Discovery 26: Configure Control Plane Policing: Task 1: Configure and Verify Copp On R1
Discovery 26: Configure Control Plane Policing: Task 1: Configure and Verify Copp On R1
com/content/xtrac/2
To configure Control Plane Policing, you must complete the following tasks:
Create ACLs that will identify the control plane traffic that needs to be policed by CoPP. The definition of these ACLs is one of the most critical steps in the CoPP process. MQC uses these ACLs to define the traffic classes, which in turn become the object of the policy actions (policing).
Create traffic classes that describe valid control plane traffic (ACL permit statements). You can configure as many traffic classes as you need, depending on the required granularity of your policy.
Create a traffic policy that will permit, deny, or rate-limit the configured traffic classes and therefore conserve process layer resources, or even act as a device firewall by hiding most device resources from the network.
Apply the configured traffic policy to the control plane.
Activity
Step 1: On R1, configure the following ACLs. These ACLs will be used to identify traffic going to the router’s management and control plane and that will be policed by CoPP
Password: (cisco)
R1>
Step 8: On R1, use the show policy-map control-plane command to investigate CoPP policing of ICMP and Telnet packets.
On R1, enter the following command:
R1# show policy-map control-plane
Control Plane