315
By default, the system-guard control function is disabled on a port.
Examples
# Enable system-guard control function on GigabitEthernet 1/0/1.
<sysname> system-view
[sysname] interface gigabitethernet 1/0/1
[sysname-GigabitEthernet1/0/1] system-guard control
system-guard detect-threshold
Syntax
system-guard detect-threshold
threshold-value
undo system-guard detect-threshold
View
System view
Default level
2: System level
Parameters
detect-threshold
threshold-value
: Set a rate threshold in the range of 50 to 1000, in pps (packets per
seconds).
Description
Use the
system-guard detect-threshold
command to set a rate threshold for system-guard. If the number
of packets a port submits to the CPU in a second exceeds the specified threshold, system-guard
determines that the port is under an attack.
Use the
undo
system-guard detect-threshold
command to restore the default.
By default, the rate threshold is 300 pps.
Examples
# Set the rate threshold for system-guard to 200 pps.
<Sysname> system-view
[Sysname] system-guard detect-threshold 200
system-guard enable
Syntax
system-guard enable
undo system-guard enable
View
Layer 2 Ethernet port view
Default level
2: System level
Parameters
None