networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 4 posts ] 
Author Message
PostPosted: Thu Dec 01, 2011 2:27 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Nov 23, 2009 7:55 pm
Posts: 1395
Location: South Carolina
Certs: CCNP, CCNA Sec
Hey all,

We inherited a lot of the equipment from another team of network administrators and every now and then, we run into a switch with some old code or configuration that was left behind and missed by us. Today, I discovered that CPP was enabled on 3 of our access-layer switches in one of the buildings we support. I'd like to turn the feature off but in all the documentation I've read, there's no way of doing it. I've read this:

http://www.cisco.com/en/US/docs/switche ... l_pln.html

Any suggestions? Thanks.


Top
 Profile  
 
PostPosted: Thu Dec 01, 2011 2:44 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Aug 21, 2007 2:15 pm
Posts: 8457
Location: Frederick MD
Certs: Instanity
I'd do a show run and just go into config and then control-plane
and remove any commands under there, but from this link you provided
that probably wouldn't work

I would think this would be your out

"CoPP is not enabled unless the global QoS is enabled and police action is specified. "

so if you need QoS, remove the CoPP police action, if QoS is not needed turn QoS off globally

_________________
"If you're good at anticipating the human mind. It leaves nothing to chance."
-Jigsaw


Top
 Profile  
 
PostPosted: Thu Dec 01, 2011 2:49 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Nov 23, 2009 7:55 pm
Posts: 1395
Location: South Carolina
Certs: CCNP, CCNA Sec
Also just read from that link :(

The policy-map named system-cpp-policy is dedicated for CoPP. Once attached to the control-plane, it cannot be detached.

EDIT:

One of the first things I did was disable QOS but the access-lists still show when doing a sh access-list.


Top
 Profile  
 
PostPosted: Thu Dec 01, 2011 4:57 pm 
Offline
Senior Member
Senior Member
User avatar

Joined: Sat Apr 09, 2011 3:55 pm
Posts: 388
Certs: CCIE CCNP-S CCDA MCSE RHCT Sec+ A+
If you're not actually policing anything in the policy it just sounds like what you're left with is config bloat (like when you enable https on a router then disable it, you still have the self-signed sig in the config even though it serves no purpose... or those temp ACLs that show up when you configure IOS login enhancement features). I wouldn't worry about it.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 4 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 14 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group