Features
Description
Port Security
Port security is a MAC address-based security mechanism for network
access controlling. It is an extension to the existing 802.1X authentication
and MAC authentication. This document describes:
z
Enabling Port Security
z
Setting the Maximum Number of Secure MAC Addresses
z
Setting the Port Security Mode
z
Configuring Port Security Features
z
Configuring Secure MAC Addresses
z
Ignoring Authorization Information from the Server
IP Source Guard
By filtering packets on a per-port basis, IP source guard prevents illegal
packets from traveling through, thus improving the network security. This
document describes:
z
Configuring a Static Binding Entry
z
Configuring Dynamic Binding Function
SSH2.0
SSH ensures secure login to a remote device in a non-secure network
environment. By encryption and strong authentication, it protects the
device against attacks. This document describes:
z
Configuring Asymmetric Keys
z
Configuring the Device as an SSH Server
z
Configuring the Device as an SSH Client
z
Configuring an SFTP Server
z
Configuring an SFTP Client
PKI
The Public Key Infrastructure (PKI) is a hierarchical framework designed
for providing information security through public key technologies and
digital certificates and verifying the identities of the digital certificate
owners. This document describes PKI related configuration.
SSL
Secure Sockets Layer (SSL) is a security protocol providing secure
connection service for TCP-based application layer protocols, this
document describes SSL related configuration.
Public Key
Configuration
This document describes Public Key Configuration.
ACL
An ACL is used for identifying traffic based on a series of preset matching
criteria. This document describes:
z
ACL overview and ACL types
z
ACL configuration
ARP Attack Protection
Currently, ARP attacks and viruses are threatening LAN security. The
device can provide multiple features to detect and prevent such attacks.
This document describes:
z
Configuring ARP Defense Against IP Packet Attacks
z
Configuring ARP Packet Rate Limit
z
Configuring Source MAC Address Based ARP Attack Detection
z
Configuring ARP Packet Source MAC Address Consistency Check
z
Configuring ARP Active Acknowledgement
z
Configuring ARP Detection