Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Switch recommendation wanted  (Read 1606 times)

Weaver

  • Senior Kitizen
  • ******
  • Posts: 11459
  • Retd s/w dev; A&A; 4x7km ADSL2 lines; Firebrick
Switch recommendation wanted
« on: January 01, 2020, 11:20:16 AM »

[I might have asked about this before. Apologies if so.]

I’m looking out for a new small high speed switch, very high functionality and 16 or 24 ports. Any recommendations for a bargain?
Logged

chenks

  • Kitizen
  • ****
  • Posts: 1106
Re: Switch recommendation wanted
« Reply #1 on: January 01, 2020, 02:37:17 PM »

can't go wrong with ubiquiti equipment
Logged

g3uiss

  • Kitizen
  • ****
  • Posts: 1151
  • You never too old to learn but soon I may be
    • Midas Solutions
Re: Switch recommendation wanted
« Reply #2 on: January 01, 2020, 02:37:25 PM »

HP Procurve switches are excellent. They can be obtained cheaply second hand, with the added bonus of a lifetime warranty from HP. I’ve only ever had one fail and I had a new one from HP in 24hrs.

The 24 port versions are very common

Tony
Logged
Cerebus FTTP 500/70 Draytec 2927 VOXI 4G fallback.

Weaver

  • Senior Kitizen
  • ******
  • Posts: 11459
  • Retd s/w dev; A&A; 4x7km ADSL2 lines; Firebrick
Re: Switch recommendation wanted
« Reply #3 on: January 02, 2020, 09:47:18 AM »

I’ll have a look around to try and find prices - many thanks
Logged

niemand

  • Kitizen
  • ****
  • Posts: 1836
Re: Switch recommendation wanted
« Reply #4 on: January 02, 2020, 05:33:30 PM »

Define 'very high functionality'. Won't basic VLAN support be enough if just using it as a switch?
Logged

Weaver

  • Senior Kitizen
  • ******
  • Posts: 11459
  • Retd s/w dev; A&A; 4x7km ADSL2 lines; Firebrick
Re: Switch recommendation wanted
« Reply #5 on: January 02, 2020, 09:24:44 PM »

I’m after security functions, LAN infrastructure defence, QoS and IPv6-speaking admin i/f and generally equal status
Logged

niemand

  • Kitizen
  • ****
  • Posts: 1836
Re: Switch recommendation wanted
« Reply #6 on: January 02, 2020, 11:30:36 PM »

Understood. I've no recommendations, most enterprises I work with don't have switches with that functionality activated  :lol:
Logged

Weaver

  • Senior Kitizen
  • ******
  • Posts: 11459
  • Retd s/w dev; A&A; 4x7km ADSL2 lines; Firebrick
Re: Switch recommendation wanted
« Reply #7 on: January 03, 2020, 11:15:31 AM »

I seem to dimly recall reading a Cisco manual about a device with infrastructure defence mechanisms and it wasn’t hellishly expensive either, but now I’ve perhaps lost track of such a thing, if it ever was a reality.
Logged

niemand

  • Kitizen
  • ****
  • Posts: 1836
Re: Switch recommendation wanted
« Reply #8 on: January 03, 2020, 11:21:37 AM »

Are you perhaps thinking of broadcast storm protection, Sir?
Logged

d2d4j

  • Kitizen
  • ****
  • Posts: 1103
Re: Switch recommendation wanted
« Reply #9 on: January 03, 2020, 12:56:28 PM »

Hi

Weaver current hp procurve switch already has storm protection as standard.

Many thanks

John
Logged

Weaver

  • Senior Kitizen
  • ******
  • Posts: 11459
  • Retd s/w dev; A&A; 4x7km ADSL2 lines; Firebrick
Re: Switch recommendation wanted
« Reply #10 on: January 03, 2020, 04:08:04 PM »

I’ve seen protection from malicious hosts who try to spoof dhcp server, dns server or the default gateway - or faking arp/ndp that kind of thing, locking down arp/ndp so that known good port placements for critical hosts are fixed.

The thing is, it wouldn’t help me much, seeing as the potentially malicious hosts are wireless so they’re all on one shared ethernet port into the switch. I currently have L2_isolation ACLs without VLANs in my ZyXEL WAP which keeps malicious stations in a box at L2. Isolates dubious stations from one another and only allows them to talk to boxes on a whitelist, and my whitelist comprises only the critical servers they need to function and thr addresses they need get out to the internet, so that is only the local dns caching proxy server, dhcp server and default gateway and nothing else. That entire list comes down to a single address which is the LAN-facing address of the Firebrick router on the LAN.

But when I saw this iirc Cisco functionality, I thought "Why buy less”.

The hpe switch I have now has a list of IPv4-only anti-DOS defences plus storm control but it has never heard of IPv6 is fairly useless to me and none of the anti spoofing, malicious takeover threats mentioned in the Cisco docs.
« Last Edit: January 03, 2020, 04:24:34 PM by Weaver »
Logged

niemand

  • Kitizen
  • ****
  • Posts: 1836
Re: Switch recommendation wanted
« Reply #11 on: January 04, 2020, 06:29:03 PM »

I'm planning to get a couple of https://mikrotik.com/product/crs305_1g_4s_in

Maybe some kit running the same software would be adequate for your needs?

https://wiki.mikrotik.com/wiki/SwOS/CRS3xx
Logged
 

anything