Infrastructure Security - Troubleshooting Control Plane Policing (CoPP
6 important questions on Infrastructure Security - Troubleshooting Control Plane Policing (CoPP
What are the 4 steps to configure Control Plane Policing (CoPP)?
- Create ACLs to identify the traffic
- Create class maps to define a traffic class
- Create policy maps to define a service policy
- Apply the service policy to the control plane
What are 5 points to focus on when troubleshooting ACLs for CoPP?
- Grouping - Have different protocols been grouped together but shouldn't have.
- Action - A permit action applies the CoPP policy, a deny action ignores the traffic.
- Protocol - Is the correct protocol defined in the ACL
- Source and Destination - Is the correct source and destination defined.
- Operators and ports - Are operators (Greater-than or equal-to) and ports defined correctly
What are 5 points to look at when troubleshooting class maps for CoPP?
- Access Group - Is the correct ACL applied
- Instruction - match-any vs match-all (important with multiple match statements)
- Protocol - If an ACL is not used is the correct protocol defined in the match statement.
- IP PREC/IP DSCP - Is it correct if chosen instead of ACL
- Case - ACL names are case sensitive
- Higher grades + faster learning
- Never study anything twice
- 100% sure, 100% understanding
What is important to remember when troubleshooting policy-maps for CoPP?
- Order of operations - Policy maps are process from the top down
- Class map - has the correct class map been defined
- Policy - Has the correct CIR or RATE been applied
- Default class - How is the default class configured. For all traffic not matching defined classes
- Case - Class map names are case sensitive
What are 3 points to focus on when configuring a Service Policy for CoPP?
- Interface - has it been applied to the correct interface?
- Direction - must the policy be applied for ingress or egress traffic?
- Case - the Policy map name is case sensitive.
What are the 4 basic steps to troubleshoot CoPP?
- Verify Service Policy. Correct direction?
show policy-map control-plane - Verifiy Policy Map.
show policy-map control-plane
show policy-map - Verify Class Map
show class-map - Verify the ACL
show access-list
The question on the page originate from the summary of the following study material:
- A unique study and practice tool
- Never study anything twice again
- Get the grades you hope for
- 100% sure, 100% understanding