
General Router Security 151
Using the classification scheme defined above, commonly required traffic is identified with
a series of ACLs:
• ACL 120: Critical traffic
• ACL 121: Important traffic
• ACL 122: Normal traffic
• ACL 123: Explicitly denies unwanted traffic (slammer worm traffic in this example)
The ACLs will then build classes of traffic that are used to define the policies.
In Example 5-11, the router IP address for control/management traffic will be 10.1.1.1.
Example 5-11 Sample Basic ACLs for CoPP Classification
! Sample basic ACLs for CoPP classification
! In this network, critical was defined at routing protocols: BGP and OSPF
access-list 120 remark ...