MES53xx, MES33xx, MES23xx Ethernet Switch Series
12
levels. The switches can use the 802.1p priority value to distribute frames
between priority queues.
2.2.6
Security features
Table 2.6. Security features
DHCP snooping
A switch feature designed for protection from DHCP attacks. Enable filtering of
DHCP messages coming from untrusted ports by building and maintaining DHCP
snooping binding database. DHCP snooping performs functions of a firewall
between untrusted ports and DHCP servers.
DHCP Option 82
An option to tell the DHCP server about the DHCP relay and port of the incoming
request.
By default, the switch with DHCP snooping feature enabled identifies and drops all
DHCP requests with Option 82, if they were received via an untrusted port.
UDP relay
Broadcast UDP traffic forwarding to the specified IP address.
DHCP server features
DHCP server performs centralised management of network addresses and
corresponding configuration parameters, and automatically provides them to
subscribers.
IP Source address guard
The switch feature that restricts and filters IP traffic according to the mapping
table from the DHCP snooping binding database and statically configured IP
addresses. This feature is used to prevent IP address spoofing.
Dynamic ARP Inspection
(Protection)
A switch feature designed for protection from ARP attacks. The switch checks the
message received from the untrusted port: if the IP address in the body of the
received ARP packet matches the source IP address.
If these addresses do not match, the switch drops this packet.
L2 – L3 – L4 ACL
(Access
Control List)
Using information from the level 2, 3, 4 headers, the administrator can configure
up to 1024 rules for processing or dropping packets.
Time Based ACL
Allow you to configure the time frame for ACL operation.
Blocked ports support
The key feature of blocking is to improve the network security; access to the
switch port will be granted only to those devices whose MAC addresses were
assigned for this port.
Port based
authentication (802.1x
standard)
IEEE 802.1x authentication mechanism manages access to resources through an
external server. Authorized users will gain access to the specified network
resources.
2.2.7
Switch Control Features
Table 2.7. Switch control features
Uploading and
downloading the
configuration file
Device parameters are saved into the configuration file that contains configuration
data for the specific device ports as well as for the whole system.