Enterasys SK5208-0808-F6 Fiche technique Page 8

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 16
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 7
Page 8
Feature-Rich Functionality
Examples of additional functionality and features that are supported by the Enterasys S-Series:
NetFlow - Provides real-time visibility, application profiling, and capacity planning
Server Load Balancing - Enabled via LSNAT without requiring costly external server load balancing hardware and software
NAT - Network Address Translation (NAT) streamlines IP addressing and IP address management schemes
LLDP-MED - Link Layer Discovery Protocol for Media Endpoint Devices enhances VoIP deployments
Flow Setup Throttling - (FST) effectively preempts and defends against DoS attacks
Web Cache Redirect - Increases WAN and Internet bandwidth efficiency
Node & Alias Location - Automatically tracks user and device location and enhances network management productivity and fault isolation
Port Protection Suite - Maintain network availability by ensuring good protocol and end station behavior
Flex-Edge Technology - Provides advanced bandwidth management and allocation for demanding access/edge devices
Virtual Switch Bonding - Provides increased resiliency and performance by combining two or more physical switches to create a single logical switch
High Availability Firmware Upgrade (In-Service Software Upgrade) - System software upgrade without service interruption
Secure https switch management via NetSight OneView
Network performance, management, and security capabilities via NetFlow are available on every S-Series I/O Fabric and I/O Module without affecting
switching/routing performance or requiring the purchase of expensive daughter cards for every blade. The S-Series tracks every packet in every flow unlike
competitor’s statistical sampling techniques. The Enterasys advantage is the Enterasys ASIC capabilities that collect NetFlow statistics for every packet
in every flow without sacrificing performance. Enterasys S-Series switches can output 9,000 flow records per second, per I/O module. This is an order of
magnitude greater NetFlow performance than any other NetFlow appliance vendor (over 70,000 flow records per second in a fully populated S8 chassis).
Flow Setup Throttling (FST) is a proactive feature designed to mitigate zero-day threats and Denial of Service (DoS) attacks before they can affect the
network. FST directly combats the effects of zero-day and DoS attacks by limiting the number of new or established flows that can be programmed on
any individual switch port. This is achieved by monitoring the new flow arrival rate and/or controlling the maximum number of allowable flows.
In network operations, it is very time consuming to locate a device or find exactly where a user is connected. This is especially important when reacting
to security breaches. Enterasys S-Series modules automatically track the network’s user/device location information by listening to network traffic as it
passes through the switch. This information is then used to populate the Node/Alias table with information such as an end-station’s MAC address and
Layer 3 alias information (IP address, IPX address, etc). This information can then be utilized by Enterasys NMS Suite management tools to quickly
determine the switch and port number for any IP address and take action against that device in the event of a security breach. This node and alias
functionality is unique to Enterasys and reduces the time to pinpoint the exact location of a problem from hours to minutes.
For organizations looking to deploy VoIP technologies, the Enterasys S-Series provides significant capabilities through its support for the industry-
standard discovery protocol, LLDP-MED (Link Layer Discovery Protocol for Media Endpoint Devices). This protocol allows for the accurate representation
of network topologies within Network Management Systems (NMS). S-Series switches are able to learn about all the devices connected to them to
identify VoIP phones, tell the phone which VLAN to use for voice, and even negotiate the power that the phone can consume. LLDP–MED also enables
911 emergency services location functions whereby the location of a phone can be determined by the switch port.
Enterasys S-Series support for Network Address Translation (NAT) provides a practical solution for organizations who wish to streamline their IP
addressing schemes. NAT operates on a router connecting two networks, simplifying network design and conserving IP addresses. NAT can help
organizations merge multiple networks together and enhance network security by helping to prevent malicious activity initiated by outside hosts from
entering the corporate network; this improves the reliability of local systems by stopping worms and augments privacy by discouraging scans.
Within server farm environments, the S-Series can help to increase reliability and performance via the implementation of Load Sharing Network Address
Translation (LSNAT). Based on RFC 2391, LSNAT uses a number of load sharing algorithms to transparently offload network load on a single server and
distributes the load across a pool of servers.
The S-Series also supports a comprehensive portfolio of port protection capabilities, such as SPANguard and MACLock, which provide the ability to
detect unauthorized bridges in the network and restrict a MAC address to a specific port. Other port protection features include Link Flap, Broadcast
Suppression, and Spanning Tree Loop protection which protects against mis-configuration and protocol failure. The S-Series Virtual Switch Bonding
technology allows two or more S-Series systems to create a single virtual switch.
Enterasys S-Series Flex-Edge technology provides line rate traffic classification for all access ports with guaranteed priority delivery for control plane
traffic and high-priority traffic as defined by the Enterasys policy overlay. In addition to allocating resources for important network traffic, prioritized
bandwidth can be assigned on a per port or per authenticated user basis. Flex-Edge technology is ideal for deployment in wiring closets and distribution
points that can often suffer from spikes in utilization that cause network congestion. With Flex-Edge technologies, organizations no longer have to fear a
momentary network congestion event that would result in topology changes and random packet discards.
CoreFlow2 policy enabled edge and core switches managed via NetSight play fundamental and essential roles in moving data reliably, efficiently and
securely. The combined hardware and management suite provide superior traffic visibility, enforcement and security.
Vue de la page 7
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16

Commentaires sur ces manuels

Pas de commentaire