
Operation Manual – 802.1x and System Guard
H3C S5600 Series Ethernet Switches
Chapter 4 System Guard Configuration
4-3
To do...
Use the command...
Remarks
Enable System Guard
against TCN attacks
system-guard tcn
enable
Required
Disabled by default
Set the threshold of
TCN/TC packet receiving
rate
system-guard tcn
rate-threshold
rate-threshold
Optional
1 pps by default
Note:
As the system monitoring cycle is 10 seconds, the system sends trap and log
information if more than 10 TCN/TC packets are received within 10 seconds by default.
If the TCN/TC packet receiving rate is lower than the set threshold within a 10-second
monitoring cycle, the system will not send trap or log information in the next 10-second
monitoring cycle.
4.2.3 Enabling Layer 3 Error Control
Follow these steps to enable Layer 3 error control:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Enable Layer 3 error
control
system-guard l3err
enable
Required
Enabled by default
4.3 Displaying and Maintaining System Guard Configuration
To do...
Use the command...
Remarks
Display the monitoring
result and parameter
settings of System Guard
against IP attacks
display system-guard ip
state
Display the information
about IP packets received
by the CPU
display system-guard
ip-record
Display the status of
Layer 3 error control
display system-guard
l3err state
Display the status of TCN
display system-guard
tcn state
Available in any view