Stacking*
|
- Up to 6 x 25 GbE stacking ports
- Supports stackable up to 6 units
- Up to 144 ports in a single stack
- Supports spine and leaf line-rate topologies
|
Layer 3 IPv4 / 6 Routing (IPv6 Ready)
|
- Static routing / Inter VLAN routing
- Policy based routing*
- Unicast routing RIPv1 / v2, OSPFv1 / v2, BGP4*, RIPng, OSPFv3, BGP4+, ISIS and BEIGRP*
- MPLS: MP-BGP*, VRF*
- Multicast routing DVMRP, PIM-SM, PIM-DM, PIM-SSM, PIMv6
- Redundant VRRP, VRRPv3
- Supports IGMP v1 / v2 / v3, MLD v1 / v2
- BFD (Bidirectional Forwarding Detection)
- Floating static route for failover*
- Configurable maximum active routing rules
|
NAT (Network Address Translation)
|
- Hardware NAT Translations: Wire-speed performance
- One-to-One NAT
- Port Forwarding
- Dynamic NAT
- Port Overload (PAT-Port Address Translations): TCP Timeout (sec.) UDP Timer (sec.)
- Port Mapping Protocol
- ALG (Application Level Gateway)
|
MACsec
|
- 128-bit and 256-bit cipher suites (GCM-AES-256)
|
Link Aggregation
|
- Static & Dynamic aggregation (IEEE 802.3ad LACP)
- Maximum 8 groups (LAGs) and max 8 member ports per LAG
|
Broadcast / Multicast / Unicast Storm Suppression
|
- Storm suppression based on port bandwidth percentage & PPS
|
MAC Address Table
|
- Static & Blackhole MAC address
- MAC learning limit
|
VLAN
|
- IEEE 802.1Q Tag VLAN (up to 4094 VLANs)
- Port-based VLAN (up to 4094 VLANs)
- Protocol-based / IP subnet-based / MAC-based VLAN
- QinQ (double-tag VLAN)
- VLAN Mapping (VLAN Translation)
- Voice VLAN
- GVRP
- ISM VLAN (MVR)*
- MVRP
|
Spanning Tree
|
- Supports STP / RSTP / MSTP
- BPDU Guard and Root Guard
|
Loop Protect
|
- Loopback detection and prevention by physical port or VLAN based
|
ERPS
|
- ITU G.8032 Ethernet ring protection switching (ERPS)
|
DHCP
|
- DHCP Client including option 66
- DHCP Snooping
- DHCP Relay including option 82
- DHCP Server
- MAC-based can assign IP address by specific host
- Port-based can assign IP address by specific port
|
Mirroring
|
- Local port mirroring: Ingress, Egress or both direction per port
- Remote port mirroring: RSPAN
|
Quality of Service
|
- Port-based priority with 802.1p CoS priority override
- 802.1p CoS priority and IPv4 / IPv6 DSCP priority
- 8 Hardware queues per port
- Flexible queue scheduling algorithms including SP, WRR, and SP + WRR, and Weighted Deficit Round Robin (WDRR)
- Time-Based QoS
- QoS on Routing
|
Bandwidth Control (Rate Limit)
|
- Bi-directional Rate limit in percentage (Ingress and Egress)
- In the ingress direction, packet type (Broadcast / Multicast / Unicast packet) combination rules are allowed
- Traffic shaping in egress
- Flow-based bandwidth management*
|
ACL
|
- Layer 2, Layer 3 (IPv4 / IPv6), Layer 4 packet filtering
- Traffic classification based on source MAC, destination MAC, source IP, destination IP, TCP / UDP port, and VLAN
- Bi-directional ACLs (Ingress and Egress)
- Time range-based ACLs
- VLAN-based ACL issuing
|
Discovery Protocol
|
- Link Layer Discovery Protocol (LLDP) and CDP (Cisco Discovery Protocol)
|
Multicast
|
- IGMP Snooping v1 / v2 / v3 and MLD Snooping v1 / v2
|
Security
|
- Hierarchical user management and password protection
- Supports up to 10 IP addresses to access the switch
- HTTPS for secure access to the web interface
- SSH 2.0 for secure shell to command line interface
- MAC-based authentication
- 802.1X
- 802.1X with VLAN assignment
- 802.1X dynamic access control list (ACL) based on RADIUS attributes
- RADIUS and TACACS+ Authentication
- Guest VLAN
- Supports Port Isolation
- AAA authentication (PAP, CHAP, MS-CHAP)
- Dynamic ARP Inspection
- DoS Protection for SYN flood, SSH attack, HTTP / HTTPS attack, and port scan prevention
- Unicast Reverse Path Forwarding (uRPF)*
|
SNMP & MIB
|
- SNMP v1 / v2c / v3 and Trap
- SNMP v1 / v2 providing light security by means of the community strings
- SNMP v3 providing User-based Security Model (USM) and Transport Security Model (TSM)
- Remote Monitoring (RMON) alarm, event, and history recording
- Remote Monitoring (RMON) (RFC2819) Groups 1,2,3,9
- RFC 1213 MIB II, RFC 1157 SNMP MIB, RFC 1573 IF MIB, RFC 1757 RMON, Private MIB
|
IP Stack for Managed Interface
|
- Both IPv4 and IPv6 stack simultaneously
|
IPv6 for Managed Interface
|
- Neighbor Discovery (ND)
- IPv6 PMTU
- IPv6 FIB
- IPv6-Ping, IPv6-Tracert, IPv6-Telnet, and IPv6-TFTP
- DHCP Client for IPv6
|
IPv6 Transition*
|
- NAT-PT
- 4over6
- IPSec v6
- GRE
- 6to4
- ISATAP
|
Configuration Import and Export
|
- Readable text configuration file for system quick installation
- Supports HTTP / HTTPs / FTP / FTP-SSL / SFTP / TFTP backup and restore config file
|
Firmware
|
- Upgrading via HTTP / HTTPs / FTP / FTP-SSL / SFTP / TFTP
|
Management
|
- Supports CLI via SSH 2.0, Telnet and Console
- System log, alarming based on severity
- WEB UI management through HTTP / HTTPs
- NTP, SNTP
- Ping, Tracert
- TFTP Server
- TFTP, FTP Client
- Netflow*
- IP SLA* for best path selection, or for evaluating like delay, latency, jitter, packet loss
- ARP Table
|
Remote Management
|
|
DHCP for IPv6
|
- DHCPv6 Client including option 66
- DHCPv6 Snooping
- DHCPv6 Relay including option 18 / 37
- DHCPv6 Server
- MAC-based can assign IP address by specific host
- Port-based can assign IP address by specific port
|
VPN and Tunnel*
|
- IPSec
- L2TP
- PPTP
- GRE
- IKE
- VxLAN
- L2VPN
- L3VPN
|
WAN Protocol*
|
- PPP and PPPoE (Client / Serv)
- PPP Bridge
- VTI Tunnel
|
Dying Gasp*
|
- Sending the alarm message when power failures
|
OAM*
|
- 802.3ah link layer remote loopback and discovery
- IEEE 802.1ag CFM (Connectivity Fault Management) protocols
|