Monday 7 April 2008

End-to-end QoS - Control Plane Policing (CoPP)

Packets destined for the control-plane generally include routing protocol control packets, SNMP management traffic, packets destined for the local router's IP address, for example telnet.

It is important to configure QoS for the control-plane in order to prevent DoS attacks that could damage the network infrastructure, for example:

- High CPU utilisation
- Loss of routing updates and keep-alives, resulting in routing-flaps
- Slow response times including access through CLI and VTY lines
- Queue build-ups resulting in packet drops

MQC can be used to define 'trusted' traffic that is allowed un-restricted access to the control-plane, whilst policing all other traffic. QoS policies can be applied to the control-plane in the similar fashion as a router interface.

No comments: