11. Security and Reliability Functions
1. The tenderer shall specify whether his/her products support the following security functions, and specify their implementation process:
MAC address filtering
IP address filtering
MAC address anti-spoofing
IP anti-spoofing
Ethernet Access List
IP Access List
Limitation of broadcast storms (in which way, exceptions, etc)
Limitation traffic of ARP packet
Blocking of user-to-user flows
Limitation of MAC address base on service flow
Dynamic binding MAC address base on service flow
2. The tenderer shall specify the IGMP versions and the associated security functions supported by his products.
3. The tenderer shall specify the security functions enabling to protect his products during management operations. The GPON shall support Radius authentication for operators.
4. Please describe in detail the mechanism in GPON to ensures security between L2 customers
5. Please describe the mechanism in GPON to protect users against the following attacks from other users connected on the same device:
ARP spoofing / ARP cache poisoning
IP spoofing
DHCP spoofing
Broadcast flooding
MAC address spoofing
MAC flooding
6. GPON shall support SSH V2 function for user logging in.
7. The tenderer is invited to describe all the other security functionalities supported by his products
8. The proposed equipment shall support BFD for static route, OSPF, IS-IS, BGP/BGP4+, RSVP and the detection time shall be less than 50ms.
9. The proposed equipment shall support ring-detection function in order to prevent loop-back in user side
10. The proposed equipment can detect the optical power transmission of every ONT, once that it detects some problems in the status of the optical transmission power , the system shall disable the defective ONT automatically in order to guarantee the normally use of the others.
11. The proposed equipment can shutdown the power of service board automatically when the service board temperature is higher than the limitation and also can start-up when the temperature becomes normal.
12. The proposed equipment shall support service overload control function.
13. The proposed equipment shall be provided with 1+1 redundant network interface. The redundant (i.e. standby) network interface shall automatically take over from the primary (i.e. live) network interface when the latter fails. The duration of protection switching shall be less than 50ms. Details of this implementation shall be provided.
14. The proposed equipment shall support 1:1 VMAC and N:1 VMAC.