The
The
TE CHN I CAL | SPECIFICAT | IONS |
Performanc e and capaci ty
•
•Remote APs: Up to 8,192
•Users: Up to 32,768
•MAC addresses: Up to 256,000
•VLAN IP interfaces: 512
•Fast Ethernet ports (10/100): Up to 72
•Gigabit Ethernet ports (GBIC or SFP): Up to 40
•10 Gigabit Ethernet ports (XFP): Up to 8
•Active firewall sessions: Up to 2,097,200
•Concurrent IPSec tunnels: Up to 32,768
•Firewall throughput: Up to 80 Gbps
•Encrypted throughput (3DES): Up to 32 Gbps
•Encrypted throughput
Wireless LAN security and control features
•802.11i security
•802.1X user and machine authentication
•
•Centralized
•802.11iPMK cachingfor fast roamingapplications
•EAP offload for AAA server scalability and survivability
•Stateful 802.1X authenticationfor standaloneAPs
•MAC address, SSID and
•
•
•Secure AP control and management over IPSec or GRE
•
•DistributedWLAN mode for remoteAP deployments
•Simultaneous centralized and distributed WLAN support
Identity-bas ed security features
•Captive portal, 802.1X and MAC address authentication
•Username,IP address,MAC addressand encryption key binding for strong network identity creation
•
•RADIUS and
•Internal user database for AAA server failover protection
•
•Robust policy enforcement with stateful packet inspection
•
•
•Configurable acceptable use policies for guest access
•
•xSec option for wired LAN authentication and encryption(802.1X authentication,
Convergence features
•Voice and data on a single SSID for converged devices
•
•
•Strict priority queuing for
•802.11e support – WMM,
•QoS policing for preventing network abuse via 802.11e
•DiffServ marking and 802.1p support for network QoS
•
•VoIP call admission control (CAC) using VFC
•Call reservation thresholds for mobile VoIP calls
•
•Fast roaming support for ensuring mobile voice quality
•SIP early media and ringing tone generation (RFC 3960)
•
Adaptive radio management (ARM) features
•Automatic channel and power settings for thin APs
•Simultaneousair monitoringand end user services
•
•Dense deploymentoptionsfor capacityoptimization
•AP load balancing based on number of users
•AP load balancing based on bandwidth utilization
•Coverage hole and RF interference detection
•802.11hsupportfor radar detectionand avoidance
•Automated location detection for active RFID tags
•
Wireless intrusion protection features
•Integration with WLAN infrastructure
•Simultaneous or dedicated air monitoring capabilities
•Rogue AP detection and
•Automatic rogue, interfering and valid AP classification
•
•Adhoc WLAN network detection and containment
•Windows client bridging and wireless bridge detection
•Denial of service attack protection for APs and stations
•Misconfigured standalone AP detection and containment
•Third party AP performance monitoring and troubleshooting
•Flexible attack signature creation for new WLAN attacks
•EAP handshake and sequence number analysis
•Valid AP impersonation detection
•Framefloods,FakeAP and Airjackattack detection
•ASLEAP, death broadcast, null probe response detection
•
Stateful firewall features
•Stateful packet inspection tied to user identity or ports
•Location and
•802.11 station awareness for WLAN firewalling
•
•Session mirroring and
2