Campus Fabric security considerations
The following table indicates which security features are available on PE units in a Campus Fabric domain. All security features are available in a CB stack configuration, unless otherwise noted. Refer to the RUCKUS FastIron Features and Standards Support Matrix for additional information.
Security features supported in a Campus Fabric domain
| Feature group | Feature name | FastIron support |
|---|---|---|
| Security features - Layer 2 | MAC filters | Yes |
| Security features - Layer 3 | IPv4 ingress ACLs | Yes |
| IPv6 ingress ACLs | Yes | |
| IPv4 egress (outbound) ACLs | Yes | |
| IPv6 egress (outbound) ACLs | Yes | |
| Security features - DDoS attack protection | TCP-SYN attack prevention | Yes |
| ICMP attack protection | Yes | |
| Security features - Services | Dynamic ARP Inspection | Yes |
| ND Inspection | Yes | |
| DHCPv4 snooping | Yes | |
| DHCPv6 snooping | Yes | |
| IPv4 Source Guard | Yes | |
| IPv6 RA Guard | Yes | |
| Policy Based Routing | Yes | |
| RADIUS | Yes | |
| Flex-Authentication - dynamic ACLs | Yes | |
| Flex-Authentication - dynamic MAC filters | Yes | |
| Openflow | No | |
| Outbound ACLs for CPU traffic | Yes | |
| DSCP remarking | Yes | |
| PCP remarking | Yes | |
| ACL accounting | Yes | |
| ACL logging | Yes | |
| ACL-based traffic policy | Yes | |
| PPPVLAN | Yes | |
| ACL on ARP | Yes | |
| Traffic management and monitoring | ARP rate limiting | Yes |
| Ingress port rate limiting | Yes | |
| Egress port rate shaping | Yes | |
| ACL-based mirroring | Yes | |
| Web-auth | Yes1 | |
| sFlow | Yes |
Security design considerations
From FastIron release 08.0.70 onward, the use of Campus Fabric and OpenFlow features are mutually exclusive by design.
Security performance considerations
Pay attention to the following security performance considerations in a Campus Fabric domain:
- When more than 5,000 ACL filters are configured, PE units require significant time to resync following a reload. In a Campus Fabric domain with maximum ACL filters (8,000), the time required for PE units to resync is approximately 13 to 17 minutes.
- An ACL request is considered complete only after the request has been completed on every related unit. Consequently, an ACL request may take longer when it is distributed across CB and PE units.
- The distribution model is based on recovery from failure using a rollback mechanism, with the rollback occurring on each successful unit. The rollback mechanism can incur additional delays.
- All CLI requests are blocked on the security framework until ACL requests are completed.
Additional security considerations
In a Campus Fabric domain, the following security considerations apply:
- Foundry Discovery Protocol (FDP) packets are blocked at PE interfaces, even when FDP
pass through is configured. However, the packets are still forwarded upstream for
processing in the CB. Although FDP neighbors can be displayed within the Campus Fabric
domain, for example, with the
show fdp neighborcommand, no FDP packets are forwarded to non-SPX devices (that is, to devices that are connected to PEs but that are not part of the Campus Fabric domain).
- User-based ACLs are not supported in Web-auth for either CB or PE units. ↩