I didn't want to plug for myself so thanks. ;)...as we are going to present the OPSEC WG in about 10 minutes at IETF. ;)

In this draft we want to raise the awareness of protecting the control plane and give a simplistic and minimalistic example. No two deployments are the same so it's critical they be tested and constantly evaluated for changes needed which is why we kept it somewhat general.

Rodney



On 3/23/10 4:01 PM, Buhrmaster, Gary wrote:
Can there really *BE* a best practices for the 6500 when you either can't
configure a drop action in your default, or you risk rate-limiting/dropping
ARP gleans?

Well, here is some guidance for CoPP, authored by
a number of people from Cisco and Juniper:

http://tools.ietf.org/html/draft-dugal-opsec-protect-control-plane-02

As always, YMWV.

_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/
_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to