Other Content

6
Access control lists (ACLs)
Provide IP L3 ltering, based on the source/destination IP address/subnet and source/
destination TCP/UDP port number
Source-port ltering
Allows only specied ports to communicate with each other
RADIUS/TACACS+
Eases switch management security administration by using a password authentication server
IEEE 802.1X, MAC, or Web authentication
Provides concurrent network access control and Web authentication of up to 24 clients per
port
Secure shell (SSH)
Encrypts all transmitted data for secure remote CLI access over IP networks
Secure sockets layer (SSL)
Encrypts all HTTP trac, allowing secure access to the browser-based management GUI in the
switch
Port security
Allows access only to specied MAC addresses, which can be learned or specied by the
administrator
MAC address lockout
Helps prevent certain congured MAC addresses from connecting to the network
Secure FTP
Allows secure le transfer to and from the switch; and protects against unwanted le
downloads or unauthorized copying of a switch conguration le
Switch management logon security
Helps secure switch CLI logon by optionally requiring either RADIUS or TACACS+ authentication
Custom banner
Displays the security policy when users log in to the switch
STP bridge protocol data units (BPDUs) port protection
Blocks BPDUs on ports that do not require BPDUs, mitigating forged BPDU attacks
Data sheet | HP 2920 Switch Series