| Access control lists |
L2/3/4 ACLs |
|
| Anomaly analysis |
Source Media Access Control (MAC) = Destination MAC; illegal frame sizes; Source MAC is multicast; TKIP countermeasures; all zero addresses |
|
| Application Layer Gateway (ALG) support |
SIP, H323, NETBIOS, IKE, TFTP, FTP, PPTP, DNS, L2TP, SMTP, NNTP, SQL, HTTP, HTTPS, GATEKEEPER, RPC, MSGUDP, N2P, PCANYWHERE, RTSP, MSGTCP, N2PE, AIM, ICQ, MSN, ILS |
|
| Authentication |
Pre-shared keys (PSK); 802.1x/EAP-transport layer security (TLS), tunneled transport layer security (TTLS), protected EAP (PEAP); Kerberos; Integrated AAA/RADIUS server with native support for PEAP-TTLS; Support for LDAP, Radius Authentication across VPN. |
|
| IP filtering |
Configurable incoming and outgoing IP filtering policies on packets within the same subnet/WLAN and between wired and wireless hosts, Provides flexibility in defining access policies |
|
| IPSec VPN gateway |
Supports DES, 3DES, AES-128 and AES-256 encryption, with site-to-site VPN |
|
| Network address translation (NAT) support |
Yes |
|
| RADIUS support (standard and Motorola vendor specific attributes) |
Location-based authentication (Motorola VSA), User-based QoS (Motorola VSA), MAC-based authentication (standard), Allowed ESSIDs (Motorola VSA), User-based VLANs (standard) |
|
| Secure guest access (Hotspot provisioning) |
URL redirection for user login, Local web-based authentication, Customizable login/welcome pages, Support for external authentication/billing systems |
|
| Stateful Layer 3 firewall |
Yes |
|
| Transport encryption |
WPA2-CCMP (AES), WEP 40/128 (RC4), WPA-TKIP, KeyGuard |
|
| URL filtering |
Allow or deny access to specific web sites: Reverse DNS lookup to block access by IP address; URL Blacklist; URL Whitelist; Keyword analysis in URL; trusted host provisioning |
|
| Wired IDS/IPS |
Inline signature analysis of data traffic, performed on traffic from both wired and wireless hosts; configurable by protocol — Telnet, POP3, IMAP, NNTP, FTP, SNMP, TCP-DNS, UDP-DNS, TCP-RPC, UDP-RPC, HTTP, SMTP, TCPGEN, UDPGEN, ICMP, TCP, UDP, IP; Denial of Service (DOS) Attack Protection. Logging of detected attacks |
|
| Wireless IDS/IPS |
Multi-mode rogue AP detection, client blacklisting, excessive authentication,/associations; excessive probes; excessive disassociation/deauthentications; excessive decryption errors; excessive authentication failures; excessive 802.11 replay; excessive crypto IV failures( TKIP/CCMP replay)
|
|
| 802.11 a/b/g support |
Yes; Supports 6 AP300 (802.11a/b/g) per switch;
Automatic access port adoption with ACLs; Auto channel selection capability
|
|
| Bandwidth management |
Congestion Control with Bandwidth Management and throttling per WLAN |
|
| Clustered access ports/points |
Supports 1-6 802.11a/b/g access ports; Automatic access port adoption with ACLs; Auto channel selection capability |
|
| IP routing support |
Yes |
|
| Layer 2 adoption |
Yes |
|
| Layer 3 adoption |
Yes |
|
| Layer 3 mobility (intersubnet roaming) |
Yes |
|
| RF management |
Yes; Dynamic Frequency Selection and Transmit Power Control (TPC);Country Code based RF Configuration; Self Healing for Neighbor Recovery and Interference Avoidance; Automatic Channel Selection Capability |
|
| Roaming |
Supports hyper fast secure roaming with Opportunistic Channel Scan; Power Save Protocol; pre-emptive roaming and credential caching |
|
| VLAN support |
Wireless LAN to VLAN mapping; auto-assignment of VLANs based on user authentication; VLAN to ESSID mapping; Auto Assignment of VLANs (on RADIUS authentication); supports 6 IP subnets |
|
| Wireless LAN |
Supports 8 WLANs; Virtual AP - Multi-ESS/BSSID traffic segmentation; Pre-emptiveRoaming; Automatic Load Balancing |
|
| Wireless bridging/Mesh |
The WS2000 with the AP300 can operate as a base bridge and wireless bridge with the AP51X1 access Points for data backhaul in a mesh configuration, as well as provide both based and client bridge capability by operation as a mesh node itself |
|