H3C S2600 series switches support the unique ARP intrusion detection function, which can effectively prevent hackers or attackers from implementing the increasingly popular "ARP spoofing attack" through ARP packets. Support IP Source Guard feature to prevent illegal address spoofing including MAC spoofing, IP spoofing, MAC / IP spoofing, and DoS attacks. In addition, the use of DHCP Snooping's trusted port feature can also effectively prevent private DHCP servers and ensure the authenticity and consistency of the DHCP environment. H3C S2600 series switches support the port security feature family, which can effectively prevent attacks based on MAC addresses and allow / restrict traffic based on MAC addresses. H3C S2600 series switches have powerful hardware ACL capabilities, can deeply identify packets, support L2 to L4 packet filtering, and provide source MAC address, destination MAC address, source IP address, destination IP address, IP protocol type, and TCP / UDP ports. , TCP / UDP port range, VLAN, VLAN range, etc. to define ACLs so that the switch can perform subsequent processing to achieve flexible and secure access control. H3C S2600 series switches provide 802.1X and MAC authentication methods to authenticate access users, support client software version detection, Guest VLAN and other functions, and cooperate with iMC can also achieve proxy detection, dual network card detection and other functions. Through the application of these functions, the legitimacy of users can be fully checked and controlled, and the harm to network security by illegal users can be reduced to the greatest extent.