Distributed IP Routing-providesdynamictrafcoptimization,broadcast
containment and more efficient network resilience
• Baseroutingfeaturesincludestaticroutes,RIPv1/RIPv2,IPv4and
Multicastroutingsupport(DVMRP,IGMPv1/v2,PIM-SM)
• Advancedroutingfeaturesarelicensedseparatelythroughthe
purchaseofN-EOS-L3andincludeLSNAT,VRRP,DHCPrelay,PIM,
OSPF,DVMRPandExtendedACLs.DiamondDFEsincludeadvanced
routing at no additional charge.
Security (User, Network and Host) - protects a business against network
misuse, and controls access to resources and confidential information
• Usersecurity
−Authentication(802.1X,MACandWeb),MAC(StaticandDynamic)
port locking
− Multi-user authentication/policies
•Networksecurity
−AccessControlLists(ACL)–basicandextended
−Policy-basedsecurityservices(examples:spoong,unsupported
protocolaccess,intrusionprevention,DoSattackslimits)
•Host
−SecureaccesstotheMatrixN-SeriesviaSSH,SSL,SNMPv3
Management, Control and Analysis - provide streamlined tools for
maintaining network availability and health
•Conguration
−Industry-standardCLIandwebsupport
− Multiple images with editable configuration files
•NetworkAnalysis
−SNMPv1/v2c/v3,RMON/RMONII,andSMON(rfc2613)VLANand
Stats
−Port/VLANmirroring(onetoone,onetomany,manytomany)
−LinerateNetFlow
•Automatedset-upandreconguration
−ReplacementDFEwillautomaticallyinheritpreviousDFEs
configuration
– New blades added to chassis will automatically be updated with
active configuration and firmware
Optimized High-Availability Services
Aside from the standard high-availability features of typical wiring closet
and data center switches, the Matrix N-Series includes many advanced
features such as dynamic service fail-over, automatic module self-
configuration, and multi-image support.
Dynamicservicefail-overenableseachDiamond/PlatinumDFE
service(e.g.,hostmanagement,switching/VLANs,routing,etc.)tobe
automaticallyswitchedtoanotherDiamond/PlatinumDFEinanevent
ofmoduleorprocessfailure.This“selfhealing”capabilityhappens
inmillisecondsbecauseeachserviceisreplicatedoneveryDiamond/
PlatinumDFE.
Automatic module self-configuration is another innovative feature that
allowsaDFEmodulestoreceivetheircongurationfromotherDFEs
automatically. This is ideal for replacing failed modules without manually
reconguringthereplacementDFE.
Matrix N-series allow you to download and store multiple image files, this
feature is useful for reverting back to a previous version in the event that
a firmware upgrade fails. This multi-image support provides significant
operational efficiencies especially with regard to the application of
firmware patches.
Feature Rich Functionality
Examples of additional functionality and features that can be found
within the Matrix N-Series include;
• NetFlow
• LSNAT
• NAT
• LLDP-MED
• FlowSetupThrottling
• WebCacheRedirect
• Node&AliasLocation
• WebCacheRedirect
• PortProtectionSuite
To expand on some of the above, network performance management and
securitycapabilitiesviaNetFlowareavailableoneveryMatrixN-Series
DFEwithoutslowingdownswitching/routingperformanceorrequiringthe
purchase of expensive daughter cards for every blade. Enterasys tracks
every packet in every flow as opposed to competitor’s statistical sampling
techniques.TheEnterasysadvantageisthenTERAASICcapabilitiesthat
collectNetFlowstatisticsforeverypacketineveryowwithoutsacricing
performance,Matrix™N-Seriesswitchescancollect9,000owrecords
persecond,perbladeonGold,PlatinumandDiamondDFEs
ThisisanorderofmagnitudegreaterNetFlowcollectionperformance
thananyotherNetFlowappliancevendor(over60,000owrecordsper
secondinafullypopulatedchassis).
FlowSetupThrottling(FST)isaproactivefeaturedesignedtomitigate
zero-daythreatsandDenialofService(DoS)attacksbeforetheycan
wreakhavoconthenetwork.FSTdirectlycombatstheeffectsofzero-day
andDoSattacksbylimitingthenumberofneworestablishedows
that can be programmed on any individual switch port. This is achieved
by monitoring the new flow arrival rate and/or controlling the maximum
number of allowable flows.
Innetworkoperations,itisverytimeconsumingtolocateadeviceor
find exactly where a user is connected. This is especially important when
reactingtosecuritybreaches.TheMatrixN-SeriesDFEsautomatically
track the network’s user/device location information by listening to
the network traffic as it passes through the switch. This information is
then used to populate the Node/Alias table with information such as
anend-station’s(Node’s)MACaddressandLayer3aliasinformation
(IPAddress,IPXAddress,etc).Thisinformationcanthenbeutilized
byNetSightmanagementtoolstoquicklydeterminethatIPAddress
Page 6