A network engineer is configuring Control Plane Policing (CoPP) on a Cisco IOS XE router to protect against excessive ARP traffic. The engineer applies the following policy: policy-map COPP-POLICY class ARP-CLASS police 8000 conform-action transmit exceed-action drop After applying the service-policy to the control-plane, the engineer notices that legitimate ARP requests are being dropped during peak hours. Which action should the engineer take to resolve this issue while maintaining protection?
The police rate of 8000 bps is too low for peak ARP traffic, causing legitimate ARP requests to be dropped. Increasing the rate to a value that matches normal peak traffic while still providing an upper bound protects the control plane without dropping legitimate traffic. This is the correct tuning approach for CoPP.
Why this answer
CoPP police rates must be tuned to allow legitimate control-plane traffic while blocking excess. A rate of 8000 bps is insufficient for ARP during peak hours, so increasing the rate to a realistic peak value resolves drops while preserving protection. Changing exceed-action to transmit removes protection, moving the policy to the data plane is ineffective, and splitting classes without raising the rate does not fix the underlying issue.
Exam trap
The trap here is thinking that any drop means the policy is too strict and should be disabled, rather than tuning the rate to match legitimate traffic patterns.