background image

 

 

© 2004 Cisco Systems, Inc. All rights reserved. 

Important notices, privacy statements, and trademarks of Cisco Systems, Inc. can be found on cisco.com. 

Page 7 of 18 

 
 

Feature 

Benefit 

Security 

Network-Security 

Features 

 

Filtering of incoming traffic flows based on Layer 2, Layer 3 or Layer 4 access control parameters (ACPs) prevents 

unauthorized data flows. 

 

The following Layer 2 ACPs or a combination can be used for security classification of incoming packets: source Media 

Access Control (MAC) address, destination MAC address, and 16-bit Ethertype. 

 

The following Layer 3 and Layer 4 fields or a combination can be used for security classification of incoming packets: 

source/destination IP address, TCP source/destination port number, User Datagram Protocol (UDP) source, or destination 
port number. ACLs can also be applied to filter based on DSCP values. 

 

Time-based ACLs allow configuration of differentiated services based on time-periods. 

 

Private VLAN edge provides security and isolation between ports on a switch, ensuring that voice traffic travels directly 

from its entry point to the aggregation device through a virtual path and cannot be directed to a different port. 

 

Support for the IEEE 802.1x standard allows users to be authenticated regardless of which LAN port they are accessing, 

and provides unique benefits to customers who have a large base of mobile (wireless) users accessing the network. 

 

IEEE 802.1x with VLAN assignment allows a dynamic VLAN assignment for a specific user regardless of where 
the user is connected. 

 

IEEE 802.1x with voice VLAN to permit an IP phone access to the voice VLANirrespective of the authorized or 
unauthorized state of the port. 

 

IEEE 802.1x with port security for authenticating the port and managing network access for all MAC addresses, 
including that of the client. 

 

IEEE 802.1x with Guest VLAN allows guests without 802.1x clients to have limited network access on the Guest 
VLAN. 

 

SSHv2 and SNMPv3 provide network security by encrypting administrator traffic during Telnet and SNMP sessions. 

SSHv2 and the crypto version of SNMPv3 require a special crypto software image due to US export restrictions 

 

Port Security and unicast MAC filtering secures the access to a port based on MAC addresses. The aging feature of port 

security removes the MAC address from the switch after a specific timeframe to allow another device to connect to the 
same port. Unicast MAC filtering allows non-IP packets to be filtered as well. 

 

With unknown unicast/multicast port blocking, the switch will not flood packets with unknown destination MAC 

addresses to all Ethernet ports. Unknown unicast/multicast port blocking disables flooding on a per-port basis. (Catalyst 
2950G24, 2950G48, 2950G12, 2950G24DC only) 

 

MAC Address Notification allows administrators to be notified of new users added or removed from the network. 

 

Spanning-tree root guard (STRG) prevents edge devices not in the network administrator's control from becoming 

Spanning-Tree Protocol root nodes. 

 

The Spanning-Tree Protocol PortFast/bridge protocol data unit (BPDU) guard feature disables access ports with 

SpanningTree Protocol PortFastenabled upon reception of a BPDU, and increases network reliability, manageability, 
and security. 

 

Multilevel security on console access prevents unauthorized users from altering the switch configuration. 

 

 and RADIUS authentication enable centralized control of the switch and restrict unauthorized users from 

altering the configuration. 

 

The user-selectable address-learning mode simplifies configuration and enhances security. 

 

Trusted Boundary provides the ability to trust the QoS priority settings if an IP phone is present, and to disable the trust 

settings in the event that the IP phone is removed. This prevents a rogue user from overriding prioritization policies in 
the network. 

 

IGMP Filtering provides multicast authentication by filtering out nonsubscribers and limits the number of concurrent 

multicast streams available per port. 

Summary of Contents for 2950C-24 - Catalyst Switch - Stackable

Page 1: ...s Setup and Cisco Network Assistant reduce the cost of deployment by enabling less skilled personnel to set up switches quickly Furthermore Cisco Catalyst 2950 Series switches provide extensive management tools using Simple Network Management Protocol SNMP network management platforms such as CiscoWorks This product line offers two distinct sets of software features and several configurations to a...

Page 2: ...re investments in Category 5 copper cabling Maximum power availability for a converged voice and data network is attainable when a Cisco Catalyst 2950 Switch is combined with the Cisco Redundant Power System 675 for protection against internal power supply failures and an uninterruptable power supply UPS system to safeguard against power outages ADDITIONAL CISCO CATALYST 2950 SERIES SWITCHES Cisco...

Page 3: ...mediate reactions to intruder and hacker detection These enhancements are available free of charge by downloading the latest software release for the Cisco Catalyst 2950 Series Secure Shell version 2 SSHv2 and Simple Network Management Protocol version 3 SNMPv3 protect information from being eavesdropped or being tampered with by encrypting information being passed on the network thereby guarding ...

Page 4: ... goes through classification policing and marking it is assigned to the appropriate queue before exiting the switch Cisco Catalyst 2950 Series switches support four egress outgoing port queues per port which allows the network administrator to be more discriminating and specific in assigning priorities for the various applications on the LAN At the egress level the switch performs scheduling which...

Page 5: ... eliminating the need for more complex terminal emulation programs and knowledge of the CLI Cisco Device Manager and Cisco Express Setup reduce the cost of deployment by enabling less skilled personnel to quickly and simply set up switches Cisco Network Assistant Software provides an integrated management interface for delivering intelligent services such as multilayer switching QoS multicast and ...

Page 6: ...ct fiber optic wiring or port faults Integrated Cisco IOS Software Features for Bandwidth Optimization Bandwidth aggregation up to 4 Gbps two ports full duplex through Gigabit EtherChannel technology and up to 16 Gbps eight ports full duplex through Fast EtherChannel technology enhances fault tolerance and offers higher speed aggregated bandwidth between switches to routers and individual servers ...

Page 7: ...ited network access on the Guest VLAN SSHv2 and SNMPv3 provide network security by encrypting administrator traffic during Telnet and SNMP sessions SSHv2 and the crypto version of SNMPv3 require a special crypto software image due to US export restrictions Port Security and unicast MAC filtering secures the access to a port based on MAC addresses The aging feature of port security removes the MAC ...

Page 8: ...Layer 3 type of service ToS field DSCP values The following Layer 3 and Layer 4 fields or a combination can be used to classify incoming packets to define QoS flows source destination IP address TCP source destination port number or UDP source destination port number QoS Metering and Policing at Ingress Support for metering and policing of incoming packets restricts incoming traffic flows to a cer...

Page 9: ...as switch level status LEDs for system redundant power supply and bandwidth utilization provide a comprehensive and convenient visual management system Cisco Network Assistant Software Cisco Network Assistant Software is a free standalone network management application software that simplifies the administration of networks of up to 250 users It supports a wide range of Cisco Catalyst intelligent ...

Page 10: ...s of forwarding bandwidth when daisy chained with up to nine switches Auto configuration eases deployment of switches in the network by automatically configuring multiple switches across a network via a boot server Automatic QoS Auto QoS greatly simplifies the configuration of QoS in VoIP networks by issuing interface and global switch commands that allow the detection of Cisco IP phones the class...

Page 11: ...lyst 2950G 48 10 1 Mpps wire speed forwarding rate Cisco Catalyst 2950G 24 6 6 Mpps wire speed forwarding rate Cisco Catalyst 2950G 24 DC 6 6 Mpps wire speed forwarding rate Cisco Catalyst 2950G 12 4 8 Mpps wire speed forwarding rate Cisco Catalyst 2950T 24 6 6 Mpps wire speed forwarding rate Cisco Catalyst 2950C 24 3 9 Mpps wire speed forwarding rate 8 MB memory architecture shared by all ports U...

Page 12: ...O IP MIB OLD CISCO MEMORY MIB OLD CISCO SYSTEM MIB OLD CISCO TCP MIB OLD CISCO TS MIB RFC1213 MIB MIB II RFC1398 MIB ETHERNET MIB RMON MIB RFC 1757 RS 232 MIB SNMPv2 MIB SNMPv2 SMI SNMPv2 TC TCP MIB UDP MIB Standards IEEE 802 1x support IEEE 802 1w IEEE 802 1s IEEE 802 3x full duplex on 10BASE T 100BASE TX and 1000BASE T ports IEEE 802 1D Spanning Tree Protocol IEEE 802 1p class of service CoS pri...

Page 13: ...ry 5 UTP cabling 100BASE FX ports MT RJ connectors 50 125 or 62 5 125 micron multimode fiber optic cabling 1000BASE T 1000BASE SX LX LH ZX GBIC based ports SC fiber connectors single mode or multimode fiber Cisco GigaStack GBIC ports copper based Cisco GigaStack cabling Management console port 8 pin RJ 45 connector RJ 45 to RJ 45 rollover cable with RJ 45 to DB9 adapter for PC connections for term...

Page 14: ...ower supply receptacle with this connector Indicators Per port status LEDs link integrity disabled activity speed and full duplex indications System status LEDs system RPS and bandwidth utilization indications Environmental Ranges Operating temperature 32 to 113 F 0 to 45 C Storage temperature 13 to 158 F 25 to 70 C Operating relative humidity 10 to 85 percent noncondensing Operating altitude Up t...

Page 15: ... AS NZS 3548 Class A CE Marking CNS 13438 BSMI Class A MIC Network Equipment Building Standards NEBS for WS C2950G 24 EI DC only Bellcore GR 1089 CORE GR 63 CORE SR 3580 Level 3 Warranty Limited lifetime warranty SERVICE AND SUPPORT The services and support programs described in the following table are available as part of the Cisco Desktop Switching Service and Support solution and are available ...

Page 16: ...ports two 1000BASE X ports Enhanced Image software installed WS C2950G 24 EI 24 10 100 ports two 1000BASE X ports Enhanced Image software installed WS C2950G 24 EI DC 24 10 100 ports two 1000BASE X ports DC power Enhanced Image software installed WS C2950G 12 EI 12 10 100 ports two 1000BASE X ports Enhanced Image software installed WS C2950T 24 24 10 100 ports two 1000BASE T ports Enhanced Image s...

Page 17: ...sted on the Cisco Web site at www cisco com go offices Argentina Australia Austria Belgium Brazil Bulgaria Canada Chile China PRC Colombia Costa Rica Croatia Cyprus Czech Republic Denmark Dubai UAE Finland France Germany Greece Hong Kong SAR Hungary India Indonesia Ireland Israel Italy Japan Korea Luxembourg Malaysia Mexico The Netherlands New Zealand Norway Peru Philippines Poland Portugal Puerto...

Page 18: ... 2004 Cisco Systems Inc All rights reserved Important notices privacy statements and trademarks of Cisco Systems Inc can be found on cisco com Page 18 of 18 ...

Reviews: