A network administrator is implementing Control Plane Policing (CoPP) on a Cisco ASR 1000 router to protect against DoS attacks. The router has a management plane that must remain accessible via SSH and SNMP, and a control plane that must process BGP and OSPF routing updates. The administrator applies a CoPP policy that rate-limits all traffic destined to the control plane to 1000 pps, except for traffic from trusted management subnets. After applying the policy, BGP sessions flap intermittently. What is the most likely cause?
CoPP policies that apply a blanket rate limit to all control plane traffic can inadvertently throttle essential routing protocol messages like BGP keepalives and updates. If the rate limit is too low or not exempting BGP, sessions may flap due to missed keepalives or delayed updates. The policy must be fine-tuned to allow sufficient bandwidth for routing protocols.
Why this answer
CoPP policies must be carefully designed to avoid throttling critical control plane protocols. A blanket rate limit of 1000 pps may be insufficient for BGP, especially if there are many peers or frequent updates. BGP keepalives are sent every 60 seconds by default, but updates and other messages can burst.
If the policer drops these, sessions can flap. The correct approach is to create granular class-maps that match BGP and other routing protocols, and assign appropriate rates or exempt them from policing.
Exam trap
The trap here is assuming that a single rate limit for all control plane traffic is safe, without considering the specific needs of routing protocols like BGP.