cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1638
Views
0
Helpful
2
Replies

Cannot edit control-plane policy

Colin Higgins
Level 2
Level 2

I have a Catalyst 3650 switch running 16.3 code, and I want to edit the system-cpp-policy that is attached to the control-plane by default

 

Because of a security advisory, I need to drop udp 18999 traffic on the switch.

 

So I created a class-map for the traffic called undesirable-udp, but when I go to the system-cpp-policy and try to apply that map with a drop action, I get the following message

 

"undesirable-udp is not a valid class in system-cpp-policy: class rejected"

 

anyone know what is going on here?

1 Accepted Solution

Accepted Solutions

Reza Sharifi
Hall of Fame
Hall of Fame
2 Replies 2

Reza Sharifi
Hall of Fame
Hall of Fame

The  system-cpp-policy can't be deleted or modified.

Have a look at this link and see section "restrictions for CoPP"

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/16-1/configuration_guide/b_161_consolidated_3850_cg/b_161_consolidated_3850_cg_chapter_01011101.pdf

HTH

 

So I would have to remove the system-cpp-policy altogether and apply a different policy on the control plane?

Review Cisco Networking for a $25 gift card