Product Data Sheet / Brochure

GARP VLAN Registration Protocol
allows automatic learning and dynamic assignment of VLANs
Per-VLAN Spanning Tree Plus (PVST+)
allows each VLAN to build a separate spanning tree to improve link bandwidth usage in network environments with multiple
VLANs
Security
Access control lists (ACLs)
accommodates IPv4/IPv6 port and VLAN-based ACLs (IPv6 ACL is supported only on Gigabit Ethernet and 48-port models)
Source-port filtering
allows only specified ports to communicate with each other
RADIUS/TACACS+
eases switch management security administration by using a password authentication server
Secure Sockets Layer (SSL)
encrypts all HTTP traffic, allowing secure access to the browser-based management GUI in the switch
Port security
allows access only to specified MAC addresses, which can be learned or specified by the administrator
MAC address lockout
prevents particular configured MAC addresses from connecting to the network
Multiple user authentication methods
IEEE 802.1X
uses an IEEE 802.1X supplicant on the client in conjunction with a RADIUS server to authenticate in accordance with
industry standards
Web-based authentication
provides a browser-based environment, similar to IEEE 802.1X, to authenticate clients that do not support the IEEE
802.1X supplicant
MAC-based authentication
authenticates the client with the RADIUS server based on the client's MAC address
Secure shell (SSHv2; client and server)
encrypts all transmitted data for secure, remote CLI access over IP networks
Secure shell
encrypts all transmitted data for secure remote CLI access over IP networks
STP BPDU port protection
blocks Bridge Protocol Data Units (BPDUs) on ports that do not require BPDUs, preventing forged BPDU attacks
STP root guard
protects the root bridge from malicious attacks or configuration mistakes
Secure management access
delivers secure encryption of all access methods (CLI, GUI, or MIB) through SSHv2 and SNMPv3
Custom banner
displays security policy when users log in to the switch
Secure FTP
allows secure file transfer to and from the switch; protects against unwanted file downloads or unauthorized copying of a switch
configuration file
Protected ports CLI
offers intuitive CLI to configure the source-port filters feature by allowing specified ports to be isolated from all other ports on
the switch; the protected port or ports can communicate only with the uplink or shared resources
Authentication flexibility
Multiple IEEE 802.1X users per port
provides authentication for up to eight IEEE 802.1X users per port; prevents a user from "piggybacking" on another user's
QuickSpecs
HP 2530 Switch Series
Overview
DA - 14447 Worldwide — Version 6 — December 9, 2013
Page 4