Control Plane Policing Probe

The Control Plane Policing (COPP) probe validates output on all managed switches in the fabric and protects the control plane CPU from overload caused by host-path punted packets. This probe raises per-protocol violations, with each violation indicating a dropped packet. You can use this probe to help troubleshoot unexpected network forwarding behavior. Supported platforms include Junos OS, Junos OS EVO, Arista EOS, CISCO NX-OS, and SONiC.

The Control Plane Policing (COPP) probe:

  • Collects the system response of Control Plane Policing outputs. The collector uses the following commands:

    • Arista EOS: show policy-map copp-system-policy

    • CISCO NXOS: show policy-map interface control-plane

    • SONiC: debugsh -c, ORCHAGENT -e show system internal orchagent copp policers

    • JUNOS: show ddos-protection protocols

Probe Settings

To specify the probe settings, follow the instructions in Instantiating the Predefined Probe. Select the Control Plane Policing probe from the drop-down menu and specify the probe parameters.

Configuration interface for instantiating a predefined probe for Control Plane Policing with fields for probe type, label, time window, collection period, history retention, drop count threshold, description, and options to create another probe or finalize creation.

To configure the probe, navigate to Analytics > Probes and click the Control Plane Policing probe.

Monitoring tool interface showing tabs like Dashboard, Anomalies, Analytics, and Time Voyager. Probes section selected with rows listing probe details such as label, anomalies, operational state, last updated info, enabled toggle, and action buttons. Create Probe button visible.

Processor: Control Place Policing

Control Plane Policing (COPP) stops host-path punted packets from overwhelming the control plane CPU. Violations indicate that applications may behave unexpectedly, and the switch protects itself accordingly.

This diagnostic probe raises per-protocol violations, and each violation indicates a dropped packet. Unchecked violations can disrupt routing protocols and management access, especially during COPP attacks or high-volume traffic. Analyzing this diagnostic probe can help troubleshoot unexpected network forwarding behavior.

Extensible Service Collector

The Extensive Service Collector ingests data from custom telemetry services. Use this processor for services built with custom telemetry collectors.

User interface for Extensible Service Collector with two sections: Graph filters nodes by roles, system IDs, deployment modes, and name; Telemetry shows system ID, service name copp, interval 120, input dynamic, and state values mapped to Normal, Violated, Unknown.

Control Plane Policing

The Control Plane Policing page shows the COPP counters exposed for each device. Control packets such as SSH, ICMP, Telnet, ARP, and BGP are handled by the local processor.

Control Plane Policing interface with metrics table showing counters like Violation Count, Arrival Rate, Drop Count, and Max Rate, plus data source selection and pagination.

Processor: Periodic Dropped Packets

Anomalies occur when dropped packets exceed the Drop Count Threshold during the Aggregation Period. Periodic packet loss often indicates network congestion, outdated drivers, or faulty hardware. Significant packet loss overwhelms router buffers, causing slower load times and latency.

Telemetry synchronization issues, specifically within the GRPD communication channel, or misconfigured IBA probes can also cause packet loss. The dropped-packet process measures the dropped packet count between collection intervals.

Periodic Change

The Periodic Change Processor calculates absolute changes over a defined period for each input value. Input values increase monotonically, ensuring the number of values never decreases over time.

Configuration interface for processor Periodic Dropped Packets with options for periodic changes, processing interval of 300 seconds, and advanced settings including graph query and streaming disabled.

Periodic Dropped Packets

The Periodic Dropped Packets table tracks dropped packets between collection intervals. You can view the data in real time or as a time series.

Dashboard showing Periodic Dropped Packets with a table of system metrics including System ID, Name, dropped packet count, and last update time. Data source set to Real Time.

Processor: COPP Violations

Range Processor

The Range Processor checks a value against a defined range. It can evaluate either the series value or a series aggregation, such as sum, average, last, standard deviation, or sample count.

Configuration screen for COPP Violations processor. Defines detection parameters for dropped packets, anomaly logging, and retention settings.

COPP Violations

COPP violations raise anomalies if dropped packets exceed the Drop Count Threshold within the defined Aggregation Period.

An anomaly is raised if the Drop count threshold value specified in Probe Settings exceeds the Time Window. For example, a threshold of 1 and 300 seconds raises an anomaly after 1 dropped packet in 300 seconds. The anomaly clears if the counter stays below the threshold in the next time window.

Network analytics dashboard showing COPP Violations with a red warning icon for dropped packets. Includes anomaly details, metrics, a graph, and navigation options.

Here is an example of a COPP violation (filtered view), which occurs when ARP packets exceed the threshold within the specified time value.

Network analytics dashboard focused on Control Plane Policing violations with navigation tabs, filters, data table listing systems and roles, time-series graph showing trends, and anomalies highlighted.

This example shows when the anomalies are resolved.

Control Plane Policing dashboard showing CPU protection against excessive traffic, with data table, navigation panel, status indicators, and search tools for network analysis.