conjunction with a RADIUS server
Web-based authentication
Web-based authenticationWeb-based authentication
Web-based authentication
: similar to IEEE 802.1X, provides a browser-based environment to authenticate clients that
do not support the IEEE 802.1X supplicant
MAC-based authentication
MAC-based authenticationMAC-based authentication
MAC-based authentication
: client is authenticated with the RADIUS server based on the client's MAC address
Authentication flexibility
Authentication flexibilityAuthentication flexibility
Authentication flexibility
:
Multiple IEEE 802.1X users per port
Multiple IEEE 802.1X users per portMultiple IEEE 802.1X users per port
Multiple IEEE 802.1X users per port
: provides authentication of up to eight IEEE 802.1X users per port; prevents user
"piggybacking" on another user's IEEE 802.1X authentication
Dynamic ARP protection
Dynamic ARP protectionDynamic ARP protection
Dynamic ARP protection
: blocks ARP broadcasts from unauthorized hosts, preventing eavesdropping or theft of network data
Port security
Port securityPort security
Port security
: allows access only to specified MAC addresses, which can be learned or specified by the administrator
MAC address lockout
MAC address lockoutMAC address lockout
MAC address lockout
: prevents configured particular MAC addresses from connecting to the network
Secure FTP
Secure FTPSecure FTP
Secure FTP
: allows secure file transfer to/from the switch; protects against unwanted file downloads or unauthorized copying
of switch configuration file
RADIUS/TACACS+
RADIUS/TACACS+RADIUS/TACACS+
RADIUS/TACACS+
: eases switch management security administration by using a password authentication server
Source-port filtering
Source-port filteringSource-port filtering
Source-port filtering
: allows only specified ports to communicate with each other
Secure Shell
Secure ShellSecure Shell
Secure Shell
(SSHv2): encrypts all transmitted data for secure, remote command-line interface (CLI) access over IP networks
Secure Sockets Layer
Secure Sockets LayerSecure Sockets Layer
Secure Sockets Layer
(SSL): encrypts all HTTP traffic, allowing secure access to the browser-based management GUI in the
switch
Switch management logon security
Switch management logon securitySwitch management logon security
Switch management logon security
: can require either RADIUS or TACACS+ authentication for secure switch CLI logon
Custom banner
Custom bannerCustom banner
Custom banner
: displays security policy when users log in to the switch
STP BPDU port protection
STP BPDU port protectionSTP BPDU port protection
STP BPDU port protection
: blocks Bridge Protocol Data Units (BPDUs) on ports that do not require BPDUs, preventing forged
BPDU attacks
Convergence
ConvergenceConvergence
Convergence
IP multicast
IP multicast IP multicast
IP multicast
(data-driven IGMPv3): Automatically prevents flooding of IP multicast traffic
IEEE 802.1AB Link Layer Discovery Protocol
IEEE 802.1AB Link Layer Discovery Protocol IEEE 802.1AB Link Layer Discovery Protocol
IEEE 802.1AB Link Layer Discovery Protocol
(LLDP): Automated device discovery protocol for easy mapping by network
management applications
LLDP-MED
LLDP-MED LLDP-MED
LLDP-MED
(Media Endpoint Discovery): A standard extension of LLDP that stores values for parameters such as QoS and
VLAN to automatically configure network devices such as IP phones
Quality of Service (QoS)
Quality of Service (QoS)Quality of Service (QoS)
Quality of Service (QoS)
Traffic prioritization
Traffic prioritization Traffic prioritization
Traffic prioritization
(IEEE 802.1p): allows real-time traffic classification into 8 priority levels mapped to 8 queues
Class of Service
Class of ServiceClass of Service
Class of Service
(CoS): sets the IEEE 802.1p priority tag based on IP address, IP Type of Service (ToS), L3 protocol, TCP/UDP
port number, source port, and DiffServ
Layer 4 prioritization
Layer 4 prioritizationLayer 4 prioritization
Layer 4 prioritization
: Enables prioritization based on TCP/UDP port numbers
Manageability
ManageabilityManageability
Manageability
sFlow
sFlow sFlow
sFlow
(RFC 3176): Wire-speed traffic accounting and monitoring
RMON and XRMON
RMON and XRMONRMON and XRMON
RMON and XRMON
: Provide advanced monitoring and reporting capabilities for statistics, history, alarms, and events
Dual flash images
Dual flash imagesDual flash images
Dual flash images
: Provides independent primary and secondary operating system files for backup while upgrading
Multiple configuration files
Multiple configuration filesMultiple configuration files
Multiple configuration files
: allows a config file to be stored to flash image
Friendly port names
Friendly port namesFriendly port names
Friendly port names
: Allow assignment of descriptive names to ports
Stacking capability
Stacking capabilityStacking capability
Stacking capability
: single IP address management for a virtual stack of up to 16 switches, including the HP ProCurve Switch
2500 Series, 2510 Series, 2600 Series, 2800 Series, 2810 Series, 2900 Series, 3400cl Series, 3500yl Series, 4200vl Series,
6108, 6200yl-24G-mGBIC, and 6400cl Series
Find-Fix-and-Inform
Find-Fix-and-InformFind-Fix-and-Inform
Find-Fix-and-Inform
: Finds and fixes common network problems automatically, then informs administrator
Software updates
Software updatesSoftware updates
Software updates
: Free downloads from the Web
Troubleshooting
TroubleshootingTroubleshooting
Troubleshooting
: Ingress/egress port monitoring enables network problem-solving
QuickSpecs
HP ProCurve Switch 4200vl Series
HP ProCurve Switch 4200vl SeriesHP ProCurve Switch 4200vl Series
HP ProCurve Switch 4200vl Series
Overview
DA - 12435 Worldwide — Version 8 — August 20, 2009
Page 3