background image

© 2009 Extreme Networks, Inc. All rights reserved. 

Summit X250e Series—Page 4

Extreme Networks Data Sheet

Comprehensive Security Functionality Using Defense-in-Depth 

User Authentication and Host 

Integrity Checking

Network Login and  

Dynamic Security Profile

Network Login capability enforces user 
admission and usage policies. Summit X250e 
series switches support a comprehensive 
range of Network Login options by 
providing an 802.1x agent-based approach, 
a Web-based (agent-less) login capability 
for guests, and a MAC-based authentica-
tion model for devices. With these modes 
of Network Login, only authorized users 
and devices are permitted to connect to 
the network and be assigned to the 
appropriate VLAN. The Universal Port 
scripting framework lets you implement 
Dynamic Security Profiles which in sync 
with Network Login allows you to imple-
ment fine-grained and robust security 
policies. Upon authentication, the switch 
can load dynamic ACL/QoS for a user or 
group of users, to deny/allow the access to 
the application servers or segments within 
the network.

Multiple Supplicant Support

Shared ports represent a potential vulner-
ability in a network. Multiple supplicant 
capability on a switch allows it to uniquely 
authenticate and apply the appropriate 
policies and VLANs for each user or device 
on a shared port. 

Multiple supplicant support helps secure IP 
Telephony and wireless access. Converged 
network designs often involve the use of 
shared ports (see Figure 4).

MAC Security

MAC security allows the lockdown of a port 
to a given MAC address and limiting the 
number of MAC addresses on a port. This can 
be used to dedicate ports to specific hosts or 
devices such as VoIP phones or printers and 
avoid abuse of the port—an interesting 
capability specifically in environments such 
as hotels. In addition, an aging timer can be 
configured for the MAC lockdown, protecting 
the network from the effects of attacks using 
(often rapidly) changing MAC addresses. 

IP Security

ExtremeXOS IP security framework helps 
protect the network infrastructure, network 
services such as DHCP and DNS, and host 
computers from spoofing and man-in-the-
middle attacks. It also helps protect the 
network from statically configured and/or 
spoofed IP addresses and builds an external 
trusted database of MAC/IP/port bindings so 
you know where the traffic from a specific 
address comes from for immediate defense. 

Host Integrity Checking

Host integrity checking helps keep infected 
or non-compliant machines off the network. 
Summit X250e series switches support a host 
integrity or endpoint integrity solution that is 
based on the model from the Trusted 
Computing Group. Summit X250e interfaces 
with Sentriant AG200 endpoint security 
appliance from Extreme Networks to verify 
that each endpoint meets the security 
policies that have been set and quarantines 
those that are not in compliance.

Network Intrusion Detection 

and Response

 

Hardware-Based sFlow Sampling

sFlow is a sampling technology that provides 
the ability to continuously monitor applica-
tion-level traffic flows on all interfaces 
simultaneously. The sFlow agent is a 
software process that runs on Summit X250e 
and packages data into sFlow datagrams that 
are sent over the network to an sFlow 
collector. The collector gives an up-to-the-
minute view of traffic across the entire 
network, providing the ability to trouble-
shoot network problems, control congestion 
and detect network security threats.  

Port Mirroring

For threat detection and prevention, 
Summit X250e supports many-to-one and 
one-to-many port mirroring. This allows 
the mirroring of traffic to an external 
network appliance such as an intrusion 
detection device for trend analysis or for 
utilization by a network administrator for 
diagnostic purposes. Port Mirroring can 
also be enabled across switches in a stack.

Line-Rate ACLs

ACLs are one of the most powerful 
components used in controlling network 
resource utilization as well as protecting 
the network. Summit X250e supports 
1,024 centralized ACLs per 24-port block 
based on Layer 2, 3 or 4-header information 
such as the MAC, IPv4 and IPv6 address or 
TCP/UDP port. 

Denial of Service Protection

Summit X250e can effectively handle DoS 
attacks. If the switch detects an unusually 
large number of packets in the CPU input 
queue, it will assemble ACLs that automat-
ically stop these packets from reaching the 
CPU. After a period of time, these ACLs 
are removed, and reinstalled if the attack 
continues. ASIC-based LPM routing 
eliminates the need for control plane 
software to learn new flows, allowing more 
network resilience against DoS attacks. 

Secure Management

To prevent management data from being 
intercepted or altered by unauthorized 
access, Summit X250e supports SSH2, SCP 
and SNMPv3 protocols. The MD5 hash 
algorithm used in authentication prevents 
attackers from tampering with valid data 
during routing sessions.  

Implementing a secure network means providing protection at the network perimeter as well as the core. Working together with 

the Sentriant

®

 family of products from Extreme Networks, Summit X250e series uses a defense-in-depth strategy to help protect 

your network from known or potential threats. Security offerings from Extreme Networks encompass three key areas: user and 

host integrity, threat detection and response, and hardened network infrastructure. 

Summit X250e offers multiple supplicant which helps provide per-MAC 

based authentication with dynamic VLAN allocation

`

`

`

VLAN Green

VLAN Orange

VLAN Purple

Rogue Clients

`

`

`

`

`

`

Figure 4: Multiple Supplicant Support

Summary of Contents for Summit X250e-24p

Page 1: ...uctivity Optional redundant power supplies are available with each switch to help secure against power anomalies Target Applications Edge Power over Ethernet PoE and non PoE switch providing intelligent 10 100BASE T connectivity to the desktop in a network running ExtremeXOS from the core to the edge Carrier Ethernet edge switching with 100BASE X provides advanced fiber connectivity to the custome...

Page 2: ...uch as OSPF VRRP and ESRP ESRP supported in Layer 2 or Layer 3 and dynamically routes traffic around the problem Equal Cost Multipath Routing Equal Cost Multipath ECMP routing allows uplinks to be load balanced for performance and cost savings while also supporting redundant failover If an uplink fails traffic is automatically routed to the remaining uplinks and connectivity is maintained Link Agg...

Page 3: ...t of powered LAN devices is quick and easy with its support of the IEEE 802 3af standard and full Class 3 power availability on all ports backed up 100 by the EPS 500 redundant power supply Summit X250e 24p Summit X250e 48p can provide up to 370W of PoE power and can be increased up to 740W of PoE power to provide full 15 4W Class 3 devices on all 48 ports by adding an External Power System EPS C ...

Page 4: ...aces with Sentriant AG200 endpoint security appliance from Extreme Networks to verify that each endpoint meets the security policies that have been set and quarantines those that are not in compliance Network Intrusion Detection and Response Hardware Based sFlow Sampling sFlow is a sampling technology that provides the ability to continuously monitor applica tion level traffic flows on all interfa...

Page 5: ...0e Summit X250e 1 2ABC DEF3 4GHI 5ABC MNO6 7PQRS 8TUV 0 U WXYZ9 1 2ABC DEF3 4GHI 5ABC MNO6 7PQRS 8TUV 0 U WXYZ9 Edge Connectivity for Advanced Carrier Ethernet Applications Carrier Ethernet edge switching with 100BASE X provides advanced fiber connectivity to the customer Summit X250e is deployed as an intelligent Fast Ethernet edge switch extending the benefits of the ExtremeXOS operating system ...

Page 6: ... comes with a DC output cable to connect between the Summit switch and EPS 150DC Front View Summit X250e Series Redundant PSUs EPS 160 and EPS T EPS 160 is the redundant AC Power Supply for lower power consuming AC PSU based Summit switches The EPS T power tray is required to rack mount this external power supply EPS T power tray can take up to two EPS 160 power modules and each EPS 160 works indi...

Page 7: ...dule SNMPv3 user based security with encryption authentication see above RFC 1492 TACACS RFC 2138 RADIUS Authentication RFC 2139 RADIUS Accounting RFC 3579 RADIUS EAP support for 802 1x RADIUS Per command Authentication Access Profiles on All Routing Protocols Access Policies for Telnet SSH 2 SCP 2 Network Login 802 1x Web and MAC based mechanisms IEEE 802 1x 2001 Port Based Network Access Control...

Page 8: ... Requirements RFC 2460 Internet Protocol Version 6 IPv6 Specification RFC 2461 Neighbor Discovery for IP Version 6 IPv6 RFC 2463 Internet Control Message Protocol ICMPv6 for the IPv6 Specification RFC 2464 Transmission of IPv6 Packets over Ethernet Networks RFC 2465 IPv6 MIB General Group and Textual Conventions RFC 2466 MIB for ICMPv6 RFC 2462 IPv6 Stateless Address Auto configuration Host Requir...

Page 9: ...t Dissipation 51W 174 BTU h Power Consumption 51W 174 BTU h Acoustic Noise Low FAN Speed 37 dBA per ISO 7779 Acoustic Noise High FAN Speed 47 dBA per ISO 7779 Summit X250e 24x General Specifications Performance 48 8 Gbps switch fabric bandwidth 36 3 Mpps frame forwarding rate 9 216 Byte maximum packet size Jumbo Frame 128 load sharing trunks up to 8 members per trunk 8 QoS queues port 4 094 VLANs ...

Page 10: ...er ISO 7779 Summit X250e 48p General Specifications Performance 97 6 Gbps switch fabric bandwidth 39 9 Mpps frame forwarding rate 9 216 Byte maximum packet size Jumbo Frame 128 load sharing trunks up to 8 members per trunk 8 QoS queues port 4 094 VLANs Port Protocol IEEE 802 1Q 1 024 centralized ACL rules per 24 port Forwarding Tables Layer 2 MAC Addresses 8K IPv4 LPM Entries 512 IPv6 LPM Entries ...

Page 11: ...t Dissipation 31W 105 8 BTU h Power Consumption 31W 105 8 BTU h Acoustic Noise Low FAN Speed 37 dBA per ISO 7779 Acoustic Noise High FAN Speed 45 dBA per ISO 7779 Summit X250e 48tDC General Specifications Performance 97 6 Gbps switch fabric bandwidth 39 9 Mpps frame forwarding rate 9 216 Byte maximum packet size Jumbo Frame 128 load sharing trunks up to 8 members per trunk 8 QoS queues port 4 094 ...

Page 12: ... AS NZS 60950 1 Australia New Zealand EMI EMC Standards North America EMC for ITE FCC CFR 47 part 15 Class A U S A ICES 003 Class A Canada European EMC standards EN 55022 2003 Class A EN 55024 A2 2003 Class A includes IEC 61000 4 2 3 4 5 6 11 EN 61000 3 2 2006 Harmonics EN 61000 3 3 1995 A1 2001 Flicker ETSI EN 300 386 v1 3 3 2005 04 EMC Telecom munications 2004 108 EC EMC Directive International ...

Page 13: ...wer Consumption 801W 2733 1BTU h EPS T2 Height 1 77 Inches 4 5 cm Width 17 32 Inches 44 0 cm Depth 8 66 Inches 22 0 cm Weight 4 0 Lbs 1 82 Kg Power EPS 150DC Voltage Input Range 36 to 72VDC 6 0A Input Current Rating 5 5A 36VDC 2 6A 72VDC Output 50 VDC 7 5A max 375 Watts 12 VDC 7 5A max 90 Watts Power Supply Input Socket IEC 320 C14 Power Cord Input Plug IEC 320 C13 Heat Dissipation 158W 539 1 BTU ...

Page 14: ...nector for EPS 150DC external redundant PSU 15122 Summit X250e 48tDC 48 10 100BASE TX 2 gigabit combo ports 2 unpopulated gigabit SFP and 10 100 1000BASE T 2 SummitStack stacking ports ExtremeXOS Edge license 1 DC PSU connector for EPS 150DC external redundant PSU 15123 Summit X250e 24xDC 24 100BASE T SFP ports 2 gigabit combo ports 2 unpopulated gigabit SFP and 10 100 1000BASE T 2 SummitStack sta...

Page 15: ...cking Cable 3 0M SummitStack UniStack stacking cable 3 0M 16105 Stacking Cable 5 0M SummitStack Stacking Cable 5 0M not supported for UniStack Ordering Information Part Number Name Description 2009 Extreme Networks Inc All rights reserved Extreme Networks the Extreme Networks logo EPICenter Extreme Standby Router Protocol ExtremeXOS ExtremeXOS Screenplay Sentriant Summit SummitStack and UniStack a...

Reviews: