On Aug 7, 2014, at 11:11 PM, randal k <[email protected]> wrote: > So, we have deployed a demo control-plane based policer/dropper to make sure > that the WAN interface ACL doesn't have to be perfect (or even be > there, which is the goal).
If these devices are all on networks under your administrative control, it's generally far better to drop undesirable packets at the edge, and far easier to get an iACL and/or tACL right and deploy on edge interfaces, than to get CoPP right. CoPP is a Good Thing, don't get me wrong - but it should come second after iACLs and relevant tACLs, IMHO. OTOH, if they're deployed on networks not under your control, then individual iACLs/tACLs combined with CoPP is probably the best answer. ---------------------------------------------------------------------- Roland Dobbins <[email protected]> // <http://www.arbornetworks.com> Equo ne credite, Teucri. -- Laocoön _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
