cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
927
Views
0
Helpful
2
Replies

Trying to understand the differences between the data/control/management planes

wrainwater
Level 1
Level 1

I see these terms get thrown around a lot. In my cisco novice mind im assuming

data = all the data packets flowing through the switch.

control = not sure. assuming the protocols that control the traffic ??

Management = the traffic flowing through the management interface ??? not sure either.

 

can someone help me understand them?

2 Replies 2

I will give you an example to make it closer. In IPSec VPN,

data is the actual encrypted traffic (called esp or ah)
control is the traffic required to setup vpn (called isakmp)

management is the management traffic to the box such as telnet, ssh, etc

Similarly for BGP routing

data is the actual traffic going from one router to another
control is the traffic required to establish BGP neighborship

Dennis Mink
VIP Alumni
VIP Alumni

I look at it like this:

 

data plane:  the hardware and logic required to process packets, for instance from eth1/16 to eth 1/1 on a nexus switch. if an ethernet frame goes between these ports only the cam table is used and the frame is simply switched without the intervention of the control plane.

the control plane, where the configuration lives, process traffic for instance if it need to router traffic or encapsulate it into IPSEC.

management plane, all that is needed to manage the device. firewall can have a dedicated port for that.

 

read up on ISSU on a nexus switch, this gives you an inside of how the data and control plan can work independently

 

Please remember to rate useful posts, by clicking on the stars below.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: