01-08 Configuration File Management Configuration
01-08 Configuration File Management Configuration
Switches
Configuration Guide - Basic Configuration 8 Configuration File Management Configuration
Purpose
Configuration file management allows you to view, save, compare, back up,
restore, and compress configuration files, as well as deleteand roll back
configurations in the files. You can also specify the configuration file to be loaded
at the next device startup. All this ensures correct configurations on the device,
prevents configuration loss, and facilitates configuration migration.
Hardware Requirements
Series Models
Feature Requirements
For security purposes, FTP and TFTP are not S5735-S- S5735-S24P4XE-
recommended. By default, the device provides V2 series V2/S5735-
the weak security algorithm/protocol feature S5735-L- S24T4XE-V2/
package WEAKEA. If you need to use the weak V2 series S5735-S24U4XE-
security algorithm/protocol feature package V2/S5735-
WEAKEA, run the install feature-software S3710-H S48P4XE-V2/
WEAKEA command to install it. series S5735-S48T4XE-
S5735I-L- V2/S5735-
V2 series S48U4XE-V2
S5732-H- S5735-L10T4X-A-
V2 series V2/S5735-
S5735I-S- L10T4X-TA-V2/
V2 series S5735-L16T4S-A-
V2/S5735-
S6730-H- L16T4X-QA-V2/
V2 series S5735-L24P4S-A-
V2/S5735-
L24P4XE-A-V2/
S5735-L24P4XE-
TA-V2/S5735-
L24T4S-A-V2/
S5735-L24T4X-
QA-V2/S5735-
L24T4XE-A-V2/
S5735-L24T4XE-
D-V2/S5735-
L48LP4S-A-V2/
S5735-L48LP4XE-
A-V2/S5735-
L48P4XE-A-V2/
S5735-L48T4S-A-
V2/S5735-
L48T4XE-A-V2/
S5735-L48T4XE-
TA-V2/S5735-
L48T4XE-D-V2/
S5735-L8P2T4X-
A-V2/S5735-
L8P2T4X-TA-V2/
S5735-L8P4S-A-
V2/S5735-L8P4X-
QA-V2/S5735-
L8T4S-A-V2/
S5735-L8T4X-QA-
V2
S3710-H24P4S-A/
S3710-H24T4S-A/
S3710-H48LP4S-
A/S3710-H48T4S-
A
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
S5735I-L10T4X-A-
V2/S5735I-L8P4X-
A-V2
S5732-
H24S4X6QZ-TV2/
S5732-
H24S4X6QZ-V2/
S5732-
H24UM4Y2CZ-
TV2/S5732-
H24UM4Y2CZ-V2/
S5732-
H44S4X6QZ-TV2/
S5732-
H44S4X6QZ-V2/
S5732-
H48UM4Y2CZ-
TV2/S5732-
H48UM4Y2CZ-V2
S5735I-S24T4XE-
V2/S5735I-
S24T4XE-T-V2/
S5735I-S24U4XE-
V2/S5735I-
S24U4XE-T-V2/
S5735I-S8T4SN-
V2/S5735I-
S8T4XN-T-V2/
S5735I-S8T4XN-
V2/S5735I-
S8U4XN-V2
S6730-H24X6C-
TV2/S6730-
H24X6C-V2/
S6730-H28X6CZ-
TV2/S6730-
H28X6CZ-V2/
S6730-H48X6C-
TV2/S6730-
H48X6C-V2/
S6730-H48X6CZ-
TV2/S6730-
H48X6CZ-V2/
S6730-H48Y6C-
TV2/S6730-
H48Y6C-V2
Next After the system starts, you can Run the display startup
startup specify a configuration file as command to check the
configurati the initial configurations for the configuration file to be used for
on next startup, known as the next the next startup.
startup configurations Run the display saved-
configuration command to
check content in the
configuration file to be used for
the next startup.
To use modified configurations as the next startup configurations, run the save
command to save them to the default storage medium.
NOTE
If a command is configured in an incomplete format, the system saves the command to the
configuration file in its complete format. As a result, the command may have more than
510 characters, which is the maximum length supported by the system. Such a command
cannot be restored after the system restarts.
Procedure
Procedure
● Enable the system to automatically save configurations.
NOTE
If the local storage medium does not have sufficient space or is damaged, or the
configuration file needs to be backed up, you can run this command to specify a file
server for saving the backup configuration file.
SFTP has higher security and is therefore recommended for saving the configuration
file to the file server.
The configuration file is saved on the server as a compressed package, named in the
[Link] [Link] format (for example,
[Link]). After decompression, the file with the file name
extension .cfg is the configuration file.
d. (Optional) Configure the function for uploading the configuration file at
a specific time point of a certain day every month.
configuration current backup-to-server monthly date date-value [ time time-value ]
The configuration file name extension must be .zip, .dat, or .cfg. If the
configuration file will be loaded during system startup, it must be stored
in the root directory of the storage medium.
If the configuration-file parameter is not specified, the system asks you
whether to name the configuration file [Link] when you save the
configuration file for the first time. The [Link] file is the default
configuration file and does not contain any configuration in the initial
state. If configurations are not saved for the first time, they will be saved
in the running configuration file. You can run the display startup
command to check the name of the running configuration file.
– Enter a password to save the configuration file.
save shareable-configuration configuration-file [ password ]
NOTE
----End
Context
When the system restarts, it uses the specified configuration file to restore
configurations.
Before specifying the file for the next startup, you can run the display startup
command to view the current specified file.
NOTE
Procedure
● Configure the configuration file for the next startup.
startup saved-configuration configuration-file
● Configure the configuration file containing key information for the next
startup.
startup shareable-configuration configuration-file [ password ]
If the configuration file configured for the next startup contains key
information, you need to enter a password for authentication before using the
file.
----End
Context
A configuration file may contain a ciphertext encrypted using a system master key.
As a system master key is automatically and randomly generated by default,
different devices have different system master keys. The ciphertext in a
configuration file of a device cannot be decrypted on another device. As a result,
the ciphertext cannot be restored on another device and will be used as a
plaintext. To decrypt the ciphertext in the configuration file on another device,
perform the following operations.
Procedure
Step 1 Export the configuration file from device A.
1. Save the configuration file.
save shareable-configuration configuration-file [ password ]
For details, see 8.3.11 Backing Up the Configuration File to an SFTP Server
or Client.
For details, see 8.3.16 Copying the Configuration File from an SFTP Server
or Client to the Device.
2. Configure the exported configuration file as the configuration file to be
loaded for the next startup of device B.
startup shareable-configuration configuration-file [ password ]
----End
Context
You can compare the current configuration file with the specified configuration file
to check whether they are consistent and determine whether to use the specified
configuration file for the next startup.
NOTE
Procedure
Context
You can copy configurations on the screen to back up them as a configuration file
to the hard disk of the PC. The backup configuration file can be used if the
configuration file restoration fails due to unexpected device damage.
Procedure
Step 1 Copy configurations on the screen. Specifically, run the following command and
copy all command output to a .txt file on the PC. The configurations are then
saved on the PC.
display current-configuration
NOTE
If the configuration of a single command is too long, the configuration may be displayed in
multiple lines on the terminal screen, depending on the terminal software. When copying a
multi-line configuration from the screen to a .txt file, ensure that the configuration occupies
one line in the .txt file. Otherwise, such a configuration may fail to be restored when
the .txt file is used.
----End
Context
You can back up the configuration file to the storage medium. The backup
configuration file can be used if the configuration file restoration fails due to
unexpected device damage.
Procedure
Step 1 (Optional) Save the configuration file.
save configuration-file
----End
Prerequisites
Before backing up the configuration file to an FTP server or client, you have
completed the following tasks:
● If the device functions as an FTP client, connect it to an FTP server. For details,
see "Configuring a Device as an FTP Client" in CLI Configuration Guide > Basic
Configuration.
● If the device functions as an FTP server, connect it to an FTP client. For details,
see "Configuring a Device as an FTP Server" in CLI Configuration Guide >
Basic Configuration.
● Run the install feature-software WEAKEA command to install the weak
security algorithm/protocol feature package (WEAKEA).
Context
If the device is unexpectedly damaged, the configuration file cannot be restored.
In this case, a backup configuration file is required for restoring the device
configurations. You can back up the configuration file through FTP using either of
the following methods:
NOTE
Backing up the configuration file through FTP is a simple process, which however may pose
security risks. In scenarios featuring high security requirements, SFTP and SCP are
recommended for configuration file backup.
In FIPS mode, FTP cannot be used to back up configuration files.
Procedure
● Back up the configuration file to the FTP server when the device functions as
an FTP client.
a. Set up an FTP connection with the FTP server.
ftp [ ipv6 ] host-ip
On the device, run the put command to upload the configuration file to
the specified path on the PC that functions as an FTP server.
put local-filename [ remote-filename ]
● Back up the configuration file to the FTP client when the device functions as
an FTP server.
a. On the PC that functions as an FTP client, initiate an FTP connection with
the device.
On the PC, run the get command to download the configuration file to
the specified path on the PC.
ftp> get remote-filename [ local-filename ]
----End
Prerequisites
Before backing up the configuration file to a TFTP server, you have completed the
following tasks:
● Ensure that the device has been connected to the TFTP server. For details, see
"Configuring a Device as a TFTP Client" in CLI Configuration Guide > Basic
Configuration.
● Run the install feature-software WEAKEA command to install the weak
security algorithm/protocol feature package (WEAKEA).
Context
If the device is unexpectedly damaged, the configuration file cannot be restored.
In this case, a backup configuration file is required for restoring the device
configurations. You can back up the configuration file through TFTP.
NOTE
Backing up the configuration file through TFTP is a simple process, which however may
pose security risks. In scenarios featuring high security requirements, SFTP and SCP are
recommended for configuration file backup.
In FIPS mode, TFTP cannot be used to back up configuration files.
Procedure
Step 1 Back up the configuration file to the TFTP server.
tftp [ ipv6 ] hostname-ip put sourcefilename [ destination-filename ]
----End
Prerequisites
Before backing up the configuration file to an SFTP server or client, you have
completed the following tasks:
● If the device functions as an SFTP client, connect it to an SFTP server. For
details, see "Configuring a Device as an SFTP Client" in CLI Configuration
Guide > Basic Configuration.
● If the device functions as an SFTP server, connect it to an SFTP client. For
details, see "Configuring a Device as an SFTP Server" in CLI Configuration
Guide > Basic Configuration.
Context
If the device is unexpectedly damaged, the configuration file cannot be restored.
In this case, a backup configuration file is required for restoring the device
configurations. You can back up the configuration file through SFTP using either of
the following methods:
● If the device functions as an SFTP client, back up the configuration file to an
SFTP server.
● If the device functions as an SFTP server, back up the configuration file to an
SFTP client.
NOTE
Backing up the configuration file through FTP or TFTP is a simple process, which however
may pose security risks. In scenarios featuring high security requirements, SFTP and SCP are
recommended for configuration file backup.
Procedure
● Back up the configuration file to the SFTP server when the device functions as
an SFTP client.
a. Enter the system view.
system-view
On the device, run the put command to upload the configuration file to
the specified path on the PC that functions as an SFTP server.
put local-filename [ remote-filename ]
● Back up the configuration file to the SFTP client when the device functions as
an SFTP server.
a. On the PC that functions as an SFTP client, initiate an SFTP connection
with the device.
On the PC, run the get command to transfer the configuration file to the
specified path on the PC.
sftp> get remote-filename [ local-filename ]
----End
Context
If the device is unexpectedly damaged, the configuration file cannot be restored.
In this case, a backup configuration file is required for restoring the device
configurations. You can back up the configuration file through SCP using either of
the following methods:
● If the device functions as an SCP client, back up the configuration file to an
SCP server.
● If the device functions as an SCP server, back up the configuration file to an
SCP client.
Select one method as required.
Procedure
● Back up the configuration file to the SCP server when the device functions as
an SCP client.
a. Enter the system view.
system-view
For example, to back up the [Link] file to the SCP server at [Link]
in SCP mode, run the following command. (The following information is
for reference only.)
<HUAWEI> system-view
[HUAWEI] scp [Link] scpuser@[Link]:flash:/[Link]
Trying [Link]...
Press CTRL+K to abort
Connected to [Link]...
The server is not authenticated. Continue to access it? [Y/N]:y
Save the server's public key? [Y/N]:y
The server's public key will be saved with the name [Link]. Please wait...
Please select public key type for user authentication [R for RSA/D for DSA/E for ECC] Please
select [R/D/E]:e
Enter password:
[Link] 100% 261Bytes 1Kb/s
● Back up the configuration file to the SCP client when the device functions as
an SCP server.
On the PC that functions as an SCP client, run the following command to
back up the configuration file to the specified path on the PC:
scp source-filename destination-filename
For example, to back up the [Link] file to the SCP client in SCP mode, run
the following command. The IP address of the device is [Link]. (The
following information is for reference only.)
C:\Documents and Settings\Administrator> scp scpuser@[Link]:flash:/[Link] [Link]
The authenticity of host '[Link] ([Link])' can't be established.
DSA key fingerprint is 46:b2:8a:52:88:42:41:d4:af:8f:4a:41:d9:b8:4f:ee.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '[Link]' (DSA) to the list of known hosts.
scpuser@[Link]'s password:
[Link] 100% 1257 1.2KB/s 00:00
Read from remote host [Link]: Connection reset by peer
----End
Procedure
Step 1 Copy the backup configuration file and specify the name for the configuration file
copy.
copy source-filename destination-filename [ all ]
Step 3 Restart the device for the configuration file to take effect.
reboot fast
----End
Prerequisites
Before copying the configuration file from an FTP server or client to the device,
you have completed the following tasks:
● If the device functions as an FTP client, connect it to an FTP server. For details,
see "Configuring a Device as an FTP Client" in CLI Configuration Guide > Basic
Configuration.
● If the device functions as an FTP server, connect it to an FTP client. For details,
see "Configuring a Device as an FTP Server" in CLI Configuration Guide >
Basic Configuration.
● Run the install feature-software WEAKEA command to install the weak
security algorithm/protocol feature package (WEAKEA).
Context
If functions do not operate properly due to incorrect configurations, you can copy
the backup configuration file of the device from an FTP server or client to restore
the configuration file using either of the following methods:
● If the device functions as an FTP client, copy the configuration file from an
FTP server to the device.
● If the device functions as an FTP server, copy the configuration file from an
FTP client to the device.
NOTE
Restoring the configuration file through FTP is a simple process, which however may pose
security risks. In scenarios featuring high security requirements, SFTP and SCP are
recommended for configuration file restoration.
In FIPS mode, FTP cannot be used to restore configuration files.
Procedure
● Copy the configuration file from the FTP server when the device functions as
an FTP client.
a. Set up an FTP connection with the FTP server.
ftp [ ipv6 ] host-ip
On the device, run the get command to copy the configuration file from
the PC that functions as an FTP server to the specified path on the device.
get remote-filename [ local-filename ]
● Copy the configuration file from the FTP client when the device functions as
an FTP server.
a. On the PC that functions as an FTP client, initiate an FTP connection with
the device.
In this example, the IP address of the device is [Link], the FTP
user name created on the device is huawei, and the password of the FTP
user is YsHsjx_202206.
C:\Documents and Setting\Administrator> ftp [Link]
Connected to [Link].
220 FTP service ready.
User ([Link]:(none)): huawei
331 Password required for huawei.
Password:
230 User logged in.
----End
Context
If functions do not operate properly due to incorrect configurations, you can copy
the backup configuration file from the TFTP server to the device to restore the
functions.
NOTE
Restoring the configuration file through TFTP is a simple process, which however may pose
security risks. In scenarios featuring high security requirements, SFTP and SCP are
recommended for configuration file restoration.
In FIPS mode, TFTP cannot be used to restore configuration files.
Procedure
Step 1 Copy the configuration file from the TFTP server to the device.
tftp [ ipv6 ] hostname-ip get source-filename [ destination-filename ]
----End
Context
If functions do not operate properly due to incorrect configurations, you can copy
the backup configuration file of the device from an SFTP server or client to restore
the configuration file using either of the following methods:
● If the device functions as an SFTP client, copy the configuration file from an
SFTP server to the device.
● If the device functions as an SFTP server, copy the configuration file from an
SFTP client to the device.
Select one method as required.
Procedure
● Copy the configuration file from the SFTP server when the device functions as
an SFTP client.
a. Enter the system view.
system-view
----End
Context
If functions do not operate properly due to incorrect configurations, you can copy
the backup configuration file of the device from an SCP server or client to restore
the configuration file using either of the following methods:
● If the device functions as an SCP client, copy the configuration file from an
SCP server to the device.
● If the device functions as an SCP server, copy the configuration file from an
SCP client to the device.
Select one method as required.
Procedure
● Copy the configuration file from the SCP server when the device functions as
an SCP client.
a. Enter the system view.
system-view
On the device, run the following command to copy the configuration file
from the PC that functions as an SCP server to the specified path on the
device:
scp source-filename destination-filename
For example, to copy the [Link] file from the SCP server at [Link] to
the device using SCP, run the following command. (The following
information is for reference only.)
<HUAWEI> system-view
[HUAWEI] scp scpuser@[Link]:flash:/[Link] [Link]
Trying [Link]...
Press CTRL+K to abort
Connected to [Link]...
The server is not authenticated. Continue to access it? [Y/N]:y
Save the server's public key? [Y/N]:y
The server's public key will be saved with the name [Link]. Please wait...
Please select public key type for user authentication [R for RSA/D for DSA/E for ECC] Please
select [R/D/E]:e
Enter password:
[Link] 100% 261Bytes 1Kb/s
● Copy the configuration file from the SCP client when the device functions as
an SCP server.
Run the following command to copy the configuration file from the PC that
functions as an SCP client to the specified path on the device:
scp source-filename destination-filename
For example, to copy the [Link] file from the SCP client to the device at
[Link] using SCP, run the following command. (The following information is
for reference only.)
C:\Documents and Settings\Administrator> scp [Link] scpuser@[Link]:flash:/vrpcfg-
[Link]
The authenticity of host '[Link] ([Link])' can't be established.
DSA key fingerprint is 46:b2:8a:52:88:42:41:d4:af:8f:4a:41:d9:b8:4f:ee.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '[Link]' (DSA) to the list of known hosts.
scpuser@[Link]'s password:
[Link] 100% 1257 1.2KB/s 00:00
Read from remote host [Link]: Connection reset by peer
----End
Procedure
● Compress the configuration file.
zip source-filename destination-filename [ password password ]
----End
NOTICE
To configure an interface on a device for other uses, you need to first delete
existing configurations from the interface one by one. If the interface has a large
number of configurations, this can take a long time. A single command is
available for deleting all configurations on an interface, reducing the maintenance
workload and simplifying the deletion operation.
Procedure
● Delete configurations for the next startup.
a. Cancel the configuration file specified for the next startup to restore the
default configurations.
reset saved-configuration
NOTE
After the configuration file specified for the next startup is canceled, the device
will use default configurations for startup, unless the startup saved-
configuration command is used to specify a new configuration file, or new
configurations have been saved to the configuration file for the next startup.
Before the reset saved-configuration command is executed, the system checks
whether the configuration files used for the current startup and the next startup
are the same:
● If they are the same, running the reset saved-configuration command clears
both configuration files, and the default configuration file will be used for the
next startup.
● If they are not the same, running the reset saved-configuration command
clears the configuration file for next startup, but the current configuration file
remains unchanged.
● If the current configuration file is empty and the configuration file for next
startup is not empty, running the reset saved-configuration command clears
the configuration file for next startup.
● If the configuration file for next startup is empty and the current
configuration file is not empty, after the reset saved-configuration
command is run, the system reports an error and does not clear any
configuration file. If you run the command to restart a device, addresses
configured for management interfaces on the device will become invalid, and
you must log in to the device through a console interface to re-configure
these addresses.
b. Restart the device to validate the configuration.
reboot fast
NOTE
This command will delete all configurations of a specified interface. Exercise caution
when running this command.
Ensure that the specified interface type and number are correct. Otherwise, the
configurations of another interface may be deleted, causing service interruption.
----End
NOTE
The system configuration takes effect in immediate mode. After you enter a command line
and press Enter, the system performs a syntax check. The configuration takes effect as soon
as it passes the syntax check, and you do not need to run the commit command to commit
the configuration.
Procedure
Step 1 Check the configuration rollback points and the latest configuration changes.
Step 2 Roll back the system to the historical configuration state by specifying a
configuration rollback point.
rollback configuration { to commit-id commit-id | to label label | to file file-name }
Step 3 (Optional) Set the user label for a configuration rollback point.
set configuration commit commit-id label label-string
Step 4 (Optional) Delete the user label of the specified configuration rollback point or
the earliest configuration rollback point list generated in the system.
clear configuration commit { commit-id label | oldest number-of-commits }
Step 5 (Optional) Delete the configuration rollback point with a specified user label.
----End
Example
A user logs in to the device and finds that the configuration is incorrect. The user
then rolls back the system using a backup configuration file.
1. Check the name of the backup configuration file on the current device.
<HUAWEI> dir
Directory of flash:/
Networking Requirements
As shown in Figure 8-1, the current system software cannot meet user needs. The
device must load new software version with more features. Then the device
software needs to be upgraded remotely.
Figure 8-1 Network diagram of specifying the configuration file to be loaded for
next startup
Configuration Roadmap
The configuration roadmap is as follows:
1. Upload the new system software to the root directory of the device.
2. Save the current configuration so that it remains effective after upgrade.
3. Specify the system software to be loaded for next startup.
4. Specify the configuration file to be loaded for next startup.
5. Restart the device to complete upgrade.
Procedure
Step 1 Upload the new system software to the root directory of the device.
1. Before configuration, run the display startup command to view the files for
next startup.
<HUAWEI> display startup
MainBoard:
Configured startup system software: flash:/[Link]
Startup system software: flash:/[Link]
Next startup system software: flash:/[Link]
Startup saved-configuration file: flash:/[Link]
Next startup saved-configuration file: flash:/[Link]
Startup paf file: default
Next startup paf file: default
Startup patch package: NULL
Next startup patch package: NULL
2. Configure the device as an SFTP server.
Upload the new system software to the device. This example uses SFTP to
transfer the system software. Configure the device as an SFTP server and
upload the system software to the device from the SFTP client. Ensure that
there is enough space in the storage medium before uploading files. If the
space is insufficient, delete unnecessary files from the storage medium.
# Configure an IP address for the SFTP server.
<HUAWEI> system-view
[HUAWEI] sysname SSH Server
[SSH Server] interface 10ge 1/0/1
[SSH Server-10GE1/0/1] undo portswitch
[SSH Server-10GE1/0/1] ip address [Link] [Link]
[SSH Server-10GE1/0/1] quit
# Configure the public key algorithm, encryption algorithm, key exchange
algorithm list, HMAC authentication algorithm, and minimum key length on
the SSH server.
[SSH Server] ssh server cipher aes128_ctr aes256_ctr aes192_ctr aes128_gcm aes256_gcm
[SSH Server] ssh server hmac sha2_256 sha2_512
[SSH Server] ssh server key-exchange dh_group_exchange_sha256 dh_group16_sha512
[SSH Server] ssh server publickey rsa_sha2_256 rsa_sha2_512
[SSH Server] ssh server dh-exchange min-len 3072
# On the server, generate a local key pair and enable the SFTP server
function.
[SSH Server] dsa local-key-pair create
Info: The key name will be: Host_DSA
Info: The key modulus can be any one of the following :
2048.
Info: Key pair generation will take a short
while.
Info: Generating keys...
Info: Succeeded in creating the DSA host keys.
The system displays a message indicating that the current configuration will be
saved and asks you whether to continue. Enter y and the configuration will be
saved to the device.
Step 3 Specify the system software to be loaded for next startup.
<SSH Server> startup system-software [Link]
NOTE
In step 1, you can run the display startup command to check the configuration file for next
startup. The message "Next startup saved-configuration file: flash:/[Link]" will be
displayed. This means that the [Link] configuration file has been specified for next
startup, so skip this step. To specify another file for next startup, perform this step.
Run the following command to view the system software and configuration file
for next startup.
<SSH Server> display startup
MainBoard:
Configured startup system software: flash:/[Link]
Startup system software: flash:/[Link]
Next startup system software: flash:/[Link]
Startup saved-configuration file: flash:/[Link]
Next startup saved-configuration file: flash:/[Link]
Startup paf file: default
Next startup paf file: default
Startup patch package: NULL
Next startup patch package: NULL
# Because the configuration file has been saved, run the following command to
restart the device quickly.
<SSH Server> reboot fast
When the system asks you whether to continue with a system restart, enter y.
----End
Configuration Scripts
#
sysname SSH Server
#
acl number 2000
rule 5 permit source [Link] [Link]
#
aaa
local-user client password irreversible-cipher $1d$+,JS+))\\2$KVNj(.3`_5x0FCKGv}H&.kUTI`Ff&H*[Link]>)$
local-user client service-type terminal ssh
local-user client privilege level 3
#
interface 10GE1/0/1
undo portswitch
ip address [Link] [Link]
#
sftp server enable
ssh server-source all-interface
ssh server acl 2000
ssh user client
ssh user client authentication-type password
ssh user client service-type sftp
ssh user client sftp-directory flash:
#
ssh server cipher aes128_ctr aes256_ctr aes192_ctr aes128_gcm aes256_gcm
ssh server hmac sha2_256 sha2_512
ssh server key-exchange dh_group_exchange_sha256 dh_group16_sha512
ssh server publickey rsa_sha2_256 rsa_sha2_512
ssh server dh-exchange min-len 3072
#
return