Restrictions for Control Plane Policing
Output Rate-Limiting Support
Output rate-limiting is performed in silent (packet discard) mode. Silent mode enables a router to silently discard packets using policy maps applied to output control plane traffic with the service-policy output command. For more information, see the “Output Rate-Limiting and Silent Mode Operation” section.
MQC Restrictions
The Control Plane Policing feature requires the Modular QoS CLI (MQC) to configure packet classification, packet marking, and traffic policing. All restrictions that apply when you use the MQC to configure traffic policing also apply when you configure control plane policing. Only two MQC commands are supported in policy maps—police and set .
Match Criteria Support and Restrictions
The following classification (match) criteria are supported:
-
Standard and extended IP access control lists (ACLs).
-
In class-map configuration mode, match criteria specified by the following commands: - match dscp
- match ip dscp
- match ip precedence
- match precedence
- match protocol arp
- match protocol ipv6
- match protocol pppoe
Note |
The match protocol pppoe command matches all PPPoE data packets that are sent to the control plane. |
-
match protocol pppoe-discovery
Note |
The match protocol pppoe-discovery command matches all PPPoE control packets that are sent to the control plane. |
-
match qos-group
Note |
The match input-interface command is not supported. |
Note |
Features that require Network-Based Application Recognition (NBAR) classification may not work well at the control plane level. |