Chapter 2: About the CSX4002-16CyberSWITCH CSX400 and CSX400-DC Installation GuideIEEE 802.1d Bridging — The CSX400 supports the IEEE 802.1d standard for LAN to LANbridging. Bridging is provided over PPP and Frame Relay as well as adjacent LAN ports. Thebridging software uses transparent bridging. When the CSX400 is configured as a bridge, the unitbridges data packets to the destination, regardless of the network protocols used. The CSX400 usesthe Spanning Tree Algorithm to provide bridging redundancy while preventing data loops andduplicate data. This is a self-learning bridge, i.e., the bridge builds and updates an address tablewith each MAC source address and associated information when the packets are received.IP Routing — IP routing support provides the ability to process TCP/IP frames at the networklayer for routing. IP routing support includes the Routing Information Protocol (RIP) that allowsthe exchange of routing information on a TCP/IP network. The CSX400 receives and broadcastsRIP messages to adjacent routers and workstations.IPX Routing — Internet Packet Exchange (IPX) routing support provides the ability to processNovell proprietary frames at the network layer for routing. IPX routing support includes bothRouting Information Protocol (RIP) and Service Advertising Protocol (SAP) that allows theexchange of routing information on a Novell NetWare network. The SAP provides routers andservers containing SAP agents with a means of exchanging internetwork service information.Bridging and Routing Protocol FilteringFiltering is used to allow efficient usage of network resources and provide security for yournetwork and hosts.IP Internet Firewall — The CSX400 supports IP Internet Firewall filtering to preventunauthorized access to your system and network resources from the Internet or a corporateIntranet. Security can be configured to permit or deny IP traffic. The security is established byconfiguring IP access filters, which are based on source IP address, source mask, destination IPaddress, destination mask, protocol type, and application port identifiers for both TransmissionControl Protocol (TCP) and User Datagram Protocol (UDP) protocols. These IP access filtersallow individual IP source and destination pair filtering as well as IP address ranges and wildcarding to match any IP address. These Firewall filters can be defined to allow inbound only,outbound only, or bi-directional IP communication up to the UDP and TCP application port level.Firewall access filters provide a lot of flexibility to establish a powerful IP security barrier. TheCSX400 supports the IP Access Control (from the ctip-mib) Internet Firewall Filter.