Yusuf's Lab 1, Control Plane Protection question asks to filter ICMP from
non-1918 address space to the router.

In his solution, the policy-map is tied to the control-plane. Also he uses
two ACLs - one permitting ICMP from any and the other permitting ICMP from
1918 addresses.

In my solution, I placed the policy-map under the host subinterface on the
control-plane. I also only used one ACL - denying ICMP from 1918 addresses
and permitting ICMP any any.
My test results were the same.

Question - does it make a difference that I did it this way i.e used
"control-plane host" and not "control-plane" to tie the policy-map and yet
still got the same results. That is:

control-plane host
 service-policy input COPP

Which is the recommended way to do it ? I assume Yusuf's way, since he wrote
the book !!

Thanks again.

Mark
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to