Switch/Router Features
AAA Client
802.1x RADIUS TACACS+
Layer 2 Protocols
VLAN(802.1q, Port)
Multiple STP (Support Backward Compatibility with STP & RSTP)
Management
SNMP v1/v2/v3, CLI, Telnet, SNTP, TFTP, DHCP, SSHv2
Web-based Device Manager, MINs, Syslog, Diagnostic
Quality of Service
DiffServ, Classification (5-tuple)
Marker/Meter (srTCM/trTCM)
Policing/Shaping
Queuing (CBQ, PQ)
Congestion Avoidance (WRED)
Bandwidth Guarantee, Auto QoS, LF& I
Mapping of IP QoS to Frame Relay, QoS for FR PVC
Routing Protocols
Static Routing, OSPF v1/v2, RIP v1/v2, IGMP v1/v2
PIM-SM, DVMRP
VRRP
Policy-Based Forwarding/Router
WAN Protocols
HDLC, FR/MLFR, PPP/MLPPP, PPP/MLPPP over ISDN PRI
FR Congestion Management and Traffic Policing, DDR (Dial-on Demand Routing)
PPP over Ethernet, PPP over FP, MLPPP over FR, PPP over MFR
Platform Features
DRAM (Default/Max)
512M/1G
Fixed Ethernet Ports
5 (4 10/100Base-T, 1 100M SFP)
Power Supply Slot
Integrated
Power Supply
DC Power Connector
Security
Firewall
Stateful Packet Inspection
NAT (Static, Dynamic, PAT)
SIP ALG, Web ALG, SBC (50 endpoints)
Application Content Filtering: Block Java based on extension, Block URLs based on file extensions, Block ActiveX based on file extensions, FTP's protocol command filtering, SMTP's protocol command filtering, RPC program number filtering
Cyber Defense Engine: Dos/ Ddos, IP Spoofing, IP/ TCP fragment attack protection (Protection for 60+ attacks)
Multiple Security Zone (DMZ)
Scheduling
URL Filtering
Rate limiting: Maximum connections per policy basis, Connection creation rate per policy basis, Bandwidth per policy basis
VPN
H/W acceleration
IPSec for Site to Site, remote Access
IPSec: Protocols: ESP, AH, AH over ESP/ Encryption: DES-CBC, 3DES-CBC, AES-CBC(128, 192, 256)/ Hashing: HMAC-SHA1, HMAC-MD5/ Modes: Tunnel, Transport, Config Mode
IKE: Authentication: Preshared, RSA/DSA Signatures, Xauth/ Modes: Main, Aggressive, Quick/ Diffie-Hellman Group: Group 1 (MODP 768), 2 (MODP 1024), 5 (MODP 1536)/ Encryption: DES, 3DES, AES (128,192,256)/ Hash: SHA1, MD5
L2TP, GRE
PKI Support (SCEP, Manual, CRL, OCSP)
IPSec NAT Traversal