Huawei vs H3C CLI Commands: Side-by-Side VRP Reference - 夜莺博客

Huawei vs H3C CLI Commands: Side-by-Side VRP Reference

Huawei and H3C switches dominate government and enterprise networks across Asia, and their configuration logic is similar - both are influenced by the same early VRP heritage - yet their command syntax diverges just enough to trip up engineers who move between brands. This side-by-side reference maps the most common tasks on Huawei VRP and H3C Comware so you can configure either platform without guessing.

The two operating systems are close enough that a configuration copied between them usually looks plausible, which is exactly what makes the differences dangerous. A line either parses and does the right thing, parses and does something slightly different, or fails in a way that leaves the port in an unexpected state. This article concentrates on that third category - the divergences that cost time during an outage - and pairs every table with the operational reason the two vendors chose different keywords.

Where the Two CLIs Came From

Comware and VRP grew out of the same engineering tradition, which is why the view hierarchy, the display verb and the undo keyword appear on both. As the two products diverged commercially, each vendor evolved its own conventions for the areas it invested in most: Huawei standardised early on the Eth-Trunk and Vlanif naming that appears throughout its S-series documentation, while H3C kept the Bridge-Aggregation and Vlan-interface names that came from its Comware lineage. Neither is more correct; knowing which vocabulary belongs to which vendor is the whole skill.

Navigation and System Commands

Task Huawei (VRP) H3C (Comware)
Enter user view <HUAWEI> (default) <H3C> (default)
Enter system view system-view system-view
Set hostname sysname SW1 sysname SW1
Return to user view return return
Show version display version display version
Show running config display current-configuration display current-configuration
Save config save save force
Disable screen paging screen-length 0 temporary screen-length disable
Show device inventory display device display device
Show interface summary display ip interface brief display ip interface brief

Both platforms use display (not show) and system-view; the biggest practical difference is that H3C's save prompts for filename confirmation while save force skips it, whereas Huawei's save just confirms with Y.

The paging difference is worth writing into any automation runbook. On VRP, screen-length 0 temporary disables the pager for the current session only - a fresh SSH connection restores it; on Comware, screen-length disable turns it off until you re-enable it. Scripts that scrape display current-configuration from a mixed fleet must send the right paging command per vendor, or half the captures will be silently truncated at the first 24 lines.

Interface and IP Commands

Task Huawei H3C
Enter physical port interface GigabitEthernet0/0/1 interface GigabitEthernet1/0/1
Enable port undo shutdown undo shutdown
Disable port shutdown shutdown
Set speed/duplex speed 1000 / duplex full speed 1000 / duplex full
Management VLAN IF interface Vlanif 20 interface Vlan-interface 20
IP on SVI ip address 192.168.1.2 24 ip address 192.168.1.2 24
Interface description description UPLINK-TO-CORE description UPLINK-TO-CORE
Set MTU mtu 9000 mtu 9000
Add to aggregation eth-trunk 1 port link-aggregation group 1

Note the naming: Huawei S-series ports count from 0 (GigabitEthernet0/0/1) while H3C S-series commonly start at 1 (GigabitEthernet1/0/1), and the management SVI is Vlanif on Huawei versus Vlan-interface on H3C. Interface numbering is not merely cosmetic: it affects every port range command, every ACL interface reference and every line of an automation inventory. Always confirm the slot convention from display interface brief on the actual device rather than assuming from the model number.

VLAN and Trunk Commands

# Huawei
[HUAWEI] vlan batch 10 20 30
[HUAWEI] interface GigabitEthernet0/0/1
[HUAWEI-GigabitEthernet0/0/1] port link-type access
[HUAWEI-GigabitEthernet0/0/1] port default vlan 10

# H3C
[H3C] vlan batch 10 20 30
[H3C] interface GigabitEthernet1/0/1
[H3C-GigabitEthernet1/0/1] port link-type access
[H3C-GigabitEthernet1/0/1] port access vlan 10

For trunks, Huawei uses port trunk allow-pass vlan 10 20 and H3C uses port trunk permit vlan 10 20 - the same concept, different verb. H3C also lets you set a management VLAN with management-vlan 20.

Comware creates VLANs individually with vlan 10 or as a range with vlan 10 to 30, so the vlan batch form shown above is the VRP spelling; when a Huawei template moves to an H3C switch, that line is the first thing to rewrite. Remember also that both vendors support a third link type, hybrid, which IOS engineers have no equivalent for:

# Huawei hybrid port
[HUAWEI-GigabitEthernet0/0/1] port link-type hybrid
[HUAWEI-GigabitEthernet0/0/1] port hybrid pvid vlan 10
[HUAWEI-GigabitEthernet0/0/1] port hybrid vlan 10 untagged
[HUAWEI-GigabitEthernet0/0/1] port hybrid vlan 20 tagged

Hybrid mode is the reason a Huawei or H3C access switch can natively terminate one VLAN for a downstream device while still trunking the rest of the VLAN list upstream - useful in healthcare and campus designs where IP phones and PCs share a port and the phone expects untagged traffic.

Routing Protocol Commands

Static routing and OSPF are close to identical between the two platforms, which makes the small differences easy to miss. The static-route keyword pair reverses the Cisco order, and the OSPF area view is written as 0.0.0.0 even when you type 0.

# Static route (identical on both)
[HUAWEI] ip route-static 0.0.0.0 0 192.168.1.254
[H3C]     ip route-static 0.0.0.0 0 192.168.1.254

# OSPF (identical on both, area shown in dotted decimal)
[HUAWEI] ospf 1 router-id 1.1.1.1
[HUAWEI-ospf-1] area 0
[HUAWEI-ospf-1-area-0.0.0.0] network 10.0.0.0 0.0.0.255
[HUAWEI-ospf-1-area-0.0.0.0] quit
[HUAWEI-ospf-1] quit

# Verification
display ospf peer brief
display ospf routing
display ospf interface

# BGP address family naming is where they differ
[HUAWEI-bgp] ipv4-family unicast          # Huawei VRP
[H3C-bgp]    address-family ipv4 unicast  # H3C Comware

The BGP address-family line is the one that bites during a migration: VRP says ipv4-family unicast and Comware says address-family ipv4 unicast. Both then require an explicit peer <ip> enable inside that view before prefixes are exchanged, which is a rule IOS engineers are not used to because IOS enables the peer as soon as the neighbour statement is written.

Link Aggregation and Spanning Tree

# Huawei: Eth-Trunk
[HUAWEI] interface Eth-Trunk 1
[HUAWEI-Eth-Trunk1] mode lacp-static
[HUAWEI] interface GigabitEthernet0/0/1
[HUAWEI-GigabitEthernet0/0/1] eth-trunk 1

# H3C: Bridge-Aggregation
[H3C] interface Bridge-Aggregation 1
[H3C-Bridge-Aggregation1] link-aggregation mode dynamic
[H3C] interface GigabitEthernet1/0/1
[H3C-GigabitEthernet1/0/1] port link-aggregation group 1

Neither vendor uses Cisco's port-channel/channel-group vocabulary. Huawei's manual mode is the default and is used where the peer does not speak LACP; the LACP modes are lacp-static on VRP and dynamic on Comware. Spanning tree is closer to identical - both support stp mode stp, stp mode rstp and stp mode mstp, both elect a root with stp root primary inside the relevant instance view, and Comware 7 adds an explicit stp global enable at the top level.

User and Security Commands

# Huawei: set super (privilege) password
[HUAWEI] super password cipher <password>
# H3C: set super password
[H3C] super password <password>
[H3C] local-user admin password irreversible-cipher <password>
[H3C] local-user admin service-type ssh

H3C's local-user model is more explicit (create the user, then bind service types); Huawei uses the aaa view with local-user similarly but enables the user with local-user privilege level. A complete working pair of SSH configurations shows the shape of each:

# Huawei VRP
[HUAWEI] stelnet server enable
[HUAWEI] aaa
[HUAWEI-aaa] local-user admin password irreversible-cipher Str0ngP@ss
[HUAWEI-aaa] local-user admin privilege level 15
[HUAWEI-aaa] local-user admin service-type ssh
[HUAWEI] user-interface vty 0 4
[HUAWEI-ui-vty0-4] authentication-mode aaa
[HUAWEI-ui-vty0-4] protocol inbound ssh

# H3C Comware
[H3C] ssh server enable
[H3C] local-user admin
[H3C-luser-manage-admin] password irreversible-cipher Str0ngP@ss
[H3C-luser-manage-admin] service-type ssh
[H3C-luser-manage-admin] authorization-attribute user-role network-admin
[H3C] line vty 0 63
[H3C-line-vty0-63] authentication-mode scheme
[H3C-line-vty0-63] protocol inbound ssh

Two differences stand out. Huawei grants administrative capability through a numeric privilege level, while H3C 7 grants it through a named role (network-admin, or a custom role created with the RBAC commands). And the VTY line range differs by convention - Huawei typically exposes vty 0 4 and H3C vty 0 63 - so a script that binds authentication to a specific line range may work on one platform and leave the other's higher-numbered lines unauthenticated. On both platforms remember that the SSH server itself must be enabled before the user configuration has any effect.

File Management, Backups and Rollback

display current-configuration
display saved-configuration
save
reset saved-configuration
dir
tftp 192.0.2.10 put flash:/vrpcfg.zip backup-vrpcfg.zip

The boot configuration is a file in flash - vrpcfg.zip on VRP, startup.cfg (or startup.cfg concatenated per device, depending on release) on Comware - so backups and restores are file transfers rather than console pastes. That is a genuine advantage over IOS, because restoring a device is a tftp put and a reload rather than reconstructing a configuration by hand. The catch is that both platforms keep old copies of the startup file on flash, and a device restored from a stale file will boot with a per-interface configuration that no longer matches the cabling.

Fast Reference: Which Command Lands Where

  • Identical: system-view, sysname, quit, return, display version, display current-configuration, display ip interface brief, ip route-static, the whole OSPF stanza, shutdown/undo shutdown, ping, tracert.
  • Different verb, same idea: port default vlan vs port access vlan; port trunk allow-pass vlan vs port trunk permit vlan; Eth-Trunk vs Bridge-Aggregation; Vlanif vs Vlan-interface; ipv4-family unicast vs address-family ipv4 unicast.
  • Different behaviour: save (prompts) vs save force (silent); privilege-level model vs named user roles; screen-length 0 temporary vs screen-length disable.

Common Mistakes When Moving Between VRP and Comware

Four errors account for most of the wasted time on mixed Huawei and H3C estates, and all four are avoidable with a checklist.

  1. Assuming the port number starts at 0. Typing interface GigabitEthernet0/0/1 on an H3C fixed switch usually fails, but on some chassis the same string addresses a different slot entirely - and the configuration then lands on the wrong physical port without any error that a hurried engineer would notice.
  2. Using the wrong access-VLAN verb. port default vlan 10 is meaningless on Comware and port access vlan 10 is meaningless on VRP. The port stays in its previous VLAN, and the outage only becomes visible when a host cannot reach its gateway.
  3. Forgetting the address family for BGP. Both platforms silently exchange nothing until the peer is enabled inside the IPv4 unicast family view. Sessions show Established while the prefix count stays at zero, which sends engineers looking at routing policy instead of the family configuration.
  4. Saving with the wrong command. A Huawei session ended with save force and an H3C session ended with save both look the same on the console, but only the correct form actually writes the file in a non-interactive script. Always verify with display saved-configuration afterwards rather than trusting the prompt's echo.

A fifth, subtler trap is the hybrid port. Once a port is set to port link-type hybrid, the access and trunk keywords stop applying, and reverting to access requires an explicit port link-type access before the VLAN assignment takes effect again. Engineers who inherit a switch and try to re-purpose a hybrid port often conclude the port is broken when the configuration is simply still in hybrid mode.

Related Reading on This Site

See the H3C vs Huawei CLI comparison and the Cisco vs Juniper troubleshooting cheat sheet for the other big vendor pair. If you are coming from Cisco, the Huawei/H3C/Cisco command equivalents table adds the IOS column, and VRP vs Comware CLI commands compared covers the day-to-day verification commands.

原文链接:https://blog.router-switch.com/2023/06/master-the-basic-command-configurations-of-huawei-h3c-ruijie-and-cisco-switches-with-router-switch-com/