A network engineer is implementing Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against control plane overload. The router has management traffic (SSH, SNMP) and routing protocol traffic (OSPF, BGP). After applying the CoPP policy, the engineer notices that OSPF adjacencies are flapping. Which action should the engineer take to resolve this issue while maintaining control plane protection?
OSPF adjacency flapping indicates that OSPF hello packets are being dropped due to the policer rate being too low. Increasing the rate limit for the OSPF class allows legitimate OSPF control traffic to pass while still protecting the control plane from excessive traffic. This is the correct action because it directly addresses the dropped OSPF packets without removing protection entirely.
Why this answer
OSPF adjacency flapping after CoPP deployment indicates that OSPF hello packets are being dropped by the policer. The CoPP policy likely has a rate limit for OSPF that is too low for the network's requirements. Increasing the rate limit for the OSPF class allows OSPF traffic to pass while still enforcing a policer to protect against excess traffic.
This maintains control plane protection and resolves the flapping.
Exam trap
The trap here is assuming that any CoPP issue requires removing the policy, when in fact tuning the rate limits for specific classes is the correct approach to balance protection and protocol operation.