◦
acl-dhcp
◦
acl-dhcp-relay-response
◦
acl-dhcp6
◦
acl-dhcp6-relay-response
◦
acl-ptp
•
Multicast-based static CoPP ACL substrings:
◦
acl-igmp
For more information on static CoPP ACLs, see
Guidelines and Limitations for CoPP, on page 125
.
Default Policing Policies
When you bring up your Cisco NX-OS device for the first time, the Cisco NX-OS software installs the default
copp-system-p-policy-strict policy to protect the supervisor module from DoS attacks. You can set the level
of protection by choosing one of the following CoPP policy options from the initial setup utility:
•
Strict
—
This policy is 1 rate and 2 color.
•
Moderate
—
This policy is 1 rate and 2 color. The important class burst size is greater than the strict
policy but less than the lenient policy.
•
Lenient
—
This policy is 1 rate and 2 color. The important class burst size is greater than the moderate
policy but less than the dense policy.
•
Dense
—
This policy is 1 rate and 2 color. The policer CIR values are less than the strict policy.
•
Skip
—
No control plane policy is applied. (This option is removed starting with Cisco NX-OS Release
7.0(3)I2(1). For previous releases, Cisco does not recommend using the Skip option because it will
impact the control plane of the network.)
If you do not select an option or choose not to execute the setup utility, the software applies strict policing.
We recommend that you start with the strict policy and later modify the CoPP policies as required.
Strict policing is not applied by default when using POAP, so you must configure a CoPP policy.
Note
The copp-system-p-policy policy has optimized values suitable for basic device operations. You must add
specific class and access-control list (ACL) rules that meet your DoS protection requirements. The default
CoPP policy does not change when you upgrade the software.
Selecting the skip option and not subsequently configuring CoPP protection can leave your Cisco NX-OS
device vulnerable to DoS attacks.
Caution
You can reassign the CoPP default policy by entering the setup utility again using the
setup
command from
the CLI prompt or by using the
copp profile
command.
Cisco Nexus 3600 NX-OS Security Configuration Guide, Release 7.x
113
Configuring Control Plane Policing
Control Plane Protection