Product Datasheet
Systemdefaultsautomaticallysetper-portbroadcast,multicast,andunicaststormcontrolfortypical,robustprotectionagainstDoSattacksandfaultyclientswhich
can,withBYOD,oencreatenetworkandperformanceissues
IPTelephonyadministrationissimpliedwithconsistentVoiceVLANcapabilitiespertheindustrystandardsandautomaticfunctionsassociated
Comprehensivesetof"systemutilities"and"Clear"commandshelptroubleshootconnectivityissuesandrestorevariouscongurationstotheirfactorydefaultsfor
maximumadmineciency:traceroute(todiscovertheroutesthatpacketsactuallytakewhentravelingonahop-by-hopbasisandwithasynchronousresponsewhen
initiatedfromtheCLI),cleardynamicallylearnedMACaddresses,counters,IGMPsnoopingtableentriesfromtheMulticastforwardingdatabaseetc...
Allmajorcentralizedsowaredistributionplatformsaresupportedforcentralsowareupgradesandcongurationlesmanagement(HTTP,TFTP),includinginhighly
securedversions(HTTPS,SFTP,SCP)
SimpleNetworkTimeProtocol(SNTP)canbeusedtosynchronizenetworkresourcesandforadaptationofNTP,andcanprovidesynchronizednetworktimestamp
eitherinbroadcastorunicastmode(SNTPclientimplementedoverUDP-port123)
EmbeddedRMON(4groups)andsFlowagentspermitexternalnetworktracanalysis
Remotemirroring(RSPAN)cantransportpacketscapturedonaninterfaceonasourceswitchacrossthenetworktoadestinationonapossiblydierentdestination
switch
Engineered for convergence
Audio(VoiceoverIP)andVideo(multicasting)comprehensiveswitching,ltering,routingandprioritization
Auto-VoIP,VoiceVLANandLLDP-MEDsupportforIPphonesQoSandVLANconguration
IGMPSnoopingandProxyforIPv4,MLDSnoopingandProxyforIPv6andQueriermodefacilitatefastreceiversjoinsandleavesformulticaststreamsandensuremulti-
cast trac only reaches interested receivers everywhere in a Layer 2 or a Layer 3 network
MulticastVLANRegistration(MVR)usesadedicatedMulticastVLANtoforwardmulticaststreamsandavoidduplicationforclientsindierentVLANs
Multicastrouting(PIM-SMandPIM-DM,bothIPv4
andIPv6)ensuremulticaststreamscanreachreceivers
in dierent L3 subnets
• Multicast static routes
• Multicastdynamicrouting(PIMassociatedwithOSPF)includingPIMmulti-hopRPsupportforrouting
around damage advanced capabilities
PoE power management and schedule enablement
Powerredundancyforhigheravailabilitywhenmissioncriticalconvergentinstallation,includinghot-swapmainPSUreplacementwithoutinterruption
Enterprise security
TraccontrolMACFilterandPortSecurityhelprestrictthetracallowedintoandoutofspeciedportsorinterfacesinthesysteminordertoincreaseoverallsecurity
and block MAC address flooding issues
DHCPSnoopingmonitorsDHCPtracbetweenDHCPclientsandDHCPserverstolterharmfulDHCPmessageandbuildsabindingsdatabaseof(MACaddress,IP
address,VLANID,port)tuplesthatareconsideredauthorizedinordertopreventDHCPserverspoongattacks
IPsourceguardandDynamicARPInspectionusetheDHCPsnoopingbindingsdatabaseperportandperVLANtodropincomingpacketsthatdonotmatchanybinding
andtoenforcesourceIP/MACaddressesformalicioususerstracelimination
Time-basedLayer2/Layer3-v4/Layer3-v6/Layer4AccessControlLists(ACLs)canbebindedtoports,Layer2interfaces,VLANsandLAGs(LinkAggregation
GroupsorPortchannel)forfastunauthorizeddatapreventionandrightgranularity
ACLsonCPUinterface(ControlPlaneACLs)areusedtodenetheIP/MACorprotocolthroughwhichmanagementaccessisallowedforincreasedHTTP/HTTPSor
Telnet/SSHmanagementsecurity
Bridgeprotocoldataunit(BPDU)GuardallowsthenetworkadministratortoenforcetheSpanningTree(STP)domainbordersandkeeptheactivetopologyconsistent
andpredictable-unauthorizeddevicesorswitchesbehindtheedgeportsthathaveBPDUenabledwillnotbeabletoinuencetheoverallSTPtopologybycreating
loops
SpanningTreeRootGuard(STRG)enforcestheLayer2networktopologybypreventingroguerootbridgespotentialissueswhenforinstance,unauthorizedor
unexpected new equipment in the network may accidentally become a root bridge for a given VLAN
Dynamic802.1xVLANassignmentmode,including
DynamicVLANcreationmodeandGuestVLAN/
UnauthenticatedVLANaresupportedforrigoroususer
andequipmentRADIUSpolicyserverenforcement
• Upto48clients(802.1x)perportaresupported,includingtheauthenticationoftheusersdomain,in
ordertofacilitateconvergentdeployments:forinstancewhenIPphonesconnectPCsontheirbridge,IP
phones and PCs can authenticate on the same switch port but under dierent VLAN assignment policies
(VoiceVLANversusdataVLAN)
ProSAFE® Next-Gen Edge Managed Switches Data Sheet
M5300 series
Page 8 of 38










