Feature
Description
MAC address authentication
Portal authentication
ARP security
Dynamic ARP Inspection (DAI) and Static ARP Inspection (SAI)
Egress ARP Inspection (EAI)
ARP packet suppression based on source IP addresses, interfaces,
and VLANs, and global ARP packet suppression
IP security
ICMP attack defense
IP source guard
Local attack
defense
CPU attack defense
MFF
MAC-Forced Forwarding (MFF)
DHCP
Snooping
DHCP Snooping
Option 82 and dynamic DHCP packet rate limiting
Attack
defense
Defense against flood attacks without IP payloads, attacks from
IGMP null payload packets, LAND attacks, Smurf attacks, and
attacks from packets with invalid TCP flag bits
Defense against attacks from many fragments, attacks from many
packets with offsets, attacks from repeated packet fragments,
Tear Drop attacks, Syndrop attacks, NewTear attacks, Bonk
attacks, Nesta attacks Rose attacks, Fawx attacks, Ping of Death
attacks, and Jolt attacks
Defense against TCP SYN flood attacks, UDP flood attacks
(including Fraggle attacks and UDP diagnosis port attacks), and
ICMP flood attacks
Network
manage
ment
-
Ping and traceroute
Network Time Protocol (NTP)
HTTP
Hypertext Transfer Protocol Secure (HTTPS)
SNMPv1/v2/v3
Standard MIB
Remote network monitoring (RMON)
S1720 Series Ethernet Switches
Product Description
4 Product Performance
Issue 01 (2014-07-20)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
24