LightningEdge® Service Delivery Switch Family
Advanced Security
Every Service Delivery Switch from World Wide Packets delivers an advanced set of security features to protect the CPE and concentration points of the network and to be fully interoperable with security protocols in the core of the network. LE-3xx Service Delivery Switches implement security tools at the access point of the network, including user authentication and dynamic policy-based network access solutions. Advanced authentication protocols, such as IEEE 802.1x Port-based Network Access Control, are based on password encryption and can be authenticated through a RADIUS server for comprehensive network-wide security coordination. Policy-based network access implements advanced Service Access Control that can be configured with dynamic or static access control lists. Service Delivery Switches also support both ingress and egress port filtering and Layer 2 + Layer 4 protocol filtering, as well as SSH2 for an encrypted management channel when connecting systems over an insecure network such as the Internet.
Security features supported in the Service Delivery Switch Family include:
- Security features operate at full line rate
- SSH File Transfer Protocol (SFTP) for secure file transfer
- VLAN ingress filtering prevents VLAN leakage
- Egress port restriction eliminates customer cross-talk over a shared distribution infrastructure
- Dynamic and static Service Access Control (Access Control Lists)
- User authentication
• Local or RADIUS authentication
• MD5 encryption of passwords
• 3 levels of privilege (Limited, Super, Diagnostic) - Ingress Protocol Filtering
• MAC address types
• TCP/UDP ports
• IP protocols
• User defined filters
• Per-port per-VLAN - Broadcast Containment and Unknown Multicast Filtering (UMF) prevents broadcast and multicast Denial of Service (DoS) attacks
