5400R ZL2 Switch Series Data Sheet

DATA SHEET
ARUBA 5400R ZL2 SWITCH SERIES
• MAC address lockout prevents particular congured MAC
addresses from connecting to the network
• Source-port ltering allows only specied ports to
communicate with each other
• RADIUS/TACACS+ eases switch management security
administration by using a password authentication server
• Secure shell encrypts all transmitted data for secure
remote CLI access over IP networks
• Secure Sockets Layer (SSL) encrypts all HTTP trac,
allowing secure access to the browser-based management
GUI in the switch
• Secure FTP allows secure le transfer to and from the
switch; protects against unwanted le downloads or
unauthorized copying of a switch conguration le
• Open Authentication Role simplies rst-time deployment
of AAA in browneld deployments by allowing full network
access for failed clients and provides instant connectivity
as soon as a client is plugged-in
• Critical Authentication Role ensures that important
infrastructure devices such as IP phones are allowed
network access even in the absence of a RADIUS server
• MAC Pinning allows non-chatty legacy devices to stay
authenticated by pinning client MAC addresses to the port
until the clients logo or get disconnected
• Management Interface Wizard helps secure management
interfaces such as SNMP, telnet, SSH, SSL, Web, and USB at
the desired level
• Switch management logon security helps secure switch
CLI logon by optionally requiring either RADIUS or
TACACS+ authentication
• Security banner displays a customized security policy when
users log in to the switch
• IEEE 802.1AE MACsec provides security on a link between
two switch ports (1Gbps or 10Gbps) using standard
encryption and authentication (requires v3 modules)
Convergence
• IP multicast routing includes PIM Sparse and Dense modes
to route IP multicast trac
• IP multicast snooping (data-driven IGMP) prevents ooding
of IP multicast trac
• Protocol Independent Multicast for IPv6 supports one-to-
many and many-to-many media casting use cases such as
IPTV over IPv6 networks
• LLDP-MED (Media Endpoint Discovery) denes a standard
extension of LLDP that stores values for parameters such
as QoS and VLAN to automatically congure network
devices such as IP phones
• PoE allocations supports multiple methods (automatic,
IEEE 802.3af class, LLDP-MED, or user-specied) to allocate
PoE power for more ecient energy savings
• Auto VLAN conguration for voice
- RADIUS VLAN uses a standard RADIUS attribute and LLDP-
MED to automatically congure a VLAN for IP phones
- CDPv2 uses CDPv2 to congure legacy IP phones
• Local MAC Authentication assigns attributes such as VLAN
and QoS using locally congured prole that can be a list
of MAC prexes
Warranty and support
• Limited Lifetime Warranty
See www.hpe.com/networking/warrantysummary for
warranty and support information included with your
product purchase.
• Software releases to nd software for your product, refer
to www.hpe.com/networking/support; for details on the
software releases available with your product purchase,
refer to www.hpe.com/networking/warrantysummary