User Guide

Standards Compatibility
1-6 Introduction
TheSecureNetworksPolicyArchitectureconsistsof3components:ClassificationRules,
NetworkServices,andBehavioralProfiles.Thesearedefinedasfollows:
ClassificationRulesdeterminehowspecifictrafficflows(identifiedbyLayer2,Layer
3,andLayer4informationinthedatapacket)aretreatedbyeachSwitchorRouter.In
general,
ClassificationRulesareappliedtothenetworkinginfrastructureatthe
networkedge/ingresspoint.
•NetworkServicesarelogicalgroupsofClassificationRules thatidentifyspecific
networkedapplicationsorservices.Usersmaybepermittedordeniedaccesstothese
servicesbasedontheirrolewithintheorganization.Priorityandbandwidthrate
limitingmay
alsobecontrolledusingNetworkServices.
•BehavioralProfiles(orroles)areusedtoassignNetworkServicestogroupsofusers
whosharecommonneeds–forexampleExecutiveManagers,HumanResources
Personnel,orGuestUsers.Access,resources,andsecurityrestrictionsareappliedas
appropriatetoeachBehavioralProfile.Avarietyofauthentication
methodsincluding
802.1X,EAPTLS,EAPTTLS,andPEAPmaybeusedtoclassifyandauthorizeeach
individualuser;andtheITAdministratormayalsodefineaBehavioralProfileto
applyintheabsenceofanauthenticationframework.
Standards Compatibility
TheDFE moduleisfullycomplia ntwiththeIEEE802.32002,802.3ae2002,802.3af2003,
802.1D1998,and802.1Q1998standards.TheDFEGoldmoduleprovidesIEEE
802.1D1998SpanningTreeAlgorithm(STA)supporttoenhancetheoverallreliabilityof
thenetworkandprotectagainst“loop”conditions.
LANVIEW Diagnostic LEDs
LANVIEWdiagnosticLEDsserveasanimportanttroubleshootingaidbyprovidingan
easywaytoobservethestatusofindividualportsandoverallnetworkoperations.