xStack® DGS-3120 Series Layer 3 Managed Gigabit Ethernet Switch Web UI Reference Guide
395
Figure 8-91 Trusted Host window
When the user clicks the Edit button, one will be able to edit the service allowed to the selected host.
The fields that can be configured are described below:
Parameter Description
Click the Add button to add a new entry based on the information entered.
Click the Delete All button to remove all the entries listed.
Click the Edit button to re-configure the specific entry.
Click the Delete button to remove the specific entry.
Safeguard Engine Settings
Periodically, malicious hosts on the network will attack the Switch by utilizing packet flooding (ARP Storm) or other
methods. These attacks may increase the switch load beyond its capability. To alleviate this problem, the
Safeguard Engine function was added to the Switch’s software.
The Safeguard Engine can help the overall operability of the Switch by minimizing the workload of the Switch while
the attack is ongoing, thus making it capable to forward essential packets over its network in a limited bandwidth.
The Safeguard Engine has two operating modes that can be configured by the user, Strict and Fuzzy. In Strict
mode, when the Switch either (a) receives too many packets to process or (b) exerts too much memory, it will enter
the Exhausted mode. When in this mode, the Switch will drop all ARP and IP broadcast packets and packets from
un-trusted IP addresses for a calculated time interval. Every five seconds, the Safeguard Engine will check to see if
there are too many packets flooding the Switch. If the threshold has been crossed, the Switch will initially stop all