
28
QNOS software supports RADIUS-based assignment (via 802.1X) of VLANs, including guest and
unauthenticated VLANs. The Dot1X feature also supports RADIUS-based assignment of filter IDs as well as
MAC-based authentication, which allows multiple supplicants connected to the same port to each
authenticate individually.
1.2.9.
MAC Authentication Bypass
QNOS software also supports the MAC-based Authentication Bypass (MAB) feature, which provides 802.1x-
unaware clients (such as printers and fax machines) controlled access to the network using the devices'
MAC address as an identifier. This requires that the known and allowable MAC address and corresponding
access rights be pre-populated in the authentication server. MAB works only when the port control mode of
the port is MAC-based.
1.2.10.
DHCP Snooping
DHCP Snooping is a security feature that monitors DHCP messages between a DHCP client and DHCP server. It
filters harmful DHCP messages and builds a bindings database of (MAC address, IP address, VLAN ID, port)
tuples that are specified as authorized. DHCP snooping can be enabled globally and on specific VLANs. Ports
within the VLAN can be configured to be trusted or untrusted. DHCP servers must be reached through
trusted ports. This feature is supported for both IPv4 and IPv6 packets.
1.2.11.
Dynamic ARP Inspection
Dynamic ARP Inspection (DAI) is a security feature that rejects invalid and malicious ARP packets. The feature
prevents a class of man-in-the-middle attacks, where an unfriendly station intercepts traffic for other stations
by poisoning the ARP caches of its unsuspecting neighbors. The malicious station sends ARP requests or
responses mapping another station's IP address to its own MAC address.
1.2.12.
IP Source Address Guard
IP Source Guard and Dynamic ARP Inspection use the DHCP snooping bindings database. When IP Source
Guard is enabled, the switch drops incoming packets that do not match a binding in the bindings database.
IP Source Guard can be configured to enforce just the source IP address or both the source IP address and
source MAC address. Dynamic ARP Inspection uses the bindings database to validate ARP packets. This
feature is supported for both IPv4 and IPv6 packets.
1.2.13.
Service Prohibit Access
In the network design, the switch front ports are usually used for normal L2/L3 traffic and the service port is
used for switch management and monitoring. The better way to prevent malicious hacker trying to access
switch via switch front port is to isolate management traffic via service port only. The Service Prohibit
Access feature allows you to disable telnet/ssh/snmp access via switch front port.
1.3.
Quality of Service Features
Summary of Contents for QuantaMesh QNOS5
Page 1: ...QuantaMesh Ethernet Switch Configuration Guide QNOS5 NOS Platform ...
Page 209: ...209 Table 7 8 IPv6 Neighbor Discovery Settings ...
Page 226: ...226 Table 8 2 L3 Multicast Defaults ...
Page 254: ...254 Appendix A Term and Acronyms Table 9 5 Terms and Acronyms ...