7
•DHCPsnooping
HelpsensurethatDHCPclientsreceiveIPaddressesfromauthorizedDHCPserversand
maintainalistofDHCPentriesfortrustedports;preventsreceptionoffakeIPaddressesand
reducesARPattacks,improvingsecurity
•DHCPv6snooping
EnsuresthatDHCPv6clientsobtainIPv6addressesfromauthorizedDHCPv6serversand
recordIP-to-MACmappingsofDHCPv6clients
•DynamicARPprotection
BlocksARPbroadcastsfromunauthorizedhosts,preventingeavesdroppingortheftof
networkdata
•STProotguard
Protectstherootbridgefrommaliciousattacksorcongurationmistakes
•GuestVLAN
Providesabrowser-basedenvironmenttoauthenticatedclientsthatissimilartoIEEE802.1X
•Portisolation
Protectsandaddsprivacy,andpreventsmaliciousattackersfromobtaininguserinformation
•EndpointAdmissionDefense(EAD)
Providessecuritypoliciestousersaccessinganetwork
•RADIUS/HWTACACS
Easesswitchmanagementsecurityadministrationbyusingapasswordauthenticationserver
•Securemanagementaccess
Deliverssecureencryptionofallaccessmethods(CLI,GUI,orMIB)throughSSHv2andSNMPv3
•UnicastReversePathForwarding(URPF)
Allowsnormalpacketstobeforwardedcorrectly,butdiscardstheattachingpacketduetolack
ofreversepathrouteorincorrectinboundinterface;preventssourcespoonganddistributed
attacks;supportsdistributedUFPF
•IPsourceguard
HelpspreventIPspoongattacks
•IPv6sourceguard
HelppreventIPv6spoongattacksusingNDSnoopingaswellasDHCPv6Snooping
•NDSnooping
AllowsonlypacketswithalegallyobtainedIPv6addresstopass
Virtual private network (VPN)
•GenericRoutingEncapsulation(GRE)
TransportsLayer2connectivityoveraLayer3pathinasecuredway;enablesthesegregation
oftraicfromsitetosite
Datasheet|HP5500HISwitchSeries
Kommentare zu diesen Handbüchern