Control Plane Policing (Copp); Overview - Dell Force10 Z9000 Configuration Manual

Ftos configuration guide for z9000 system
Hide thumbs Also See for Force10 Z9000:
Table of Contents

Advertisement

Control Plane Policing (CoPP)

Control Plane Policing (CoPP)

Overview

Control Plane Policing (CoPP) uses ACL rules and QoS policies to create filters for a system's control
plane. That filter prevents traffic not specifically identified as legitimate from reaching the system control
plane, rate-limits, traffic to an acceptable level.
Control Plane Policing (CoPP) increases security on the system by protecting the Routing Processor from
unnecessary or DoS traffic, giving priority to important control plane and management traffic. CoPP uses a
dedicated control plane configuration through the ACL and QoS CLIs to provide filtering and rate-limiting
capabilities for the control plane packets.
Figure 11-1. CoPP architecture example
OPSF
ICMP
PING
Packets
Figure 11-2
show an example of the difference bet wen having CoPP implemented and not having CoPP
implemented.
is supported on platforms:
Hardware Queue
Rate Limiting
OSPF, VRRP, RIPv2,
Q7
IGMP, PIM, xSTP,
1100 PPS
LACP, PVST, GVRP, LLDP
BGP, ICMP Echo, ICMP
Q6
Reply, ARP Reply, NTP
400 PPS
L3 Local Traffic
ARP Req, DHCP, Unknown L3,
Q5
L2 Broadcast on L3 VLAN,
400 PPS
Broadcast L2 DST on VLAN6095
Q4
Stacking, IPC, IRC, VLT
2000 PPS
Q3
sFlow
300 PPS
MAC Learning Limit
Q2
Violation Log, HyperPull
300 PPS
Q1
MC Data
300 PPS
Q0
BFD
1300 PPS
z
CoPP Rule
Examples
200 PPS
50 PPS
Per-Protocol
Rate Limiting
OSPF 200 PPS
BGP 100 PPS
STP 100 PPS
ICMP 50 PPS
.
.
.
.
Control Plane Policing (CoPP) | 279
11
OPSF
ICMP
PING

Advertisement

Table of Contents
loading

Table of Contents