
Distributed IP Routing-providesdynamictrafcoptimization,broadcast
containment, and more efficient network resilience
• Baseroutingfeaturesincludestaticroutes,RIPv1/RIPv2,VRRP,IPv4,
andMulticastroutingsupport(DVMRP,IGMPv1/v2,PIM-SM)
• Advancedroutingfeaturesarelicensedseparatelythroughthe
purchaseofN-EOS-L3andincludeLSNAT,DHCPrelay,PIM,OSPF,
DVMRP,andExtendedACLs.DiamondDFEsincludeadvanced
routing at no additional charge.
Security (User, Network, and Host) - protects a business against network
misuse and controls access to resources and confidential information
• Usersecurity
−Authentication(802.1X,MAC,andWeb),MAC(StaticandDynamic)
portlocking(perport802.1XauthenticationwithRADIUSsupport)
−Multi-userauthentication/policies
•Networksecurity
−AccessControlLists(ACL)–basicandextended
−Policy-basedsecurityservices(examples:spoong,unsupported
protocolaccess,intrusionprevention,DoSattackslimits)
•Host
−SecureaccesstotheN-SeriesviaSSH,SSL,SNMPv3(switchlogin
withRADIUSsupport)
Management,Control,andAnalysis-providestreamlinedtoolsfor
maintaining network availability and health
•Conguration
−Industry-standardCLIandwebsupport
−Multipleimageswitheditablecongurationles
•NetworkAnalysis
−SNMPv1/v2c/v3,RMON/RMONII,andSMON(rfc2613)VLANand
Stats
−Port/VLANmirroring(one-to-one,one-to-many,many-to-many)
−LinerateNetFlow
•Automatedset-upandreconguration
−ReplacementDFEwillautomaticallyinheritpreviousDFEs
configuration
– New blades added to chassis will automatically be updated with
active configuration and firmware
Optimized, High-Availability Services
Aside from the standard high-availability features of typical wiring closet
and data center switches, the N-Series includes many advanced features
such as dynamic service fail-over, automatic module self-configuration,
and multi-image support.
Dynamicservicefail-overenableseachDiamond/PlatinumDFE
service(e.g.,hostmanagement,switching/VLANs,routing,etc.)tobe
automaticallyswitchedtoanotherDiamond/PlatinumDFEinanevent
ofmoduleorprocessfailure.This“selfhealing”capabilityhappens
inmillisecondsbecauseeachserviceisreplicatedoneveryDiamond/
PlatinumDFE.
Automatic module self-configuration is another innovative feature that
allowsaDFEmoduletoreceivetheircongurationfromotherDFEs
automatically. This is ideal for replacing failed modules without manually
reconguringthereplacementDFE.
The N-series allow you to download and store multiple image files, this
feature is useful for reverting back to a previous version in the event that
a firmware upgrade fails. This multi-image support provides significant
operational efficiencies especially with regard to the application of
firmware patches.
Feature-Rich Functionality
Examplesofadditionalfunctionalityandfeaturesthatcanbefound
within the N-Series include:
• NetFlow
• LSNAT
• NAT
• LLDP-MED
• FlowSetupThrottling
• WebCacheRedirect
• Node&AliasLocation
• WebCacheRedirect
• PortProtectionSuite
Toexpandonsomeoftheabove,networkperformancemanagementand
securitycapabilitiesviaNetFlowareavailableoneveryN-SeriesDFE
without slowing down switching/routing performance or requiring the
purchaseofexpensivedaughtercardsforeveryblade.Enterasystracks
every packet in every flow as opposed to competitor’s statistical sampling
techniques.TheEnterasysadvantageisthenTERAASICcapabilitiesthat
collectNetFlowstatisticsforeverypacketineveryowwithoutsacricing
performance,N-Seriesswitchescancollect9,000owrecordsper
second,perbladeonGold,Platinum,andDiamondDFEs
ThisisanorderofmagnitudegreaterNetFlowcollectionperformance
thananyotherNetFlowappliancevendor(over60,000owrecordsper
secondinafully-populatedchassis).
FlowSetupThrottling(FST)isaproactivefeaturedesignedtomitigate
zero-daythreatsandDenialofService(DoS)attacksbeforetheycan
wreakhavoconthenetwork.FSTdirectlycombatstheeffectsofzero-day
andDoSattacksbylimitingthenumberofneworestablishedows
that can be programmed on any individual switch port. This is achieved
bymonitoringthenewowarrivalrateand/orcontrollingthemaximum
number of allowable flows.
Innetworkoperations,itisverytimeconsumingtolocateadeviceor
ndexactlywhereauserisconnected.Thisisespeciallyimportantwhen
reactingtosecuritybreaches.TheN-SeriesDFEsautomaticallytrackthe
network’s user/device location information by listening to the network
traffic as it passes through the switch. This information is then used to
populate the Node/Alias table with information such as an end-station’s
(Node’s)MACaddressandLayer3aliasinformation(IPAddress,
IPXAddress,etc).Thisinformationcanthenbeutilizedbynetwork
managementtoolstoquicklydeterminethatIPAddress123.145.2.23
islocatedonswitch5port3andintheeventofasecuritybreachtake
Page 6
Kommentare zu diesen Handbüchern