The Cisco® Catalyst® 2960-SF Series of Fast Ethernet switches (Figure 1) provides
enterprise-class Layer 2 switching for branch and midsized campus access
applications. They enable reliable and secure business operations and lower total
cost of ownership through a range of innovative features including FlexStack, Power
over Ethernet Plus (PoE+), and Cisco Catalyst SmartOperations.
Cisco Catalyst 2960-SF LAN Base models feature:
Ɣ
2 or 4 Small Form-Factor Pluggable (SFP) uplinks for Gigabit performance and business continuity
Ɣ
24 or 48 Fast Ethernet ports
Ɣ
Cisco FlexStack for simplified management with 20 Gbps of stack throughput, when deployed with the
FlexStack stacking module
Ɣ
IEEE 802.3at-compliant PoE+ for up to 30W of power per port
Ɣ
Models offering 370W or 740W of combined POE/POE+ budget
Ɣ
Enhanced troubleshooting for problem solving, including link connectivity and cable diagnostics
Ɣ
USB storage for file transfers, backups, and simplified operations
Ɣ
Support for Cisco Catalyst SmartOperations features including Smart Install and Auto Smartports
Ɣ
Extended limited lifetime hardware warranty, including next-business-day replacement with 90-day service
and support
Cisco Catalyst 2960-SF LAN Lite models feature:
Ɣ
2 SFP uplinks for Gigabit performance and business continuity
Ɣ
24 or 48 Fast Ethernet ports
Ɣ
Enhanced troubleshooting for problem solving, including link connectivity and cable diagnostics
Ɣ
USB storage for file transfers, backups, and simplified operations
Ɣ
Support for Cisco Catalyst SmartOperations features, including Smart Install and Auto Smartports
Cisco FlexStack and IOS software provide true stacking, with all switches in a stack acting as a single switch unit.
FlexStack provides a unified data plane, unified configuration, and single IP address for switch management. The
advantages of true stacking include lower total cost of ownership through simplified management, and higher
availability. FlexStack supports cross-stack features including EtherChannel, SPAN, and FlexLink.
The FlexStack stack module is hot-swappable and can be added to any Cisco Catalyst 2960-SF switch with LAN
Base software, even while the switch is operating. Switches connected to a stack will upgrade to the correct Cisco
®
IOS
Software version and transparently become a stack member. The FlexStack module also enables mixed
stacking: 2960-SF series switches and 2960-S series switches can be combined in a single stack.
Cisco Catalyst 2960-SF switches support both IEEE 802.3af Power over Ethernet and IEEE 802.3at PoE+, which
provides up to 30W of power per port. The Cisco Catalyst 2960-SF Series Switches lower total cost of ownership
for deployments that incorporate Cisco IP phones, Cisco Aironet® wireless access points, or other standardscompliant PoE/PoE+ end devices. PoE removes the need to supply wall power to PoE-enabled devices and
eliminates the cost of adding electrical cabling and circuits that would otherwise be necessary in IP phone and
WLAN deployments. Table 3 shows the total PoE/PoE+ power available in each 2960-SF model.
Table 3. Switch PoE and PoE+ Power Capacity
Switch Model PoE+ (IEEE 802.3at) Budget
Cisco Catalyst 2960S-48FPS-L 24 ports up to 30W 48 ports up to 15.4W 740W
Cisco Catalyst 2960S-48LPS-L 12 ports up to 30W 24 ports up to 15.4W or
Cisco Catalyst 2960S-F24PS-L 12 ports up to 30W 24 ports up to 15.4W 370W
*
Intelligent power management al l ows fl exible power allocation across all ports.
*
PoE (IEEE 802.3af) Budget* Total PoE/PoE+ Budget*
370W
48 ports up to 7.7W
Cisco EnergyWise
Cisco EnergyWise is an innovative architecture, added to fixed configuration switches, promoting companywide
sustainability by reducing energy consumption across an entire corporate infrastructure and affecting more than
50 percent of global greenhouse gas emissions created by worldwide building infrastructure, a much greater effect
than the 2 percent generated by the IT industry. Cisco EnergyWise enables companies to measure the power
consumption of network infrastructure and network-attached devices and manage power consumption with
specific policies, reducing power consumption to realize increased cost savings, potentially affecting any powered
device.
EnergyWise encompasses a highly intelligent network-based approach to communicate messages that measure
and control energy between network devices and endpoints. The network discovers Cisco EnergyWisemanageable devices, monitors their power consumption, and takes action based on business rules to reduce
power consumption. EnergyWise uses a unique domain-naming system to query and summarize information from
large sets of devices, making it simpler than traditional network management capabilities. Cisco EnergyWise’s
management interfaces allow facilities and network management applications to communicate with endpoints and
each other using the network as a unifying fabric. The management interface uses standard SNMP or TCP to
integrate Cisco and third-party management systems.
Cisco Catalyst SmartOperations
Cisco Catalyst SmartOperations is a comprehensive set of capabilities that simplify LAN planning, deployment,
monitoring, and troubleshooting.
Ɣ
Cisco Smart Install is a transparent plug-and-play technology to configure the Cisco IOS Software image
and switch configuration without user intervention. Smart Install utilizes dynamic IP address allocation and
the assistance of other switches to facilitate installation providing transparent network plug and play.
Ɣ
Cisco Auto Smartports enables automatic configuration of switch ports as devices connect to the switch,
with settings optimized for the device type.
Ɣ
Cisco Smart Troubleshooting is an extensive array of diagnostic commands and system health checks
within the switch, including Smart Call Home.
For more information about Cisco Catalyst SmartOperations, visit http://www.cisco.com/go/smartoperations.
Ease-of-Use Features
Ɣ
Automatic QoS (AutoQoS) simplifies QoS configuration in voice over IP (VoIP) networks by issuing
interface and global switch commands to detect Cisco IP phones, classify traffic, and help enable egress
queue configuration.
Ɣ
Stacking Master configuration management and Cisco FlexStack stacking helps ensure that all switches
are automatically upgraded when the master switch receives a new software version. Automatic software
version checking and updating help ensure that all stack members have the same software version.
Ɣ
Dynamic Host Configuration Protocol (DHCP) autoconfiguration of multiple switches through a boot
server eases switch deployment.
Ɣ
Auto-negotiation on all ports automatically selects half- or full-duplex transmission mode to optimize
bandwidth.
Ɣ
Dynamic Trunking Protocol (DTP) facilitates dynamic trunk configuration across all switch ports.
Ɣ
Port Aggregation Protocol (PAgP) automates the creation of Cisco Fast EtherChannel® groups or Gigabit
EtherChannel groups to link to another switch, router, or server.
Ɣ
Link Aggregation Control Protocol (LACP) allows the creation of Ethernet channeling with devices that
conform to IEEE 802.3ad. This feature is similar to Cisco EtherChannel technology and PAgP.
Ɣ
Automatic media-dependent interface crossover (MDIX) automatically adjusts transmit and receive
pairs if an incorrect cable type (crossover or straight-through) is installed.
Ɣ
Unidirectional Link Detection Protocol (UDLD) and Aggressive UDLD allow unidirectional links caused
by incorrect fiber-optic wiring or port faults to be detected and disabled on fiber-optic interfaces.
Ɣ
Switching Database Manager (SDM) templates for access, routing, and VLAN deployment allow the
administrator to easily maximize memory allocation to the desired features based on deployment-specific
requirements.
Ɣ
Local Proxy Address Resolution Protocol (ARP) works in conjunction with Private VLAN Edge to
minimize broadcasts and maximize available bandwidth.
Ɣ
Internet Group Management Protocol (IGMP) Snooping for IPv4 and IPv6 MLD v1 and v2 Snooping
provide fast client joins and leaves of multicast streams and limit bandwidth-intensive video traffic to only
the requestors.
Ɣ
Multicast VLAN Registration (MVR) continuously sends multicast streams in a multicast VLAN while
isolating the streams from subscriber VLANs for bandwidth and security reasons.
Ɣ
Per-port broadcast, multicast, and unicast storm control prevents faulty end stations from degrading
overall systems performance.
Ɣ
Voice VLAN simplifies telephony installations by keeping voice traffic on a separate VLAN for easier
administration and troubleshooting.
Ɣ
Cisco VLAN Trunking Protocol (VTP) supports dynamic VLANs and dynamic trunk configuration across
all switches.
Ɣ
Remote Switch Port Analyzer (RSPAN) allows administrators to remotely monitor ports in a Layer 2
switch network from any other switch in the same network.
For enhanced traffic management, monitoring, and analysis, the Embedded Remote Monitoring (RMON)
software agent supports four RMON groups (history, statistics, alarms, and events).
Ɣ
Layer 2 traceroute eases troubleshooting by identifying the physical path that a packet takes from source
to destination.
Ɣ
Trivial File Transfer Protocol (TFTP) reduces the cost of administering software upgrades by
downloading from a centralized location.
Ɣ
Network Time Protocol (NTP) provides switches with accurate and consistent time of day.
Network Management
The Cisco Catalyst 2960-SF Series Switches offer a superior CLI for detailed configuration and administration.
2960-SF switches can also be managed with Cisco Network Assistant, a PC-based tool for quick configuration
based on preset templates, or the Cisco Prime™ enterprise network management suite.
Cisco Network Assistant
A PC-based network management application designed for small and medium-sized business (SMB) networks
with up to 250 users, Cisco Network Assistant offers centralized network management and configuration
capabilities. Cisco Network Assistant uses Cisco Smartports technology to simplify both initial deployment and
ongoing maintenance. This application also features an intuitive GUI where users can easily apply common
services across Cisco switches, routers, and access points, such as:
Ɣ
Configuration management
Ɣ
Troubleshooting advice
Ɣ
Inventory reports
Ɣ
Event notification
Ɣ
Network security settings
Ɣ
Password synchronization
Ɣ
Drag-and-drop Cisco IOS Software upgrades
Ɣ
Secure wireless
For detailed information about Cisco Network Assistant, visit http://www.cisco.com/go/cna
Cisco Prime Network Management
Cisco Prime network management solutions provide comprehensive network lifecycle management. Prime
provides an extensive library of easy-to-use features to automate the initial and day-to-day management of your
Cisco network. Cisco Prime integrates hardware and software platform expertise and operational experience into a
powerful set of workflow-driven configuration, monitoring, troubleshooting, reporting, and administrative tools.
Including:
Ɣ
Support for new Cisco hardware platforms the day they ship
Ɣ
Configuration management tools built from Cisco experience and Cisco Validated Design
recommendations
Ɣ
Monitoring and troubleshooting capabilities that incorporates Cisco hardware best practices and
diagnostics features
Automation in managing hardware inventories, security vulnerabilities (PSIRTS) and platform end-of-life
and support cycles
For detailed information about Cisco Prime, visit http://www.cisco.com/go/prime
.
Security Features
The Cisco Catalyst 2960-SF Series Switches provide superior Layer 2 threat defense capabilities for mitigating
man-in-the-middle attacks (such as MAC, IP, and ARP spoofing). TrustSec, a primary element of Borderless
Security Architecture, helps enterprise customers secure their networks, data and resources with policy-based
access control, identity and role-aware networking, pervasive integrity, and confidentiality. Borderless security is
enabled by the following feature sets in the Cisco Catalyst 2960-SF Series Switches:
Ɣ
Threat defense
Ɣ
Cisco TrustSec
Ɣ
Other advanced security features
Threat Defense
Cisco Integrated Security Features is an industry-leading solution available on Cisco Catalyst Switches that
proactively protects your critical network infrastructure. Delivering powerful, easy-to-use tools to effectively prevent
the most common and potentially damaging Layer 2 security threats, Cisco Integrated Security Features provides
robust security throughout the network. Cisco Integrated Security Features include Port Security, DHCP Snooping,
Dynamic ARP Inspection, and IP Source guard.
Ɣ
Port Security secures the access to an access or trunk port based on MAC address. It limits the number of
learned MAC addresses to deny MAC address flooding.
Ɣ
DHCP Snooping prevents malicious users from spoofing a DHCP server and sending out bogus
addresses. This feature is used by other primary security features to prevent a number of other attacks
such as ARP poisoning.
Ɣ
Dynamic ARP Inspection (DAI) helps ensure user integrity by preventing malicious users from exploiting
the insecure nature of the ARP protocol.
Ɣ
IP source guard prevents a malicious user from spoofing or taking over another user’s IP address by
creating a binding table between the client’s IP and MAC address, port, and VLAN.
Cisco TrustSec
TrustSec secures access to the network, enforces security policies, and delivers standard based security solutions
such as 802.1X enabling secure collaboration and policy compliance. TrustSec capabilities reflect Cisco thought
leadership, innovations, and commitment to customer success. These new capabilities include:
Ɣ
Flexible authentication that supports multiple authentication mechanisms including 802.1X, MAC
Authentication Bypass and web authentication using a single, consistent configuration.
Ɣ
Open mode that creates a user friendly environment for 802.1X operations.
Ɣ
Integration of device profiling technology and guest access handling with Cisco switching to
significantly improve security while reducing deployment and operational challenges.
Ɣ
RADIUS Change of Authorization and downloadable calls for comprehensive policy management
capabilities.