1.1 Product Positioning
The S1720 series Ethernet switches (S1720 for short) are next-generation energy-saving 1000M
Ethernet switches delivering high performance.
The S1720 utilizes next-generation high-performance hardware and Huawei Versatile Routing
Platform (VRP) software. It is easy to install and maintain. The S1720 can be flexibly deployed
on a network, provides comprehensive security and QoS policies, and is designed using energy-
saving technologies. With an S1720, a network can carry multiple services and support multi-
service access. The S1720 is applicable to the 1000M access of enterprise campus networks and
1000M-to-desktop scenarios, helping enterprises construct future-oriented IT networks.
1.2 Product Characteristics
Diversified Management and Maintenance Methods
The S1720 supports various management and maintenance methods, including SNMPv1/v2c/
v3, CLI, web, Telnet, and SSHv2.0. It provides user-friendly man-machine interaction interface
and web-based graphic interface, and supports alarm management and graphic configuration.
The S1720 adopts new ASIC switching chip and the fanless design, which reduces failure points
and avoid condensed water and dust.
Flexible Service Control
The S1720 supports VLAN assignment based on interfaces, MAC addresses, protocols, and IP
subnets. It applies to networks where users move frequently and networks demanding high
security. The S1720 supports STP, RSTP, and MSTP to ensure network reliability.
Various Security Protection Measures
The S1720 supports DHCP snooping, which generates user binding entries based on MAC
addresses, IP addresses, IP address leases, VLAN IDs, and interface numbers of users. The
DHCP snooping function protects networks against common attacks such as bogus IP packet
attacks, man-in-the-middle attacks, and bogus DHCP server attacks.
The S1720 can limit the number of MAC addresses learned on an interface to prevent packet
flooding that occurs when an attacker frequently changes source MAC addresses. The S1720
supports strict ARP learning. This feature prevents ARP spoofing attackers from exhausting
ARP entries so that users can connect to the Internet normally. It provides IP source check to
prevent DoS attacks caused by IP address spoofing.
The S1720 supports centralized MAC address authentication and 802.1x authentication. It
authenticates users based on statically or dynamically bound user information such as the user
name, IP address, MAC address, VLAN ID, and interface number. VLANs and ACLs can be
applied to users dynamically.
Comprehensive QoS Policies
The S1720 supports complex traffic classification based on VLAN IDs, MAC addresses, IP
protocols, source addresses, destination addresses, priorities, or TCP or UDP port numbers of
S1720 Series Ethernet Switches
Product Description
1 Product Overview
Issue 01 (2014-07-20)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2