Supports automatic display of the source MAC address of the host
that launches an attack, and automatic binding of IP and MAC
addresses, to prevent the ARP tables of normal users from being
tampered in ARP spoofing and gateway IP addresses from being
forged in ARP attacks.
The ARP traffic of each user can be limited and users with
abnormal ARP traffic may be automatically blacklisted.
Supports effective protection against various DOS attacks (such
as ARP attack, Synflood attack, Smurf attack, ICMP attack), ARP
monitoring, network worms and Blaster virus attack.
Supports port trust functions to detect illegitimate DHCP servers
and Radius servers.
Supports Unicast Reverse Path check (URPF), which can
effectively prevent IP address forgery and attacks.
Supports ACL-based flow filtering.
Supports IEEE 802.1x and AAA/Radius authentication.
Enables users to bind IP addresses, VLAN IDs, MAC addresses
and port numbers.
Supports DHCP Option82, and PPPoE + so that the physical
location information of users can be uploaded.
Supports plaintext authentication of OSPF, RIPv2 and BGPv4
packets and MD5 ciphertext authentication.
Supports IP Source Guard, guaranteeing DHCP service security.
Supports RFC3176 sFlow traffic analysis, achieving protocol or
address-based traffic monitoring and statistics.
Supports broadcast packet suppression.
Supports data logging and RFC 3164 BSD syslog Protocol.
Supports SSHv2 Secure Shell.
Supports login through Telnet of Security IP and password-based
login.
Supports hierarchical user protection to prevent intrusion from
unauthorized users, and grants different levels of users different
configuration rights.