🔥 3-day streak
Cisco CCNP Enterprise ENARSI (300-410)17 / 127
Question 17 of 127
A network engineer configured CoPP on a core router to protect the control plane. After applying the policy, users report that transit traffic passing through the router is unaffected, but a newly added deny-all class at the end of the policy-map (applied to catch unclassified traffic to the router itself) is dropping legitimate SSH sessions to the device from a management subnet. The management subnet was intentionally omitted from the permit ACLs. Which characteristic of CoPP explains why only the router-destined SSH traffic is impacted and not the transit traffic?
Reviewed for accuracy · Report an issueNext question