H3C S3600 Series Switches Agenda Market Trends S3600 Overview - - PowerPoint PPT Presentation

h3c s3600 series switches agenda
SMART_READER_LITE
LIVE PREVIEW

H3C S3600 Series Switches Agenda Market Trends S3600 Overview - - PowerPoint PPT Presentation

H3C S3600 Series Switches Agenda Market Trends S3600 Overview S3600 Key Features V1. V1.5 New New Feat Feature IRF IRF RPS10 S1000 00-A Featu ature S re Summar mary End-to-End Intelligent Solution Summary www.h3c.com.cn 2


slide-1
SLIDE 1

H3C S3600 Series Switches

slide-2
SLIDE 2

www.h3c.com.cn

2

Agenda

Market Trends S3600 Overview S3600 Key Features

V1. V1.5 New New Feat Feature IRF IRF RPS10 S1000 00-A Featu ature S re Summar mary

End-to-End Intelligent Solution Summary

slide-3
SLIDE 3

www.h3c.com.cn

3

Agenda

Market Trends S3600 Overview S3600 Key Features End-to-End Intelligent Solution Summary

slide-4
SLIDE 4

www.h3c.com.cn

4

Challenges for Enterprise Networks

How to manage/operate/control the network equipments located in different sites?

Application server farm

How to make easy network expansion without any network interruption? How to avoid single failure on the networks ? How to Maximum the bandwidth for Voice traffic?How to ensure the critical applications?

slide-5
SLIDE 5

www.h3c.com.cn

5

Five Key Factors for Enterprise Network

Reliability

Achi chiev eving ng r relia liable le n netwo tworks ks is still ill a chal alle lenge ge

Network Management

Ne Network man management is is a a lab labor int intensive and and cos costly job job

Intelligence

Effec ectiv tive e Applica icatio tion-Awar warene eness ss

Network Expansion

Co Continue to be a to be a “puzz uzzle le” for netwo work rk admini inistr strato ators rs – eve even the the sim simplest exp expansion can can bri bring hidde den n threats ats t to relia iabil bility ity Exist sting ing netwo work rk expans ansion ion techn hnolo

  • logie

gies s are like e adding ng a floor t r to an exist isting ng house use – an an “ad add on

  • n” but

but nev never “tru true par part of

  • f it

it”

Security

To pro To protect you your net network aga against ill illegal use use / / ano anonymous vir virus

slide-6
SLIDE 6

www.h3c.com.cn

6

New Generation Switches Innovation

H3C S3600

Reliability Network Management Intelligence Network Expansion Security

slide-7
SLIDE 7

www.h3c.com.cn

7

Agenda

Market Trends S3600 Overview S3600 Key Features End-to-End Intelligent Solution Summary

slide-8
SLIDE 8

www.h3c.com.cn

8

Comprehensive Switch Portfolio

S3100-SI L2 Switch S3600 L2/3 Switch S5100/S5600 Intelligent Switch S7500 modular chassis switch S9500 Core Routing switch

Core Modular Chassis Deployment Focus

  • Multiple service options
  • Highest availability & 10/100/1000

densities

  • Abundant service modules
  • Wire-speed 10GE aggregation
  • Core
  • Distribution
  • Data center access/core service
  • High performance wiring closet

Mid-range Modular Chassis Deployment Focus

  • Resilient L3 routing & Intelligent L4

services

  • Highest density 10/100/1000
  • 10GE aggregation
  • Medium wiring closet
  • Small/Medium Distribution/Core
  • Data center access/core
  • Large/Medium branch

Advanced GE fixed configuration Deployment Focus

  • Resilient L3 routing & Intelligent L4

services

  • Medium density 10/100/1000
  • Resilient stacking
  • 10GE uplinks
  • wiring closet
  • Middle branch office
  • Data center
  • Medium Network aggregation

Optimized fixed configuration Deployment Focus

  • Wire-speed L2 switching and

resilient L3/L4 services

  • 10/100 + 4 x GE uplinks
  • Resilient stacking
  • Advanced QoS mechanism
  • Small wiring closet
  • Small branch office
  • Small network aggregation
  • Desktop/Workgroup switch

Basic fixed configuration Deployment Focus

  • Wire-speed L2 switching
  • Stacking
  • Intelligent Service
  • Small wiring closet
  • Small branch office
  • Desktop/Workgroup switch

Gigabit / 10G 10/100M

slide-9
SLIDE 9

www.h3c.com.cn

9

S3600 FE Series Switches

 24 / 48 10/100M Ethernet Ports  4 x 1000 Base-X SFP Port  802.3af POE compatible  8 Hardware Queues  Voice VLAN  Enhanced L2-L4 functionalities  Static/RIP/OSPF(EI)  802.1x local / external radius authentication  ACL both inbound and outbound direction

Switch Capacity : 12.8Gbps/17.6Gbps Forwarding rate: 9.5/11.78 Mpps Deployment Focus

  • Small wiring closet
  • Small branch office
  • Small network aggregation (EI)
  • Desktop/Workgroup switch

S3600-28F-EI S3600-52P-SI S3600-52P-EI S3600-52P- PWR-SI S3600-52P- PWR-EI S3600-28TP-SI S3600-28P-SI S3600-28P-EI S3600-28P- PWR - SI S3600-28P- PWR - EI

slide-10
SLIDE 10

www.h3c.com.cn

10

S3600-SI Series Switches Features

Target use: Enterprise wiring closet access switch; branch

  • ffice switch

Availability: Simply power the switch via a standard AC input Scalability: Patented IRF technology automatically creates a stack of switches and allows single IP management; Extend connectivity with a mixture of PoE Connectivity: Each switch allows up to 4 active Gigabit ports with any combination of copper and/or fibre accepted Application-Aware: Automatically detects, prioritizes and places VoIP traffic in a separate VLAN Port Configurations: 24 x 10/100 Ports + 4 SFP 48 x 10/100 Ports + 4 SFP

Includes Standard Image (SI) software IRF: Distributed Device Management Sc Scalable to 384 to 384 10/ 10/100 + + 32 SFP 32 SFP Built-in r resilient l loop s stacking v via S SFP ports Features Highlights: 64 Static Routes Dynamic routing (RIPv1/2) – 1K ent 1K entries 2K ARP 2K ARP Tab Table Intel elli ligent nt s secur urit ity s services es i inclu ludi ding 8 802.1X RADA – RADIUS US Authe hentic icate ted D Device A Access SSHv1 v1.5 .5 / S SNMPv3 v3 Full l QoS P Prioriti tisa sation

  • n a

and f full c classifica cation 8 Egress Queues 4K 4K Por Port-Bas ased V VLANs Ns AC inp AC input 802.3 .3ad ad Link A k Aggreg egatio ion n – up to up to 8 groups Multiple/Rapid Spa Spanning Tre Tree wit with STP STP Rou Route Gua Guard IGMP S P Snoopi ping ng V V1/V2 V2 NT NTP / / FTP FTP Ser Server and and Cli Client

Key Points

Switch 3600 -- The new choice for access network deployments

H3C S3600-28P(PWR) 24-Port + 4 SFP H3C S3600-52P(PWR) 48-Port + 4 SFP H3C S3600-28TP 24-Port + 2*10/100/1000Base-T+2SFP

slide-11
SLIDE 11

www.h3c.com.cn

11

S3600-EI Series Switches Features

Target use: Advanced Enterprise wiring closet access switch; small aggregation Availability: Routing functions are totally distributed across all switches in the stack massively increasing performance and uptime Scalability: Extend connectivity with a mixture of PoE and fibre switches Connectivity: Jumbo Frames are supported on all gigabit uplinks for interoperability with equipment downstream Application-Aware: Advanced Time-Based ACLs are supported that can be automatically executed on a per user or machine basis

Includes Enhanced Image (EI) software Includes A ALL S SI software p plus: IRF Distributed Device Management Mi Mix and and mat match any any S36 S3600-EI pro product in a in a sta stack, inclu ludi ding P PWR Distributed Link Aggregation Al Allows up up to to 8 8 gro groups to to be be spr spread acr across any any por ports in in th the sta stack (8 (8 FE FE / / 4 4 GE GE per per gro group) Distributed Resilient Routing Al All swi switches in in the the sta stack are are act actively rou routing and and sh sharing LSD LSDB and and ARP ARP tab tables RIP/O /OSP SPF Multicast R Routing P PIM S Sparse Mode / / Dense M Mode Jumbo boFr Frame AC & AC & DC DC inp input Centr tral al MAC a authe hent nticat atio ion Time-bas ased A Acces ess Control L l Lists DHCP T Tracker ECMP, P,VR VRRP,Q ,Qin inQ Traff ffic ic R Redir irecti tion

  • n

HWTAC ACAC ACS Traff ffic ic M Mirro roring ng Syslog

Key Points

Switch 3600 -- The new choice for access network deployments

H3C S3600-28P(PWR) 24-Port + 4 SFP H3C S3600-52P(PWR) 48-Port + 4 SFP H3C S3600-28F 24-Port + 2 SFP + 2 1000BaseT

slide-12
SLIDE 12

www.h3c.com.cn

12

Enterprise Networking with S3600

10/100M Desktops Space -Constrained Server Racks Mission-Critical 10/100/1000M Workstations

Network Core Availability

  • IP Unicast Routing
  • Static, RIPv1/v2, OSPF,
  • IP Multicast Routing
  • VRRP
  • DTP and PAgP
  • Dynamic VLANs
  • IGMP snooping
  • STP enhancements
  • Distributed L2/L3 functions
  • MAC address notification
  • DHCP interface tracker
  • CMS security wizard
  • Access control lists
  • Private VLAN edge
  • Port security
  • SNMPv3
  • 802.1x
  • SSH

Security

  • Queue servicing:
  • Shaped round robin and

strict priority queuing

  • Weighted tail drop
  • Ingress traffic policing
  • Egress traffic shaping
  • 802.1p CoS and DSCP
  • Congestion avoidance
  • Granular rate limiting
  • Jumbo Frames

Quality of Service S3600

slide-13
SLIDE 13

www.h3c.com.cn

13

Agenda

Market Trends S3600 Overview S3600 Key Features

V1. V1.5 New New Feat Feature IRF IRF RPS10 S1000 00-A Featu ature S re Summar mary

End-to-End Intelligent Solution Summary

slide-14
SLIDE 14

www.h3c.com.cn

14

S3600 V1.5 New Features New!

✔VRRP (EI) ✔HGMPv2 ✔DHCP-SERVER (EI) ✔QINQ ✔GVRP ✔MVR ✔DLDP ✔IGMP Snooping Fast Leave ✔DHCP Snooping Trust ✔DHCP Relay Security ✔DHCP Option 82 ✔802.1X and Mac address Authentication At the Same Time/ Port ✔802.1X with PEAP/TLS ✔Dynamic VLAN Delivery ✔Guest VLAN ✔Jumbo Frame for SI ✔Group Policy ✔Protocol Based VLAN ✔SSHv2 ✔VCT (Virtual Circuit Test) ✔RSPAN (Remote Port Mirroring) ✔HWTACACS

slide-15
SLIDE 15

www.h3c.com.cn

15

VRRP

In the VRRP router Standby Group, there always exists a Master router to complete the task of virtual router. All other routers in the group serve as Backup to monitor the Master all the time. When the Master fails to work, the Backups will elect a new Master automatically to fulfill the task.

VRRP (Virtual Router Redundancy Protocol)

Master Router Backup Router

Benefits:

✔ Improve the network reliability ✔ Transparent to the end users

S3600

slide-16
SLIDE 16

www.h3c.com.cn

16

HGMPv2

HGMP (Huawei Group Management Protocol)

HGMP

H3C S5600 series

H3C S3600 series H3C S3600 series

Command Switch Member Switches

Benefits:

✔ Save IP address for network management ✔ Easy to install and maintain

  • S5600 series are designated as

command switch

  • S3600 series automatically join the

cluster after startup as member switches

  • Handshake and status maintenance

between S5600 and S3600 series

  • Alarm failure and recovery on

line ……

slide-17
SLIDE 17

www.h3c.com.cn

17

QinQ

Without QinQ With QinQ

Benefits:

✔ Save VLAN Resource

slide-18
SLIDE 18

www.h3c.com.cn

18

QinQ Application for Service Provider

                VLAN 20 VLAN 30 VLAN 20 VLAN 30

header data user vlan 20 header data user vlan header data user vlan

 Tunnel port for assigning or extracting exterior VLAN tag  Client side: single tag, PE side: double tags.

slide-19
SLIDE 19

www.h3c.com.cn

19

802.1X with PEAP/TLS

802.1X authentication

PC Supplicant

S5600 Series

Radius/EAP server S3600 Authenticator PC Supplicant PC Supplicant

Benefits:

✔ Improve the security ✔ Provide AAA (Authentication, Authorization, Accounting) functions

  • Efficient port/MAC based
  • Built-in 802.1X server
  • Support EAP relay function
slide-20
SLIDE 20

www.h3c.com.cn

20

802.1X and MAC Authentication

Without 802.1X Client With 802.1X Client

How can PC and IP phone be authenticated on the same port?

IP Phone PC

S3600 supports 802.1X and MAC Authentication at the Same Time on One Port Benefits:

✔ Authenticate devices with or without 802.1x Client at the same time

slide-21
SLIDE 21

www.h3c.com.cn

21

Dynamic VLAN via 802.1x

Core Core

CAMS

4、Authenticated legally,users accept the vlanid ,ACL,/usage parameter control sended by CAMS, and accquire the IP

S3100 S3600

DHCP Server

Solve user roaming

  • 1. User authentication

initiate.

  • 2. User can’t access anywhere and

get IP address before authentication.

  • 3. Authenticated by user name and

password, if legality,assign the dynamic vlan

  • 5. User can access Internet after getting IP

address, then IP+MAC+VLAN binding by switch.

slide-22
SLIDE 22

www.h3c.com.cn

22

VCT (Virtual Cable Test)

H3C S3600

Benefits:

✔ Easy maintenance ✔ Save labour

X

slide-23
SLIDE 23

www.h3c.com.cn

23

What is IRF ?

Huawei-3Com’s industry leading stacking technology Innovation of LAN switching Create Intelligent Resilient Framework Network Core features: Distributed Device Management (DDM) Distributed Link Aggregation (DLA) Distributed Resilient Routing (DRR)

Intelligent Resilient Framework

I R F

Distributed Fabric Flexible High efficient Cost-effective

slide-24
SLIDE 24

www.h3c.com.cn

24

IRF Based Easy Management

All switches act as a single logical device Resilient architecture provides access to management in the event of ANY switch failing Rapid stack-wide feature configuration Hot-insert and removal of switches Automatic and manual stack configuration Stack up to 8 units

Stack Management

Single entity for SNMP, WEB and CLI Management ACL configurations in one screen with All the device View Reduces configuration time Improved monitoring responsiveness

Distributed Device Management (DDM)

1 3 4

Only one logical device

2 3 4

IRF fabric

slide-25
SLIDE 25

www.h3c.com.cn

25

S3600 IRF Stacking

Eac Each swit switch uses uses the last the last two port two ports to to prov provide a a 2 2 * * 2 2 Gbp Gbps stac stacking,

No extra hardware required

Sta Stack up to 8 up to 8 unit units Autom tomati atic c or manual s nual stack c ck config figura uratio tion A A retu return link link prov provides rapi rapid fail fail-over in in the eve the event of

  • f a

a norm normal lin link or

  • r unit

unit fail failing IRF S F Stack u ack units t its togethe gether o r over er 70Km 70Km apar apart

Normal Stacking Link: 1 Gbps UP / 1 Gbps DOWN Standby Stacking loop connection: 1 Gbps UP / 1 Gbps DOWN

H3C S3600

Use SFP to link the units together

IRF Stacking

slide-26
SLIDE 26

www.h3c.com.cn

26

IRF Based Network Expansion

Creates incredibly resilient network design Allows connections from ANY port across the fabric to be connected together using IEEE 802.3ad LACP – as aggregated links

Distributed Link Aggregation (DLA)

H3C S5600 H3C S3600

4 Gbps Load-balanced LAG

H3C S3600

 DLA will facilitate the re-distribution of traffic in case of any uplink fail

slide-27
SLIDE 27

www.h3c.com.cn

27

IRF Based Resilient Network

Changes traditional L3 forwarding of stack devices with implementing new distributed L3 forwarding procedure Each unit provides local L3 switching and holds distributed routing tables Unit failure in the IRF stack will not affect routing for the other units Master device is not required – all commands and data are synchronized across all units

1 2

ROUTER TABLE VLAN 1 0.0.0.0 255.255.0.1

Router Interface information is synchronised across all switches L3 traffic can be handled locally by the switch and intelligently passed up or down the IRF stack

VLAN 1 VLAN 2

Distributed Resilient Routing (DRR)

slide-28
SLIDE 28

www.h3c.com.cn

28

IRF Based Resilient Network

Distributed Resilient Routing (DRR)

  • Only the active unit device (Unit 1) has the L3

forwarding capability

  • Other unit devices have to deliver the received packets

to the active unit device for L3 forwarding

L3 forwarding

IRF stack devices Traditional stack devices

  • Any Unit of a Fabric has a complete L3 forwarding capacity
  • When receiving a L3 packet to be forwarded, the Unit

directly obtains the egress port and next hop of the packets

Router1 Router2 Router3 Router4 IP packet Unit1 Unit3 Unit4 Unit2

Normal stack

Router1 Router2 Router3 Router4 IP packet Unit1 Unit3 Unit4 Unit2

IRF based Distributed forwarding

slide-29
SLIDE 29

www.h3c.com.cn

29

Basic Security Features

  • SNMPv3/ SSHv2
  • Authorized IP for management:
  • support 16 authorized management IP
  • User authentication
  • 802.1x
  • Centralized Mac authentication
  • Local password base authentication (128 users )
  • Radius based authentication (1024 users)
  • Packet Filtering
  • L2/L3/L4
  • Time-based ACLs
  • ACL entries per port
  • Others
  • DoS protection
  • DHCP security
  • Port Mirroring/Traffic Mirroring
slide-30
SLIDE 30

www.h3c.com.cn

30

Device Security

Advanced Device Security

Access Levels – 4 4 lev levels can can be set be set for for mul multiple use users SNMPv3 / SSHv2 - Enc Encrypt all SNM all SNMP and and Tel Telnet tra traffic to sto to stop mid middle-ma man a n attack tacks s 56bit 6bit / / 168bi 8bit Authorized IP - Lock a ck access cess to the e manag nagem emen ent i t interf terfac ace b e by route uted A d Access cess Contr ntrol

  • l

List ist Switch Login (RADIUS) – Sup Support RAD RADIUS Aut Authentication for CLI / for CLI / Con Console and web and web inter nterfa face ces. s. RADI ADIUS US r retur turn n attri ribu bute te w will ll set indivi dividu dual al p privi ivile lege ge l level vels Denial of Service Attack Preventions – Att Attacks to the to the hos host CPU CPU sub sub sys systems and and memor emory a y are p protec

  • tecte

ted v d via a a traff ffic ic class assif ific icat atio ion q n queuin euing s g system stem Syslog - All All com commands can can be be tra tracked and and sen sent to to a a Sys Syslog ser server

slide-31
SLIDE 31

www.h3c.com.cn

31

Application-Aware Services

Advanced Traffic Management

Voice Voice VLAN VLAN – All voice traffic can be automatically placed into a private secure VLAN;

switch will detect VoIP phone OUI and register with the correct VLAN

Traffic R ffic Redirection / rection / Mirror

  • r – Mirror or redirect any type of network traffic

based upon an ACL to any port

Configurable Q figurable Queue P e Processing essing – 8 hardware-based queues; Strict Priority;

Weighted Round Robin; Weighted Fair Queuing; WRED; WRR + SP

Advanced T anced Traffic C fic Classification sification – All ACL classifications are available Traffic Traffic Actions Actions – Remark DSCP; Drop or set the IP-Precedence, rate limit (64kbps

granularity)

Define your own Classification rule and mask for the ACL Define ACLs based upon Ingress & Egress Control Source / Destination IP Address Source / Destination MAC address Source / Destination TCP and/or UDP Port ICMP DSCP / COS / Precedence / TOS VLAN

slide-32
SLIDE 32

www.h3c.com.cn

32

Voice Queue Data Queue 1 Data Queue 2

Voice VLAN

  • 1. Mac address 00E0-BB00-0000 mask ffff-ff00-0000
  • 2. Ah! It is an IP Phone of Vendor A, B, C……( Totally, 16 Vendors)
  • 3. Put the traffic from IP Phone into Voice VLAN automatically
  • 4. Other traffic will be processed with lower priority

Voice Data Other Data

Voice VLAN

Benefits:

✔ Guarantee the QoS of voice data ✔ Improve the security

slide-33
SLIDE 33

www.h3c.com.cn

33

RPS1000-A Front Panel

slide-34
SLIDE 34

www.h3c.com.cn

34

RPS1000-A Rear Panel

Two Outputs for PoE Device or Non PoE Device Six Outputs for Non PoE Device Only The two main inputs are for the two PSUs in the RPS1000-A rack respectively

slide-35
SLIDE 35

www.h3c.com.cn

35

S3600 Rear Panel

(1) (2) (1) (2)

S3600-EI rear panel, AC input socket S3600-EI rear panel, DC input socket.

(1) (2) (3) (1) (2) (3)

S3600-SI rear panel, AC input socket

RPS Connects Here! Only S3600-EI Supports RPS S3600-SI S3600-EI

slide-36
SLIDE 36

www.h3c.com.cn

36

RPS1000-A Connects to PoE Device

OUTPUT3: -54V;8A OUTPUT4: -54V;8A OUTPUT5: -54V;8A OUTPUT6: -54V;8A OUTPUT7: -54V;8A OUTPUT8: -54V;8A + + + + + + + +

! ! ! ! ! ! ! !

RPS1000-A OUTPUT1: -54V;25A OUTPUT2: -54V;25A

(1) (2) (3) (1) (2) (3)

BOM:0404A053 - Cable with JD5 type connector for PoE switches Two Outputs for PoE Device

  • r Non PoE Device
slide-37
SLIDE 37

www.h3c.com.cn

37

RPS1000-A Connects to Non PoE Device

OUTPUT3: -54V;8A OUTPUT4: -54V;8A OUTPUT5: -54V;8A OUTPUT6: -54V;8A OUTPUT7: -54V;8A OUTPUT8: -54V;8A + + + + + + + +

! ! ! ! ! ! ! !

RPS1000-A OUTPUT1: -54V;25A OUTPUT2: -54V;25A

(1) (2) (3) (1) (2) (3)

BOM:0404A055 - Cable with JD5 type connector for Non- PoE switches BOM:0404A054 - Cable with JD5-A type connector for Non- PoE switches

Six Outputs for Non PoE Device Only Two Outputs for PoE Device or Non PoE Device

slide-38
SLIDE 38

www.h3c.com.cn

38

Feature Summary

Port Features SPAN (Port Mirroring) RSPAN (Remote Port Mirroring) New! New! Port Isolation Port Rate-limiting (64kbps) IP + MAC + Port Binding DUD (Disconnect Unauthorized Device) New New! DLDP (smillar to UDLD) New! New! VCT (Virtual Cable Test) New New! High Performance 4 GE uplinks 4K VLAN/16K MAC Jumbo Frame High Reliability STP/RSTP/MSTP VRRP for S3600-EI New! New! ECMP for S3600-EI Redundant Power Supply for S3600-EI Redundant Power Supply for S3600-EI Distributed Layer 2 and Layer 3 IRF! IRF! Layer 2/3 failover with nonstop forwarding IRF IRF! 4Gbps fault tolerant bidirectional stack interconnection IRF! IRF! Cross-stack link aggregations technology, cross-stack QoS IRF IRF!

slide-39
SLIDE 39

www.h3c.com.cn

39

Feature Summary (Cont.)

Abundant Security SSHv2 New! New! SNMPv3 MAC Black Hole Disconnect Unauthorized Device 802.1X with PEAP/TLS New! New! Centralized MAC Address Authentication Enable 802.1X and MAC Authentication on the same port New! New! Dynamic VLAN Delivery/Guest VLAN New! New! DHCP Relay Security New! New! DHCP Snooping Trust New! New! Abundant QACL WRED 8 Queues/SP/WRR/WFQ/SP+WRR/SP+WFQ CAR Ingress & Egress ACL ACL Traffic Limit Traffic Classification/Traffic Shaping Tail Drop DSCP<->CoS Voice VLAN

slide-40
SLIDE 40

www.h3c.com.cn

40

Feature Summary (Cont.)

Multicast MVR New New! IGMPv1/v2 Snooping IGMPv1/v2 Snooping Fast Leave New! New! PIM-SM/PIM-DM for S3600-EI Extends Web-based management suite Ease Management GVRP New! New! SNMPv1/v2/v3 HGMPv2 New New! One IP address and configuration file for entire stack IRF IRF! Extends Web-based management suite Automatic stacking configuration of new units when connected to the stack IRF! IRF! Cost Effective PoE QinQ New! New! 802.1X Server DHCP Option 82 New! New! DHCP Server for S3600-EI New New! Return of Investment High Performance/Cost Ratio Seamless Network Expansion IRF! IRF!

slide-41
SLIDE 41

www.h3c.com.cn

41

Agenda

Market Trends S3600 Overview S3600 Key Features End-to-End Intelligent Solution Summary

slide-42
SLIDE 42

www.h3c.com.cn

42

S3600 Deployment Scenario

Application server farm H3C S3600 H3C S3600 H3C S3600 H3C S3600 H3C S5600 H3C S5600

 Voice VLAN  POE  IRF stacking

slide-43
SLIDE 43

www.h3c.com.cn

43

End-to-End Intelligent Solution

Application server farm

S7500 Security Policy Control Security Automatic User Security Authentication, Authorisation and Accounting; Peace of mind for businesses PoE: Powered, traffic optimized and secured by Switch 3600

Router AR4600

Best of Breed Core Performance Industry leading Terabit Performance with investment protected backplane Industry Leading Performance Unique Distributed Resilient 96Gbps link via IRF Total Flexibility Comprehensive media flexibility for abundant applications S3600

SecPath Security System

S9500

Service System Fully Standards Based Infrastructure

Unique Investment Protection Add Power over Ethernet anytime to the Switch S5600 S5600 S3600

slide-44
SLIDE 44

www.h3c.com.cn

44

Shinsei Bank Office Building Network

PC PC S3600-52-PWR-EI IP Phone S9505 S9505 OSPF VRRP RSTP Root IP Phone VRRP S3600-52P-PWR-EI S3600-52P- PWR-EI DHCP Server PC Data and IP Phone data are forwarded into different VLAN. S3600-52P-PWR-EI Voice VLAN method set IP Phone packets with high priority. Power over Ethernet IP Phone PC Data Multicast S5516 S5516 S5516 S5516 RSTP Root Backbone Network

Shinsei Bank is one of the first group customers in Japan who introduced IP Phone Solution into their enterprises’ network.

  • Reliability ensured by dual-host, dual-homing, VRRP and RSTP
  • Voice VLAN and PoE deployment

S3600-52-PWR-EI

slide-45
SLIDE 45

www.h3c.com.cn

45

Agenda

Market Trends S3600 Overview S3600 Key Features End-to-End Intelligent Solution Summary

slide-46
SLIDE 46

www.h3c.com.cn

46

Summary

IRF based Easy management IRF based Network Expansion IRF based Resilient Network Advanced Network Security Network Application-Awareness

H3C S3600

Low TCO

Enterprise-class services High Availability: IP Routing, VRRP, MSTP, 802.1s/w, IGMP snooping, RPS Security: ACL, port security, MAC address notify, RADIUS/TACAC+, 802.1x, SSHv2, SNMPv3, DUD, Advanced QoS: Layer 2–4 QoS with CoS/DSCP, shaped round robin, WRR,strict priority queuing, Ingress and Egress ACL (only for S3600) VOICE VLAN/PoE Abundant Security SSHv2/SNMPv3 802.1X with PEAP/TLS, Centralized MAC Address Authentication/Enable 802.1X and MAC Authentication on the same port Dynamic VLAN Delivery/Guest VLAN DHCP Relay Security/DHCP Snooping Trust IRF technology 4Gbps fault tolerant bidirectional stack interconnection Distributed architecture Layer 2/3 failover with nonstop forwarding Cross-stack link aggregations technology, cross-stack QoS Single network instance (IP, SNMP, CLI, STP, VLAN)

slide-47
SLIDE 47

www.h3c.com.cn

47

Summary (Cont.)

IRF based Easy management IRF based Network Expansion IRF based Resilient Network Advanced Network Security Network Application-Awareness

H3C S3600

Low TCO

High performance Gigabit Ethernet and Fast Ethernet configurations provide Distributed Layer 2 and Layer 3 Ease of management/deployment One IP address and configuration file for entire stack Extends Web-based management suite to Layer 2/3/4 services Automatic stacking configuration of new units when connected to the stack Return of Investment High Performance/Cost Ratio Seamless Network Expansion

slide-48
SLIDE 48

www.h3c.com.cn

48