Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityEasy
A network security engineer is configuring a Cisco router to protect its control plane from denial-of-service attacks by rate-limiting traffic destined for the router's CPU. Which of the following mechanisms should be used to achieve this goal?
- AManagement Plane Policing (MPP)
- BNetwork Access Control (NAC)
- CControl Plane Policing (CoPP)
- DData Plane Policing (DPP)
Show answer & explanationAnswer & explanation
Correct answer: C. Control Plane Policing (CoPP)
Control Plane Policing (CoPP) is specifically designed to protect the router's control plane, which includes the CPU, from excessive traffic that could lead to performance degradation or denial-of-service. It uses QoS policies to classify and rate-limit traffic destined for the router itself.
Why the other options are wrong
- A. Management Plane Policing (MPP) focuses on traffic for management protocols like SSH/Telnet, not general control plane traffic.
- B. Network Access Control (NAC) is used for authenticating and authorizing users/devices accessing the network, not for protecting the router's internal components.
- D. Data Plane Policing (DPP) applies to traffic forwarding through the router, not traffic destined for the router's CPU.
Control Plane Policing (CoPP)
A quality of service (QoS) feature on Cisco devices that protects the router's control plane (CPU) from excessive traffic, ensuring the router remains stable and accessible.
- Protects the CPU from denial-of-service attacks.
- Uses class maps and policy maps to classify and rate-limit traffic.
- Applies to traffic destined for the router itself.
Memory trick: Planes need Police to stay safe.