spanningtreeoperations;andbroadcast
andmulticastpacketratelimiting.
Additionalsecurityfeaturesincludedynamic
ARPinspection,DHCPsnooping,andIP
sourceguardtoprotectagainstaddress
spoongandman-in-themiddleattacks.
Network Access Control (NAC)
Organizationscanrelyonkeyfeatures
suchasmulti-deviceportauthentication
and802.1Xauthenticationwithdynamic
policyassignmenttocontrolnetworkaccess
andperformtargetedauthorizationona
per-userlevel.Inaddition,theBrocadeFCX
SeriessupportsenhancedMediaAccess
Control(MAC)policieswiththeabilityto
denytrafctoandfromMACaddresseson
aper-VLANbasis.Thispowerfultoolhelps
organizationscontrolaccesspoliciesper
endpointdevice.
Standards-basedNACalsofacilitates
best-in-classsolutionsforauthenticating
networkusersandvalidatingthesecurity
postureofconnectingdevices.Supportfor
policy-controlledMAC-basedVLANsprovides
additionalcontrolofnetworkaccess,
enablingpolicy-controlledassignmentof
devicestoLayer2VLANs.
Trafc Monitoring and
Lawful Intercept
Organizationsmightneedtosetuplawful
trafcinterceptduetotoday’sheightened
securityenvironment.Forexample,in
theUnitedStates,theCommunications
AssistanceforLawEnforcementAct
(CALEA)requiresorganizationstobeableto
interceptandreplicatedatatrafcdirected
toaparticularuser,subnet,port,andso
on.Thiscapabilityisparticularlyessential
innetworksimplementingVoIPphones.
BrocadeFCXSeriesswitchesprovidethe
capabilitytomeetthisrequirementthrough
AccessControlList(ACL)-basedmirroring,
MAClter-basedmirroring,andVLAN-based
mirroring.
Fiber to the Desktop for Security-
Sensitive Applications
TheBrocadeFCX624S-Fprovides24
SFP100/1000Mbpsber-opticportsfor
governmentandmilitarynetworkinitiatives
orforapplicationsrequiringadditional
securityandresiliency.Forthesetypes
ofnetworkenvironments,ber-opticcable
istheultimatetransmissionmedium,
becauseitdoesnotemitelectromagnetic
signalsthatcanbeintercepted.And,unlike
copperwires,opticalbercannotbetapped
withoutdetection.Fiber-opticnetwork
linksarealsoimmunetoRadioFrequency
Interference(RFI)andElectro-Magnetic
Interference(EMI).
Threat Detection and Mitigation
TheBrocadeFCXSeriesutilizesembedded
hardware-basedsFlowtrafcsamplingto
extendBrocadeIronShield360securityto
thenetworkedge.Thisuniqueandpowerful
closed-loopthreatmitigationsolutionuses
best-in-classintrusiondetectionsystemsto
inspecttrafcsamplesforpossiblenetwork
attacks.Inresponsetoadetectedattack,
BrocadeNetworkAdvisorcanautomatically
applyasecuritypolicytothecompromised
port,stoppingnetworkattacksinrealtime
withoutadministratorintervention.
Advanced Multicast Features
TheBrocadeFCXSeriessupportsarich
setofLayer2multicastsnoopingfeatures
thatenableadvancedmulticastservices
delivery.InternetGroupManagement
Protocol(IGMP)snoopingforIGMPversion
1,2,and3issupported.Supportfor
IGMPv3source-basedmulticastsnooping
improvesbandwidthutilizationandsecurity
formulticastservices.Toenablemulticast
servicesdeliveryinIPv6networks,the
BrocadeFCXSeriessupportsMulticast
ListenerDiscovery(MLD)version1and2
snooping——themulticastprotocolsusedin
IPv6environments.
NETWORK RESILIENCY THROUGH
FAULT DETECTION
SoftwarefeaturessuchasVirtualSwitch
RedundancyProtocol(VSRP),Brocade
Metro-RingProtocol(MRP)v1andv2,Rapid
SpanningTreeProtocol(RSTP),protected
linkgroups,802.3adLinkAggregation,
andtrunkgroupsprovidealternatepaths
fortrafcintheeventofalinkfailure.
Sub-secondfaultdetectionutilizingLink
FaultSignaling(LFS)andRemoteFault
Notication(RFN)helpsensurefastfault
detectionandrecovery.
Enhancedspanningtreefeaturessuch
asRootGuardandBPDUGuardprevent
roguehijackingofaspanningtreeroot
andmaintainacontention-andloop-free
environment,especiallyduringdynamic
networkdeployments.Inaddition,the
BrocadeFCXSeriessupportsport-loop
detectiononedgeportsthatdonothave
spanningtreeenabled.Thiscapability
protectsthenetworkfrombroadcaststorms
andotheranomaliesthatcanresultfrom
Layer1orLayer2loopbacksonEthernet
cablesorendpoints.
Protectedlinkgroupsminimizedisruption
tothenetworkbyprotectingcriticallinks
fromlossofdataandpower.Inaprotected
linkgroup,oneportinthegroupactsas
theprimaryoractivelink,andtheother
portsactassecondaryorstandbylinks.The
activelinkcarriesthetrafcand,ifitgoes
down,oneofthestandbylinkstakesover.
UniDirectionalLinkDetection(UDLD)
monitorsalinkbetweentwoBrocadeFCX
Seriesswitchesandbringsdowntheports
onbothendsofthelinkifthelinkfailsat
anypointbetweenthetwodevices.
TheBrocadeFCXSeriesalsosupports
stabilityfeaturessuchasportap
dampening,single-linkLinkAggregation
ControlProtocol(LACP),andport
loopdetection.
ADVANCED CAPABILITIES
Tomeetawiderangeofrequirements,the
BrocadeFCXSeriesprovidesfullLayer3
capabilities,alongwithmetrofeaturesfor
connectingbuildingsandcampuses.
Full Layer 3 Capabilities
AllBrocadeFCXswitchescomestandard
withpowerfulLayer3switchingcapabilities.
OrganizationscanuseLayer3featuressuch
asIPv4OSPFandRIProuting,policy-based
routing,VRRP,andProtocol-Independent
Multicast(PIM)toreducecomplexityand
enhancethereliabilityoflargeenterprise
networksbybringingLayer3capabilities
tothenetworkedge.
Advanced(-ADV)modelsincludeBGP
routingcapabilities,enablingremote
ofcestoconnectBrocadeFCXSeries
switchestoserviceprovidernetworks.
BGProutingcanalsobeaddedtoany
BrocadeFCXSeriesswitchmodelthrough
softwarekey-basedactivation.