Features

Comprehensive Support to IPv6

Based on IPv4/IPv6 double stack and IPv6 over IPv4 tunnel(6 to 4 tunnel/ISATAP tunnel/ Automatic IPv4-compatible IPv6 tunnel manually configured tunnel), the H3C S3610 series can support various IPv6 features comprehensively, which makes them adapt well to IPv4-only, IPv6-only, and hybrid networks. This protects customer’s investment in network very well, and makes customer’s network can not only adapt present internet condition, but also meet future internet development requirements.

The S3610 series switches support abundant IPv6 routing protocols, including RIPng, ISISv6, OSPFV3, BGP4+for IPv6, support Neighbor Discovery Protocol (NDP), manage the interactions among neighboring nodes on the same link. Support Path Maximum Transport Unit(PMTU), the mechanism can determine an appropriate MTU for a link from the source node to destination node, this helps to utilize network resources more efficiently and to gain the optimal throughput.

Abundant Qos Policies

The S3610 series switches support powerful ACL features, they can be classified based on the information about the link layer, the network layer, and the transport layer, such as the source MAC, destination MAC, VLAN Tag, VLAN range, IP protocol, IP source address, IP destination address, UDP/TCP port number and etc.

The S3610 series switches support four priority criteria: IP-precedence priority, DSCP priority, 802.1P priority, discard priority.

The S3610 series switches support the queue scheduling algorithms of Strict priority(SP) and Weighted Round Robin(WRR).

The S3610 series switches support diversified flow-based QoS actions, based on the ACL defined, the switches can perform the following QoS actions: traffic mirroring, traffic redirection, rate limit, traffic statistics, and priority marking.

Comprehensive Security

The S3610 series switches support EAD(Endpoint Admission Defense). It enhances the proactive defense capacity of network terminals, and restrains the spread of viruses and worms in a network. Additionally, it disables the access authorities of terminals that fail to meet the security requirements, preventing insecure terminals from endangering the entire network..

The S3610 series switches support ARP detection to guard ARP spoofing launching by hackers or attackers. According the ARP detection function, the switches check the validity of the ARP packets by using the DHCP-Snooping table or the manually configured IP binding table. You can also set trusted ports. ARP packets coming from the trusted ports will not be checked, while those from other ports will be checked through the DHCP-Snooping table or the manually configured IP binding table.

The S3610 series switches support 802.1x authentication to identify users who attempt to access the network. With the 802.1x client version checking function enabled on a switch, the switch checks the version and validity of the 802.1x client running on supplicant systems to prevent those that use earlier versions of 802.1x client or illegal clients from logging in.

The S3610 series switches support Centralized MAC address authentication, it controls accesses to a network through ports and MAC addresses. This kind of authentication requires no client software. When operating in centralized MAC address authentication mode, a switch begins to authenticate the user if it detects a new user MAC address. Further more, the H3C S3610 series can Performe 802.1x authentication and MAC address-based authentication simultaneously.

MAC-IP-port binding allows a device to filter packets and thus enhance security. With MAC-IP-port binding configured, a port checks whether the source MAC and IP addresses of an inbound packet is identical to the configured MAC-to-IP binding on the port. If so, it forwards the packet; otherwise, it discards the packet.

High Reliability

The S3610 series switches support STP/RSTP/MSTP: This feature can be greatly improved to guarantee the network stability by the redundancy back-up and error tolerance capability.

The S3610 series switches support LACP, It is a simple and cheap way to expand the bandwidth of a switch port and balance the traffic among all the ports in a link aggregation. Moreover, it enhances the connection reliability.

The S3610 series switches support VRRP, It is a fault-tolerant protocol that can improve the reliability of the connection between a router and an external network. VRRP ensures reliability by assigning the routers on a LAN segment to a standby group. S3610 series support both VRPP v2 and V3, which are based on IPv4 and IPv6 respectively.

The S3610 series provide two power supply modules, allows for power load balancing and redundant backup.

Superior Manageability and Maintainability

The S3610 series support Simple Network Management Protocol (SNMP) v1/v2/v3 and RMON (Remote Monitoring) v1/2/3/9 groups of MIBs. They can be managed by general network management platform such as H3C iMC network management system.

The S3610 series support HGMP V2 cluster management, After enabling HGMP V2, the network administrator can manage several member switches through one command switch and only the command switch need a public network IP address, it can save public IP address greatly and manage the network more efficiently.

The S3610 series support VCT (Virtual Cable Test) which is convenient for troubleshooting. Customers can start the virtual cable test (VCT) to make the system test the cable connected to the current electrical Ethernet port. The test items include: whether short or open circuit exists in the Rx/Tx direction of the cable, and what is the length of the cable in normal status or the length from the port to the fault point of the cable.

The S3610 series support DLDP (Device Link Detection Protocol), DLDP can detect the link status of the optical fiber cable or copper twisted pair. If DLDP finds a unidirectional link, it disables the related port automatically or informs users to disable it manually depending on specific configuration, to avoid potential network problems.