cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4448
Views
0
Helpful
4
Replies

Auto Copp Policy

Hi

I have to install two new cisco 6509 with Sup 2T 10G modules.

Now there is a small problem in configuration which is there by default.

It is not getting erased..can anyone help???

I am mentioning below the configuration which I'll have to remove.

I already used the command

"no service-policy input policy-default-autocopp", but upon erasing class map and policy map and then rebooting the unit again same configuration appears.

class-map match-any class-copp-icmp-redirect-unreachable

class-map match-all class-copp-glean

class-map match-all class-copp-receive

class-map match-all class-copp-options

class-map match-all class-copp-broadcast

class-map match-all class-copp-mcast-acl-bridged

class-map match-all class-copp-slb

class-map match-all class-copp-mtu-fail

class-map match-all class-copp-ttl-fail

class-map match-all class-copp-arp-snooping

class-map match-any class-copp-mcast-copy

class-map match-any class-copp-ip-connected

class-map match-any class-copp-match-igmp

  match access-group name acl-copp-match-igmp

class-map match-all class-copp-unknown-protocol

class-map match-any class-copp-vacl-log

class-map match-all class-copp-mcast-ipv6-control

class-map match-any class-copp-match-pimv6-data

  match access-group name acl-copp-match-pimv6-data

class-map match-any class-copp-mcast-punt

class-map match-all class-copp-unsupp-rewrite

class-map match-all class-copp-ucast-egress-acl-bridged

class-map match-all class-copp-ip-admission

class-map match-all class-copp-service-insertion

class-map match-all class-copp-mac-pbf

class-map match-any class-copp-match-mld

  match access-group name acl-copp-match-mld

class-map match-all class-copp-ucast-ingress-acl-bridged

class-map match-all class-copp-dhcp-snooping

class-map match-all class-copp-wccp

class-map match-all class-copp-nd

class-map match-any class-copp-ipv6-connected

class-map match-all class-copp-mcast-rpf-fail

class-map match-any class-copp-ucast-rpf-fail

class-map match-all class-copp-mcast-ip-control

class-map match-any class-copp-match-pim-data

  match access-group name acl-copp-match-pim-data

class-map match-any class-copp-match-ndv6

  match access-group name acl-copp-match-ndv6

class-map match-any class-copp-mcast-v4-data-on-routedPort

class-map match-any class-copp-mcast-v6-data-on-routedPort

!

!

policy-map policy-default-autocopp

  class class-copp-mcast-v4-data-on-routedPort

   police rate 10 pps burst 1 packets    conform-action drop     exceed-action drop

  class class-copp-mcast-v6-data-on-routedPort

   police rate 10 pps burst 1 packets    conform-action drop     exceed-action drop

  class class-copp-match-mld

   police rate 10000 pps burst 10000 packets    conform-action set-discard-class-transmit 48    exceed-action transmit

  class class-copp-match-igmp

   police rate 10000 pps burst 10000 packets    conform-action set-discard-class-transmit 48    exceed-action transmit

  class class-copp-icmp-redirect-unreachable

   police rate 100 pps burst 10 packets    conform-action transmit     exceed-action drop

  class class-copp-ucast-rpf-fail

   police rate 100 pps burst 10 packets    conform-action transmit     exceed-action drop

  class class-copp-vacl-log

   police rate 2000 pps burst 1 packets    conform-action transmit     exceed-action drop

  class class-copp-mcast-punt

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-mcast-copy

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-ip-connected

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-ipv6-connected

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-match-pim-data

   police rate 1000 pps burst 1000 packets    conform-action transmit     exceed-action drop

  class class-copp-match-pimv6-data

   police rate 1000 pps burst 1000 packets    conform-action transmit     exceed-action drop

  class class-copp-match-ndv6

   police rate 1000 pps burst 1000 packets    conform-action set-discard-class-transmit 48    exceed-action drop

policy-map policy-default-autocopp

  class class-copp-mcast-v4-data-on-routedPort

   police rate 10 pps burst 1 packets    conform-action drop     exceed-action drop

  class class-copp-mcast-v6-data-on-routedPort

   police rate 10 pps burst 1 packets    conform-action drop     exceed-action drop

  class class-copp-match-mld

   police rate 10000 pps burst 10000 packets    conform-action set-discard-class-transmit 48    exceed-action transmit

  class class-copp-match-igmp

   police rate 10000 pps burst 10000 packets    conform-action set-discard-class-transmit 48    exceed-action transmit

  class class-copp-icmp-redirect-unreachable

   police rate 100 pps burst 10 packets    conform-action transmit     exceed-action drop

  class class-copp-ucast-rpf-fail

   police rate 100 pps burst 10 packets    conform-action transmit     exceed-action drop

  class class-copp-vacl-log

   police rate 2000 pps burst 1 packets    conform-action transmit     exceed-action drop

  class class-copp-mcast-punt

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-mcast-copy

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-ip-connected

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-ipv6-connected

   police rate 1000 pps burst 256 packets    conform-action transmit     exceed-action drop

  class class-copp-match-pim-data

   police rate 1000 pps burst 1000 packets    conform-action transmit     exceed-action drop

  class class-copp-match-pimv6-data

   police rate 1000 pps burst 1000 packets    conform-action transmit     exceed-action drop

  class class-copp-match-ndv6

   police rate 1000 pps burst 1000 packets    conform-action set-discard-class-transmit 48    exceed-action drop

!

!

!

ip access-list extended acl-copp-match-igmp

permit igmp any any

ip access-list extended acl-copp-match-pim-data

deny   pim any host 224.0.0.13

permit pim any any

!

!

!

!

ipv6 access-list acl-copp-match-mld

permit icmp any any mld-report

permit icmp any any mld-query

permit icmp any any mld-reduction

permit icmp any any 143

!

ipv6 access-list acl-copp-match-ndv6

permit icmp any any nd-na

permit icmp any any nd-ns

permit icmp any any router-advertisement

permit icmp any any router-solicitation

permit icmp any any redirect

!

ipv6 access-list acl-copp-match-pimv6-data

deny 103 any host FF02::D

permit 103 any any

!

control-plane

service-policy input policy-default-autocopp

!

4 Replies 4

John Blakley
VIP Alumni
VIP Alumni

Try going into the control-plane first, remove it from there and then you should be able to remove it from the config. Don't forget to save changes before reloading the switch...

HTH,
John

*** Please rate all useful posts ***

HTH, John *** Please rate all useful posts ***

Ivan Shirshin
Cisco Employee
Cisco Employee

Hi,

It is intended to work like this.  If the policy map itself is removed, it will be recreated at the time of reload and it will be tried to apply on the copp interface, as it is default configuration for the CoPP.

If you want to remove the control plane policy, better remove it from the control-plane interface using "no service-policy <> <>". Save the config after removing the service policy from the interface and reload, the should not be seen.

Kind Regards,
Ivan Shirshin

**Please grade this post if you find it useful.

Kind Regards,
Ivan

Hi Ivan

I removed it from the control plane interface and its getting removed alsot. After the rebooting of swithc its also not showing under control plane, but class map and policy maps are still there. Then again if I am removing the class maps and policy maps, and rebooting the switch, again the complete config appears itself.

R's

Manjeet

stmsystems
Level 1
Level 1

All these default copp entries are polluting my basic config on a Nexus 3048.  It seems I'm unable to remove this:

(config)# control-plane

(config-cp)# no service-policy input copp-system-policy

% Invalid command at '^' marker.

Is the documentation for this switch model hinting that this is impossible to hide?  Does it not make sense to hide defaults unless they have been overriden?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card