User`s guide
XSR User’s Guide 3
Chapter 1
Overview
Quality of Service - The XSR provides traffic classification using IP
Precedence and DSCP bits, bandwidth control via metered, policed
and prioritized traffic queues, and queue management utilizing Drop
Tail and Random Early Detection (RED).
Virtual Private Network - The XSR supports VPN tunnels using L2TP,
PPP or IPSec protected by DES, 3DES, RC4, MD5 or SHA-1
encryption. VPN tunnels are authenticated/authorized for
credentials using pre-shared keys or Public Key Infrastructure (PKI).
Also supported: DF Bit override, OSPF over VPN, and interaction
between firewall/NAT/VPN.
Security - In its firewall feature set, the XSR provides stateful firewall
protection against a variety of Denial of Service attacks, FTP and
H.323 ALG support, application command filtering for FTP, SMTP
and HTTP, firewall logging and authentication, and supports Access
Control Lists to manage network access. Also supported: AAA for
firewall, Console/Telnet and SSHv2 users.
Dialer Interface - Dial Services are a cost-saving alternative to the
leased line connection between two peers and they can be
implemented for different types of media for both inbound and
outbound connections.
Dial Backup - The dialed backup feature provides a backup link over a
dial line. The backup link is brought up when a failure occurs in a
primary link, and it is brought down when the primary link is
restored. This feature is supported for PPPoE to enable cable backup
over FastEthernet/GigabitEthernet sub-interfaces.
ISDN - The XSR’s BRI and PRI switched and leased lines set up and
tear down calls, usually under the control of the Dialer. The XSR’s
ISDN services BRI and PRI lines with a 1, 2 or 4 port Channelized
NIM card for PRI lines, 1 or 2 port BRI-S/T NIM card, or 1 or 2 port
BRI U NIM card. Also supported: bandwidth optimization through
DoD, BoD and BAP, security through caller ID, call monitoring, and
ISDN callback.