Overview of features and benefits
The HP ProCurve Switch 8200zl, 5400zl, 3500, and 6200yl series use the same software image base and ship
with the Intelligent Edge feature set standard. For the HP ProCurve Switch 8200zl, 5400zl, and 3500 series,
the IP Base Routing feature set is also standard; an optional Premium License is available to enable Advanced
Routing features. For the HP ProCurve Switch 6200yl, the Advanced Routing feature set is also standard. The IP
Base Routing feature set includes Static Routing and RIP. In addition to OSPF, the Advanced Routing feature set
includes additional aggregation layer features: Q-in-Q, PIM-SM, PIM-DM, OSPF-ECMP, and VRRP. The primary
differences among these switch families are hardware-related and include such aspects as port density and the
number of power supplies and fans.
The following summary of features and benefits applies to the HP ProCurve Switch 8200zl, 5400zl, 3500, and
6200yl series. Any differences that exist among the switches are noted.
Performance
•ProVisionASICtechnology:poweredbytheProVisionASICs,theswitchfamiliesofferstate-of-the-arthigh-
capacity switch fabric performance—691.2 Gbps for the 8212zl/5412zl, 345.6 Gbps for the 8206zl/5406zl,
153.6 Gbps for the 3500yl-48G-PWR, 105.6 Gbps for the 3500yl-24G-PWR and 6200yl-24G-mGBIC,
16.8 Gbps for the 3500-48 and 3500-48-PoE, and 12.0 Gbps for the 3500-24 and 3500-24-PoE.
•Selectablequeueconfigurations:increaseperformancebyselectingthenumberofqueuesandassociated
memory buffer that best meet the requirements of network applications.
Security features
•VirusThrottle:connectionRateFilteringthwartsvirusspreadingbyblockingroutingfromcertainhosts
exhibiting abnormal traffic behavior
•ICMPthrottling:defeatsICMPdenial-of-serviceattacksbyenablinganyswitchporttoautomaticallythrottle
ICMP traffic
•Filteringcapabilities:includefast,flexibleAccessControlLists(ACLs),upto3,000permodule(inlater
release, more precise detailed control via the fast Policy Enforcement Engine), source port, multicast MAC
address, and other protocol-based filtering capabilities
•SwitchCPUprotection:providesautomaticprotectionagainstmaliciousnetworktraffictryingtoshutdownthe
switch
•Detectionofmaliciousattacks:monitorstentypesofnetworktrafficandsendsawarningifananomaly
occurs, signaling the detection of a potential malicious attack
•USBsecureautorun:usesUSBflashdrivetodeploy,troubleshoot,orupdateswitches;workswithsecure
credential to prevent tampering
•STProotguard:protectsSTProotbridgefrommaliciousattackorconfigurationmistakes
•DHCPprotection:blocksDHCPpacketsfromunauthorizedDHCPservers,preventingdenial-of-serviceattack
•BPDUportprotection:blocksBridgeProtocolDataUnit(BPDU)onportsthatdonotrequireBPDU,preventing
forged BPDU attack
•DynamicARPprotection:blocksAddressResolutionProtocol(ARP)broadcastfromunauthorizedhosts,
preventing eavesdropping or data theft of network data
•DynamicIPlockdown:workswithDHCPprotectiontoblocktrafficfromunauthorizedhost,preventingIP
source address spoofing
•IdentityDrivenManager:supportsHPProCurveIdentityDrivenManager(IDM)whichcandynamicallyapply
per-user security, access, and performance settings to infrastructure devices based on approved user, location,
and time
43