DGS-3700-12/DGS-3700-12G Series Layer 2 Gigabit Ethernet Switch User Manual
145

Section 5

Security
Safeguard Engine
Trusted Host
IP-MAC-Port Binding
Port Security
DHCP Server Screening Settings
802.1X
SSL Settings
SSH
Access Authentication Control
MAC-based Access Control
Web Authentication
NetBIOS Filtering

Safeguard Engine

Periodically, malicious hosts on the network will attack the Switch b y utilizing packet flooding ( ARP Storm) or other
methods. These attacks may increase the Safeguard Engine be yond its capability. To alleviate this problem, the
Safeguard Engine function was added to the Switch’s software.
The Safeguard Engine can help the overall operability of the Switch b y minimizing the workload of the Switch while the
attack is ongoing, thus making it capable to forward essential pack ets over its network in a limited bandwidth. W hen
the Switch either (a) receives too many packets to process or (b) exerts too m uch mem ory, it will enter an Ex hausted
mode. When in this mode, the Switch only receives a small amount of ARP or IP broadcast pack ets for a calculated
time interval. Every five seconds, the Switch will check to see if there are too many packets flooding the Switch. If the
threshold has been crossed, the Switch will do a rate limit and only allow a sm all amount of ARP and IP broadcast
packets for five seconds. After another five-second checking interval arrives, t he Switch will again check the ingress
flow of packets. If the flooding has stopped, the Switch will a gain begin accepting all pack ets. Yet, if the checking
shows that there continues to be too many packets floodi ng the Switch, it will still only accept a small amount of ARP
and IP broadcast packets for double the time of the previous sto p period. This doubling of time for stopping ingr ess
ARP and IP broadcast packets will continue until the maximum time has bee n reached, which is 320 seconds an d
every stop from this point until a return to normal ingress flow would be 320 se conds. For a better understanding,
examine the following example of the Safeguard Engine.