Cisco CD-3550-EMI Скачать руководство пользователя страница 8

 

 

© 2005 Cisco Systems, Inc. All rights reserved. 

Important notices, privacy statements, and trademarks of Cisco Systems, Inc. can be found on cisco.com. 

Page 8 of 18 

 
 

Feature 

Benefit 

SECURITY 

Security 

 

Bridge protocol data unit (BPDU) guard shuts down Spanning-Tree Protocol PortFast-enabled interfaces when 

BPDUs are received to avoid accidental topology loops. 

 

Spanning-tree root guard (STRG) prevents edge devices not in the network administrator's control from becoming 

Spanning-Tree Protocol root nodes. 

 

IGMP Filtering provides multicast authentication by filtering out non-subscribers and limits the number of 

concurrent multicast streams available per port. 

 

Private VLAN edge provides security and isolation between ports on a switch, ensuring that users cannot snoop on 

other users’ traffic. 

 

Trusted Boundary provides the ability to trust the QoS priority settings if an IP phone is present and disable the trust 

setting in the event that the IP phone is removed, thereby preventing a malicious user from overriding prioritization 
policies in the network. 

 

Switch Port Analyzer (SPAN) for Cisco Secure Intrusion Detection System (IDS) support allows the IDS to take 

action when an intruder is detected. 

 

The user-selectable address-learning mode simplifies configuration and enhances security. 

 

Cisco CMS Software Security Wizards ease the deployment of security features for restricting user access to a server, 

a portion of the network or access to the network. 

Network 

Administration 

Security 

 

 and RADIUS authentication to enable centralized control of the switch and restrict unauthorized users 

from altering the configuration. Multilevel security on console access prevents unauthorized users from altering the 
switch configuration. 

 

SSH, Kerberos, and SNMPv3 provides network security by encrypting administrator traffic during Telnet and SNMP 

sessions—SSH, Kerberos, and the crypto version of SNMPv3 require a special crypto software image due to US 
export restrictions. 

User and Device 

Authentication 

 

IEEE 802.1x for dynamic port-based security to prevent unauthorized clients from gaining access to the network. 

 

Port Security secures the access to a port based on the MAC address of a users device. The aging feature removes the 

MAC address from the switch after a specific timeframe to allow another device to connect to the same port, thereby 
eliminating administrative overhead associated with this feature. 

Granular Access 

Control and Identity-

based Network 

Services 

 

Cisco security VLAN ACLs (VACLs) on all VLANs to prevent unauthorized data flows to be bridged within 

VLANs. 

 

Cisco standard and extended IP security Router ACLs (RACLs) for defining security policies on routed interfaces 

for control plane and data plane traffic. 

 

Port-based ACLs (PACLs) for Layer 2 interfaces allows security policies to be applied on individual switch ports. 

 

Time-based ACLs allow the implementation of security settings during specific periods of the day or days of the 

week. 

 

802.1x with VLAN assignment allows a dynamic VLAN assignment for a specific user regardless of where the user 

is connected. 

 

802.1x with an ACL assignment allows for specific security policies based on a user regardless of where the user is 

connected. 

 

802.1x with voice VLAN to permit an IP phone access to the voice VLAN irrespective of the authorized or 

unauthorized state of the port. 

 

802.1x and port security for authenticating the port and managing network access for all MAC addresses, including 

that of the client. 

 

Support for dynamic VLAN assignment through implementation of VLAN Membership Policy Server (VMPS) 

client functionality provides flexibility in assigning ports to VLANs. Dynamic VLAN enables fast assignment 
of IP address. 

Содержание CD-3550-EMI

Страница 1: ...t Power System 675 RPS 675 for seamless protection against internal power supply failures and an uninterruptable power supply UPS system to safeguard against power outages The Cisco Catalyst 3550 Series Intelligent Ethernet Switches include the following configurations Catalyst 3550 24 Switch 24 10 100 ports and two Gigabit Interface Converter GBIC based Gigabit Ethernet ports 1 rack unit RU Catal...

Страница 2: ...networks as the strategic business infrastructure it is more important than ever to ensure their high availability security scalability and control By adding Cisco intelligent functionality to the wiring closet customers can now deploy network wide intelligent services that address these requirements in a consistent way from the desktop to the core and through the WAN With Cisco Catalyst Intellige...

Страница 3: ...racle SAP etc voice IP telephony traffic and CAD CAM over less time sensitive applications such as FTP or e mail Simple Mail Transfer Protocol SMTP For example it would be highly undesirable to have a large file download destined to one port on a wiring closet switch and have quality implications such as increased latency in voice traffic destined to another port on this switch This condition is a...

Страница 4: ...te Access Dial In User Service RADIUS authentication enables centralized access control of switches and restricts unauthorized users from altering the configurations Alternatively a local username and password database can be configured on the switch itself Fifteen levels of authorization on the switch console and two levels on the web based management interface provide the ability to give differe...

Страница 5: ...itive assistance In addition Cisco AVVID Architecture for Voice Video and Integrated Data Wizards provide automated configuration of the switch to optimally support video streaming or videoconferencing voice over IP VoIP and mission critical applications Additional wizards for LAN security and multicast traffic are available too These Wizards can save hours of time for network administrators elimi...

Страница 6: ...w Rapid Spanning Tree Protocol RSTP provides rapid convergence of the spanning tree independent of spanning tree timers Supports Cisco HSRP to create redundant fail safe routing topologies Redundant stacking connections provide support for a redundant loopback connection for top and bottom switches in an independent stack backplane cascaded configuration Command switch redundancy enabled in the CM...

Страница 7: ...configuration eases deployment of switches in the network by automatically configuring multiple switches across a network via a boot server Automatic QoS Auto QoS greatly simplifies the configuration of QoS in VoIP networks by issuing interface and global switch commands that allow the detection of Cisco IP phones the classification of traffic and egress queue configuration Auto sensing on each no...

Страница 8: ...SNMPv3 provides network security by encrypting administrator traffic during Telnet and SNMP sessions SSH Kerberos and the crypto version of SNMPv3 require a special crypto software image due to US export restrictions User and Device Authentication IEEE 802 1x for dynamic port based security to prevent unauthorized clients from gaining access to the network Port Security secures the access to a por...

Страница 9: ...ow as 8 Kbps Rate limiting based on source destination IP address source destination MAC address or Layer 4 TCP UDP information or any combination of these fields using QoS ACLs IP ACLs or MAC ACLs class maps and policy maps Per port per VLAN ingress policing enables the rate limiting of individual VLANs on trunk ports Ability to easily manage data flows asynchronously upstream and downstream from...

Страница 10: ...twork topology Supported by the CiscoWorks LAN Management Solution includes Resource Manager Essentials Campus Manager CiscoView and Device Fault Manager QoS Policy Manager QPM ACS User Registration Tool URT CiscoWorks SNMS Service Level Manager and Internet Performance Monitor IPM Superior Cisco IOS CLI support provides common user interface and command set with all Cisco Manageability routers an...

Страница 11: ...SCO BULK FILE MIB CISCO CDP MIB CISCO CLUSTER MIB CISCO CONFIG COPY MIB CISCO CONFIG MAN MIB CISCO ENVMON MIB CISCO FLASH MIB CISCO FTP CLIENT MIB CISCO HSRP EXT MIB CISCO HSRP MIB CISCO IGMP FILTER MIB CISCO IMAGE MIB CISCO IPMROUTE MIB CISCO MAC NOTIFICATION MIB CISCO MEMORY POOL MIB CISCO PAGP MIB CISCO PORT QOS MIB CISCO PROCESS MIB CISCO RTTMON MIB CISCO STACKMAKER MIB CISCO STACK MIB CISCO S...

Страница 12: ... 1000BASE CWDM GBIC 1550nm 1000BASE CWDM GBIC 1570nm 1000BASE CWDM GBIC 1590nm 1000BASE CWDM GBIC 1610nm RMON I and II standards SNMPv1 SNMPv2c SNMPv3 Y2K Y2K compliant Connectors and Cabling 10BASE T ports RJ 45 connectors two pair Category 3 4 or 5 unshielded twisted pair UTP cabling 100BASE TX ports RJ 45 connectors two pair Category 5 UTP cabling 1000BASE T ports RJ 45 two pair Category 5 UTP ...

Страница 13: ...ers connection for an optional Cisco RPS 300 that uses AC input and supplies DC output to the switch The connector offers a 300 watt redundant power system that can support six external network devices and provides power to one failed device at a time The connector automatically senses when the internal power supply of a connected device fails and provides power to the failed device preventing los...

Страница 14: ...770 bystander position operating to an ambient temperature of 30 degrees Celsius Catalyst 3550 12G and 3550 12T 58 dBa Catalyst 3550 24 and 3550 24 DC 48 dBa Catalyst 3550 48 and 3550 24 FX 46 dBa Catalyst 3550 24 PWR 47 dBa Mean Time Between Failure MTBF 110 332 hours Catalyst 3550 12G 113 658 hours Catalyst 3550 12T 166 356 hours Catalyst 3550 24 PWR 193 000 hours Catalyst 3550 24 163 000 hours ...

Страница 15: ... technical repositories Telephone support through the Technical Assistance Center Advance replacement of hardware parts Enables proactive or expedited issue resolution Lowers cost of ownership by utilizing Cisco expertise and knowledge Minimize network downtime Table 3 Ordering Information Model Numbers Configuration WS C3550 12G 10 1000BASE X ports 2 10 100 1000BASE T ports 1 5 RU stackable multi...

Страница 16: ...e multilayer switch integrated inline power Delivers enterprise class intelligent services to the network edge EMI installed Provides advanced IP routing WS C3550 48 SMI 48 10 100 ports 2 1000BASE X ports 1 RU stackable multilayer switch Delivers enterprise class intelligent services and basic IP routing to the network edge SMI installed upgradeable to advanced IP routing WS C3550 48 EMI 48 10 100...

Страница 17: ...sia Saudi Arabia Scotland Singapore Slovakia Slovenia South Africa Spain Sweden Switzerland Taiwan Thailand Turkey Ukraine United Kingdom United States Venezuela Vietnam Zimbabwe Copyright 2005 Cisco Systems Inc All rights reserved CCSP CCVP the Cisco Square Bridge logo Follow Me Browsing and StackWise are trademarks of Cisco Systems Inc Changing the Way We Work Live Play and Learn and iQuick Stud...

Страница 18: ... 2005 Cisco Systems Inc All rights reserved Important notices privacy statements and trademarks of Cisco Systems Inc can be found on cisco com Page 18 of 18 ...

Отзывы: