Yusuf's Lab 1, Control Plane Protection question asks to filter ICMP from non-1918 address space to the router.
In his solution, the policy-map is tied to the control-plane. Also he uses two ACLs - one permitting ICMP from any and the other permitting ICMP from 1918 addresses. In my solution, I placed the policy-map under the host subinterface on the control-plane. I also only used one ACL - denying ICMP from 1918 addresses and permitting ICMP any any. My test results were the same. Question - does it make a difference that I did it this way i.e used "control-plane host" and not "control-plane" to tie the policy-map and yet still got the same results. That is: control-plane host service-policy input COPP Which is the recommended way to do it ? I assume Yusuf's way, since he wrote the book !! Thanks again. Mark
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
