Data plane, control plane and management plane

The three functional layers of a network device: the data plane forwards traffic, the control plane decides where it goes, and the management plane configures and monitors.

Every network device can be described as three planes. The data plane, also called the forwarding plane, moves packets from an input to an output using tables it has been given. The control plane decides what those tables contain, for example by running routing protocols such as BGP with neighbouring devices. The management plane is how people and tools configure and monitor the device, through interfaces such as SSH, SNMP and APIs.

Each plane needs its own protection. Flooding the data plane is a denial of service against throughput. Corrupting the control plane, with a false route announcement for example, redirects traffic without touching any device’s configuration. Taking over the management plane hands an attacker the device itself, which is why management access is commonly restricted and moved to out-of-band management. Software-defined networking separates the control plane from the data plane and logically centralises it in a controller, programmed through APIs. That gives consistent policy, but the controller and its APIs become high-value targets, so centralisation concentrates risk as well as control.

Exam relevance: questions in this area tend to describe an attack or a function and ask which plane it belongs to. Candidates are expected to reject the claim that SDN is more secure simply because it is centralised.