Huawei S5700-28C-EI-24 optical fiber switch and Huawei S2326-EI connected to a company's network core network transformation, core equipment new procurement of S5700-28C-EI-24S 10-Gigabit optical fiber switch (four photoelectric multiplexing port), convergence layer switch are S2326-EI equipment, there are two optical fiber Multiplexing ports. The S5700 and 2326 are linked through the single-mode single-fiber mode. Note: (the Single-mode single-fiber module requires one pair of 1 K to buy the original one, and the domestic one is about 400 ). 5700 the default value is optical port self-adaptation, but S2326 will automatically negotiate successfully only after a command is run. huawei S2326TP-EI into the optical port using the negotiation auto command changed to automatic negotiation 2. the following command to enable WEB management # int vlan 1 ip add 192.168.1.1 24 Quidway> system-view # http server load S5700SI-V100R005C01SPC100.web.zip # http server enable detection method: Open the browser http://192.168.1.1/view/login.html User: admin Pwd: admin3. configure the package to filter # acl number 3111 rule 10 permit ip source 192.168.1.0 0.0.255 ------------ open the 192.168.1.0/24 segment and access other segments. Rule 20 permit ip destination 192.168.1.0 255.30 deny ip source 192.168.0.0 0.0.255.255 destination 192.168.0.0 restrict mutual access between other network segments # traffic classifier authentication acl 3111 # traffic behavior 3111 # traffic policy 3111 classifier 3111 behavior 3111 # interface GigabitEthernet5/0/23 ----- apply the policy on the upstream firewall port. Traffic-policy 3111 inboundtraffic-policy 3111 outbound 4. Topology