Enterasys ANG-1000 Bedienungsanleitung Seite 8

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 14
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 7
Page 8
Feature-Rich Functionality
Examples of additional functionality and features that are supported by the Enterasys S-Series:
NetFlow - Provides real-time visibility, application profiling, and capacity planning
Server Load Balancing - Enabled via LSNAT without requiring costly external server load balancing hardware and software
NAT - Network Address Translation (NAT) streamlines IP addressing and IP address management schemes
LLDP-MED - Link Layer Discovery Protocol for Media Endpoint Devices enhances VoIP deployments
Flow Setup Throttling - (FST) effectively preempts and defends against DoS attacks
Web Cache Redirect - Increases WAN and Internet bandwidth efficiency
Node & Alias Location - Automatically tracks user and device location and enhances network management productivity and fault isolation
Port Protection Suite - Maintain network availability by ensuring good protocol and end station behavior
Flex-Edge Technology - Provides advanced bandwidth management and allocation for demanding access/edge devices
Network performance, management, and security capabilities via NetFlow are available on every S-Series I/O Fabric and I/O Module without affecting
switching/routing performance or requiring the purchase of expensive daughter cards for every blade. The S-Series tracks every packet in every flow
unlike competitor’s statistical sampling techniques. The Enterasys advantage is the Enterasys ASIC capabilities that collect NetFlow statistics for every
packet in every flow without sacrificing performance. Enterasys S-Series switches can output 9,000 flow records per second, per I/O module. This is an
order of magnitude greater NetFlow performance than any other NetFlow appliance vendor (over 70,000 flow records per second in a fully populated
S8 chassis).
Flow Setup Throttling (FST) is a proactive feature designed to mitigate zero-day threats and Denial of Service (DoS) attacks before they can affect the
network. FST directly combats the effects of zero-day and DoS attacks by limiting the number of new or established flows that can be programmed on
any individual switch port. This is achieved by monitoring the new flow arrival rate and/or controlling the maximum number of
allowableows.
In network operations, it is very time consuming to locate a device or find exactly where a user is connected. This is especially important when reacting
to security breaches. Enterasys S-Series modules automatically track the networks user/device location information by listening to network traffic as it
passes through the switch. This information is then used to populate the Node/Alias table with information such as an end-stations MAC address and
Layer 3 alias information (IP address, IPX address, etc). This information can then be utilized by Enterasys NMS Suite management tools to quickly
determine the switch and port number for any IP address and take action against that device in the event of a security breach. This node and alias
functionality is unique to Enterasys and reduces the time to pinpoint the exact location of a problem from hours to minutes.
For organizations looking to deploy VoIP technologies, the Enterasys S-Series provides significant capabilities through its support for the industry-
standard discovery protocol, LLDP-MED (Link Layer Discovery Protocol for Media Endpoint Devices). This protocol allows for the accurate representation
of network topologies within Network Management Systems (NMS). S-Series switches are able to learn about all the devices connected to them to
identify VoIP phones, tell the phone which VLAN to use for voice, and even negotiate the power that the phone can consume. LLDP–MED also enables
911 emergency services location functions whereby the location of a phone can be determined by the switch port.
Enterasys S-Series support for Network Address Translation (NAT) provides a practical solution for organizations who wish to streamline their IP
addressing schemes. NAT operates on a router connecting two networks, simplifying network design and conserving IP addresses. NAT can help
organizations merge multiple networks together and enhance network security by helping to prevent malicious activity initiated by outside hosts from
entering the corporate network; this improves the reliability of local systems by stopping worms and augments privacy by discouraging scans.
Within server farm environments, the S-Series can help to increase reliability and performance via the implementation of Load Sharing Network Address
Translation (LSNAT). Based on RFC 2391, LSNAT uses a number of load sharing algorithms to transparently offload network load on a single server and
distributes the load across a pool of servers.
The S-Series also supports a comprehensive portfolio of port protection capabilities, such as SPANguard and MACLock, which provide the ability to
detect unauthorized bridges in the network and restrict a MAC address to a specific port. Other port protection features include Link Flap, Broadcast
Suppression, and Spanning Tree Loop protection which protects against mis-configuration and protocol failure. The S-Series is also Virtual Chassis
Technology ready. Virtual Chassis Technology allows two S-Series systems to create a single virtual switching system.
Enterasys S-Series Flex-Edge technology provides line rate traffic classification for all access ports with guaranteed priority delivery for control plane
traffic and high-priority traffic as defined by the Enterasys policy overlay. In addition to allocating resources for important network traffic, prioritized
bandwidth can be assigned on a per port or per authenticated user basis. Flex-Edge technology is ideal for deployment in wiring closets and distribution
points that can often suffer from spikes in utilization that cause network congestion. With Flex-Edge technologies, organizations no longer have to fear a
momentary network congestion event that would result in topology changes and random packet discards.
Seitenansicht 7
1 2 3 4 5 6 7 8 9 10 11 12 13 14

Kommentare zu diesen Handbüchern

Keine Kommentare