
MES3000 Ethernet switch series
15
DHCP Option 82
Option that allows to inform DHCP server about DHCP relay and port of incoming
request.
By default, the switch with DHCP snooping function enabled identifies and drops
all DHCP requests with Option 82 if they were received via untrusted port.
UDP relay
Broadcast UDP traffic forwarding to the specified IP address.
DHCP server functions
DHCP server performs centralized management of network addresses and
corresponding configuration parameters and automatically provides them to
subscribers.
IP Source Address Guard
Switch function restricts IP traffic and filters it according to the match table from
DHCP snooping binding database and static configured IP addresses. This function
allows to prevent IP address spoofing.
Dynamic ARP Inspection
(Protection)
Switch function is designed for protection from ARP based attacks. The switch
checks if the IP address in the body of received ARP packet on trusted port
matches the IP address of the sender.
If these addresses do not match, the switch drops this packet.
L2 – L3 – L4 ACL (Access
Control List)
Using information contained in headers of level 2, 3 ,4, the administrator can
configure rules for processing or dropping packets.
Time-Based ACL
Allows to configure the timeperiod for ACL operation.
Blocked ports support
Main function of blocking is to improve the network security; access to the switch
port will be granted only to those devices, whose MAC addresses have been
assigned for this port.
Port-based
authentication (IEEE
802.1x)
IEEE 802.1x authentication mechanism manages access to resources through the
external server. Authorized users will gain access to the selected network
resources.
2.2.7
Switch control functions
Table 2.7 — Switch control functions
Configuration file
download and upload
Device parameters are saved into the configuration file that contains configuration
data for the specific device ports as well as for the whole system.
Trivial File Transfer
Protocol
TFTP protocol is used for file read and write operations. Protocol is based on UDP.
MES3000 devices are able to download and transfer configuration files and
firmware images via this protocol.
SCP (Secure Copy
protocol)
SCP is used for file read and write operations. Protocol is based on SSH network
protocol.
Devices are able to download and transfer configuration files and firmware images
via this protocol.
Remote monitoring
(RMON)
Remote monitoring (RMON)—extension of SNMP, that performs the monitoring of
computer networks. Compatible devices gather diagnostics data using the
network management station. RMON is the standard MIB database that contains
actual and historic MAC level statistics and control objects providing real-time
data.