|
|
• |
802.1X multi-client, multi-VLAN support for per-client authentication and VLAN assignment |
|
• |
802.1X with group mobility |
|
• |
802.1X with MAC-based authentication, group mobility or “guest” VLAN support |
|
• |
MAC-based authentication for non-802.1X host |
|
• |
Authenticated VLAN that challenges users with username and password and supports dynamic VLAN access based on user |
|
• |
Captive Portal – a new Access Guardian policy that uses embedded web portal for user authentication.* |
|
• |
Public Key Infrastructure (PKI) authentication for SSH access |
|
• |
Support for host integrity check* and remediation VLAN |
|
• |
Learned Port Security (LPS) or MAC address lockdown allows only known devices to have network access preventing unauthorized network device access |
|
• |
Support of Microsoft® Network Access Protection (NAP)* |
|
|
|
Containment, monitoring and quarantine
|
|
• |
Support for Alcatel-Lucent OmniVista 2770 Quarantine Manager and quarantine VLAN |
|
• |
ACLs to filter out unwanted traffic including denial of service attacks; flow-based filtering in hardware (Layer 1 to Layer 4) |
|
• |
DHCP snooping, DHCP IP spoof protection |
|
• |
Dynamic ARP protection and ARP poisoning detection |
|
• |
Bridge Protocol Data Unit (BPDU) blocking – automatically shuts down switch ports being used as user ports if a spanning tree BPDU packet is seen. Prevents unauthorized spanning-treeenabled attached bridges from operating |
|
• |
sFlow v5 support to monitor and effectively control and manage the network usage |
|
|
|
Secure management
|
|
• |
RADIUS and Lightweight Directory Access Protocol (LDAP) admin authentication prevents unauthorized switch management |
|
• |
TACACS+ client allows for authentication, authorization and accounting with a remote TACACS+ server |
|
• |
Secure Shell (SSH), Secure Socket Layer (SSL) for HTTPS access and SNMPv3 for encrypted remote management communication |
|
• |
Secure file upload using Secure File Transfer Protocol (SFTP), or Secure Copy (SCP) |
|
• |
Switch protocol security |
|
|
- MD5 for Routing Information Protocol (RIP) v2 and SNMPv3 |
|
|
- SSH for secure CLI session with PKI support |
|
|
- SSL for secure HTTP session |
|
|
|
Ethernet access services |
|
• |
DHCP Option 82 – configurable relay agent information |
|
• |
Q-in-Q (VLAN stacking) |
|
• |
Ethernet OAM compliant with 802.1ag |
|
• |
Alcatel-Lucent 5620 SAM support (5620 SAM release 6.1) |
|
• |
Private VLAN feature |
|
• |
IP Multicast VLAN (IPMVLAN) |
|
• |
Ethernet services: |
|
|
- Service VLAN (SVLAN) and Customer VLAN (CVLAN) transparent LAN services |
|
|
- Ethernet network-to-network interface (NNI) and user network interface (UNI) services |
|
|
- Service Access Point (SAP) profile identification |
|
• |
MEF 9 and 14 certified |
|
• |
UDLD protection |
|
• |
Up to 16,000 MAC address learning |
|
• |
Up to 2000 QOS policy rules |
|
• |
Up to 1000 ACL policy rules |
|
• |
Up to 4096 VLANs per switch |
|
|
|
Power supplies and power consumption |
|
• |
Supports redundant hot-swappable power supplies |
|
• |
AC supplies: 90 V to 220 V AC |
|
• |
DC supplies: 36 V to 72 V DC |