12.2 Control Plane Policing (CoPP): Protecting the Route Processor with MQC

Key Takeaways

  • Enterprise network devices separate operations into the Data Plane (hardware ASICs executing line-rate transit forwarding) and the Control Plane (the Route Processor / CPU managing routing protocols, signaling, and administrative sessions).

  • Distributed Denial of Service (DoS) attacks, malformed packets, and broadcast storms directed at the device IP address can overwhelm the Route Processor, triggering high CPU utilization, routing adjacency loss, and administrative lockout.

  • Control Plane Policing (CoPP) protects the Route Processor by treating it as an inbound logical interface (control-plane) managed through Cisco Modular QoS CLI (MQC).

  • CoPP establishes a three-tier architecture: Class Maps identify and classify traffic via ACLs, Policy Maps define policing thresholds and burst limits, and a Service Policy enforces rate limiting in the inbound direction.

  • In CoPP policies, critical routing protocols (BGP, OSPF, EIGRP) and essential infrastructure traffic (ARP, ICMP, DHCP) are segregated from management sessions (SSH, SNMP) and default untrusted traffic, ensuring protocol stability during volumetric floods.

Last updated: October 2026

Control Plane Policing (CoPP): Protecting the Route Processor with MQC

Modern enterprise campus and core routers are architected around distributed hardware pipelines designed to switch millions of packets per second without host CPU intervention. However, all network devices possess a finite, shared computational resource: the Route Processor (RP), or central CPU. When malicious actors launch distributed denial-of-service (DoS) attacks, network recon sweeps, or protocol flood exploits, the resulting packet influx targets the control plane. Without protection, route processor exhaustion causes dropped routing keepalives, collapsing routing protocols, network-wide route flap, and total management lockout. Control Plane Policing (CoPP) prevents these catastrophic failures by treating the route processor as an interface and enforcing strict traffic rate limits using the Modular QoS CLI (MQC).

Enterprise Network Plane Architecture

To implement effective infrastructure protection, network architects divide device operations into three functional planes:

+-------------------------------------------------------------------------+
|                       MANAGEMENT PLANE                                  |
|             SSH (TCP 22), HTTPS (TCP 443), SNMP (UDP 161),              |
|             NTP (UDP 123), TACACS+ (TCP 49), Syslog                     |
+-------------------------------------------------------------------------+
                                     │
                                     ▼
+-------------------------------------------------------------------------+
|                        CONTROL PLANE                                    |
|        Route Processor (CPU), OSPF, EIGRP, BGP, ARP Resolution,         |
|             ICMP Generation, STP BPDUs, LDP, IGMP                       |
+-------------------------------------------------------------------------+
                   ▲                                     │
                   │ (Punted Traffic Exception Path)     │ (FIB / Adjacency Updates)
                   │                                     ▼
+-------------------------------------------------------------------------+
|                         DATA PLANE                                      |
|       Hardware ASICs, Ternary Content-Addressable Memory (TCAM),        |
|       Forwarding Information Base (FIB), Line-Rate Transit Forwarding   |
+-------------------------------------------------------------------------+

1. The Data Plane (Forwarding Plane)

The data plane comprises dedicated hardware Application-Specific Integrated Circuits (ASICs), Ternary Content-Addressable Memory (TCAM), and line cards. It handles transit traffic traversing through the device from an ingress interface to an egress interface. Using pre-computed hardware forwarding tables—the Forwarding Information Base (FIB) and Adjacency Table populated by Cisco Express Forwarding (CEF)—the data plane processes and switches packets entirely in silicon at physical wire speed with microsecond latency.

2. The Control Plane

The control plane is executed by the central Route Processor (CPU) and system RAM. It governs network topology intelligence, calculating optimal paths, negotiating peer adjacencies, and managing state machines. Protocols executing in the control plane include interior and exterior gateway routing protocols (OSPF, EIGRP, BGP, IS-IS), Spanning Tree Protocol (STP), First Hop Redundancy Protocols (HSRP, VRRP), Address Resolution Protocol (ARP), and ICMP error generation. The control plane programs the data plane hardware tables but does not forward standard transit packets.

3. The Management Plane

A functional subset of the control plane dedicated to administrative access and telemetry. It handles interactive Secure Shell (SSH) and Telnet sessions, web-based HTTPS interfaces, Simple Network Management Protocol (SNMP) polling, Network Time Protocol (NTP) time synchronization, and AAA authentication queries.

Route Processor Denial of Service (DoS) Vulnerabilities

Packets that cannot be resolved directly by data plane ASICs must be diverted—or punted—from hardware silicon to the Route Processor CPU. Punted traffic includes:

  • Packets Addressed to the Device: Any traffic whose destination IPv4 or IPv6 address matches an active router interface (e.g., routing updates, SSH sessions, SNMP queries, ICMP echo requests).
  • Packets Requiring CPU Processing: Packets with IP Options enabled, packets with Time-to-Live expired (TTL=1) requiring an ICMP Time Exceeded generation, packets exceeding interface MTU where fragmentation is required, or packets matching an ACL configured with the log keyword.
  • Unresolved Layer 2 Adjacencies: Packets destined for an IP address whose Layer 2 MAC address is not present in the ARP cache, triggering the CPU to generate ARP request broadcasts.

Consequences of Control Plane Exhaustion

Unlike data plane ASICs, which process hundreds of gigabits per second, the Route Processor CPU can process only a modest packet rate (tens of thousands of packets per second). If an attacker floods the router with spoofed SYN packets, ICMP sweeps, or random ARP requests, the CPU queue overflows. Critical routing protocol hello packets and keepalives (such as OSPF Hellos or BGP Keepalives) are dropped in the queue. Consequently, neighbor dead timers expire, adjacencies drop, the router withdraws all routes, and transit traffic across the entire enterprise collapses—even though the data plane hardware was completely functional.

Control Plane Policing (CoPP) Architecture

Control Plane Policing (CoPP) addresses this vulnerability by configuring the Route Processor as a special logical interface within Cisco IOS XE: control-plane. CoPP applies rate limiting, traffic policing, and packet filtering to all traffic entering the route processor before it reaches the CPU execution queue.

CoPP is implemented entirely through the Modular QoS CLI (MQC) framework, adhering to a three-tier architecture:

  1. Class Maps (class-map): Identify and classify incoming control plane traffic categories using ACLs.
  2. Policy Maps (policy-map): Define security actions, rate limits, and burst sizes for each classified traffic category using the police command.
  3. Service Policy (service-policy): Binds the policy map directly to the control-plane interface in the inbound direction (service-policy input <policy-name>). CoPP operates strictly on ingress traffic arriving at the CPU.
Incoming Ingress Packet (Targeting Device IP)
                     │
                     ▼
        ┌─────────────────────────┐
        │ Classify via Class Maps │
        └─────────────────────────┘
                     │
       ┌─────────────┼─────────────┐
       ▼             ▼             ▼
[Routing Class] [Mgmt Class]  [Undesirable]
       │             │             │
       ▼             ▼             ▼
[High Rate/Pass][Strict Limit][Aggressive Drop]
       │             │             │
       └─────────────┬─────────────┘
                     │ Conform Traffic
                     ▼
        ┌─────────────────────────┐
        │ Route Processor (CPU)   │
        │ (Protected & Stable)    │
        └─────────────────────────┘

Traffic Classification Strategy and Class Categories

A robust CoPP policy divides control plane traffic into discrete functional classes, ensuring that low-priority traffic cannot exhaust bandwidth reserved for mission-critical protocols:

1. Critical Routing Protocol Traffic

Routing protocol stability is paramount. If routing adjacencies fail, all network forwarding ceases. This class matches protocols essential for path convergence:

  • OSPF (IP Protocol 89)
  • EIGRP (IP Protocol 88)
  • BGP (TCP Port 179)
  • Bidirectional Forwarding Detection (BFD, UDP Port 3784)
  • Intermediate System to Intermediate System (IS-IS) Policy Action: Permissive rate limits or unconstrained throughput with high committed information rates (CIR) to ensure hello packets and link-state updates are never dropped during network reconvergence.

2. Network Management Traffic

Management protocols allow administrators to access, configure, and monitor network health:

  • Secure Shell (SSH, TCP Port 22)
  • HTTPS (TCP Port 443)
  • SNMP (UDP Port 161/162)
  • Network Time Protocol (NTP, UDP Port 123)
  • TACACS+ (TCP Port 49) / RADIUS (UDP 1812/1813) Policy Action: Strictly rate-limited to prevent brute-force dictionary attacks, TCP SYN floods, or SNMP amplification attacks, while reserving sufficient bandwidth to guarantee interactive administrative CLI access during an incident.

3. Critical Infrastructure Traffic

Fundamental network services required for end-to-end host communication:

  • Address Resolution Protocol (ARP), which is not IP traffic, so it needs its own class (match protocol arp) instead of an IP ACL
  • ICMP Control Messages (Echo request, Echo reply, Unreachable, TTL-Expired)
  • DHCP Snooping and Relay (UDP Ports 67 and 68) Policy Action: Aggressively policed. ICMP echo requests (ping) should be capped at modest rates (e.g., 500 kbps to 1 Mbps) to prevent ping floods and subnet sweeps from consuming CPU cycles. ARP resolution is policed to prevent broadcast storm storms from overwhelming the ARP queue.

4. Undesirable and Default Traffic (class-default)

All punted packets that fail to match any explicitly defined class map fall into the default class (class-default). This includes malformed packets, unsupported IP protocols, scanning sweeps, and unauthorized connection attempts. Policy Action: Extremely restrictive rate limiting or immediate dropping (police rate ... exceed-action drop).

CoPP Traffic Classification Reference

Traffic ClassificationProtocol & Header MatchingMQC Matching MechanismRecommended CoPP ActionOperational Rationale
Critical RoutingOSPF (IP 89), EIGRP (IP 88), BGP (TCP 179), BFDNamed Extended ACL matching protocol numbers and portsHigh CIR (e.g., 10–50 Mbps); exceed-action dropProtects routing engine; prevents adjacency drops and route flaps
Management PlaneSSH (TCP 22), HTTPS (TCP 443), SNMP (UDP 161), NTPNamed Extended ACL matching destination portsModerate CIR (e.g., 2–5 Mbps); exceed-action dropGuarantees administrative access; mitigates brute-force/SYN floods
InfrastructureARP, DHCP (UDP 67/68), ICMP (Type 8 echo, Type 11 TTL)Named Extended ACL matching ICMP and UDP portsLow CIR (e.g., 500 kbps–1 Mbps); exceed-action dropMitigates ping floods and ARP storms; permits basic diagnostic reachability
Default / ScavengerAll unmatched punted trafficAutomatic (class-default)Minimal CIR (e.g., 100 kbps); exceed-action dropDiscards unauthorized sweeps and malformed traffic without impacting CPU

Note

The MQC example in this section fits IOS XE routers such as the Catalyst 8000 family. Catalyst 9000 switches apply a system-defined CoPP policy (system-cpp-policy) by default; on those switches you tune the policer rates of the predefined CPU queues instead of writing your own control-plane policy.

Rate Limiting and Policing Actions in CoPP

Within an MQC policy map, the police command defines the bandwidth contract enforced upon a traffic class. CoPP policies primarily utilize single-rate two-color or single-rate three-color token bucket policers:

police rate <cir> [burst <bc>] conform-action <action> exceed-action <action> [violate-action <action>]
  • Committed Information Rate (CIR): The sustained bandwidth allowed for the class, measured in bits per second (bps).
  • Burst Size (Bc): The maximum volume of traffic permitted to exceed the CIR in a brief interval before policing occurs, measured in bytes.
  • Conform Action: Action applied to packets within the CIR threshold. For legitimate control and management traffic, the conform action is transmit.
  • Exceed / Violate Action: Action applied when the traffic rate exceeds the CIR and burst allocation. In CoPP, the standard exceed action is drop.
Token Bucket Mechanism:
Tokens arrive at CIR rate ──► [ Token Bucket (Depth: Bc) ]
                                        │
                    Packet Arrives ─────┤
                                        ├── Tokens Available? ──► [CONFORM: Transmit]
                                        │
                                        └── No Tokens? ────────► [EXCEED: Drop]

Step-by-Step CLI Configuration Walkthrough

The following configuration establishes an enterprise-grade Control Plane Policy on Cisco IOS XE, including classification ACLs, MQC class maps, policy map definitions, and control-plane interface binding:

! Step 1: Define Classification ACLs for Control Plane Traffic
ip access-list extended ACL-COPP-ROUTING
 10 permit ospf any any
 20 permit eigrp any any
 30 permit tcp any any eq 179
 40 permit tcp any eq 179 any
 50 permit udp any any eq 3784

ip access-list extended ACL-COPP-MGMT
 10 permit tcp 192.168.0.0 0.0.255.255 any eq 22
 20 permit tcp 192.168.0.0 0.0.255.255 any eq 443
 30 permit udp 192.168.0.0 0.0.255.255 any eq 161
 40 permit udp any any eq 123

ip access-list extended ACL-COPP-INFRA
 10 permit icmp any any echo
 20 permit icmp any any echo-reply
 30 permit icmp any any unreachable
 40 permit icmp any any time-exceeded
 50 permit udp any eq 67 any eq 68

! Step 2: Create MQC Class Maps referencing the ACLs
class-map match-all CM-COPP-ROUTING
 match access-group name ACL-COPP-ROUTING

class-map match-all CM-COPP-MGMT
 match access-group name ACL-COPP-MGMT

class-map match-all CM-COPP-INFRA
 match access-group name ACL-COPP-INFRA

! Step 3: Define the MQC Policy Map with Strict Rate Limits
policy-map PM-COPP-ENTERPRISE
 class CM-COPP-ROUTING
  police rate 20000000 burst 250000
   conform-action transmit
   exceed-action drop
 class CM-COPP-MGMT
  police rate 5000000 burst 62500
   conform-action transmit
   exceed-action drop
 class CM-COPP-INFRA
  police rate 1000000 burst 12500
   conform-action transmit
   exceed-action drop
 class class-default
  police rate 250000 burst 3125
   conform-action transmit
   exceed-action drop

! Step 4: Apply the Policy Map to the Control Plane Interface
control-plane
 service-policy input PM-COPP-ENTERPRISE

Verification and Operational Troubleshooting

To verify that the CoPP policy is operational and inspect packet counters to detect active attacks:

Inspecting CoPP Counters (show policy-map control-plane)

The primary operational command for monitoring control plane protection is show policy-map control-plane input:

Router# show policy-map control-plane input
 Control Plane 

  Service-policy input: PM-COPP-ENTERPRISE

    Class-map: CM-COPP-ROUTING (match-all)
      124890 packets, 11989440 bytes
      5 minute offered rate 12000 bps, drop rate 0000 bps
      Match: access-group name ACL-COPP-ROUTING
      police:
          cir 20000000 bps, bc 250000 bytes
        conformed 124890 packets, 11989440 bytes; actions:
          transmit 
        exceeded 0 packets, 0 bytes; actions:
          drop 

    Class-map: CM-COPP-INFRA (match-all)
      5892100 packets, 471368000 bytes
      5 minute offered rate 4850000 bps, drop rate 3850000 bps
      Match: access-group name ACL-COPP-INFRA
      police:
          cir 1000000 bps, bc 12500 bytes
        conformed 1215400 packets, 97232000 bytes; actions:
          transmit 
        exceeded 4676700 packets, 374136000 bytes; actions:
          drop 

Diagnosing Active Attacks and Tuning Policer Rates

In the operational output above, examine the CM-COPP-INFRA class:

  • Offered Rate: 4.85 Mbps
  • Configured CIR: 1.00 Mbps
  • Drop Rate: 3.85 Mbps with over 4.6 million packets dropped by the exceed action.

This immediate disparity indicates an ongoing ICMP or infrastructure flood targeting the device. The exceed policer successfully dropped the 3.85 Mbps excess, keeping the Route Processor CPU at baseline operational levels while routing protocols (CM-COPP-ROUTING) maintained zero drops. If legitimate administrative operations (such as bulk network management polling) trigger drops under CM-COPP-MGMT, engineers should adjust the CIR or burst size (bc) rather than disabling the policy.

Test Your Knowledge

Which statement correctly describes the architectural difference between the Data Plane and the Control Plane on an enterprise router?

A

The Data Plane executes OSPF and BGP routing algorithms, while the Control Plane switches transit frames using TCAM tables

B

The Control Plane processes transit packets in hardware ASICs, while the Data Plane handles Telnet and SSH management sessions

C

The Data Plane forwards transit traffic in hardware using CEF tables, while the Control Plane CPU runs the routing protocols

D

The Data Plane inspects management credentials, while the Control Plane encapsulates frames into 802.1Q VLAN trunks

Test Your Knowledge

A network security administrator must configure Control Plane Policing (CoPP) to protect a core router from volumetric denial-of-service attacks. What configuration step binds the completed Modular QoS CLI (MQC) policy map to the route processor?

A

Entering control-plane configuration mode and applying the command service-policy input <policy-name>

B

Applying service-policy output <policy-name> under the global system template

C

Applying ip access-group <policy-name> in on all physical WAN interfaces

D

Entering line vty 0 15 configuration mode and applying control-plane service-policy <policy-name> to the lines

Test Your Knowledge

During an ongoing distributed denial-of-service attack, an engineer examines the command output of show policy-map control-plane input and observes millions of dropped packets in the ICMP traffic class while the OSPF class reports zero drops and CPU utilization remains at 12%. What does this output demonstrate?

A

The router line cards have crashed and are failing to punt routing updates to the control plane

B

The CoPP policer is misconfigured and dropping OSPF keepalives inside the ICMP traffic queue

C

The TCAM forwarding table has overflowed, forcing transit traffic to drop at ingress

D

The CoPP policy is actively dropping the excessive ICMP flood while preserving routing protocol stability

Sections you finish are checked off in the contents.