0
POPSCDP+ACL > > There is not a public document that mentions that MAC access-list does not block CDP packets. > However I have spoken with the development team and you can use this email as confirmation of fact that MAC access-lists do not block the control packets like CDP/VTP/DTP or STP bpdu. > Any packet with a destination mac as reserved like the ones mentioned below are sent to the SP cpu before the action in the ACL takes place. > The current hardware doesn't have the capability to apply ACL on BPDU or CDP/VTP/DTP packets. > > CDP packets are processed differently than, other protocol packets. All packets with destination mac as 0100.0CCC.CCCC (CDP/VTP/DTP) go to the SP cpu. > The SP cpu examines the packets and understands which protocol it is. The CDP packets are sent to RP by the SP. > This is the way it is designed depending on the underlying architecture and this is a design issue. It is not possible to send the CDP packet directly to RP for processing. > > I do understand yo