Other Content
6
• Access control lists (ACLs)
Provide IP L3 ltering, based on the source/destination IP address/subnet and source/
destination TCP/UDP port number
• Source-port ltering
Allows only specied ports to communicate with each other
• RADIUS/TACACS+
Eases switch management security administration by using a password authentication server
• IEEE 802.1X, MAC, or Web authentication
Provides concurrent network access control and Web authentication of up to 24 clients per
port
• Secure shell (SSH)
Encrypts all transmitted data for secure remote CLI access over IP networks
• Secure sockets layer (SSL)
Encrypts all HTTP trac, allowing secure access to the browser-based management GUI in the
switch
• Port security
Allows access only to specied MAC addresses, which can be learned or specied by the
administrator
• MAC address lockout
Helps prevent certain congured MAC addresses from connecting to the network
• Secure FTP
Allows secure le transfer to and from the switch; and protects against unwanted le
downloads or unauthorized copying of a switch conguration le
• Switch management logon security
Helps secure switch CLI logon by optionally requiring either RADIUS or TACACS+ authentication
• Custom banner
Displays the security policy when users log in to the switch
• STP bridge protocol data units (BPDUs) port protection
Blocks BPDUs on ports that do not require BPDUs, mitigating forged BPDU attacks
Data sheet | HP 2920 Switch Series










