Operation Manual – 802.1x-System Guard
H3C S3100 Series Ethernet Switches
Chapter 5 System-Guard Configuration (For S3100-SI)
5-2
5.2.2 Configuring System-Guard-Related Parameters
Table 5-2
lists the operations to configure system-guard-related parameters, including
system-guard mode, checking interval, threshold (in terms of the number of the
received packets), and controlling period. Note that the configuration takes effect only
after you enable the system-guard function.
Table 5-2
Configure system-guard related parameters
Operation
Command
Description
Enter system view
system-view
—
Configure
system-guard-relat
ed parameters
system-guard mode
rate-limit interval-time
threshold timeout
Required
The default system-guard-related
parameters are as follows.
interval-time
: 5 seconds
threshold
:
64
timeout
: 60 seconds
5.2.3 Enabling System-Guard on Ports
Table 5-3
lists the operations to enable system-guard on ports.
Table 5-3
Enable system-guard on ports
Operation
Command
Description
Enter system view
system-view
—
Enable system-guard on
specified ports
system-guard permit
interface-list
Required
Note:
After system-guard is enabled on a port, if the number of packets the port received and
sent to the CPU in a specified interval exceeds the specified threshold, the system
considers that the port is under attack and begins to limit the packet receiving rate on
the port (this function is also called inbound rate limit). if the rate of incoming packets on
the port exceeds the threshold of inbound rate limit, any service packets, including
BPDU packets, are possible to be dropped at random, which may result in state
transition of STP.