On Aug 7, 2014, at 11:11 PM, randal k <[email protected]> wrote:

> So, we have deployed a demo control-plane based policer/dropper to make sure 
> that the WAN interface ACL doesn't have to be perfect (or even be
> there, which is the goal).

If these devices are all on networks under your administrative control, it's 
generally far better to drop undesirable packets at the edge, and far easier to 
get an iACL and/or tACL right and deploy on edge interfaces, than to get CoPP 
right.

CoPP is a Good Thing, don't get me wrong - but it should come second after 
iACLs and relevant tACLs, IMHO.

OTOH, if they're deployed on networks not under your control, then individual 
iACLs/tACLs combined with CoPP is probably the best answer.

----------------------------------------------------------------------
Roland Dobbins <[email protected]> // <http://www.arbornetworks.com>

                   Equo ne credite, Teucri.

                          -- Laocoön


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to