Campus Fabric security considerations

The following table indicates which security features are available on PE units in a Campus Fabric domain. All security features are available in a CB stack configuration, unless otherwise noted. Refer to the RUCKUS FastIron Features and Standards Support Matrix for additional information.

Note: ICX7400-SERVICE-MOD IPsec modules are not supported in ICX 7450 devices used as PE units.

Security features supported in a Campus Fabric domain

Feature group Feature name FastIron support
Security features - Layer 2 MAC filters Yes
Security features - Layer 3 IPv4 ingress ACLs Yes
IPv6 ingress ACLs Yes
IPv4 egress (outbound) ACLs Yes
IPv6 egress (outbound) ACLs Yes
Security features - DDoS attack protection TCP-SYN attack prevention Yes
ICMP attack protection Yes
Security features - Services Dynamic ARP Inspection Yes
ND Inspection Yes
DHCPv4 snooping Yes
DHCPv6 snooping Yes
IPv4 Source Guard Yes
IPv6 RA Guard Yes
Policy Based Routing Yes
RADIUS Yes
Flex-Authentication - dynamic ACLs Yes
Flex-Authentication - dynamic MAC filters Yes
Openflow No
Outbound ACLs for CPU traffic Yes
DSCP remarking Yes
PCP remarking Yes
ACL accounting Yes
ACL logging Yes
ACL-based traffic policy Yes
PPPVLAN Yes
ACL on ARP Yes
Traffic management and monitoring ARP rate limiting Yes
Ingress port rate limiting Yes
Egress port rate shaping Yes
ACL-based mirroring Yes
Web-auth Yes1
sFlow Yes

Security design considerations

From FastIron release 08.0.70 onward, the use of Campus Fabric and OpenFlow features are mutually exclusive by design.

Security performance considerations

Pay attention to the following security performance considerations in a Campus Fabric domain:

  • When more than 5,000 ACL filters are configured, PE units require significant time to resync following a reload. In a Campus Fabric domain with maximum ACL filters (8,000), the time required for PE units to resync is approximately 13 to 17 minutes.
  • An ACL request is considered complete only after the request has been completed on every related unit. Consequently, an ACL request may take longer when it is distributed across CB and PE units.
  • The distribution model is based on recovery from failure using a rollback mechanism, with the rollback occurring on each successful unit. The rollback mechanism can incur additional delays.
  • All CLI requests are blocked on the security framework until ACL requests are completed.

Additional security considerations

In a Campus Fabric domain, the following security considerations apply:

  • Foundry Discovery Protocol (FDP) packets are blocked at PE interfaces, even when FDP pass through is configured. However, the packets are still forwarded upstream for processing in the CB. Although FDP neighbors can be displayed within the Campus Fabric domain, for example, with the show fdp neighbor command, no FDP packets are forwarded to non-SPX devices (that is, to devices that are connected to PEs but that are not part of the Campus Fabric domain).

  1. User-based ACLs are not supported in Web-auth for either CB or PE units. ↩