31-1
31
System Guard Configuration
The CPU protection function is added. See
CPU Protection
and
Configuring CPU Protection
.
e
, go to these sections for information you are interested in:
Wh n configuring System Guard
z
System Guard Overview
Configuring System Guard
z
stem Guard Configuration
z
Displaying and Maintaining Sy
ew
Guar
Guard enabled will take the following action: If the packets from the source IP address
need to be processed by the CPU, the switch decreases the precedence of delivering such packets to
Guar
CN/TC packets within a given period of time, the switch sends only one
TCN/TC packet in every 10 seconds to the CPU and discards the rest TCN/TC packets, while outputting
n.
Layer
With the Layer 3 error control feature enabled, the switch delivers all Layer 3 packets that the switch
error packets to the CPU.
CPU
PU protection function allows you to control the amount of
packets sent to the CPU within a given time period by setting the CPU protection parameter, thus
preventing exceptionally high CPU usage.
System Guard Overvi
d Against IP Attacks
System-guard operates to inspect the IP packets over 10-second intervals for the CPU for suspicious
source IP addresses. Once the packets from such an IP address hit the predefined threshold, the switch
with System
the CPU.
d Against TCN Attacks
System Guard monitors the rate at which TCN/TC packets are received on the ports. If a port receives
an excessive number of T
trap and log informatio
3 Error Control
considers to be
Protection
When the device is under attack, a large amount of packets will be sent to the device CPU for
processing, which causes the device CPU usage to become exceptionally high and thus adversely
affects normal services on the device. The C