System-Guard Permit - H3C S3100 Series Command Manual

Hide thumbs Also See for S3100 Series:
Table of Contents

Advertisement

Use the undo system-guard mode command to revert to the default system-guard configuration.
Related command: display system-guard config.
Example
# Implement the system-guard function by means of port rate limit, with the checking interval being 5
seconds, the threshold being 100, and the timeout time being 30 seconds.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] system-guard mode rate-limit 5 100 30
Upon detection of an attacked port, an S3100-SI switch applies a port rate limit of 64 kbps to the port.

system-guard permit

Syntax
system-guard permit interface-list
undo system-guard permit interface-list
View
System view
Parameter
permit: Specifies the ports to which with the system-guard function is to be applied.
interface-list: Specifies an Ethernet port list, which can contain multiple Ethernet ports. The interface-list
argument is in the format of interface-list = { interface-type interface-number [ to interface-type
interface-number ] } & <1-10>, where interface-type represents the port type, interface-number
represents the port number, and & <1-10> means that you can provide up to 10 port indexes/port index
lists for this argument. The start port number must be smaller than the end number and the two ports
must of the same type.
Description
Use the system-guard permit command to specify the ports to which the system-guard function is to
be applied to. A switch checks the ports with the system-guard function applied regularly for attacked
ports.
Use the undo system-guard permit command to disable the system-guard function for specified ports.
5-3

Advertisement

Table of Contents
loading

Table of Contents