Datasheet

© 2015 Cisco and/or its affiliates. This document is Cisco Public Information. Page 12 of 30
Advanced Security Features
Cisco Catalyst 3850 Series Switches support advanced security features including but not limited to:
Protection against attackers:
Port security secures the access to an access or trunk port based on MAC address. It limits the number
of learned MAC addresses to deny MAC address flooding.
DHCP snooping prevents malicious users from spoofing a DHCP server and sending out bogus
addresses. This feature is used by other primary security features to prevent a number of other attacks
such as ARP poisoning.
Dynamic ARP inspection (DAI) helps ensure user integrity by preventing malicious users from exploiting
the insecure nature of ARP.
IP source guard prevents a malicious user from spoofing (that is, taking over) another users IP address
by creating a binding table between the clients IP and MAC address, port, and VLAN, and by using it to
selectively block bogus packets.
The Unicast Reverse Path Forwarding (uRPF) feature helps mitigate problems caused by the
introduction of malformed or forged (spoofed) IP source addresses into a network by discarding IP
packets that lack a verifiable IP source address.
Bidirectional data support on a SPAN port allows the Cisco intrusion detection system (IDS) to take
action when an intruder is detected.
User authentication:
Flexible authentication that supports multiple authentication mechanisms, including 802.1X, MAC
authentication bypass, and web authentication using a single, consistent configuration.
RADIUS change of authorization and downloadable calls for comprehensive policy management
capabilities.
Private VLAN edge restricts traffic between hosts in a switch by segregating traffic at Layer 2, turning a
broadcast segment into a nonbroadcast multiaccess like segment. Private VLAN edge provides security
and isolation between switch ports, which helps ensure that users cannot snoop on other users traffic.
Multidomain authentication allows an IP phone and a PC to authenticate on the same switch port while
placing them on appropriate voice and data VLAN.
MAC address notification allows administrators to be notified of users added to or removed from the
network.
Mobility and security for secure, reliable wireless connectivity and consistent end-user experience.
Increased network availability through proactive blocking of known threats.
IGMP filtering provides multicast authentication by filtering out nonsubscribers and limits the number of
concurrent multicast streams available per port.
ACLs:
Cisco security VLAN ACLs on all VLANs prevent unauthorized data flows from being bridged within
VLANs.
Cisco standard and extended IP security router ACLs define security policies on routed interfaces for
control-plane and data-plane traffic. IPv6 ACLs can be applied to filter IPv6 traffic.
Port-based ACLs for Layer 2 interfaces allow security policies to be applied on individual switch ports.