Data Sheet
SECURITY
NetworkStormProtection,DoS
Broadcast,Unicast,MulticastDoSProtection
DenialofServiceProtection(controlplane)
DenialofServiceProtection(dataplane)
Yes
Yes
Yes
SwitchCPUprotection
SwitchTracprotection
DoSAttacksProtection SIPDIP
SMACDMAC
FIRSTFRAG
TCPFRAG
TCPFLAG
TCPPORT
UDPPORT
TCPFLAGSEQ
TCPOFFSET
TCPSYN
TCPSYNFIN
TCPFINURGPSH
L4PORT
ICMP
ICMPV4
ICMPV6
ICMPFRAG
PINGFLOOD
SYNACK
CPURateLimiting Yes
AppliedtoIPv4andIPv6multicastpacketswithunknownL3addresseswhenIP
routing/multicastenabled
ICMPthrottling Yes RestrictICMP,PINGtracforICMP-basedDoSattacks
Management
ManagementACL(MACAL)
MaxRules
Yes
64
ProtectsmanagementCPUaccessthroughtheLAN(inbandmanagement)
OutofbandManagement Yes
In-bandmanagementcanbeshutdownentirelywhenout-of-bandmanagement
network
Radiusaccounting Yes RFC2565andRFC2866
TACACS+ Yes
MaliciousCodeDetection Yes SowareimagelesandCongurationleswithdigitalsignatures
NetworkTrac
AccessControlLists(ACLs) L2/L3/L4 MAC,IPv4,IPv6,TCP,UDP
Time-basedACLs Yes
Protocol-basedACLs Yes
ACLoverVLANs Yes
DynamicACLs Yes
IEEE802.1xRadiusPortAccessAuthentication Yes
Upto48clients(802.1x)perportaresupported,includingtheauthenticationof
theusersdomain
802.1xMACAddressAuthenticationBypass(MAB) Yes
Supplementalauthenticationmechanismfornon-802.1xdevices,basedontheir
MACaddressonly
NetworkAuthenticationSuccessiveTiering Yes
Dot1x->MAP->CaptivePortalsuccessiveauthenticationmethodsbasedon
conguredtime-outs
PortSecurity Ye s
DHCPSnooping YesIPv4/IPv6
DynamicARPInspection YesIPv4
IPv6RAGuardStatelessMode Yes
MACFiltering Yes
PortMACLocking Yes
PrivateEdgeVLAN Yes
Aprotectedportdoesn’tforwardanytrac(unicast,multicast,orbroadcast)toany
otherprotectedport-sameswitch
PrivateVLANs Yes
ScalesPrivateEdgeVLANsbyprovidingLayer2isolationbetweenportsacross
switchesinsameLayer2network
ProSAFE® Intelligent Edge Managed Switches Data Sheet
M4200 series
Page 18 of 31










