[c-nsp] Cisco 6500/Sup720 ARP CoPP

Saku Ytti saku at ytti.fi
Tue Feb 9 14:37:32 EST 2010


On (2010-02-09 13:23 -0600), Brandon Ewing wrote:

> Some of the earlier threads today sparked me to re-check some CoPP I had
> deployed to see if the ARP limiting I placed in was affective, as I had

You must mean the thread where glean was mentioned, you probably are aware
but just for sake of posterity policing glean and ARP are two different
things, any packet can be glean punt while policing ARP is matching only
incoming ARP packet.

> What are other providers using for CoPP configurations on their 6500s?  Is
> it functioning correctly for you?  Are there any other pitfalls I should be
> aware of?

I think you've gathered relevant and correct data, I don't think PFC3
supports ARP match in CoPP. So you must use MLS rate-limiter, where you
have to remember that AFAIK this is also for transit ARP which you might be
bridging as a switch.

-- 
  ++ytti


More information about the cisco-nsp mailing list