Cisco EtherSwitch Service Modules Feature Guide
Information About the Cisco EtherSwitch Service Modules
•Kerberos security system to authenticate requests for network resources by using a trusted third party (requires the cryptographic versions of the Cisco EtherSwitch service module software image)
•802.1Q tunneling to allow customers with users at remote sites across a service provider network to keep VLANs segregated from other customers, and Layer 2 protocol tunneling to ensure that the customer network has complete STP, CDP, and VTP information about all users (available on the Cisco EtherSwitch service module but not on the integrated services router [ISR])
QoS and CoS Features
•Automatic QoS
•
•Classification
–Classification on a physical interface or on a
–IP
–IP ToS/DSCP and 802.1p CoS marking based on
–Trusted port states (CoS, DSCP, and IP precedence) within a QoS domain and with a port bordering another QoS domain.
–Trusted boundary for detecting the presence of a Cisco IP phone, trusting the CoS value received, and ensuring port security.
•Policing
–Policing on a physical interface or on a
–
–Aggregate policing for policing traffic flows in aggregate to restrict specific applications or traffic flows to metered, predefined rates.
•
•Ingress queueing and scheduling
–Two configurable ingress queues for user traffic (one queue can be the priority queue).
–Weighted tail drop (WTD) as the
–Shaped round robin (SRR) as the scheduling service for specifying the rate at which packets are dequeued to the stack internal ring (sharing is the only supported mode on ingress queues).
Cisco IOS Release 12.2(25)SEC
10