
KEY FEATURES SUMMARY CONTINUED
Denial of Service Protection—Monitoring, throttling, and locking out of ICMP and TCP SYN
trafc both to the management address of the switch and for transit trafc
Man-in-the-Middle prevention using Dynamic ARP Inspection and DHCP Snooping*
Port Security and MAC Address Locking limits the number MAC addresses learned
on a port. Using Port Security network managers can allow specic MAC addresses
access to the network for specic time periods.
MAC address authentication including multiple device authentication and dynamic
policy conguration
Policy-controlled MAC-based VLANs provide additional control
Advanced Quality of Service
Packet classication, reclassication, policing, marking, and re-marking
Identication, classication, and reclassication of trafc based on specic criteria
such as port, source/destination MAC address, 802.1p priority bit, source/destination
IP address, Type of Service (ToS), Differentiated Services Codepoints (DSCP), or
TCP/UDP port
Flexible queue servicing utilizing congurable Weighted Round Robin (WRR), Strict
Priority (SP), or hybrid SP/WRR
8 hardware queues for exible QoS management
Ingress rate limiting—standard and extended ACL control
ACLs congured on a per-port per-VLAN basis
Egress rate limiting—per-port, per-queue
Support for up to 256 wire-speed ingress trafc policers with each policer supporting
congurable metering with maximum and burst size settings, color aware and out-of-
prole packet remarking or dropping sFlow and port mirroring on the same port
System and Network Resilience
Advanced Layer 2 service protection features: Metro Ring Protocol (versions I and II),
Virtual Switch Redundancy Protocol, Rapid Spanning Tree, Multiple Spanning Tree, Per
VLAN Spanning Tree (PVST, PVST+), Protected Link groups, Link Fault Signaling (LFS),
Remote Fault Notication (RFN)
Digital optical monitoring
Port range with port speed downshift and selective auto negotiation
Port loop detection to detect Layer 1/Layer 2 loops
Image checksum verication
Next boot information
Port ap dampening
Single link LACP as a standards-based bi-directional link detection protocol
Auto-conguration
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
*Available only on the standalone FastIron LS. This feature is not available on the IronStack enabled FastIron LS.
Komentáře k této Příručce