Hello Johan,

You are right. The special "port-filter" and "queue-threshold" policy-maps
can only be applied on the control-plane "HOST" subinterface.

Along with this, what i meant by Management Plane protection was using the
"management-interface" command
http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/htsecmpp.html

Using Management plane protection , you can control what managment protocols
( ex : telnet , ssh , http , etc ) are allowed on specific physical
interfaces on the router. This is only possible on the "control-plane HOST
subinterface"

Cheers,
TacACK
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to