
Cisco Systems, Inc.
All contents are Copyright © 1992–2002 Cisco Systems, Inc. All rights reserved. Important Notices and Privacy Statement.
Page 9 of 17
Service Security
Network-wide security features • Filtering of incoming traffic flows based on Layer 2, Layer 3, or Layer 4 ACPs
prevents unauthorized data flows. Up to four ACPs are supported in
configuring either QoS or security filters.
– The following Layer 2 ACPs or a combination can be used for security
classification of incoming packets: source MAC address, destination MAC
address, and 16-bit Ethertype.
– The following Layer 3 and Layer 4 fields or a combination can be used for
security classification of incoming packets: source IP address, destination
IP address, TCP source or destination port number, UDP source, or
destination port number.
• Private VLAN edge provides security and isolation between ports on a
switch, ensuring that voice traffic travels directly from its entry point to the
aggregation device through a virtual path and cannot be directed to a
different port.
• IEEE 802.1x for dynamic port-based security.
• Support for “secure ports” prevents unauthorized stations from accessing
the switch by restricting the number of concurrent MAC addresses allowed
to access the port. Up to 132 addresses can be configured per port.
• STRG prevents edge devices not in the network administrator'scontrol from
becoming STP root nodes.
• The STP PortFast/ BPDU guard feature disables access ports with STP
PortFast enabled upon reception of a BPDU, and increases network
reliability, manageability, and security.
• Multilevel security on console access prevents unauthorized users from
altering the switch configuration.
• TACACS+ and Remote Access Dial-In User Service (RADIUS) authentication
enables centralized control of the switch and restricts unauthorized users
from altering the configuration.
Service Management
Superior manageability • Cisco IE 2100 support for flow- through provisioning and integration with
OSS applications via programmatical interfaces.
• SNMP v1, v2c, v3, and Telnet interface support delivers comprehensive
in-band management, and a CLI-based management console provides
detailed out-of-band management.
• Manageable through CiscoWorks network management software on a
per-port and per-switch basis providing a common management interface
for Cisco routers, switches, and hubs.
• Comprehensive MIBs enable the service provider to collect traffic
information on the Cisco Catalyst 2950 Series for various billing methods.
Feature Benefit
Komentarze do niniejszej Instrukcji