background image

Advanced management features

BootP and TFTP support allows centralized switch IP address assignment, software upgrades,
and SNMP agent updates over the network. The security feature uses the Remote
Authentication Dial-In User Services (RADIUS) protocol to authenticate local console and
TELNET logins.

Enhanced security

The BayStack 425 Switches offer security features including Secure Shell (SSH) version 2, IEEE
802.1x based security, [also known as Extensible Authentication Protocol (EAP)], assignment of
proper VLAN and priority, Simple Network Management Protocol (SNMPv3), MAC-address
based security, and RADIUS authentication.

SSHv2 supports strong authentication and encrypted communications. It allows a user 
to log into the switch from an SSH client and perform a secure Telnet session using CLI
commands. This feature is ideal for security conscious customers such as federal governments.

For added security, BayStack 425 Switches support the 802.1x-based security feature EAP.
Based on the IEEE 802.1x standard, EAP limits access to the network based on user creden-
tials. A user is required to “login” to the network using a username/password; the user database
is maintained on the authentication server (not the switch).

EAP prevents network connectivity without password authorization for added security and
control in physically non-secure areas. It is used where the network is not 100 percent physi-
cally secure or where physical security needs enhancement—for example, banks, trading
rooms, or classroom training facilities. EAP supports client access to the network and inter-
operates with Microsoft

Windows XP and other compliant 802.1x clients.

SNMPv3 provides user authentication and data encryption for
higher security. It also offers secure configuration and monitoring.

BaySecure MAC-address based security allows authentication of
all access, not only to the switches for management and configura-
tions, but also access to the infrastructure through these switches.
This software feature limits access to only network authorized and
trusted personnel, including full tracking of network connections.
With BaySecure, network access is granted or denied via proper
MAC-address identification (up to a maximum of 448). 

The RADIUS-based security feature allows you to set up network
access control using the RADIUS security protocol to authenti-
cate local console and Telnet logins.

Port mirroring 

The port mirroring feature (sometimes referred to as ‘conversation steering’) allows the
network administrator to designate a single switch port as a traffic monitor for a specified port.
Port mirroring copies packets flowing into a specified port and sends the replicated data to the
mirrored port for in-depth analysis of switched traffic patterns to trouble-shoot problems and
optimize network configurations. Additionally, an external probe device can be attached to 
the designated monitor port.

6

Summary of Contents for 425-24T

Page 1: ... features require minimal technical expertise to configure them For more details on Nortel Networks SMB solutions please visit www nortelnetworks com smb The BayStack 425 Switches are stackable 10 100 Mbps Layer 2 Ethernet switches featuring easy configuration and stackability flexible choices for high speed uplinks and Web based management from a Web browser The BayStack 425 Switches have been ar...

Page 2: ...d device The ports deter mine whether a connected device is operating at 10 Mbps or 100 Mbps and automatically adjust to the optimal speed Each of the switched ports can also automatically detect and support full duplex connections to servers power user end stations or other switches as well as half duplex connections to legacy NICs or hubs High density stacking architecture The plug and play casc...

Page 3: ...nd will be available for free for the lifetime of the switches Other BayStack switches support a different version of BoSS BoSS version 3 1 is currently available from www nortelnetworks com support and adds support for the following features Support for BayStack 425 48T 255 VLANs support BayStack 425 only Custom Auto Negotiation Advertisements CANA Flexible stacking across BayStack 425 and 420 Sw...

Page 4: ...ded the configuration file automatically configures the switch or stack according to the NNCLI commands in the file This feature allows the flexibility of creating command configuration files that can be used on several switches or stacks with minor modifications ASCII configuration file generator This feature works by reading the current configuration on the switch and generating the appropriate ...

Page 5: ...icating with a single device It uses a common user interface and workflow that supports many Nortel Networks Ethernet switches This commonality allows the network manager to become familiar with one tool instead of multiple tools Optivity Switch Manager OSM is a Java based real time configuration management application for Nortel Networks Ethernet products including BayStack 425 Switches It enable...

Page 6: ...t is used where the network is not 100 percent physi cally secure or where physical security needs enhancement for example banks trading rooms or classroom training facilities EAP supports client access to the network and inter operates with Microsoft Windows XP and other compliant 802 1x clients SNMPv3 provides user authentication and data encryption for higher security It also offers secure conf...

Page 7: ...er Configuration parameters can be retrieved automatically to configure a replacement switch or stack with the same configuration For new installations or when a switch has failed this feature saves time in reconfiguring another switch or stack Power and space savings Low power consumption of 46W results in lower operating costs Compact one rack unit high design allows for significant space and co...

Page 8: ...otocol IEEE 802 3ad manual static IEEE 802 3ad LACP IEEE 802 1s IEEE 802 1w RFC support RFC 1213 MIB II RFC 1493 Bridge MIB RFC 2863 Interfaces Group MIB RFC 2665 Ethernet MIB RFC 2737 Entity MIBv2 RFC 2819 RMON MIB RFC 1757 RMON RFC 1271 RMON RFC 1157 SNMP RFC 2570 SNMPv3 RFC 2571 SNMP Frameworks RFC 2573 SNMPv3 Applications RFC 2574 SNMPv3 USM RFC 2575 SNMPv3 VACM RFC 2576 SNMPv3 RFC 2572 SNMP M...

Page 9: ...r AL2011013 Console Cable for use with BayStack switches The seventh character of the switch order number must be replaced with the proper code to indicate desired product nationalization A No power cord included B Includes European Schuko power cord common in Austria Belgium Finland France Germany The Netherlands Norway and Sweden C Includes power cord commonly used in the United Kingdom and Irel...

Page 10: ...ormation The company is supplying its service provider and enterprise customers with communications technology and infrastructure to enable value added IP data voice and multimedia services spanning Wireless Networks Wireline Networks Enterprise Networks and Optical Networks As a global company Nortel Networks does business in more than 150 countries More information about Nortel Networks can be f...

Reviews: