M4250 Datasheet
DoS Attacks Protection SIPDIP
SMACDMAC
FIRSTFRAG
TCPFRAG
TCPFLAG
TCPPORT
UDPPORT
TCPFLAGSEQ
TCPOFFSET
TCPSYN
TCPSYNFIN
TCPFINURGPSH
L4PORT
ICMP
ICMPV4
ICMPV6
ICMPFRAG
PINGFLOOD
SYNACK
CPURateLimiting
Yes Applied to IPv4 and IPv6 multicast packets with unknown L3 addresses when IP routing/
multicast enabled
ICMPthrottling YesRestrictICMP,PINGtrafcforICMP-basedDoSattacks
Management
ManagementACL(MACAL)
Max Rules
YesProtectsmanagementCPUaccessthroughtheLAN
64
Out of band Management Yes In-band management can be shut down entirely when out-of-band management network
Radius accounting YesRFC2565andRFC2866
TACACS+ Yes
MaliciousCodeDetection YesSoftwareimagelesandCongurationleswithdigitalsignatures
Network Trafc
AccessControlLists(ACLs) L2/L3/L4MAC,IPv4,IPv6,TCP,UDP
Time-basedACLs Yes
Protocol-basedACLs Yes
ACLoverVLANs Yes
DynamicACLs Yes
IEEE 802.1x Radius Port Access Authentication YesUpto48clients(802.1x)perportaresupported,includingtheauthenticationoftheusersdomain
802.1xMACAddressAuthenticationBypass(MAB) YesSupplementalauthenticationmechanismfornon-802.1xdevices,basedontheirMACaddressonly
Network Authentication Successive Tiering YesDot1x->MAP->CaptivePortalsuccessiveauthenticationmethodsbasedonconguredtime-outs
Port Security Yes
IP Source Guard Yes IPv4 / IPv6
DHCPSnooping Yes IPv4 / IPv6
Dynamic ARP Inspection Yes IPv4 / IPv6
IPv6 RA Guard Stateless Mode Yes
MACFiltering Yes
PortMACLocking Yes
Private Edge VLAN
YesAprotectedportdoesn’tforwardanytrafc(unicast,multicast,orbroadcast)toanyother
protected port - same switch
Private VLANs
Yes Scales Private Edge VLANs by providing Layer 2 isolation between ports across switches in same
Layer 2 network
Quality of Service (QoS) - Summary
Access Lists
L2MAC,L3IPandL4PortACLs
Ingress
Egress
Time-based
802.3ad(LAG)forACLassignment
BindingACLstoVLANs
ACLLogging
Support for IPv6 fields
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
PAGE 28 of 44
AV Line Managed Switches
Datasheet | M4250 series
AV Line Managed Switches










