background image

 

 

Data Sheet 

© 2009 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. 

Page 10 of 22 

QoS and Control 

Advanced QoS 

  Standard 802.1p CoS and DSCP field classification are provided, using marking and 

reclassification on a per-packet basis by source and destination IP address, source and 
destination MAC address, or Layer 4 TCP or UDP port number. 

  Cisco control- and data-plane QoS ACLs on all ports help ensure proper marking on a 

per-packet basis. 

  Four egress queues per port enable differentiated management of up to four traffic 

types. 

  SRR scheduling helps ensure differential prioritization of packet flows by intelligently 

servicing the ingress and egress queues. 

  Weighted tail drop (WTD) provides congestion avoidance at the ingress and egress 

queues before a disruption occurs. 

  Strict priority queuing guarantees that the highest-priority packets are serviced ahead of 

all other traffic. 

  There is no performance penalty for highly granular QoS functions. 

Granular Rate Limiting 

  The Cisco Committed Information Rate (CIR) function guarantees bandwidth in 

increments as low as 8 kbps. 

  Rate limiting is provided based on source and destination IP address, source and 

destination MAC address, Layer 4 TCP and UDP information, or any combination of 
these fields, using QoS ACLs (IP ACLs or MAC ACLs), class maps, and policy maps. 

  Asynchronous data flows upstream and downstream from the end station or on the 

uplink are easily managed using ingress policing and egress shaping. 

  Up to 64 aggregate or individual policers are available per Fast Ethernet or Gigabit 

Ethernet port. 

Security 

Networkwide Security 
Features 

  IEEE 802.1x allows dynamic, port-based security, providing user authentication. 

  IEEE 802.1x with VLAN assignment allows a dynamic VLAN assignment for a specific 

user regardless of where the user is connected. 

  IEEE 802.1x with voice VLAN permits an IP phone to access the voice VLAN 

irrespective of the authorized or unauthorized state of the port. 

  IEEE 802.1x and port security are provided to authenticate the port and manage network 

access for all MAC addresses, including those of the client. 

  IEEE 802.1x with an ACL assignment allows for specific identity-based security policies 

regardless of where the user is connected. 

  IEEE 802.1x with Guest VLAN allows guests without 802.1x clients to have limited 

network access on the guest VLAN. 

  Web authentication for non-802.1x clients allows non-802.1x clients to use an SSL-

based browser for authentication. 

  Multi-Domain Authentication allows an IP phone and a PC to authenticate on the same 

switch port while placing them on appropriate Voice and Data VLAN. 

  MAC Auth Bypass (MAB) for voice allows third-party IP phones without an 802.1x 

supplicant to get authenticated using their MAC address. 

  Cisco security VLAN ACLs (VACLs) on all VLANs prevent unauthorized data flows from 

being bridged within VLANs. 

  Cisco standard and extended IP security router ACLs (RACLs) define security policies 

on routed interfaces for control- and data-plane traffic. 

  Port-based ACLs (PACLs) for Layer 2 interfaces allow application of security policies on 

individual switch ports. 

  Unicast MAC filtering prevents the forwarding of any type of packet with a matching 

MAC address. 

  Unknown unicast and multicast port blocking allows tight control by filtering packets that 

the switch has not already learned how to forward. 

  SSHv2, Kerberos, and SNMPv3 provide network security by encrypting administrator 

traffic during Telnet and SNMP sessions. SSHv2, Kerberos, and the cryptographic 
version of SNMPv3 require a special cryptographic software image because of U.S. 
export restrictions. 

  Private VLAN Edge provides security and isolation between switch ports, helping ensure 

that users cannot snoop on other users' traffic. 

  Private VLANs restrict traffic between hosts in a common segment by segregating traffic 

at Layer 2, turning a broadcast segment into a nonbroadcast multi-access-like segment. 

  Bidirectional data support on the Switched Port Analyzer (SPAN) port allows the Cisco 

Secure Intrusion Detection System (IDS) to take action when an intruder is detected. 

   and RADIUS authentication enable centralized control of the switch and 

restrict unauthorized users from altering the configuration. 

  MAC address notification allows administrators to be notified of users added to or 

removed from the network. 

  Dynamic ARP Inspection (DAI) helps ensure user integrity by preventing malicious users 

from exploiting the insecure nature of the ARP protocol. 

  DHCP snooping allows administrators to help ensure consistent mapping of IP to MAC 

Summary of Contents for 3560-48PS - Catalyst Switch

Page 1: ...isco Network Assistant is a centralized management application that simplifies the administration tasks for Cisco switches routers and wireless access points Cisco Network Assistant provides configuration wizards that greatly simplify the implementation of converged networks and intelligent network services The Cisco Catalyst 3560 is part of a larger and more scalable family of Cisco Catalyst swit...

Page 2: ...ange of SFP transceivers including the Cisco 1000BASE T 1000BASE SX 1000BASE LX 1000BASE ZX and CWDM SFP transceivers These ports also support the Cisco Catalyst 3560 SFP Interconnect Cable for establishing a low cost Gigabit Ethernet point to point connection Power over Ethernet The Cisco Catalyst 3560 Series can provide a lower total cost of ownership TCO for deployments that incorporate Cisco I...

Page 3: ...trol By adding Cisco intelligent functions for LAN access customers can now deploy networkwide intelligent services that consistently address these requirements from the desktop to the core and through the WAN With Cisco Catalyst Intelligent Ethernet switches Cisco Systems helps enable companies to realize the full benefits of adding intelligent services into their networks Deployment of capabilit...

Page 4: ...itive portions of the network by denying packets based on source and destination MAC addresses IP addresses or TCP UDP ports ACL lookups are done in hardware so forwarding performance is not compromised when implementing ACL based security Port security can be used to limit access on an Ethernet port based on the MAC address of the device to which it is connected It also can be used to limit the t...

Page 5: ... EIGRP rather than relying on standard Spanning Tree Protocol convergence Redirection of a packet after a link failure using a routing protocol results in faster failover than a solution that uses Layer 2 spanning tree enhancements Additionally routed uplinks allow better bandwidth use by implementing equal cost routing ECR on the uplinks to perform load balancing Routed uplinks optimize the utili...

Page 6: ...t on a per packet basis The Cisco Catalyst 3560 supports four egress queues per port allowing the network administrator to be more discriminating and specific in assigning priorities for the various applications on the LAN At egress the switch performs scheduling and congestion control Scheduling is an algorithm or process that determines the order in which the queues are processed The Cisco Catal...

Page 7: ...rators eliminate human errors and help ensure that the configuration of the switch is optimized for these applications Available at no cost Cisco Network Assistant can be downloaded from Cisco com In addition to the Cisco Network Assistant the Cisco Catalyst 3560 Series switches provide for extensive management using SNMP network management platforms such as CiscoWorks LAN Management Solution LMS ...

Page 8: ... enable dynamic trunk configuration across all switch ports Port Aggregation Protocol PAgP automates the creation of Cisco Fast EtherChannel groups or Gigabit EtherChannel groups to link to another switch router or server Link Aggregation Control Protocol LACP allows the creation of Ethernet channeling with devices that conform to IEEE 802 3ad This feature is similar to Cisco EtherChannel technolo...

Page 9: ...nstructing scalable LANs The IP Services license is required IPv6 routing capability OSPFv3 EIGRPv6 is support IP Services license is required Policy Based Routing PBR allows superior control by enabling flow redirection regardless of the routing protocol configured Inter VLAN IP routing provides for full Layer 3 routing between two or more VLANs Protocol Independent Multicast PIM for IP Multicast...

Page 10: ...ased security policies regardless of where the user is connected IEEE 802 1x with Guest VLAN allows guests without 802 1x clients to have limited network access on the guest VLAN Web authentication for non 802 1x clients allows non 802 1x clients to use an SSL based browser for authentication Multi Domain Authentication allows an IP phone and a PC to authenticate on the same switch port while plac...

Page 11: ...ommon user interface and command set with all Cisco routers and Cisco Catalyst desktop switches Cisco Discovery Protocol version 2 CDPv2 allows the Cisco Catalyst 3560 Series Switch to negotiate a more granular power setting when connecting to a Cisco powered device such as IP phones or access points than what is provided by IEEE classification The PoE MIB provides proactive visibility into power ...

Page 12: ...iguration of a switch through a Web browser eliminating the need for more complex terminal emulation programs and CLI knowledge The Web interface helps less skilled personnel quickly and simply set up switches thereby reducing the cost of deployment CiscoWorks Support CiscoWorks network management software provides management capabilities on a per port and per switch basis providing a common manag...

Page 13: ... of network traffic Only the Cisco RPS 2300 model PWR RPS2300 should be attached to the redundant power supply receptacle Indicators Per port status LEDs Link integrity disabled activity speed full duplex indications PoE applied PoE error and PoE disabled indications System status LEDs System RPS link status link duplex link speed and PoE indications Dimensions H x W x D Cisco Catalyst 3560 8PC 1 ...

Page 14: ... 8PC Catalyst 3560 12PC Dissipated power 80W 273 BTUs per hour PoE 124W 45W Cisco Catalyst 3560 24TS 485W Cisco Catalyst 3560 24PS Dissipated power 115W 393 BTUs per hour PoE 370W 65W Cisco Catalyst 3560 48TS 530W Cisco Catalyst 3560 48PS Dissipated power 160W 546 BTUs per hour PoE 370W 100W Cisco Catalyst 3560G 24TS 540W Cisco Catalyst 3560G 24PS Dissipated power 170W 534 BTUs per hour PoE 370W 1...

Page 15: ...Cisco Catalyst 3560 48TS 100 240 VAC autoranging 5 5 2 8A 50 60 Hz Cisco Catalyst 3560 24PS and Catalyst 3560 48PS 100 240 VAC autoranging 3 0 1 5A 50 60Hz Cisco Catalyst 3560G 24TS and Catalyst 3560G 48TS 100 240 VAC autoranging 8 0 4 0A 50 60Hz Cisco Catalyst 3560G 24PS and Catalyst 3560G 48PS Power Rating Cisco Catalyst 3560 8PC 0 2 kVA Cisco Catalyst 3560 12PC 0 2 kVA Cisco Catalyst 3560 24TS ...

Page 16: ... relative humidity from 30 to 75 percent Typically such power draws are only seen when encountering a 100 percent traffic load made up entirely of 64 byte packets with no PoE loads on the switch and uplinks Measured 5 Percent Throughput Switch Power Consumption no PoE loads The numbers indicate the power consumed by a typical switch under normal conditions Normal conditions signify a temperature o...

Page 17: ... MIB SNMP MPD MIB SNMP NOTIFICATION MIB SNMP TARGET MIB SNMPv2 MIB TCP MIB UDP MIB Standards IEEE 802 1s IEEE 802 1w IEEE 802 1x IEEE 802 3ad IEEE 802 3af IEEE 802 3x full duplex on 10BASE T 100BASE TX and 1000BASE T ports IEEE 802 1D Spanning Tree Protocol IEEE 802 1p CoS Prioritization IEEE 802 1Q VLAN IEEE 802 3 10BASE T specification IEEE 802 3u 100BASE TX specification IEEE 802 3ab 1000BASE T...

Page 18: ...iew and product staging Access to software updates 24 hours Web access to technical repositories Telephone support through the Cisco Technical Assistance Center TAC Advance Replacement of hardware parts Supplements existing staff Helps ensure that functions meet needs Mitigates risk Helps enable proactive or expedited issue resolution Lowers TCO by taking advantage of Cisco expertise and knowledge...

Page 19: ...thernet IP Base software feature set IPB WS C3560 48PS E 48 Ethernet 10 100 ports and 4 SFP based Gigabit Ethernet ports 1RU fixed configuration multilayer switch Enterprise class intelligent services delivered to the network edge IEEE 802 3af and Cisco prestandard Power over Ethernet IP Services software feature set IPS Provides full IPv6 dynamic routing WS C3560G 24TS S 24 Ethernet 10 100 1000 p...

Page 20: ...yst 3560 RCKMNT REC 1RU 1RU recessed rack mount kit for the Cisco Catalyst 3560 RCKMNT 19 CMPCT Rack mount kit for the Cisco Catalyst 3560 8PC and Catalyst 3560 12PC compact switches CBLGRD C3560 8PC Cable guard for the Cisco Catalyst 3560 8PC compact switch CBLGRD C3560 12PC Cable guard for the Cisco Catalyst 3560 12PC compact switch GLC LH SM 1000BASE LX LH SFP transceiver module for MMF and SMF...

Page 21: ...P 100 GHz ITU grid DWDM SFP 3268 DWDM SFP 1532 68 nm SFP 100 GHz ITU grid DWDM SFP 3425 DWDM SFP 1534 25 nm SFP 100 GHz ITU grid DWDM SFP 3504 DWDM SFP 1535 04 nm SFP 100 GHz ITU grid DWDM SFP 3582 DWDM SFP 1535 82 nm SFP 100 GHz ITU grid DWDM SFP 3661 DWDM SFP 1536 61 nm SFP 100 GHz ITU grid DWDM SFP 3819 DWDM SFP 1538 19 nm SFP 100 GHz ITU grid DWDM SFP 3898 DWDM SFP 1538 98 nm SFP 100 GHz ITU g...

Page 22: ...Data Sheet 2009 Cisco Systems Inc All rights reserved This document is Cisco Public Information Page 22 of 22 Printed in USA C78 379068 08 08 09 ...

Reviews: