible with Hua wei and non-Hua wei switches at the access layer. This is beneficial for new network construction and legacy network migration scenarios.
⚫ Robust assurance: application-level service assurance
Unlike 5 tuple-based QoS in the industry, Hua wei's solution supports application-based QoS and Network Slicing. This effectively addresses the pain points of variable IP addresses and ports during SaaS-like conferencing, and achieves more accurate service identification and scheduling.
⚫ Easy O&M: real-time visibility into application faults
iPCA 2.0 measures real service flows, and CampusInsight intuitively displays network-wide application and experience quality on a dashboard. All of these help locate network faults in minutes.
Note: CloudEngine S8700-6/10 supports high-quality experience assurance board. Experience assurance scope in R23C00:Teams, Webex, Zoom, XYLink, DingTalk, HUA WEI CLOUD Meeting, and Tencent Meeting.
Intelligent O&M
⚫ CloudEngine S8700 provides telemetry technology to collect device data in real time and send the data to Hua wei campus network analyzer CampusInsight. The CampusInsight then analyzes network data based on the intelligent fault identification algorithm, accurately displays the real-time network status, effectively demarcates and locates faults in a timely manner, and identifies network problems that affect user experience, accurately guaranteeing user experiences.
⚫ CloudEngine S8700 supports NetStream for real-time collection and analysis of network traffic statistics. It supports NetStream V5 and V9 packet formats and reduces loads on the network collector. NetStream supports real-time traffic sampling, traffic attribute analysis, and traffic exception traps. This function help you monitor real-time traffic information and analyze device throughput, so as to make decisions on network structure optimization and capacity expansion.