| Interface Modes | L2, L3, tap, virtual wire (transparent mode) | 
		
			| Routing | OSPFv2/v3 with graceful restart, BGP with graceful restart, RIP, static routing Policy-based forwarding
 Point-to-Point Protocol over Ethernet (PPPoE)
 Multicast: PIM-SM, PIM-SSM, IGMP v1, v2, and v3
 Bidirectional Forwarding Detection (BFD)
 | 
		
			| SD-WAN | Path quality measurement (jitter, packet loss, latency) Initial path selection (PBF)
 Dynamic path change
 | 
		
			| IPv6 | L2, L3, tap, virtual wire (transparent mode) Features: App-ID, User-ID, Content-ID, WildFire, and SSL Decryption
 SLAAC
 | 
		
			| IPsec VPN | Key exchange: manual key, IKEv1, and IKEv2 (pre-shared key, certificate-based authentication) Encryption: 3DES, AES (128-bit, 192-bit, 256-bit)
 Authentication: MD5, SHA-1, SHA-256, SHA-384, SHA-512
 GlobalProtect large-scale VPN for simplified configuration and management
 | 
		
			| VLANs | 802.1Q VLAN tags per device/per interface: 4,094/4,094 Aggregate interfaces (802.3ad), LACP
 | 
		
			| Network Address Translation | NAT modes (IPv4): static IP, dynamic IP, dynamic IP and port (port address translation) NAT64, NPTv6
 Additional NAT features: dynamic IP reservation, tunable dynamic IP and port oversubscription
 | 
		
			| High Availability | Modes: active/active, active/passive, HA clustering Failure detection: path monitoring, interface monitoring
 | 
		
			| Mobile Network Infrastructure | GTP Security SCTP Security
 |