On (2013-06-28 15:05 +0200), "Rolf Hanßen" wrote: > no egress ACL. > On the box I tested there is no ACL bound to any interface at all, only > some in copp classes and one for the line vty.
Do you have 'class-default' configured? I have penultimate rule 'CoPP-IP' which drops, like yours, everything matching to 'ip any any' ACL. After that I have class-default, where I permit (I need it at least for ISIS). If not configured, it's permit as well. I also have: mls rate-limit unicast cef glean 200 50 mls qos protocol ARP police 2000000 62000 And no ARP issues (beware if you're switching also that the ARP police affects transit ARP also) -- ++ytti _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
