Datasheet

www.edge-core.com
Features
ECS4120-28Fv2-AF Product Specifications
TEL: +886-3-5638888 FAX: +886-3-6686111
No.1, Creation Rd. III, Hsinchu Science Park, Taiwan 30077
sales@edge-core.com www.edge-core.com
TEL: +1 (949)-336-6801
20 Mason Irvine, CA 92618
Security-continued
Management Security:
Login Security
Hierarchical User Accounts Authentication
RADIUS authentication
RADIUS accounting
TACACS + authentication
TACACS + accounting
TACACS + authorization
Management Interface Access Filtering (SNMP, Web, Telnet)
SSH (v1.5/v2.0) for security Telnet
Cipher:
aes192-ctr
aes256-ctr
aes256-gcm@openssh.com
chacha20-poly1305@openssh.com
aes128-ctr
aes128-gcm@openssh.com
KEY
ssh-rsa
rsa-sha2-512
rsa-sha2-256" in below
SSL for HTTPS
SFTP IPv4/ IPv6
SNMPv3
Green Ethernet
IEEE 802.3az Energy-Efficient Ethernet (EEE)
OAM
IEEE 802.3ah Link
IEEE 802.1ag Connectivity Fault Management:
Connectivity check
Loopback
Linktrace
ITU-T Y.1731 Performance and Throughput Management:
Frame Delay
Frame Delay variation
QoS Features
Priority Queues: 8 hardware queues per port
Traffic classification:
IEEE 802.1p CoS
IP Precedence
DSCP
MAC Access control list ( Source/Destination MAC, Ether type,
Priority ID/ VLAN ID)
IP Standard access control list (Source IP)
IP extended access control list (Source/Destination IP, Protocol,
TCP/UDP port number)
Traffic Scheduling:
Strict Priority
Weighted Round Robin
Strict + WRR
Ingress policy map (police rate, remark CoS)
Egress policy map (police rate, remark CoS/DSCP)
Support policing and shaping according to 802.1q VLAN
Support to ensure bandwidth configuration for each Switch port
according to:
Committed bandwidth, Peak rate, Excess rate, Information Rates
Rate Limiting (Ingress and Egress, per port base):
GE: Resolution 64Kbps ~ 1,000Mbps
Auto Traffic Control
IPv6 Features
IPv4/IPv6 Dual Protocol stack
IPv6 Address Types Stack: Unicast
IPv6 Neighbor Discovery:
Duplicate address
Address resolution
Unreachable neighbor detection
Stateless auto-configuration
Manual configuration
Remote IPv6 ping
IPv6 Telnet support
HTTP over IPv6
SNMP over IPv6
IPv6 Syslog support
IPv6 TFTP support
IPv6 MLD filter: MLD max-groups (throttling)
IPv6 ND snooping
MLD Snooping v1/v2
IPv6 source guard
DHCPv6 snooping
MVR6
TACACS IPv6
Routing
VLAN Interface IP address assignment
IP interface IPv4/v6: 256/128 (Shared)
IPv4/IPv6 Static Route
Host route IPv4/v6: 4K/2K
Net route IPv4/v6: 512/128
DHCP Server
RIP v1/v2
Management
IPv4, ICMPv4, UDP, TCP
Switch Management:
CLI via console port or Telnet
Web management
SNMP v1, v2c, v3
Provide complete private mib for NMS to
Partitioning Management based on functions and equipment
PPPoE 7 Parameter Configuration
IPoE 7 Parameter Configuration
IP clustering (32 members)
Firmware & Configuration:
Firmware upgrade via TFTP/HTTP/FTP server
Dual images
Multiple configuration files
Configuration file upload/download via TFTP/HTTP/FTP server
Firmware auto upgrade
RMON (groups 1, 2, 3 and 9)
BOOTP, DHCP client for IP address assignment
DHCP dynamic provision option 66, 67
SNTP/NTP IPv4/ IPv6
DNS client
Event/Error Log
Syslog
SMTP
Support LLDP (802.1ab) IPv4/IPv6
sFlow v4, v5
Cable diagnostics
Traceroute
Traceroute6
DHCP server (8 pools, 512 IP addaress)
TWAMP probe and responder
Scheduling Reboot
Support CPU, Memory, Temperature, FAN and Bandwidth Monitoring
Link Aggregation:
Static Trunk
IEEE 802.3ad Link Aggregation Control Protocol
Comply to 802.1ax standard
Trunk groups: 16, up to 8 GE ports per group
Load Balancing: SA+DA, SA, DA, SIP+DIP, SIP, DIP
LACP Backup mode: To maintain active and backup link for
redundancy purpose
Support Smart Pair Uplink Redundancy (<50ms)
IGMP Snooping:
Support 1000 IGMP Group
IGMP v1/v2/v3 snooping
IGMP Proxy reporting
IGMP Filtering
IGMP Throttling
IGMP Immediate Leave
IGMP Querier
IGMP mrouter-forward mode
IGMP router-alert-option-check
IGMP router-port-expire-time
IGMP tcn-flood
MVR (Multicast VLAN Registration): Supports 5 multicast VLANs
Port mirroring (many source ports to one destination port. One
source port to one destination port only)
Remote port mirror (RSPAN)
Security
User Security for Enterprise:
IEEE 802.1X port based and MAC based authentication
Dynamic VLAN Assignment, Auto QoS
MAC authentication
Web authentication
Voice VLAN
Guest VLAN
User Security for ISP/MSO:
L2/L3/L4 Access Control List
MAC Access control list (Source/Destination MAC, Ether type,
Priority ID/VLAN ID)
Support per port MAC Access List
IP standard access control list (Source IP)
IP extended access control list (Source/Destination IP, Protocol,
TCP/UDP port number)
DHCP Snooping (DHCP Filtering)
DHCP Option 82
Support modify Interface type for information option TR101 format
DHCP Option 82 Relay
IP Source Guard
Network Security:
IPv6 ACL
Port security
Sticky MAC
PPPoE IA
PPPoE 7 Parameter Supported
Hostname_Rack/Frame/Shelf/Slot:port_Svlan:Cvlan
IPoE 7 Parameter Supported
Hostname_Rack/Frame/Shelf/Slot:port_Svlan:Cvlan
Support modify Interface type and keep vendor tag
Dynamic ARP Inspection
CPU guard
CPU/Memory threshold and alarm
Denial of Service protection
echo-chargen
smurf
tcp-flooding
tcp-null-scan
tcp-syn-fin-scan
tcp-xmas-scan
udp-flooding
win-nuke