Layer 2 Switching
|
Spanning Tree Protocol (STP)
|
Standard 802.1d spanning tree support
Fast convergence using 802.1w (Rapid Spanning Tree Protocol [RSTP]), enabled by default
Multiple spanning tree instances using 802.1s (MSTP); 8 instances are supported
|
Port grouping/link aggregation
|
Support for IEEE 802.3ad Link Aggregation Control Protocol (LACP)
? Up to 4 groups
? Up to 8 ports per group with 16 candidate ports for each (dynamic) 802.3ad LAG
|
VLAN
|
Support for up to 256 active VLANs simultaneously
Port-based and 802.1Q tag-based VLANs
Management VLAN
|
Voice VLAN
|
Voice traffic is automatically assigned to a voice-specific VLAN and treated with appropriate levels of QoS. Auto voice capabilities deliver networkwide zero-touch deployment of voice endpoints and call control devices.
|
IGMP (versions 1, 2, and 3) snooping
|
Internet Group Management Protocol (IGMP) limits bandwidth-intensive multicast traffic to only the requesters; supports 4K multicast groups (source-specific multicasting is also supported).
|
HOL blocking
|
Head-of-line (HOL) blocking.
|
Security
|
SSL
|
Secure Sockets Layer (SSL) encrypts all HTTPS traffic, allowing secure access to the browser-based management GUI in the switch.
|
IEEE 802.1X (authenticator role)
|
RADIUS authentication, MD5 hash, single/multiple host mode, and single/multiple sessions.
|
Secure Sensitive Data (SSD)
|
A mechanism to manage sensitive data (such as passwords, keys, and so on) securely on the switch, populating this data to other devices, and secure autoconfig. Access to view the sensitive data as plaintext or encrypted is provided according to the user-configured access level and the access method of the user.
|
Port security
|
Ability to lock source MAC addresses to ports and limit the number of learned MAC addresses.
|
RADIUS
|
Supports RADIUS authentication for management access. Switch functions as a client.
|
Storm control
|
Broadcast, multicast, and unknown unicast.
|
DoS prevention
|
Denial-of-service (DoS) attack prevention.
|
Quality of Service
|
Priority levels
|
4 hardware queues
|
Scheduling
|
Strict priority and weighted round-robin (WRR)
|
Class of service
|
Port based; 802.1p VLAN priority based; IPv4/v6 IP precedence/ToS/DSCP based; DiffServ; trusted QoS
Queue assignment based on differentiated services code point (DSCP) and class of service (802.1p/CoS)
|
Rate limiting
|
Ingress policer, per VLAN, per port
|