© 2012-2013 Cisco and/or its affiliates. All rights reserved. This document is Cisco Public Information.
Page 7 of 17
Ɣ
802.1X Supplicant with Network Edge Access Transport (NEAT)
enables extended secure access
where compact switches in the conference rooms have the same level of security as switches inside the
locked wiring closet.
Other Advanced Security Features
Other Advanced Security features include but are not limited to:
Ɣ
Private VLAN Edge
provides security and isolation between switch ports, which helps ensure that users
cannot snoop on other users’ traffic.
Ɣ
Multidomain Authentication
allows an IP phone and a PC to authenticate on the same switch port while
placing them on appropriate voice and data VLAN.
Ɣ
Port-based ACLs
for Layer 2 interfaces allow security policies to be applied on individual switch ports.
Ɣ
Secure Shell (SSH) Protocol, Kerberos, and Simple Network Management Protocol Version 3
(SNMPv3)
provide network security by encrypting administrator traffic during Telnet and SNMP sessions.
SSH Protocol, Kerberos, and the cryptographic version of SNMPv3 require a special cryptographic
software image because of U.S. export restrictions.
Ɣ
Bidirectional data support on the
Switched Port Analyzer (SPAN)
port allows Cisco Intrusion Detection
System (IDS) to take action when an intruder is detected.
Ɣ
and RADIUS authentication
facilitates centralized control of the switch and restricts
unauthorized users from altering the configuration.
Ɣ
MAC Address Notification
allows administrators to be notified of users added to or removed from the
network.
Ɣ
Multilevel security on console access
prevents unauthorized users from altering the switch
configuration.
Ɣ
Bridge protocol data unit (BPDU) Guard
shuts down Spanning Tree PortFast-enabled interfaces when
BPDUs are received to avoid accidental topology loops.
Ɣ
Spanning Tree Root Guard (STRG)
prevents edge devices not in the network administrator’s control from
becoming Spanning Tree Protocol root nodes.
Ɣ
IGMP filtering
provides multicast authentication by filtering out nonsubscribers and limits the number of
concurrent multicast streams available per port.
Ɣ
Dynamic VLAN assignment
is supported through implementation of VLAN Membership Policy Server
client capability to provide flexibility in assigning ports to VLANs. Dynamic VLAN facilitates the fast
assignment of IP addresses.
High Availability
Cisco Catalyst 2960-SF Series Switches provide Cisco FlexStack stacking to support increased resiliency and
availability. Other high-availability features include:
Ɣ
Cross-Stack EtherChannel
provides the ability to configure Cisco EtherChannel technology across
different members of the Cisco FlexStack for high resiliency.
Ɣ
Flexlink
provides link redundancy with convergence time less than 100 ms.