The control plane decides where traffic should go, and the data plane moves it there. On a router or switch, the control plane runs the routing protocols and builds the tables.
The data plane, also called the forwarding plane, looks up every arriving packet in those tables and sends it on, usually in dedicated hardware. A third part, the management plane, is how people and tools configure and monitor the device.
- The control plane builds the tables. The data plane uses them
- Control plane work runs on the CPU. Data plane work runs in hardware on most switches and routers
- The management plane is SSH, SNMP, APIs and logs, and it needs its own protection
- Packets addressed to the device itself leave the fast path and go to the CPU
- SDN moves the control plane to a controller and leaves the data plane in the devices
On this page
Control planeWhat the control plane does
The control plane is the part of a network device that works out how the network is laid out and what to do with traffic. It does not touch user data. It talks to the control planes of other devices, learns the network topology and turns that knowledge into tables.
On a router, the control plane is where routing protocols run. OSPF exchanges link state information with neighbors, BGP exchanges routes with other networks, and static routes are added by hand. The control plane compares all of those sources, picks the best path to each destination and writes the result into the routing table.
On a switch, control plane functions include spanning tree, which decides which links forward and which block, plus protocols such as LLDP and LACP. ARP belongs here as well: resolving an IP address to a MAC address is a decision about where traffic goes, not the act of sending it.
All of this runs as software on the general purpose CPU of the device. It is complex, it changes slowly compared with packet rates, and it can take seconds to converge after a link fails. That is acceptable, because the control plane is not in the path of the packets.
Data planeWhat the data plane does
The data plane is the part that handles the packets themselves. A data packet arrives on an interface, the data plane looks up the destination address in the forwarding table and sends the packet out of the matching interface. Another name for it is the forwarding plane, and the two terms mean the same thing.
The routing table the control plane builds is not what the data plane reads. The control plane distills it into a forwarding table, the FIB, that holds only the winning route for each prefix with the outgoing interface and next hop already resolved. On a switch, the equivalent is the MAC address table.
Forwarding is not the only data plane job. Anything that has to happen to every packet at line rate lives here:
- Access control lists, which permit or drop packets by address and port.
- Quality of service, which classifies, marks and queues traffic.
- Address translation and encapsulation, such as NAT, VLAN tags and tunnel headers.
- Counters and flow records, which feed monitoring tools.
On hardware platforms the data plane runs in ASICs, with tables held in fast dedicated memory. That is how a layer 3 switch can route across dozens of ports at full speed with a modest CPU.
On software routers, virtual appliances and small firewalls, the data plane is code that runs on the same CPU as everything else.
Management planeWhere the management plane fits
The management plane is how the device is configured and watched. SSH sessions, a web interface, SNMP polling, syslog, NETCONF and REST APIs are all management plane traffic. Some texts treat it as part of the control plane. Keeping it separate is more useful, because it has different users and different risks.
The control plane talks to other network devices. The management plane talks to people and to management systems, and it is where policies are defined before the other two planes enforce them.
That makes it a network security priority. An attacker who reaches the management plane can change the configuration, which is worse than anything a forged routing update can do. Restrict it to a management network, put an access list on the management services and prefer an out of band port where the hardware has one.
Cloud managed networking is a management plane moved into a vendor's cloud. The devices keep their own control and data planes, which is why they keep forwarding when the dashboard is unreachable.
In practiceWhy a busy CPU does not always stop forwarding
This is where control plane vs data plane stops being theory. On a hardware switch or router, the CPU can sit at 100 percent while traffic passes normally, because transit packets never reach the CPU. The ASICs keep forwarding with the last tables they were given.
The protection is not unlimited. Some packets have to be sent, or punted, to the CPU: packets addressed to the device itself, routing protocol messages, ARP requests, packets whose TTL has expired and packets with options the hardware cannot process. A flood of those can starve the control plane.
When the control plane starves, it misses routing protocol hellos. Neighbors declare the device dead, routes are withdrawn and spanning tree may reconverge. Traffic then fails even though the data plane hardware was healthy the whole time. The outage starts in the control plane and shows up in the data plane.
Three things an administrator touches come straight from this.
Control plane policing. CoPP, in Cisco's terms, is a QoS policy applied to traffic headed for the CPU. It rate limits each class, so a ping flood cannot crowd out OSPF or BGP. Other vendors do the same job with a filter on the loopback or a built in protection profile.
Nonstop forwarding and graceful restart. Because the data plane can run on its existing tables, a device with redundant supervisors can restart its control plane, or fail over to the standby, while packets keep moving. Neighbors that support graceful restart hold the routes during the gap.
Reading high CPU correctly. On a hardware platform, high CPU with normal throughput is a control or management plane problem: a routing flap, an SNMP poller, a debug left on. On a software router or firewall, high CPU is a forwarding problem too, because the data plane shares that CPU.
SDNHow SDN and controllers move the control plane
In a traditional network architecture every device runs its own control plane and they reach agreement through protocols. Software defined networking, SDN, takes control plane vs data plane literally and separates the two.
A central controller holds the control plane and programs the forwarding tables of many devices, which keep only the data plane. OpenFlow was the first widely known protocol for that job.
Few business networks run pure SDN. What they run are products built on the same architecture. In Cisco SD-WAN, a controller distributes routes and policies across the WAN while edge routers forward the traffic. In a VXLAN fabric, a BGP EVPN control plane tells each switch where the MAC addresses are.
Network automation tools work one level up, through the management plane.
The practical question with any controller is what happens when it is unreachable. In a sound design the data plane keeps forwarding on its last known state and only changes stop. Ask the vendor that question before buying, and test it before relying on it.
Cloud usageThe same words in cloud and Kubernetes
Cloud providers borrowed the terms. AWS's fault isolation whitepaper says the terms come from routers, describes control planes as the administrative APIs used to create, read, update, delete and list resources, and describes the data plane as what provides the primary function of the service.
The consequence is the same as in a router. Launching a new virtual machine is a control plane action, and the running machine is data plane. If the provider's control plane has an outage, existing workloads usually keep running, and what you lose is the ability to change anything.
Kubernetes uses the same split. Its control plane is the API server, scheduler, controller manager and the etcd store. The worker nodes that run the containers are the data plane. A service mesh repeats the pattern again, with sidecar proxies as the data plane and a central component that configures them.
PitfallsWhere people go wrong
Reading CPU load as forwarding load. On hardware platforms the two are unrelated. A switch at 90 percent CPU may be forwarding perfectly, and a switch at 5 percent may be dropping packets in an oversubscribed ASIC queue. Check interface counters for the data plane and process lists for the control plane.
Leaving the control plane unprotected. A device with no policing on CPU bound traffic can be taken off the network by anyone who can send it enough pings or ARP requests. Where a platform ships with a default policy, treat it as a starting point, not a finished one.
Managing devices in band with no restriction. If SSH and SNMP answer on every interface, the management plane is exposed to every network the device touches, including the internet on an edge router.
Testing data plane features on the control plane. A ping to the router's own address is punted to the CPU, where answering it ranks below routing work. Slow or lost replies from the router itself say little about how it forwards transit traffic. Ping through the device, not at it.
Assuming a controller is in the data path. In SDN and SD-WAN designs the controller distributes decisions and does not carry user traffic. Sizing, placement and failure planning for it are control plane questions.
ComparisonControl plane, data plane and management plane, and what each one is responsible for
| Criterion | Control plane | Data plane | Management plane |
|---|---|---|---|
| Job | Decides where traffic goes | Moves the traffic | Configures and monitors |
| Works on | Routes, topology, neighbor state | Every packet | Configuration and telemetry |
| Runs on | CPU or a controller | ASICs on hardware platforms | CPU |
| Speed that matters | Convergence time, in seconds | Line rate, per packet | Human and tool response |
| Typical protocols | OSPF, BGP, STP, ARP, LACP | Ethernet, IP, MPLS, VXLAN forwarding | SSH, SNMP, syslog, NETCONF |
| Main table | Routing table, RIB | Forwarding table, FIB | Running configuration |
| If it fails | Tables go stale, then neighbors drop | Traffic stops at once | The device runs but cannot be changed |
| Protect it with | Policing, protocol authentication | ACLs, QoS | Management network, access lists, AAA |
The row on failure is the one to remember in a data plane vs control plane discussion. A data plane failure is immediate and obvious. A control plane failure is delayed: forwarding carries on with old tables until timers expire or the topology changes, and then the damage spreads to every connected neighbor.
FAQFrequently asked questions
What is the control plane?
The control plane is the part of a network device, or of a central controller, that decides how traffic should be forwarded. It runs routing protocols and spanning tree, learns the topology and builds the tables the data plane uses. It does not carry user traffic.
What is the data plane?
The data plane is the part of a device that forwards packets. For each packet it looks up the destination in the forwarding table, applies access lists and QoS, and sends the packet out of an interface. On most switches and routers it runs in dedicated hardware.
What is the difference in data plane vs control plane?
The control plane decides and the data plane acts. The control plane processes routing updates and topology changes on the CPU, at human timescales. The data plane processes every packet at line rate, using the tables the control plane gave it.
Is the forwarding plane the same as the data plane?
Yes. Forwarding plane and data plane are two names for the same function: moving packets from an input interface to an output interface according to the forwarding table. Mobile network standards call it the user plane.
What is the management plane?
The management plane is the set of functions used to configure, monitor and maintain a device: SSH, web interfaces, SNMP, syslog, NETCONF and APIs. It carries administrative traffic and should be reachable only from trusted management networks.
Is OSPF control plane or data plane?
OSPF is control plane. It exchanges link state information between routers and computes the best paths. The packets that later follow those paths are data plane traffic. The same applies to BGP, EIGRP, RIP and IS-IS.
Is ARP control plane or data plane?
ARP is usually treated as control plane. It builds the mapping between IP addresses and MAC addresses that the data plane needs to forward packets. ARP requests are handled by the CPU, which is why ARP floods are a classic target for control plane policing.
What is control plane policing?
Control plane policing, CoPP, is a QoS policy applied to traffic that is sent to a device's CPU. It rate limits each class of traffic so that a flood of pings or malformed packets cannot starve routing protocols and management sessions.
Can the data plane work without the control plane?
For a while. The data plane keeps forwarding with the tables it already has, which is what nonstop forwarding and graceful restart rely on. It cannot react to a failed link or a new route until the control plane returns.
How does SDN change the control plane?
SDN moves the control plane out of the individual devices into a central controller. The controller computes forwarding decisions and programs them into the devices, which keep only the data plane. The network is then configured as one system instead of box by box.
What do control plane and data plane mean in the cloud?
In cloud services the control plane is the set of APIs that create, change and delete resources. The data plane is the running resource doing its job, such as a virtual machine serving requests. The two are built and scaled separately.
What is the Kubernetes control plane?
It is the group of components that manage a cluster: the API server, the scheduler, the controller manager and the etcd data store. The worker nodes that run containers form the data plane. Workloads keep running if the control plane is briefly unavailable.
Keep readingRelated concepts
Read next · Routing OSPF Explained A routing protocol at work inside the control plane: neighbors, link state and how the best path is chosen. Open this next12 min- Infrastructure · 8 min Cisco SD-WAN, and Why the Controller Never Touches Your Traffic A product built on this split, with separate controllers for management, control and the forwarding routers.
- Infrastructure · 10 min Cloud Managed Networking, and What Happens When You Stop Paying What moves to the vendor's cloud when the management plane does, and what the license controls.
- Design · 9 min Software Defined Networking, and Where a Business Actually Meets It What happens when the control plane leaves the devices entirely and moves into a controller.