background image

4

Extreme Networks Data Sheet: 

Summit X250e Series

Technical Specifications

Comprehensive Security Management 

User Authentication and Host Integrity Checking

Network Login and Dynamic Security Profile

Network Login capability enforces user admission and usage policies. 
Summit X250e series switches support a comprehensive range of Network 
Login options by providing an 802.1x agent-based approach, a Web-based 
(agent-less) login capability for guests, and a MAC-based authentication 
model for devices. With these modes of Network Login, only authorized 
users and devices are permitted to connect to the network and be assigned 
to the appropriate VLAN. The Universal Port scripting framework lets you 
implement Dynamic Security Profiles which in sync with Network Login 
allows you to implement fine-grained and robust security policies. Upon 
authentication, the switch can load dynamic ACL/QoS profiles for a user or 
group of users, to deny/allow the access to the application servers or 
segments within the network.

Multiple Supplicant Support

Shared ports represent a potential vulnerability in a network. Multiple 
supplicant capability on a switch allows it to uniquely authenticate and 
apply the appropriate policies and VLANs for each user or device on a 
shared port. 

Multiple supplicant support helps secure IP Telephony and wireless access. 
Converged network designs often involve the use of shared ports (see 
Figure 4).

Media Access Control (MAC) Lockdown

MAC security allows the lockdown of a port to a given MAC address and 
limiting the number of MAC addresses on a port. This can be used to 
dedicate ports to specific hosts or devices such as VoIP phones or printers 
and avoid abuse of the port—a capability that can be especially useful in 
environments such as hotels. In addition, an aging timer can be configured 
for the MAC lockdown, protecting the network from the effects of attacks 
using (often rapidly) changing MAC addresses. 

IP Security

ExtremeXOS IP security framework helps protect the network 
infrastructure, network services such as DHCP and DNS, and host 
computers from spoofing and man-in-the-middle attacks. It also helps 
protect the network from statically configured and/or spoofed IP addresses 
and builds an external trusted database of MAC/IP/port bindings so 
you know where the traffic from a specific address comes from for 
immediate defense. 

Identity Manager

Identity Manager allows network managers to track users who access their 
network. User identity is captured based on NetLogin authentication, LLDP 
discovery and Kerberos snooping. ExtremeXOS uses the information to 
then report on the MAC, VLAN, computer hostname, and port location of 
the user. Further, Identity Manager can create both roles and policies, 
and then bind them together to create role-based profiles based on 
organizational structure or other logical groupings, and apply them across 
multiple users to allow appropriate access to network resources. In 

addition, support for Wide Key ACLs further improves security by going 
beyond the typical source/destination and MAC address as identification 
criteria access mechanism to provide filtering capabilities.

Host Integrity Checking

Host integrity checking helps keep infected or noncompliant machines off 
the network. Summit X250e series switches support a host integrity or 
endpoint integrity solution that is based on the model from the Trusted 
Computing Group. 

Network Intrusion Detection and Response 

CLEAR-Flow Security Rules Engine

CLEAR-Flow Security Rules Engine provides first order threat detection 
and mitigation, and mirrors traffic to appliances for further analysis of 
suspicious traffic in the network. 

Hardware-Based sFlow Sampling

sFlow is a sampling technology that provides the ability to continuously 
monitor application-level traffic flows on all interfaces simultaneously. 
The sFlow agent is a software process that runs on Summit X250e and 
packages data into sFlow datagrams that are sent over the network to an 
sFlow collector. The collector gives an up-to-the-minute view of traffic 
across the entire network, providing the ability to troubleshoot network 
problems, control congestion and detect network security threats.  

Port Mirroring

For threat detection and prevention, Summit X250e supports many-to- 
one and one-to-many port mirroring. This allows the mirroring of traffic to 
an external network appliance such as an intrusion detection device for 
trend analysis or for utilization by a network administrator for diagnostic 
purposes. Port Mirroring can also be enabled across switches in a stack.

Line-Rate ACLs

ACLs are one of the most powerful components used in controlling 
network resource utilization as well as protecting the network. Summit 
X250e supports 1,024 centralized ACLs per 24-port block based on Layer 2, 
3 or 4-header information such as the MAC, IPv4 and IPv6 address or  
TCP/UDP port. ACLs are used for filtering the traffic, as well as classifying 
the traffic flow to control bandwidth, priority, mirroring and policy-based 
routing/switching.

Denial of Service Protection

Summit X250e can effectively handle DoS attacks. If the switch detects an 
unusually large number of packets in the CPU input queue, it will assemble 
ACLs that automatically stop these packets from reaching the CPU. After a 
period of time, these ACLs are removed, and reinstalled if the attack 
continues. ASIC-based LPM routing eliminates the need for control plane 
software to learn new flows, allowing more network resilience against  
DoS attacks. 

Secure Management

To prevent management data from being intercepted or altered by 
unauthorized access, Summit X250e supports SSH2, SCP and SNMPv3 
protocols. The MD5 hash algorithm used in authentication prevents 
attackers from tampering with valid data during routing sessions.  

Summary of Contents for Summit X250e Series

Page 1: ...rtification Highlights Summit X250e series switches are based on Extreme Networks revolutionary ExtremeXOS core class operating system ExtremeXOS is a highly resilient modular operating system that helps provide continuous uptime manageability and operational efficiency at an affordable price Summit X250e provides high availability and performance with its advanced traffic management capabilities ...

Page 2: ...t Multipath Routing Equal Cost Multipath ECMP routing allows uplinks to be load balanced for performance and cost savings while also supporting redundant failover If an uplink fails traffic is automatically routed to the remaining uplinks and connectivity is maintained Link Aggregation 802 3ad Link aggregation allows trunking of up to eight links on a single logical connection for up to 2 Gigabits...

Page 3: ...s Granular QoS low latency and low jitter enable voice quality connections Summit X250e supports a range of QoS technologies that can prioritize and predictably handle high priority traffic policing or rate limiting on ingress 802 1Q tagging and Diffserv marking and shaping on egress with eight queues per port The Extreme Networks tradition of building products with low latency and jitter continue...

Page 4: ...files based on organizational structure or other logical groupings and apply them across multiple users to allow appropriate access to network resources In addition support for Wide Key ACLs further improves security by going beyond the typical source destination and MAC address as identification criteria access mechanism to provide filtering capabilities Host Integrity Checking Host integrity che...

Page 5: ...rity scalability availability mobility or management Edge Connectivity for Advanced Carrier Ethernet Applications Carrier Ethernet edge switching with 100BASE X provides advanced fiber connectivity to the customer Summit X250e is deployed as an intelligent Fast Ethernet edge switch extending the benefits of the ExtremeXOS operating system to the network edge in the Carrier Ethernet network This un...

Page 6: ...50DC and EPS T2 EPS 150DC is the redundant DC Power Supply for DC PSU based Summit switches The EPS T2 power tray is required to rack mount this external power supply EPS T2 power tray can take up to two EPS 150DC power modules and each EPS 150DC works individually EPS 150DC comes with a DC output cable to connect between the Summit switch and EPS 150DC Front View Front View Front View Front View ...

Page 7: ...with 60 100 load Line Frequency Range 47 63 Hz Power Supply Input Socket IEC 320 C14 Summit X250e 48t General Specifications Performance 97 6 Gbps switch fabric bandwidth 39 9 Mpps frame forwarding rate 9 216 Byte maximum packet size Jumbo Frame 128 load sharing trunks up to 8 members per trunk 8 QoS queues port 4 094 VLANs Port Protocol IEEE 802 1Q 1 024 centralized ACL rules per 24 port Forwardi...

Page 8: ...67 2 BTU h Power Consumption 49W 167 2 BTU h Acoustic Noise Low FAN Speed 37 dBA per ISO 7779 Acoustic Noise High FAN Speed 45 dBA per ISO 7779 Indicators Per port status LED System Status LEDs management fan and power Ports 24 ports 10 100BASE T PoE with auto speed and auto polarity 2 ports Gigabit Ethernet 100 1000BASE X SFP shared PHY with 2 10 100 1000BASE T ports 2 SummitStack stacking interf...

Page 9: ...following capability depending upon the number of EPS 600LS installed One EPS 600LS Redundant up to 370W PoE power Two EPS 600LS Redundant up to 370W PoE power Non Redundant up to 740W PoE power Three EPS 600LS Redundant up to 740W PoE power Physical Specifications Dimensions and Weight Height 1 73 Inches 4 4 Cm Width 17 35 Inches 44 1 Cm Depth 15 28 Inches 38 8 Cm Weight 12 06 lbs 5 48 Kg Operati...

Page 10: ...on 31W 105 8 BTU h Acoustic Noise Low FAN Speed 37 dBA per ISO 7779 Acoustic Noise High FAN Speed 45 dBA per ISO 7779 Summit X250e 24tDC General Specifications Performance 97 6 Gbps switch fabric bandwidth 39 9 Mpps frame forwarding rate 9 216 Byte maximum packet size Jumbo Frame 128 load sharing trunks up to 8 members per trunk 8 QoS queues port 4 094 VLANs Port Protocol IEEE 802 1Q 1 024 central...

Page 11: ...rds North American Safety of ITE UL 60950 1 1st Ed Listed Device U S CSA 22 2 60950 1 03 1st Ed Canada Complies with FCC 21CFR 1040 10 U S Laser Safety CDRH Letter of Approval U S FDA Approval European Safety of ITE EN60950 1 2001 A11 EN 60825 1 A2 2001 Lasers Safety TUV R GS Mark by German Notified Body 2006 95 EC Low Voltage Directive International Safety of ITE CB Report Certificate per IEC 609...

Page 12: ...erational Shock Half Sine 30 m s2 3g 11ms 60 Shocks Operational Random Vibration 5 500 Hz 1 5g rms Storage Transportation Conditions Packaged Transportation Temperature 40 C to 70 C 40 F to 158 F Storage and Transportation Humidity 10 to 95 RH non condensing Packaged Shock Half Sine 180 m s2 18g 6ms 600 shocks Packaged Sine Vibration 5 62 Hz Velocity 5mm s 62 500 Hz 0 2 G Packaged Random Vibration...

Page 13: ... 320 C13 Heat Dissipation 158W 539 1 BTU h Power Consumption 659W 2448 6 BTU h Dimensions and Weight EPS C Height 1 73 Inches 4 4 Cm Width 17 32 Inches 44 0 Cm Depth 11 81 Inches 30 0 Cm Weight 7 17 Lbs 3 16 Kg EPS 600LS Height 1 69 Inches 4 3 Cm Width 4 61 Inches 11 7 Cm Depth 11 81 Inches 30 9 Cm Weight 3 74 Lbs 1 70 Kg Power EPS 600LS Voltage Input Range 90 264 V Nominal Input Voltage Hz 115V 6...

Page 14: ...dundant power system chassis requires EPS 600LS 15107T Summit X250e 48p TAA U S Federal TAA 48 10 100BASE TX with PoE 2 gigabit combo ports 2 unpopulated gigabit SFP and 10 100 1000BASE T 2 SummitStack stacking ports ExtremeXOS Edge license 1 AC PSU connector for EPS C external redundant power system chassis requires EPS 600LS 15109 Summit X250e 24x 24 100BASE X SFP 2 gigabit combo ports 2 unpopul...

Page 15: ...EPS 150DC power modules Add one EPS 150DC for each redundantly powered system 10051 SX SFP 1000BASE S SFP 1000BASE SX LC Connector 10052 LX SFP External Power System 500 Watts Power cord ordered separately 10053 ZX SFP 1000BASE ZX SFP Extra Long Distance SMF 70 km 21 dB Budget LC Connector 10064 LX100 SFP 1000BASE LX100 SFP Extra Long Distance SMF 100 km 30 dB Budget LC Connector 10056 1000BX SFP ...

Reviews: