Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

Management, Data, and Control Planes in a Network Device

The CCNAAUTO 200-901 6.5 model: every network device has three logical planes. Management (SSH, SNMP, NETCONF — you talk to it). Control (routing protocols — devices talk to each other). Data (actual packets forwarded).

Quick summary
  • Management plane: how YOU (or your scripts) talk to the device — SSH, SNMP, NETCONF, RESTCONF. Config and visibility live here.
  • Control plane: how devices talk to EACH OTHER — OSPF, BGP, STP, LACP. Learned routes, MAC tables, STP topology.
  • Data plane (aka forwarding plane): the actual bytes of user traffic flowing through the switch's ASIC. Fast path. Does NOT need the CPU for every packet.

Mental model

Cisco objective 6.5 says “Describe the function of management, data, and control planes in a network device”. Every router / switch / firewall has three logical “planes” with distinct jobs.

┌─────────────────────────────────┐
│ Management plane  (SSH, SNMP,   │  How humans + scripts
│                   NETCONF, API) │  configure and monitor
├─────────────────────────────────┤
│ Control plane     (OSPF, BGP,   │  How devices learn
│                   STP, HSRP)    │  topology from each other
├─────────────────────────────────┤
│ Data plane        (ASIC-forward │  How actual user packets
│                   every packet) │  get from port A to port B
└─────────────────────────────────┘

Separating these lets each layer be designed for its priority: management for security + observability, control for correctness, data for raw speed.

Management plane

What it does

Everything you (or your scripts) touch when managing the device:

  • SSH / console login (CLI).
  • SNMP polls and traps.
  • NETCONF (port 830) / RESTCONF (port 443).
  • gNMI telemetry subscriptions.
  • Logging to syslog server.
  • NTP sync.

Characteristics

  • Lives on the device CPU.
  • Should NOT share bandwidth with user data (common best practice: a separate management VLAN or physical interface).
  • Prime target for attackers; must be hardened with AAA, ACLs, cert-based auth.

Control plane

What it does

The brain that decides how packets should be forwarded. Dialogues with neighbouring devices:

  • Routing protocols: OSPF, EIGRP, BGP, IS-IS.
  • L2 protocols: STP / RSTP (loop prevention), LACP (link bundling), CDP / LLDP (neighbour discovery).
  • First-hop redundancy: HSRP / VRRP / GLBP.
  • Address learning (MAC tables, ARP).

Characteristics

  • Also lives on the device CPU.
  • Produces tables (routing table, MAC address table) that the data plane consumes.
  • Chatty but low-volume; needs correctness, not raw speed.
  • Attacks here can poison tables; Control-Plane Policing (CoPP) rate-limits control traffic to the CPU.

Data plane

What it does

The actual forwarding of user traffic:

  • Receive packet on ingress port.
  • Look up destination in forwarding table.
  • Rewrite headers (next-hop MAC, TTL, possibly VLAN tag or MPLS label).
  • Transmit on egress port.

Characteristics

  • Usually runs in dedicated silicon (ASIC on switches, line-card FPGAs on routers). Does NOT need the CPU for every packet.
  • Hundreds of millions of packets per second per interface.
  • Receives its forwarding rules from the control plane’s tables.
  • Does the quick classification (ACL hit, QoS marking) at line rate.

Why the separation matters

Scale

A software-only router would need the CPU on every packet. Modern switches push billions of packets per second BECAUSE forwarding is offloaded to ASICs. Control-plane updates happen rarely (seconds, not nanoseconds), so the CPU can handle them while the data plane screams.

Reliability

If the control plane crashes briefly (OSPF re-converges after a link change), the data plane keeps forwarding using the last-known-good tables. “Non-stop forwarding (NSF)” explicitly keeps the data plane running during a route-processor failover.

Security

Each plane needs its own protection:

  • Management plane: tight access lists, strong auth, encrypted protocols only.
  • Control plane: CoPP, routing protocol authentication (OSPF MD5, BGP MD5).
  • Data plane: user ACLs, QoS, segmentation.

In a controller-based network

With Catalyst Center or ACI in play, you can split further:

  • Centralised control plane on the controller (e.g., APIC computes the fabric). The device just enforces what it is told.
  • Distributed control plane per device (traditional OSPF on each router).

Model-driven programmability (NETCONF/RESTCONF/gNMI) is the modern management plane. See model-driven-programmability-value.

Automation implications

PlaneWhat you automate
ManagementConfiguration pushes, telemetry subscriptions, backups, software updates
ControlRarely automated directly; you configure routing protocols VIA the management plane, which then runs the control plane
DataYou do not touch directly; ACLs / QoS / NAT policies configured via management affect data plane behaviour

Your Ansible playbook, your Catalyst Center API call, your gNMI subscription — all talk to the management plane. The device’s control plane does its thing based on your config. The data plane forwards packets based on both.

FAQ

Which plane does SNMP live in? Management plane. SNMP polls and traps are management operations.

OSPF: management or control? Control plane. OSPF is a routing protocol — devices use it to tell each other the topology.

Does the data plane know about VLANs? Yes. VLAN tagging and switching are data-plane operations done in silicon. The VLAN definitions (which VLANs exist) are management; the per-interface association is management; the actual lookup “is this frame on VLAN 10 or 20?” is data.

What is “software forwarding” vs “hardware forwarding”? Software forwarding = data-plane work happening on the CPU (slow). Hardware forwarding = ASIC-accelerated. Features that fall back to software are called “process-switched” and cripple performance.

Is NAT control-plane or data-plane? Both. The NAT rule set is control-plane state. Each packet translation is data-plane work (and ASIC-accelerated on modern platforms).

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Management, Data, and Control Planes in a Network Device. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Management, Data, and Control Planes in a Network Device fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.