CoPP vs CPPr: Which Control-Plane Defense to Deploy
CoPP is one aggregate policer; CPPr subdivides the control plane and adds port-filtering. A decision guide backed by a real CoPP police capture.
CCIE-level material for engineers past the CCNP line. Articles tagged CCIE cover expert-track routing, overlays, security and automation, with full configs and real device output from CML.
CoPP is one aggregate policer; CPPr subdivides the control plane and adds port-filtering. A decision guide backed by a real CoPP police capture.
CPPr subdivides the control plane into host, transit and cef-exception subinterfaces and adds port-filtering, next to real CoPP police captures from CML.
Zone-Based Firewall, ASA, and FTD solve different jobs. This comparison uses real command output captured from all three platforms to show you which Cisco firewall belongs where, not which one is best.
Flat ZBF policies do not scale. This post shows how nested class-maps let you reuse protocol groups across policies and combine match-all conditions with match-any protocols to build layered, maintainable firewall policy.
Your ZBF matches protocol http, but the app on TCP 8080 will not pass because the inspector cannot see it. Port-maps teach the IOS XE protocol inspector about non-standard ports. Real cat8000v output shows the failure and the fix.
The Zone-Based Firewall is the stateful firewall inside Cisco IOS XE. This anchor guide covers zones, zone-pairs, the class-map and policy-map model, and the default-drop trap that locks engineers out of their own routers.
Cisco removed Clientless SSL VPN (WebVPN) from the ASA in 9.17. Real 9.24 CLI proof, and the Secure Client remote-access VPN that replaced it.
Enable ASDM on a Cisco ASA 9.24, hit the image-not-set gotcha, and get the honest 2026 verdict on the Java GUI versus the CLI.
Endpoint versus pass-through on the Cisco ASA: inspect ipsec-pass-thru, NAT-T on UDP 4500, and the classic Phase 1 up, Phase 2 down failure.
Map IKEv1 to IKEv2 on the Cisco ASA command by command, then cut a live site-to-site tunnel over without an outage.
A real LAN-to-LAN IKEv2 tunnel from a Cisco ASA to an IOS XE peer, verified with show vpn-sessiondb from a live CML capture.
EtherType ACLs let a transparent-mode Cisco ASA filter non-IP frames a routed firewall never sees. Learn what bridges through a Layer 2 firewall by default and how to control it.