Configuring Software Based CoPP
Creating a CoPP policy requires a good understanding of which control plane and management plane protocols and services are in use. In addition, you must understand the packet rate that those protocols and services require. Too low a value for a rate limit can cause problems with passing normal traffic, and too high a value can allow attacks to slip through.
The recommended method to develop a good CoPP policy is to separate the different protocols and services into groups based on relative importance.
The most common method is to define the five following groups of traffic classes: critical, important, normal, undesirable, and default:
• Critical traffic class. Contains traffic that is crucial to the operation of the switch and network. Examples are routing protocol traffic, such as Open Shortest Path First (OSPF) and Border Gateway Protocol (BGP). This traffic should not be rate-limited or have a high rate-limit value.
• Important traffic class. Contains traffic that is necessary for normal day-to-day operations. This includes remote access (SSH and Telnet), network management protocols (SNMP), and Network Time Protocol (NTP). This traffic should be rate-limited, but with a relatively high value.
• Normal traffic class. Contains traffic that is expected, but not essential to, network operation. This includes ICMP echo requests and ICMP TTL exceeded. This traffic should be rate-limited, but with a low value to avoid misuse.
• Undesirable traffic class. Contains traffic that is identified as bad. This traffic should always be dropped.
• Default traffic class. Contains traffic that has not been classified. This traffic class should be monitored to see if it contains any traffic that should be moved to another class. This traffic should be rate-limited to avoid misuse.
The first thing to do is to create ACLs that match the traffic for the different classes. You need only four ACLs because the default class picks up everything that the first four classes do not. Example 13-7 shows how these ACLs might look.
Example 13-7 ACLs Used to Classify Traffic access-list 120 remark CoPP ACL for critical traffic ! allow BGP from a known peer to this router's BGP TCP port access-list 120 permit tcp host 47.1.1.1 host 10.9.9.9 eq bgp ! allow BGP from a peer's BGP port to this router access-list 120 permit tcp host 47.1.1.1 eq bgp host 10.9.9.9 access-list 120 permit tcp host 10.86.183.120 host 10.9.9.9 eq bgp access-list 120 permit tcp host 10.86.183.120 eq bgp host 10.9.9.9
access-list 121 remark CoPP Important traffic
! permit return traffic from TACACS host access-list 121 permit tcp host 1.1.1.1 host 10.9.9.9 established
! ssh access to the router from a subnet access-list 121 permit tcp 10.0.0.0 0.0.0.255 host 10.9.9.9 eq 22
! telnet access to the router from a subnet access-list 121 permit tcp 10.86.183.0 0.0.0.255 any eq telnet
! SNMP access from the NMS host to the router access-list 121 permit udp host 1.1.1.2 host 10.9.9.9 eq snmp ! Allow the router to receive NTP packets from a known clock source access-list 121 permit udp host 1.1.1.3 host 10.9.9.9 eq ntp access-list 122 remark CoPP normal traffic ! permit router originated traceroute access-list 122 permit icmp any any ttl-exceeded access-list 122 permit icmp any any port-unreachable ! permit receipt of responses to router originated pings access-list 122 permit icmp any any echo-reply ! allow pings to router access-list 122 permit icmp any any echo access-list 123 remark explicitly defined "undesirable" traffic
! permit, for policing, all traffic destined to UDP 1434 access-list 123 permit udp any any eq 1434
The next step is to create class maps that tie the ACLs into a traffic class. A class map can combine many ACLs into one traffic class but, in this case, you have one-to-one mapping, as Example 13-8 shows.
Example 13-8 Defining the Class Maps and Tying Them to the Previously Defined ACLs class-map CoPP-critical match access-group 120 class-map CoPP-important match access-group 121 class-map CoPP-normal match access-group 122 class-map CoPP-undesirable match access-group 123
You now tie the class maps into a policy map where you can assign rate limits to the different classes, as Example 13-9 shows.
Example 13-9 Creating the Policy Map and Assigning Rate Limits
|
! This policy allows all critical traffic to be unconditionally transmitted |
|
|
! regardless of the rate. Other traffic is rate limited except for traffic |
defined |
|
! as undesirable which is unconditionally dropped. |
|
|
policy-map CoPP |
|
|
class CoPP-critical |
|
|
police 31500000 conform-action transmit exceed-action transmit |
|
|
class CoPP-important |
|
|
police 125000 3906 3906 conform-action transmit exceed-action drop |
|
|
class CoPP-normal |
|
|
police 64000 2000 2000 conform-action transmit exceed-action drop |
|
|
! This policy drops all traffic categorized as undesirable, regardless of |
rate. |
|
class CoPP-undesirable |
|
|
police 32000 1500 1500 conform-action drop exceed-action drop |
|
|
! This class picks up all other traffic |
|
|
police 1000000 31250 31250 conform-action transmit exceed-action drop |
|
The CoPP policy is then attached to the control plane interface:
Switch(config)#control-plane Switch(config-cp)#service-policy input CoPP
To monitor the status of control plane traffic and how it is being rate-limited, use the show policy-map control-plane command, as Example 13-10 shows.
Example 13-10 Displaying the Status of CoPP (Catalyst 6500 Running IOS 12.2(18)SXF)
Switch#show policy-map control-plane
Control Plane Interface
Service-policy input: CoPP
Class-map: CoPP-critical (match-all) 372 packets, 28103 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: access-group 120
police:
cir 31500000 bps, bc 984375 bytes conformed 372 packets, 28103 bytes; action: transmit exceeded 0 packets, 0 bytes; action: transmit conformed 0 bps, exceed 0 bps
Class-map: CoPP-important (match-all) 0 packets, 0 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: access-group 121
police:
cir 125000 bps, bc 3906 bytes conformed 0 packets, 0 bytes; action: transmit exceeded 0 packets, 0 bytes; action: drop conformed 0 bps, exceed 0 bps
Class-map: CoPP-normal (match-all) 5 packets, 570 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: access-group 122
police:
cir 64000 bps, bc 2000 bytes conformed 5 packets, 570 bytes; action: transmit exceeded 0 packets, 0 bytes; action: drop conformed 0 bps, exceed 0 bps
Class-map: CoPP-undesirable (match-all) 0 packets, 0 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: access-group 123
police:
cir 32000 bps, bc 1500 bytes, be 1500 bytes conformed 0 packets, 0 bytes; action: drop exceeded 0 packets, 0 bytes; action: drop violated 0 packets, 0 bytes; action: drop conformed 0 bps, exceed 0 bps, violate 0 bps
Class-map: class-default (match-any) 10891 packets, 1077701 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any police:
cir 1000000 bps, bc 31250 bytes
Example 13-10 Displaying the Status of CoPP (Catalyst 6500 Running IOS 12.2(18)SXF) (Continued)
conformed 10900 packets, 1079262 bytes; action: transmit exceeded 0 packets, 0 bytes; action: drop conformed 1000 bps, exceed 0 bps
Example 13-10 shows how much traffic has been rate-limited and forwarded and the current rate limits. On a hardware-based platform, the output shows both the hardware-based and software-based CoPP rate limiters.
Continue reading here: Telnet Flooding Without CoPP
Was this article helpful?