Interface Modes | L2, L3, tap, virtual wire (transparent mode) |
Routing | OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing Policy-based forwarding Point-to-Point Protocol over Ethernet (PPPoE) and DHCP supported for dynamic address assignment Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3 Bidirectional Forwarding Detection (BFD) |
SD-WAN | Path quality measurement (jitter, packet loss, latency) Initial path selection (PBF) Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) |
IPv6 | L2, L3, tap, virtual wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL Decryption SLAAC |
IPsec and SSL VPN | Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) Encryption: 3des, AES (128-bit, 192-bit, 256-bit) Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512 GlobalProtect Large Scale VPN for simplified configuration and management* Secure access over IPsec and SSL VPN tunnels using GlobalProtect gateway and portals* |
VLANs | 802.1Q VLAN tags per device/per interface: 4,094/4,094 Aggregate interfaces (802.3ad), LACP |
Network Address Translation | NAT modes (IPv4): static IP, dynamic IP, Dynamic IP and Port (port address translation) NAT64, NPTv6 Additional NAT features: dynamic IP reservation, tunable Dynamic IP and Port oversubscription |
High Availability | Modes: active/active, active/passive, HA clustering Failure detection: path monitoring, interface monitoring |
Mobile Network Infrastructure† | 5G Security GTP Security SCTP Security |