| Stacking* | 
Up to 4 x 25 GbE stacking portsSupports stackable up to 6 unitsUp to 144 ports in a single stackSupports spine and leaf line-rate topologies | 
                    
                      | Layer 3 IPv4 / 6 Routing (IPv6 Ready) | 
Static routing / Inter VLAN routingPolicy based routing*Unicast routing RIPv1 / v2, OSPFv1 / v2, BGP4*, RIPng, OSPFv3, BGP4+, ISIS and BEIGRP*MPLS: MP-BGP*, VRF*Multicast routing DVMRP, PIM-SM, PIM-DM, PIM-SSM, PIMv6Redundant VRRP, VRRPv3VRRP Load Balancing*Supports IGMP v1 / v2 / v3, MLD v1 / v2BFD (Bidirectional Forwarding Detection)*Floating static route for failover*Configurable maximum active routing rules | 
                    
                      | NAT (Network Address Translation) | 
Hardware NAT Translations: Wire-speed performanceOne-to-One NATPort ForwardingDynamic NATPort Overload (PAT-Port Address Translations): TCP Timeout (sec.) UDP Timer (sec.)Port Mapping Protocol*ALG (Application Level Gateway)* | 
                    
                      | MACsec | 128-bit and 256-bit cipher suites (GCM-AES-256)
 | 
                    
                      | Link Aggregation | 
Static & Dynamic aggregation (IEEE 802.3ad LACP)Maximum 8 groups (LAGs) and max 8 member ports per LAG | 
                    
                      | Broadcast / Multicast / Unicast Storm Suppression | Storm suppression based on port bandwidth percentage & PPS
 | 
                    
                      | MAC Address Table | 
Static & Blackhole MAC addressMAC learning limit | 
                    
                      | VLAN | 
IEEE 802.1Q Tag VLAN (up to 4094 VLANs)Port-based VLAN (up to 4094 VLANs)Protocol-based / IP subnet-based / MAC-based VLANQinQ (double-tag VLAN)VLAN Mapping (VLAN Translation)Voice VLANGVRPISM VLAN (MVR)MVRP | 
                    
                      | Spanning Tree | 
Supports STP / RSTP / MSTPBPDU Guard and Root Guard | 
                    
                      | Loop Protect | Loopback detection and prevention by physical port or VLAN based
 | 
                    
                      | ERPS | ITU G.8032 Ethernet ring protection switching (ERPS)
 | 
                    
                      | DHCP | 
DHCP Client including option 66DHCP SnoopingDHCP Relay including option 82DHCP Server
MAC-based can assign IP address by specific hostPort-based can assign IP address by specific port | 
                    
                      | Mirroring | Local port mirroring: Ingress, Egress or both direction per portRemote port mirroring: RSPAN
 | 
                    
                      | Quality of Service | 
Port-based priority with 802.1p CoS priority override802.1p CoS priority and IPv4 / IPv6 DSCP priority8 Hardware queues per portFlexible queue scheduling algorithms including SP, WRR, and SP + WRR, and Weighted Deficit Round Robin (WDRR)Time-Based QoSQoS on Routing | 
                    
                      | Bandwidth Control (Rate Limit) | 
Bi-directional Rate limit in percentage (Ingress and Egress)In the ingress direction, packet type (Broadcast / Multicast / Unicast packet) combination rules are allowedTraffic shaping in egressFlow-based bandwidth management* | 
                    
                      | ACL | 
Layer 2, Layer 3 (IPv4 / IPv6), Layer 4 packet filteringTraffic classification based on source MAC, destination MAC, source IP, destination IP, TCP / UDP port, and VLANBi-directional ACLs (Ingress and Egress)Time range-based ACLsVLAN-based ACL issuing | 
                    
                      | Discovery Protocol | Link Layer Discovery Protocol (LLDP) and CDP (Cisco Discovery Protocol)
 | 
                    
                      | Multicast | IGMP Snooping v1 / v2 / v3 and MLD Snooping v1 / v2
 | 
                    
                      | Security | 
Hierarchical user management and password protectionSupports up to 10 IP addresses to access the switchHTTPS for secure access to the web interfaceSSH 2.0 for secure shell to command line interfaceMAC-based authentication802.1X802.1X with VLAN assignment802.1X dynamic access control list (ACL) based on RADIUS attributesRADIUS and TACACS+ AuthenticationGuest VLANSupports Port IsolationAAA authentication (PAP, CHAP, MS-CHAP)Dynamic ARP InspectionDoS Protection for SYN flood, SSH attack, HTTP / HTTPS attack, and port scan preventionUnicast Reverse Path Forwarding (uRPF)* | 
                    
                      | SNMP & MIB | 
SNMP v1 / v2c / v3 and TrapSNMP v1 / v2 providing light security by means of the community stringsSNMP v3 providing User-based Security Model (USM) and Transport Security Model (TSM)Remote Monitoring (RMON) alarm, event, and history recordingRemote Monitoring (RMON) (RFC2819) Groups 1,2,3,9RFC 1213 MIB II, RFC 1157 SNMP MIB, RFC 1573 IF MIB, RFC 1757 RMON, Private MIB | 
                    
                      | IP Stack for Managed Interface | Both IPv4 and IPv6 stack simultaneously
 | 
                    
                      | IPv6 for Managed Interface | 
Neighbor Discovery (ND)IPv6 PMTUIPv6 FIBIPv6-Ping, IPv6-Tracert, IPv6-Telnet, and IPv6-TFTPDHCP Client for IPv6 | 
                    
                      | IPv6 Transition* | 
NAT-PT4over6IPSec v6GRE6to4ISATAP | 
                    
                      | Configuration Import and Export | 
Readable text configuration file for system quick installationSupports HTTP / HTTPs / FTP / FTP-SSL / SFTP / TFTP backup and restore config file | 
                    
                      | Firmware | Upgrading via HTTP / HTTPs / FTP / FTP-SSL / SFTP / TFTP
 | 
                    
                      | Management | 
Supports CLI via SSH 2.0, Telnet and ConsoleSystem log, alarming based on severityWEB UI management through HTTP / HTTPsNTP, SNTPPing, TracertTFTP ServerTFTP, FTP ClientNetflow*IP SLA* for best path selection, or for evaluating like delay, latency, jitter, packet lossARP Table | 
                    
                      | Remote Management |  | 
                    
                      | DHCP for IPv6 | 
DHCPv6 Client including option 66DHCPv6 SnoopingDHCPv6 Relay including option 18 / 37DHCPv6 Server
MAC-based can assign IP address by specific hostPort-based can assign IP address by specific port | 
                    
                      | VPN and Tunnel* | 
IPSecL2TPPPTPGREIKEVxLANL2VPNL3VPN | 
                    
                      | WAN Protocol* | 
PPP and PPPoE (Client / Serv)PPP BridgeVTI Tunnel | 
                    
                      | Dying Gasp* | 
Sending the alarm message when power failures | 
                    
                      | OAM* | 
802.3ah link layer remote loopback and discoveryIEEE 802.1ag CFM (Connectivity Fault Management) protocols |