Datasheet
www.edge-core.com
Features
ECS4120-28Fv2-AF Product Specifications
TEL: +886-3-5638888 FAX: +886-3-6686111
No.1, Creation Rd. III, Hsinchu Science Park, Taiwan 30077
sales@edge-core.com www.edge-core.com
TEL: +1 (949)-336-6801
20 Mason Irvine, CA 92618
Security-continued
■ Management Security:
Login Security
Hierarchical User Accounts Authentication
RADIUS authentication
RADIUS accounting
TACACS + authentication
TACACS + accounting
TACACS + authorization
Management Interface Access Filtering (SNMP, Web, Telnet)
SSH (v1.5/v2.0) for security Telnet
Cipher:
• aes192-ctr
• aes256-ctr
• aes256-gcm@openssh.com
• chacha20-poly1305@openssh.com
• aes128-ctr
• aes128-gcm@openssh.com
KEY
• ssh-rsa
• rsa-sha2-512
• rsa-sha2-256" in below
SSL for HTTPS
SFTP IPv4/ IPv6
SNMPv3
Green Ethernet
■ IEEE 802.3az Energy-Efficient Ethernet (EEE)
OAM
■ IEEE 802.3ah Link
■ IEEE 802.1ag Connectivity Fault Management:
Connectivity check
Loopback
Linktrace
■ ITU-T Y.1731 Performance and Throughput Management:
Frame Delay
Frame Delay variation
QoS Features
■ Priority Queues: 8 hardware queues per port
■ Traffic classification:
IEEE 802.1p CoS
IP Precedence
DSCP
MAC Access control list ( Source/Destination MAC, Ether type,
Priority ID/ VLAN ID)
IP Standard access control list (Source IP)
IP extended access control list (Source/Destination IP, Protocol,
TCP/UDP port number)
■ Traffic Scheduling:
Strict Priority
Weighted Round Robin
Strict + WRR
■ Ingress policy map (police rate, remark CoS)
■ Egress policy map (police rate, remark CoS/DSCP)
■ Support policing and shaping according to 802.1q VLAN
■ Support to ensure bandwidth configuration for each Switch port
according to:
■ Committed bandwidth, Peak rate, Excess rate, Information Rates
■ Rate Limiting (Ingress and Egress, per port base):
GE: Resolution 64Kbps ~ 1,000Mbps
■ Auto Traffic Control
IPv6 Features
■ IPv4/IPv6 Dual Protocol stack
■ IPv6 Address Types Stack: Unicast
■ IPv6 Neighbor Discovery:
Duplicate address
Address resolution
Unreachable neighbor detection
■ Stateless auto-configuration
■ Manual configuration
■ Remote IPv6 ping
■ IPv6 Telnet support
■ HTTP over IPv6
■ SNMP over IPv6
■ IPv6 Syslog support
■ IPv6 TFTP support
■ IPv6 MLD filter: MLD max-groups (throttling)
■ IPv6 ND snooping
■ MLD Snooping v1/v2
■ IPv6 source guard
■ DHCPv6 snooping
■ MVR6
■ TACACS IPv6
Routing
■ VLAN Interface IP address assignment
■ IP interface IPv4/v6: 256/128 (Shared)
■ IPv4/IPv6 Static Route
■ Host route IPv4/v6: 4K/2K
■ Net route IPv4/v6: 512/128
■ DHCP Server
■ RIP v1/v2
Management
■ IPv4, ICMPv4, UDP, TCP
■ Switch Management:
CLI via console port or Telnet
Web management
SNMP v1, v2c, v3
Provide complete private mib for NMS to
Partitioning Management based on functions and equipment
PPPoE 7 Parameter Configuration
IPoE 7 Parameter Configuration
■ IP clustering (32 members)
■ Firmware & Configuration:
Firmware upgrade via TFTP/HTTP/FTP server
Dual images
Multiple configuration files
Configuration file upload/download via TFTP/HTTP/FTP server
Firmware auto upgrade
■ RMON (groups 1, 2, 3 and 9)
■ BOOTP, DHCP client for IP address assignment
■ DHCP dynamic provision option 66, 67
■ SNTP/NTP IPv4/ IPv6
■ DNS client
■ Event/Error Log
■ Syslog
■ SMTP
■ Support LLDP (802.1ab) IPv4/IPv6
■ sFlow v4, v5
■ Cable diagnostics
■ Traceroute
■ Traceroute6
■ DHCP server (8 pools, 512 IP addaress)
■ TWAMP probe and responder
■ Scheduling Reboot
■
Support CPU, Memory, Temperature, FAN and Bandwidth Monitoring
■ Link Aggregation:
Static Trunk
IEEE 802.3ad Link Aggregation Control Protocol
Comply to 802.1ax standard
Trunk groups: 16, up to 8 GE ports per group
Load Balancing: SA+DA, SA, DA, SIP+DIP, SIP, DIP
LACP Backup mode: To maintain active and backup link for
redundancy purpose
■ Support Smart Pair Uplink Redundancy (<50ms)
■ IGMP Snooping:
Support 1000 IGMP Group
IGMP v1/v2/v3 snooping
IGMP Proxy reporting
IGMP Filtering
IGMP Throttling
IGMP Immediate Leave
IGMP Querier
IGMP mrouter-forward mode
IGMP router-alert-option-check
IGMP router-port-expire-time
IGMP tcn-flood
■ MVR (Multicast VLAN Registration): Supports 5 multicast VLANs
■ Port mirroring (many source ports to one destination port. One
source port to one destination port only)
■ Remote port mirror (RSPAN)
Security
■ User Security for Enterprise:
IEEE 802.1X port based and MAC based authentication
Dynamic VLAN Assignment, Auto QoS
MAC authentication
Web authentication
Voice VLAN
Guest VLAN
■ User Security for ISP/MSO:
L2/L3/L4 Access Control List
MAC Access control list (Source/Destination MAC, Ether type,
Priority ID/VLAN ID)
Support per port MAC Access List
IP standard access control list (Source IP)
IP extended access control list (Source/Destination IP, Protocol,
TCP/UDP port number)
DHCP Snooping (DHCP Filtering)
DHCP Option 82
Support modify Interface type for information option TR101 format
DHCP Option 82 Relay
IP Source Guard
■ Network Security:
IPv6 ACL
Port security
Sticky MAC
PPPoE IA
PPPoE 7 Parameter Supported
Hostname_Rack/Frame/Shelf/Slot:port_Svlan:Cvlan
IPoE 7 Parameter Supported
Hostname_Rack/Frame/Shelf/Slot:port_Svlan:Cvlan
Support modify Interface type and keep vendor tag
Dynamic ARP Inspection
CPU guard
CPU/Memory threshold and alarm
Denial of Service protection
echo-chargen
smurf
tcp-flooding
tcp-null-scan
tcp-syn-fin-scan
tcp-xmas-scan
udp-flooding
win-nuke