Control Plane Policing (Copp); Copp Implementation; Protocol-Based Control Plane Policing - Dell C9000 Series Networking Configuration Manual

Hide thumbs Also See for C9000 Series:
Table of Contents

Advertisement

Control Plane Policing (CoPP)

Control plane policing (CoPP) protects the switch's routing, control, and line-card processors from undesired
or malicious traffic and Denial of Service (DoS) attacks by filtering control-plane flows.
CoPP uses a dedicated control-plane service policy that consists of ACLs and QoS policies, which provide
filtering and rate-limiting capabilities for control-plane packets. CoPP is only applied to control-plane packets
destined to CPUs on the switch, and not to transit protocol-control packets and data traffic that is passing
through the switch. CoPP prevents undesired or malicious traffic from reaching the control-plane CPUs and
rate limits legitimate control-plane traffic to acceptable limits.
Topics:

CoPP Implementation

CoPP Example
Configure Control Plane Policing
Troubleshooting CoPP Operation
CoPP Implementation
The system's control plane consists of multi-core CPUs with internal queues for handling packets destined to
the Route Processor, Control Processor, and line-card CPUs.
On the system, CoPP is implemented as a distributed architecture. In this architecture, CoPP operates
simultaneously in both distributed and aggregated modes. Distributed CoPP is achieved by applying protocol
rate-limiting on each port pipe on a line card. Aggregated CoPP is achieved by applying protocol rate-limiting
followed by queue rate-limiting on the centralized control plane switch.
To configure a CoPP service policy, you create extended ACL rules and specify rate limits in QoS policies.
QoS rate limits are applied to a protocol-based ACL filter or to a CPU queue.
User-configured ACLs that filter protocol traffic flows to the control plane are automatically applied or
disabled as the corresponding protocol is enabled or disabled in the system. In this way, control packets from
disabled protocols never reach the control plane.

Protocol-based Control Plane Policing

To configure a protocol-based CoPP policy, you create an extended ACL rule for the protocol and specify the
rate limit in a QoS policy. It is not necessary to specify the CPU queue because the protocol to queue
mapping is handled internally by the system. To display the protocol-queue mapping for protocols that you
can configure for protocol-based CoPP, enter the show {mac | ip | ipv6} protocol-queue-mapping command.
Control Plane Policing (CoPP)
10
268

Advertisement

Table of Contents
loading

Table of Contents