Modern router architecture design maintains a strict separation of forwarding and router control plane hardware and software. The router control plane supports routing and management functions. It is generally described as the router architecture hardware and software components for handling packets destined to the device itself as well as building and sending packets originated locally on the device. The forwarding plane is typically described as the router architecture hardware and software components responsible for receiving a packet on an incoming interface, performing a lookup to identify the packet's IP next hop and determine the best outgoing interface towards the destination, and forwarding the packet out through the appropriate outgoing interface.

Request for Comments: 6192                          D. Dugal
Juniper Networks
C. Pignataro
R. Dunn
Cisco Systems
March 2011

                   Protecting the Router Control Plane


   This memo provides a method for protecting a router's control plane    from undesired or malicious traffic.  In this approach, all    legitimate router control plane traffic is identified.  Once    legitimate traffic has been identified, a filter is deployed in the    router's forwarding plane.  That filter prevents traffic not    specifically identified as legitimate from reaching the router's    control plane, or rate-limits such traffic to an acceptable level.

   Note that the filters described in this memo are applied only to    traffic that is destined for the router, and not to all traffic that    is passing through the router.

