Netgear FSM7226P-100NES Datasheet Page 9

  • Download
  • Add to my manuals
  • Print
  • Page
    / 36
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 8
ProSAFE® Intelligent Edge Managed Switches Data Sheet
M4100 series
Page9of36
Dynamic 802.1x VLAN assignment mode, including
Dynamic VLAN creation mode and Guest VLAN/
Unauthenticated VLAN are supported for rigorous user
andequipmentRADIUSpolicyserverenforcement
• Up to 48 clients (802.1x) per port are supported, including the authentication of the users domain, in
order to facilitate convergent deployments: for instance when IP phones connect PCs on their bridge, IP
phones and PCs can authenticate on the same switch port but under dierent VLAN assignment policies
(Voice VLAN versus data VLAN)
802.1x MAC Address Authentication Bypass (MAB)
is an alternative method for non-Radius clients
• A list of authorized MAC addresses of client NICs is maintained on the RADIUS server for MAB purpose
• MAB can be configured on a per-port basis on the switch
• MAB initiates only aer the dot1x authentication process times out, and only when clients don’t respond
to any of the EAPOL packets sent by the switch
• When 802.1x unaware clients try to connect, the switch sends the MAC address of each client to the
authentication server
• The RADIUS server checks the MAC address of the client NIC against the list of authorized addresses
• The RADIUS server returns the access policy and VLAN assignment to the switch for each client
DoubleVLANs(DVLAN-QoQ)passtracfromonecustomerdomaintoanotherthroughthe“metrocore”inamulti-tenancyenvironment:customerVLANIDsare
preservedandaserviceproviderVLANIDisaddedtothetracsothetraccanpassthemetrocoreinasimple,securemanner
Private VLANs (with Primary VLAN, Isolated VLAN,
CommunityVLAN,Promiscuousport,Hostport,
Trunks) provide Layer 2 isolation between ports
that share the same broadcast domain, allowing a
VLAN broadcast domain to be partitioned into smaller
point-to-multipoint subdomains across switches in
the same Layer 2 network
• Private VLANs are useful in DMZ when servers are not supposed to communicate with each other but
need to communicate with a router; they remove the need for more complex port-based VLANs with
respective IP interface/subnets and associated L3 routing
• Another Private VLANs typical application are carrier-class deployments when users shouldn’t see, snoop
orattackotherusers’trac
SecureShell(SSH)andSNMPv3(withorwithoutMD5orSHAauthentication)ensureSNMPandTelnetsessionsaresecured
TACACS+ and RADIUS enhanced administrator management provides strict "Login" and "Enable" authentication enforcement for the switch configuration, based on
latestindustrystandards:execauthorizationusingTACACS+orRADIUS;commandauthorizationusingTACACS+andRADIUSServer;userexecaccountingforHTTP
andHTTPSusingTACACS+orRADIUS;andauthenticationbasedonuserdomaininadditiontouserIDandpassword
Superior quality of service
Advanced classifier-based hardware implementation for Layer 2 (MAC), Layer 3 (IP) and Layer 4 (UDP/TCP transport ports) prioritization
8queuesforprioritiesandvariousQoSpoliciesbasedon802.1p(CoS)andDiServcanbeappliedtointerfacesandVLANs
Advancedratelimitingdownto1Kbpsgranularityandmininum-guaranteedbandwidthcanbeassociatedwithACLsforbestgranularity
Automatic Voice over IP prioritization with Auto-VoIP
Flow Control
802.3x Flow Control implementation per IEEE 802.3
Annex31BspecicationswithSymmetricow
control,AsymmetricowcontrolorNoowcontrol
AsymmetricowcontrolallowstheswitchtorespondtoreceivedPAUSEframes,buttheportscannot
generate PAUSE frames
Symmetricowcontrolallowstheswitchtobothrespondto,andgenerateMACcontrolPAUSEframes
Allowstracfromonedevicetobethrottledforaspeciedperiodoftime:adevicethatwishestoinhibittransmissionofdataframesfromanotherdeviceonthe
LAN transmits a PAUSE frame
Modern access layer features highlights
Page view 8
1 2 3 4 5 6 7 8 9 10 11 12 13 14 ... 35 36

Comments to this Manuals

No comments