Chapter2SystemOverview
àItsupportsMAC/IP/VLAN/Portcombinationatrandom,whicheffectivelyprevents
illegalusersfromaccessingthenetwork.
àPortisolationensuresthatausercanneithermonitortrafcofanotheruseron
thesameswitchnorobtaintheuser'sinformation.
àItsupportstheGuestVlanandanti-proxyfunction,whichfacilitatesitsapplications
ineducationalnetworksandothercomplexnetworkenvironments.
àDynamicHostCongurationProtocol(DHCP)monitoringpreventsmalicious
usersfromdeceivingtheDHCPserverandsendingspuriousaddressinformation.
ItcanalsoenableIPsourceprotectionandcreateabindingtablefortheIP
address,MACaddress,andportoftheclientandtheVLANtopreventauser
fromaccessingorusingtheIPaddressofanotheruser.
lEquipment-levelsecuritycontrol
àTheCPUsecuritycontroltechnologypreventsDenialofService(DoS)attacks.
àTheSecureShell(SSH)/SimpleNetworkManagementProtocol(SNMP)v3
ensuresnetworkmanagementsecurity.
àMulti-levelaccesssecurityoftheconsolepreventsunauthorizedusersfrom
changingtheswitchconguration.
àTheRemoteAuthenticationDialInUserService(RADIUS)/T erminalAccess
ControllerAccess-ControlSystemPlus(TACACS+)identicationauthentication
putstheswitchundercentralizedcontrolandpreventsunauthorizedusersfrom
modifyingtheconguration.
lNetworksecuritycontrol
àTheAccessControlList(ACL)basedonportsandVLANsmakesitpossiblefor
userstoapplysecuritystrategiestoeachportortrunkoftheswitch.
àMACaddressbindingandsource-ordestination-basedlteringprovideeffective
address-basedtrafccontrol.
àTheportmirroringfunctionprovidesaneffectivetoolfornetworkmanagement
analysis.
QoSGuarantee
TheZXR102900EprovidesthefollowingapplicationsofQualityofService(QoS):
lProvidesStandard802.1pClassofService(CoS)andDifferentiatedServicesCode
Point(DSCP)eldsorting.Singlegroup-basedlabelingandre-sortingcanbe
performedbyusingsourceanddestinationIPaddresses,sourceanddestination
MACaddresses,andTransferControlProtocol(TCP)/UserDatagramProtocol
(UDP)portnumbers.
lProvidesqueueschedulingalgorithmsincludingStrictPriority(SP)andWeighted
RoundRobin(WRR).
lSupportstheCommittedAccessRate(CAR)function.Itmanagesasynchronous
uplinkanddownlinkdataowsfromuplinksbyingressstrategycontrolandegress
2-3
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential