
Features
Standard Compliance
• IEEE 802.3 10Base-T Ethernet
• IEEE 802.3u 100Base-Tx Ethernet
• IEEE 802.ab 1000Base-T Ethernet
• IEEE 802.3z
• IEEE 802.3x flow control
• IEEE 802.1p class of service, priority protocols
• IEEE 802.1Q VLAN tagging
• IEEE 802.3ad LACP aggregation
Traffic Management and QoS
• Rate limiting: port-based bandwidth control
with 7 grades (64 kbps, 256 kbps, 1 Mbps,
10 Mbps, 64 Mbps, 100 Mbps, 1 Gbps)
• Broadcast storm control
• IEEE 802.1p with 4 hardware priority queues per
port for different traffic types
• WRR (Weighted Round Robin)/SPQ/scheduling
algorithm
• Congestion control on all ports
• Jumbo frame support (up to 9 KB)(only for GS-
1500 group)
Auto VoIP
• Auto VoIP module explicitly matches VoIP
streams in switches and assign the highest
priority for the following VoIP packets
- SIP—Session Initiation Protocol
- MGCP—Media Gateway Control Protocol
- SCCP—Skinny Client Control Protocol
Link Aggregation
• IEEE 802.3ad LACP link aggregation compliant
• Up to 6 aggregation groups, 8 ports/per group
randomly selected
User Security and Authentication
• Specific MAC forwarding by assigned port: to
control specified MAC addresses can access the
network by assigned port
• IEEE 802.1Q tag-based
• 256 static VLAN, up to 4K dynamic VLAN
• Dynamic ARP
Auto DoS Attack Prevention
Auto DoS module explicitly matches attack
patterns in switches and prevent network outrage
• Types of DoS attacks can be prevented
- Land attacks: these attacks result from sending
a specially crafted packet to a machine where
the source host IP address is the same as the
destination host IP address. The system
attempts to reply to itself, resulting in system
lockup.
- Blat attack: these switch result from sending a
specially crafted packet to a machine where the
source host port is the same as the destination
host port. The system attempts to reply to itself,
resulting in system lockup.
- SYNFIN scans: SYNchronization (SYN,
ACKnowledgement (ACK) and FINish (FIN)
packets are used to initiate, acknowledge and
conclude TCP/IP communication sessions. The
following scans exploit weakness in the TCP/IP
specification and try to illicit a response from a
host to identify ports for an attack:
Scan SYNFIN: SYN and FIN bits are set in the
packet
Xmascan: TCP sequence number is zero and
the FIN, URG and PSH bits are set
NULL scan: TCP sequence number is zero and
all control bits are zeros
SYN with port <1024: SYN packets with
source port less than 1024
- Smurf attacks: this attack uses Internet Control
Message Protocol (ICMP) echo requests packets
(pings) to cause network congestion or
outrages
- Ping flooding: this attack floods the target
network with ICMP packets
- SYN/SYN-ACK flooding: this attack floods the
target network with SYN or SYN/ACK packets
Network Administration Security
• Password required for administrators
Network Management
• Web-based management
• SNMP-lite
• Static IP
• RMON-Lite
• Port mirroring: supports source/destination/
both port mirroring
• Cable diagnostic
Certification
• UL 60950-1
• CSA 60950-1 (future available)
• EN 60950-1
• IEC 60950-1
• EU RoHS compliant
Accessories
SFP Transceivers (Optional)
Speed Model
Type
Description
SFP-1000T
RJ-45 connector
Up to 100 m using standard Ethernet cable
SFP-SX-D
LC connector
SFP SX 550 m commercial type transceiver, DDMI version
*1
SFP-LX-10-D
LC connector
SFP LX 10 km commercial type transceiver, DDMI version
*1
Gigabit
SFP-BX1310-10-D
LC connector
Bidirectional singlemode, up to 10 km reach, DDMI version
*1, *2
SFP-BX1490-10-D
LC connector
Bidirectional singlemode, up to 10 km reach, DDMI version
*1, *2
SFP-LHX1310-40-D
LC connector
SFP LHX 1310 wavelength 40 km commercial type transceiver, DDMI version
*1
SFP-ZX-80-D
LC connector
SFP ZX 80 km commercial type transceiver, DDMI version
*1
*1: Switch 1500 series don't support DDMI (Digital Diagnostics Monitoring Interface) feature.
*2: Bi-directional SFP must be used in pairs (Example: 1 x SFP-BX1310-10-D and 1 x SFP-BX1490-10-D connected together is a solution)