
A significant additional feature of the N-Series is the capability to
supportMulti-UserAuthentication,thismeansthatmultipleusers/
devices can be connected to the same physical port, and that each one
can be authenticated individually using one of the multi-method options
(802.1x,MAC,orPWA).
Thevalueexistsintheabilitytoauthorizemultipleusers,eitherusing
dynamicpolicyorVLANassignmentforeachauthenticateduser.Inthe
caseofdynamicpolicy,thisiscalledMulti-UserPolicy.
Multi-userportcapacitieswiththeN-Seriesaredeterminedonaper
port,perDFE,andpermulti-slotsystembasis.DefaultPlatinumDFE
capacities are as follows:
Perport:8-128
Perblade(DFE):1024
Perchassis:1024
Itispossibletoincreasethesecapacitiesbypurchasingadditional
licences. The N-EOS-PPC license increases user port capacity on a per
DFEbasisfromthedefaultcapacityof8-128toamaximumof1024.
Whenpresent,theN-EOS-PUCupgradelicensesetsthechassiscapacity
at2048userspersystem,thisvaluecanbeoverriddenusingaCLI
commandsettingthemaximumof2048users/port.N-EOS-PPCand
N-EOS-PUCarenotavailableforGoldDFEsandareanoptionalpurchase
forPlatinumDFEs.DiamondDFEsincludeN-EOS-PPC.
Muti-userauthenticationandpolicycanprovidesignicantbenetsto
customersbyextendingsecurityservicestousersanddevicesconnected
to unmanaged devices, third party switches/routers, VPN concentrators,
orwirelessLANaccesspointsattheedgeoftheirnetwork.Security,
priority,andbandwidthcontrolareenhancedwhileprotectingexisting
network investments.
Dynamic, Flow-Based Packet Classification
Another unique feature that separates the N-Series from all competitive
switchesisthecapabilitytoprovideUser-BasedMulti-layerPacket
Classication/QoS.Withthewidearrayofnetworkapplicationsusedon
networkstoday,traditionalMulti-layerPacketClassicationbyitselfisnot
enough to guarantee the timely transport of business-critical applications.
IntheN-Series,User-BasedMulti-layerPacketClassicationallows
traffic classification not just by packet type, but also by the role of the
useronthenetworkandtheassignedpolicyofthatuser.WithUser-
BasedMulti-layerPacketClassication,packetscanbeclassied
basedonuniqueidentierslike“AllUsers”,“UserGroups”,and
“IndividualUser”,thusensuringamoregranularapproachtomanaging
and maintaining network confidentiality, integrity, and availability.
Layer 2
• MAC Address
• EtherType (IP, IPX, AppleTalk, etc.)
Layer 3
• IP Address
• IP Protocol (TCP, UDP, etc.)
• ToS
Layer 4
• TCP/UDP port (HTTP, SAP,
Kazza, etc.)
SwitchPortVLANUserFlow
Deny
Priority/QoS
Rate Limit
Permit
Contain
N-Series
Access Control
Class of Service
User-Based Multi-layer Packet Classification/QoS
Integrated Services Design
IntegratedServicesDesignisakeydifferentiatorthatseparatesthe
N-SeriesDFEfromthecompetition.IntegratedServicesDesignreduces
the number and type of modules required to build typical wiring closet
congurations,simplifyingtheoverallnetworkdesign.Inturn,this
signicantlyreducesthemaintenanceandsparingcostaseachDFEcan
perform all of these services unlike competitive offerings which have a
plethora of different line cards required in order to provide similar services.
Per DFE Integrated Services Design
Multi-layer packet classification - enables the delivery of critical
applications to specific users via traffic awareness and control
• User,Port,andDeviceLevel(Layer2through4packetclassication)
• QoSmappingtopriorityqueues(802.1p&IPToS/DSCP)upto16
queues per port
• Multiplequeuingmechanisms(WFQ,WRR,etc.)
• GranularQoS/ratelimiting
• VLAN-to-policymapping
Switching/VLAN services - provides high-performance connectivity,
aggregation, and rapid recovery services
• Extensiveindustrystandardscompliance(IEEEandIETF)
• Inboundandoutboundbandwidthratecontrolperow
• VLANservicessupport
−Linkaggregation(IEEE802.3ad),32trunksperN-Serieswithno
limittothenumberofportspertrunk;trunkscanspanDFEs
−Multiplespanningtrees(IEEE802.1s)
−Rapidrecongurationofspanningtree(IEEE802.1w)
•Flowsetupthrottling
Feature Summary
Page 5
Comentarios a estos manuales