Cisco 2970G 24TS - Catalyst - Ethernet Switch Bedienungsanleitung Seite 3

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 6
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 2
All contents are Copyright © 1992–2006 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 3 of 6
SECURITY
Q. How does the Cisco Catalyst 2970 Series manage the security needs of a network?
A. With the rise in internal threats to a network, Cisco Ethernet switches enhance data security through numerous features, including
Secure Shell (SSH) Protocol and Simple Network Management Protocol Version 3 (SNMPv3), access control lists (ACLs), 802.1X,
port security, private virtual LAN (VLAN) edge, Dynamic Host Configuration Protocol (DHCP) interface tracker, MAC address
notification, and RADIUS/TACACS+. Depending on your security needs, the Cisco Catalyst 2970 Series complements devices such
as firewalls, VPNs, and intrusion detection systems (IDSs).
Q. For security purposes, how can I protect unauthorized users from accessing my network?
A. The Cisco Catalyst 2970 Series supports 802.1X, which works in conjunction with a RADIUS server to authenticate users as they
access a network. The 802.1X standard is considered port-level security and is commonly used for WLANs. Additionally, portions of
the network can be restricted by using ACLs. Access can be denied based on MAC addresses, IP addresses, or Transmission Control
Protocol/User Datagram Protocol (TCP/UDP) ports. ACL lookups are done in hardware-forwarding and routing performance is not
compromised when implementing ACL-based security. Port security is an additional protection method, which ensures that the
appropriate user is on the network by limiting access to the port based on MAC addresses.
Q. For security purposes, how can I monitor or track activities in my network?
A. IDSs are tailored to monitor and track activities in a network. The Cisco Catalyst 2970 Series can complement this through features
such as MAC address notification, which will send an alert to a management station so that network administrators know when and
where users came on to the network and can take appropriate actions. The DHCP Interface Tracker (Option 82) feature will track
where a user is physically connected on a network by providing both switch and port ID to a DHCP server.
Q. For security purposes, how do I protect administration passwords and traffic going to the switch during configuration or
troubleshooting?
A. To protect administration traffic during the configuration or troubleshooting of a switch (such as passwords or device configuration
settings), the best approach is to encrypt the data. Both SSH and SNMPv3 provide encryption of data during Telnet and SNMP sessions.
NETWORK MANAGEMENT
Q. Do Cisco Catalyst 2970 Series Switches support Cisco Switch Clustering technology?
A. Yes, they can be managed using the Cisco Network Assistant software, which uses Cisco Switch Clustering technology. Cisco
Network Assistant is a PC-based network management application optimized for LANs of small and medium-sized businesses with up
to 250 users. Cisco Network Assistant offers centralized management of Cisco switches, routers, and WLAN access points. It supports
a wide range of Cisco Catalyst Intelligent Ethernet switches. Through a user-friendly GUI, users can configure and manage a wide
array of switch functions and start the device manager of Cisco routers and Cisco wireless access points. Cisco Network Assistant is
available at no cost and can be downloaded from Cisco.com.
Cisco Network Assistant provides an integrated management interface for delivering intelligent services, enabling users to manage
their entire LAN with one robust tool. By bringing the simplicity of traditional LAN switching to intelligent services such as
multilayer switching, QoS, multicast, and security ACLs, Cisco Network Assistant offers administrators benefits formerly reserved for
only the most complex networks. The Guide mode in Cisco Network Assistant leads you through the configuration of high-end
features and provides enhanced online help for context-sensitive assistance. In addition, a solution wizard provides automated
configuration of the switch for video streaming or videoconferencing.
Cisco Network Assistant supports standards-based connectivity options such as Ethernet, Fast Ethernet, Cisco Fast EtherChannel®
technology, Gigabit Ethernet, and Gigabit EtherChannel connectivity. Because Cisco Switch Clustering technology is not limited by
proprietary stacking modules, stacking cables, or interconnection media, Cisco Network Assistant expands the traditional cluster
Seitenansicht 2
1 2 3 4 5 6

Kommentare zu diesen Handbüchern

Keine Kommentare