Product Data Sheet / Brochure

provide filtering based on the IP field, source/destination IP address/subnet, and source/destination TCP/UDP port number on a
per-VLAN or per-port basis
Multiple user authentication methods
IEEE 802.1X users per port
provides authentication of multiple IEEE 802.1X users per port
Web-based authentication
authenticates from a Web browser for clients that do not support IEEE 802.1X supplicant
MAC-based authentication
authenticates client with the RADIUS server based on a client's MAC address
Concurrent IEEE 802.1X, Web, and MAC authentication schemes per port
accepts up to 32 sessions of IEEE 802.1X, Web, and MAC authentications
Virus throttling
detects traffic patterns typical of worm-type viruses and either throttles or entirely prevents the virus from spreading across the
routed VLANs or bridged interfaces without requiring external appliances
DHCP protection
blocks DHCP packets from unauthorized DHCP servers, preventing denial-of-service attacks
Secure management access
securely encrypts all access methods (CLI, GUI, or MIB) through SSHv2, SSL, and/or SNMPv3
Management Interface Wizard
helps secure management interfaces such as SNMP, telnet, SSH, SSL, Web, and USB at the desired level
Switch CPU protection
provides automatic protection against malicious network traffic trying to shut down the switch
ICMP throttling
defeats ICMP denial-of-service attacks by enabling any switch port to automatically throttle ICMP traffic
Identity-driven ACL
enables implementation of a highly granular and flexible access security policy and VLAN assignment specific to each
authenticated network user
STP BPDU port protection
blocks Bridge Protocol Data Units (BPDUs) on ports that do not require BPDUs, preventing forged BPDU attacks
Dynamic IP lockdown
works with DHCP protection to block traffic from unauthorized hosts, preventing IP source address spoofing
Dynamic ARP protection
blocks ARP broadcasts from unauthorized hosts, preventing eavesdropping or theft of network data
Detection of malicious attacks
monitors 10 types of network traffic and sends a warning when an anomaly that potentially can be caused by malicious attacks
is detected
Port security
allows access only to specified MAC addresses, which can be learned or specified by the administrator
MAC address lockout
prevents particular configured MAC addresses from connecting to the network
Source-port filtering
allows only specified ports to communicate with each other
RADIUS/TACACS+
eases switch management security administration by using a password authentication server
Secure Shell
encrypts all transmitted data for secure remote CLI access over IP networks
Secure Sockets Layer (SSL)
encrypts all HTTP traffic, allowing secure access to the browser-based management GUI in the switch
Secure FTP
allows secure file transfer to and from the switch; protects against unwanted file downloads or unauthorized copying of a switch
QuickSpecs
HP 8200 zl Switch Series
Overview
DA - 12862 Worldwide — Version 38 — February 17, 2014
Page 9