12.2 Control Plane Policing (CoPP): Protecting the Route Processor with MQC
Key Takeaways
Enterprise network devices separate operations into the Data Plane (hardware ASICs executing line-rate transit forwarding) and the Control Plane (the Route Processor / CPU managing routing protocols, signaling, and administrative sessions).
Distributed Denial of Service (DoS) attacks, malformed packets, and broadcast storms directed at the device IP address can overwhelm the Route Processor, triggering high CPU utilization, routing adjacency loss, and administrative lockout.
Control Plane Policing (CoPP) protects the Route Processor by treating it as an inbound logical interface (control-plane) managed through Cisco Modular QoS CLI (MQC).
CoPP establishes a three-tier architecture: Class Maps identify and classify traffic via ACLs, Policy Maps define policing thresholds and burst limits, and a Service Policy enforces rate limiting in the inbound direction.
In CoPP policies, critical routing protocols (BGP, OSPF, EIGRP) and essential infrastructure traffic (ARP, ICMP, DHCP) are segregated from management sessions (SSH, SNMP) and default untrusted traffic, ensuring protocol stability during volumetric floods.
Control Plane Policing (CoPP): Protecting the Route Processor with MQC
Modern enterprise campus and core routers are architected around distributed hardware pipelines designed to switch millions of packets per second without host CPU intervention. However, all network devices possess a finite, shared computational resource: the Route Processor (RP), or central CPU. When malicious actors launch distributed denial-of-service (DoS) attacks, network recon sweeps, or protocol flood exploits, the resulting packet influx targets the control plane. Without protection, route processor exhaustion causes dropped routing keepalives, collapsing routing protocols, network-wide route flap, and total management lockout. Control Plane Policing (CoPP) prevents these catastrophic failures by treating the route processor as an interface and enforcing strict traffic rate limits using the Modular QoS CLI (MQC).
Enterprise Network Plane Architecture
To implement effective infrastructure protection, network architects divide device operations into three functional planes:
+-------------------------------------------------------------------------+
| MANAGEMENT PLANE |
| SSH (TCP 22), HTTPS (TCP 443), SNMP (UDP 161), |
| NTP (UDP 123), TACACS+ (TCP 49), Syslog |
+-------------------------------------------------------------------------+
│
▼
+-------------------------------------------------------------------------+
| CONTROL PLANE |
| Route Processor (CPU), OSPF, EIGRP, BGP, ARP Resolution, |
| ICMP Generation, STP BPDUs, LDP, IGMP |
+-------------------------------------------------------------------------+
▲ │
│ (Punted Traffic Exception Path) │ (FIB / Adjacency Updates)
│ ▼
+-------------------------------------------------------------------------+
| DATA PLANE |
| Hardware ASICs, Ternary Content-Addressable Memory (TCAM), |
| Forwarding Information Base (FIB), Line-Rate Transit Forwarding |
+-------------------------------------------------------------------------+
1. The Data Plane (Forwarding Plane)
The data plane comprises dedicated hardware Application-Specific Integrated Circuits (ASICs), Ternary Content-Addressable Memory (TCAM), and line cards. It handles transit traffic traversing through the device from an ingress interface to an egress interface. Using pre-computed hardware forwarding tables—the Forwarding Information Base (FIB) and Adjacency Table populated by Cisco Express Forwarding (CEF)—the data plane processes and switches packets entirely in silicon at physical wire speed with microsecond latency.
2. The Control Plane
The control plane is executed by the central Route Processor (CPU) and system RAM. It governs network topology intelligence, calculating optimal paths, negotiating peer adjacencies, and managing state machines. Protocols executing in the control plane include interior and exterior gateway routing protocols (OSPF, EIGRP, BGP, IS-IS), Spanning Tree Protocol (STP), First Hop Redundancy Protocols (HSRP, VRRP), Address Resolution Protocol (ARP), and ICMP error generation. The control plane programs the data plane hardware tables but does not forward standard transit packets.
3. The Management Plane
A functional subset of the control plane dedicated to administrative access and telemetry. It handles interactive Secure Shell (SSH) and Telnet sessions, web-based HTTPS interfaces, Simple Network Management Protocol (SNMP) polling, Network Time Protocol (NTP) time synchronization, and AAA authentication queries.
Route Processor Denial of Service (DoS) Vulnerabilities
Packets that cannot be resolved directly by data plane ASICs must be diverted—or punted—from hardware silicon to the Route Processor CPU. Punted traffic includes:
- Packets Addressed to the Device: Any traffic whose destination IPv4 or IPv6 address matches an active router interface (e.g., routing updates, SSH sessions, SNMP queries, ICMP echo requests).
- Packets Requiring CPU Processing: Packets with IP Options enabled, packets with Time-to-Live expired (TTL=1) requiring an ICMP Time Exceeded generation, packets exceeding interface MTU where fragmentation is required, or packets matching an ACL configured with the
logkeyword. - Unresolved Layer 2 Adjacencies: Packets destined for an IP address whose Layer 2 MAC address is not present in the ARP cache, triggering the CPU to generate ARP request broadcasts.
Consequences of Control Plane Exhaustion
Unlike data plane ASICs, which process hundreds of gigabits per second, the Route Processor CPU can process only a modest packet rate (tens of thousands of packets per second). If an attacker floods the router with spoofed SYN packets, ICMP sweeps, or random ARP requests, the CPU queue overflows. Critical routing protocol hello packets and keepalives (such as OSPF Hellos or BGP Keepalives) are dropped in the queue. Consequently, neighbor dead timers expire, adjacencies drop, the router withdraws all routes, and transit traffic across the entire enterprise collapses—even though the data plane hardware was completely functional.
Control Plane Policing (CoPP) Architecture
Control Plane Policing (CoPP) addresses this vulnerability by configuring the Route Processor as a special logical interface within Cisco IOS XE: control-plane. CoPP applies rate limiting, traffic policing, and packet filtering to all traffic entering the route processor before it reaches the CPU execution queue.
CoPP is implemented entirely through the Modular QoS CLI (MQC) framework, adhering to a three-tier architecture:
- Class Maps (
class-map): Identify and classify incoming control plane traffic categories using ACLs. - Policy Maps (
policy-map): Define security actions, rate limits, and burst sizes for each classified traffic category using thepolicecommand. - Service Policy (
service-policy): Binds the policy map directly to thecontrol-planeinterface in the inbound direction (service-policy input <policy-name>). CoPP operates strictly on ingress traffic arriving at the CPU.
Incoming Ingress Packet (Targeting Device IP)
│
▼
┌─────────────────────────┐
│ Classify via Class Maps │
└─────────────────────────┘
│
┌─────────────┼─────────────┐
▼ ▼ ▼
[Routing Class] [Mgmt Class] [Undesirable]
│ │ │
▼ ▼ ▼
[High Rate/Pass][Strict Limit][Aggressive Drop]
│ │ │
└─────────────┬─────────────┘
│ Conform Traffic
▼
┌─────────────────────────┐
│ Route Processor (CPU) │
│ (Protected & Stable) │
└─────────────────────────┘
Traffic Classification Strategy and Class Categories
A robust CoPP policy divides control plane traffic into discrete functional classes, ensuring that low-priority traffic cannot exhaust bandwidth reserved for mission-critical protocols:
1. Critical Routing Protocol Traffic
Routing protocol stability is paramount. If routing adjacencies fail, all network forwarding ceases. This class matches protocols essential for path convergence:
- OSPF (IP Protocol 89)
- EIGRP (IP Protocol 88)
- BGP (TCP Port 179)
- Bidirectional Forwarding Detection (BFD, UDP Port 3784)
- Intermediate System to Intermediate System (IS-IS) Policy Action: Permissive rate limits or unconstrained throughput with high committed information rates (CIR) to ensure hello packets and link-state updates are never dropped during network reconvergence.
2. Network Management Traffic
Management protocols allow administrators to access, configure, and monitor network health:
- Secure Shell (SSH, TCP Port 22)
- HTTPS (TCP Port 443)
- SNMP (UDP Port 161/162)
- Network Time Protocol (NTP, UDP Port 123)
- TACACS+ (TCP Port 49) / RADIUS (UDP 1812/1813) Policy Action: Strictly rate-limited to prevent brute-force dictionary attacks, TCP SYN floods, or SNMP amplification attacks, while reserving sufficient bandwidth to guarantee interactive administrative CLI access during an incident.
3. Critical Infrastructure Traffic
Fundamental network services required for end-to-end host communication:
- Address Resolution Protocol (ARP), which is not IP traffic, so it needs its own class (
match protocol arp) instead of an IP ACL - ICMP Control Messages (Echo request, Echo reply, Unreachable, TTL-Expired)
- DHCP Snooping and Relay (UDP Ports 67 and 68) Policy Action: Aggressively policed. ICMP echo requests (ping) should be capped at modest rates (e.g., 500 kbps to 1 Mbps) to prevent ping floods and subnet sweeps from consuming CPU cycles. ARP resolution is policed to prevent broadcast storm storms from overwhelming the ARP queue.
4. Undesirable and Default Traffic (class-default)
All punted packets that fail to match any explicitly defined class map fall into the default class (class-default). This includes malformed packets, unsupported IP protocols, scanning sweeps, and unauthorized connection attempts.
Policy Action: Extremely restrictive rate limiting or immediate dropping (police rate ... exceed-action drop).
CoPP Traffic Classification Reference
| Traffic Classification | Protocol & Header Matching | MQC Matching Mechanism | Recommended CoPP Action | Operational Rationale |
|---|---|---|---|---|
| Critical Routing | OSPF (IP 89), EIGRP (IP 88), BGP (TCP 179), BFD | Named Extended ACL matching protocol numbers and ports | High CIR (e.g., 10–50 Mbps); exceed-action drop | Protects routing engine; prevents adjacency drops and route flaps |
| Management Plane | SSH (TCP 22), HTTPS (TCP 443), SNMP (UDP 161), NTP | Named Extended ACL matching destination ports | Moderate CIR (e.g., 2–5 Mbps); exceed-action drop | Guarantees administrative access; mitigates brute-force/SYN floods |
| Infrastructure | ARP, DHCP (UDP 67/68), ICMP (Type 8 echo, Type 11 TTL) | Named Extended ACL matching ICMP and UDP ports | Low CIR (e.g., 500 kbps–1 Mbps); exceed-action drop | Mitigates ping floods and ARP storms; permits basic diagnostic reachability |
| Default / Scavenger | All unmatched punted traffic | Automatic (class-default) | Minimal CIR (e.g., 100 kbps); exceed-action drop | Discards unauthorized sweeps and malformed traffic without impacting CPU |
Note
The MQC example in this section fits IOS XE routers such as the Catalyst 8000 family. Catalyst 9000 switches apply a system-defined CoPP policy (system-cpp-policy) by default; on those switches you tune the policer rates of the predefined CPU queues instead of writing your own control-plane policy.
Rate Limiting and Policing Actions in CoPP
Within an MQC policy map, the police command defines the bandwidth contract enforced upon a traffic class. CoPP policies primarily utilize single-rate two-color or single-rate three-color token bucket policers:
police rate <cir> [burst <bc>] conform-action <action> exceed-action <action> [violate-action <action>]
- Committed Information Rate (CIR): The sustained bandwidth allowed for the class, measured in bits per second (bps).
- Burst Size (Bc): The maximum volume of traffic permitted to exceed the CIR in a brief interval before policing occurs, measured in bytes.
- Conform Action: Action applied to packets within the CIR threshold. For legitimate control and management traffic, the conform action is
transmit. - Exceed / Violate Action: Action applied when the traffic rate exceeds the CIR and burst allocation. In CoPP, the standard exceed action is
drop.
Token Bucket Mechanism:
Tokens arrive at CIR rate ──► [ Token Bucket (Depth: Bc) ]
│
Packet Arrives ─────┤
├── Tokens Available? ──► [CONFORM: Transmit]
│
└── No Tokens? ────────► [EXCEED: Drop]
Step-by-Step CLI Configuration Walkthrough
The following configuration establishes an enterprise-grade Control Plane Policy on Cisco IOS XE, including classification ACLs, MQC class maps, policy map definitions, and control-plane interface binding:
! Step 1: Define Classification ACLs for Control Plane Traffic
ip access-list extended ACL-COPP-ROUTING
10 permit ospf any any
20 permit eigrp any any
30 permit tcp any any eq 179
40 permit tcp any eq 179 any
50 permit udp any any eq 3784
ip access-list extended ACL-COPP-MGMT
10 permit tcp 192.168.0.0 0.0.255.255 any eq 22
20 permit tcp 192.168.0.0 0.0.255.255 any eq 443
30 permit udp 192.168.0.0 0.0.255.255 any eq 161
40 permit udp any any eq 123
ip access-list extended ACL-COPP-INFRA
10 permit icmp any any echo
20 permit icmp any any echo-reply
30 permit icmp any any unreachable
40 permit icmp any any time-exceeded
50 permit udp any eq 67 any eq 68
! Step 2: Create MQC Class Maps referencing the ACLs
class-map match-all CM-COPP-ROUTING
match access-group name ACL-COPP-ROUTING
class-map match-all CM-COPP-MGMT
match access-group name ACL-COPP-MGMT
class-map match-all CM-COPP-INFRA
match access-group name ACL-COPP-INFRA
! Step 3: Define the MQC Policy Map with Strict Rate Limits
policy-map PM-COPP-ENTERPRISE
class CM-COPP-ROUTING
police rate 20000000 burst 250000
conform-action transmit
exceed-action drop
class CM-COPP-MGMT
police rate 5000000 burst 62500
conform-action transmit
exceed-action drop
class CM-COPP-INFRA
police rate 1000000 burst 12500
conform-action transmit
exceed-action drop
class class-default
police rate 250000 burst 3125
conform-action transmit
exceed-action drop
! Step 4: Apply the Policy Map to the Control Plane Interface
control-plane
service-policy input PM-COPP-ENTERPRISE
Verification and Operational Troubleshooting
To verify that the CoPP policy is operational and inspect packet counters to detect active attacks:
Inspecting CoPP Counters (show policy-map control-plane)
The primary operational command for monitoring control plane protection is show policy-map control-plane input:
Router# show policy-map control-plane input
Control Plane
Service-policy input: PM-COPP-ENTERPRISE
Class-map: CM-COPP-ROUTING (match-all)
124890 packets, 11989440 bytes
5 minute offered rate 12000 bps, drop rate 0000 bps
Match: access-group name ACL-COPP-ROUTING
police:
cir 20000000 bps, bc 250000 bytes
conformed 124890 packets, 11989440 bytes; actions:
transmit
exceeded 0 packets, 0 bytes; actions:
drop
Class-map: CM-COPP-INFRA (match-all)
5892100 packets, 471368000 bytes
5 minute offered rate 4850000 bps, drop rate 3850000 bps
Match: access-group name ACL-COPP-INFRA
police:
cir 1000000 bps, bc 12500 bytes
conformed 1215400 packets, 97232000 bytes; actions:
transmit
exceeded 4676700 packets, 374136000 bytes; actions:
drop
Diagnosing Active Attacks and Tuning Policer Rates
In the operational output above, examine the CM-COPP-INFRA class:
- Offered Rate: 4.85 Mbps
- Configured CIR: 1.00 Mbps
- Drop Rate: 3.85 Mbps with over 4.6 million packets dropped by the exceed action.
This immediate disparity indicates an ongoing ICMP or infrastructure flood targeting the device. The exceed policer successfully dropped the 3.85 Mbps excess, keeping the Route Processor CPU at baseline operational levels while routing protocols (CM-COPP-ROUTING) maintained zero drops. If legitimate administrative operations (such as bulk network management polling) trigger drops under CM-COPP-MGMT, engineers should adjust the CIR or burst size (bc) rather than disabling the policy.
Which statement correctly describes the architectural difference between the Data Plane and the Control Plane on an enterprise router?
The Data Plane executes OSPF and BGP routing algorithms, while the Control Plane switches transit frames using TCAM tables
The Control Plane processes transit packets in hardware ASICs, while the Data Plane handles Telnet and SSH management sessions
The Data Plane forwards transit traffic in hardware using CEF tables, while the Control Plane CPU runs the routing protocols
The Data Plane inspects management credentials, while the Control Plane encapsulates frames into 802.1Q VLAN trunks
A network security administrator must configure Control Plane Policing (CoPP) to protect a core router from volumetric denial-of-service attacks. What configuration step binds the completed Modular QoS CLI (MQC) policy map to the route processor?
Entering control-plane configuration mode and applying the command service-policy input <policy-name>
Applying service-policy output <policy-name> under the global system template
Applying ip access-group <policy-name> in on all physical WAN interfaces
Entering line vty 0 15 configuration mode and applying control-plane service-policy <policy-name> to the lines
During an ongoing distributed denial-of-service attack, an engineer examines the command output of show policy-map control-plane input and observes millions of dropped packets in the ICMP traffic class while the OSPF class reports zero drops and CPU utilization remains at 12%. What does this output demonstrate?
The router line cards have crashed and are failing to punt routing updates to the control plane
The CoPP policer is misconfigured and dropping OSPF keepalives inside the ICMP traffic queue
The TCAM forwarding table has overflowed, forcing transit traffic to drop at ingress
The CoPP policy is actively dropping the excessive ICMP flood while preserving routing protocol stability
Sections you finish are checked off in the contents.