hit counter script

Dynamic Mobile Hosts; Dynamic Shared Secret For Docsis - Cisco 7246VXR - uBR Router Software Configuration Manual

Universal broadband router
Table of Contents

Advertisement

Chapter 1
Overview of Cisco uBR7200 Series Software
For general information, see the description of the Cisco IOS Firewall Feature Set in the Cisco Product
Catalog. For detailed information, refer to these documents on Cisco.com:

Dynamic Mobile Hosts

This feature addresses a security hole that occurs when the Cisco uBR7200 series router supports mobile
hosts. (Mobile host are hosts that can move from one modem to another modem.) Anyone who knows
the MAC address of a mobile host can "fake" the mobile host, thereby causing denial of access for the
real mobile host.
To avoid this security hole, the Dynamic Mobile Hosts feature pings the mobile host on the old service
identifier (SID) to verify that the host has indeed been moved.
A DHCP server is used to verify addresses and can be configured with the cable source-verify dhcp command;
the no cable arp command should be configured in the CMTS to prevent it from sending ARP requests.
For additional information, refer to the Cisco IOS CMTS Cable Command Reference Guide on
Cisco.com:

Dynamic Shared Secret for DOCSIS

The Dynamic Shared Secret feature provides service providers a way of providing higher levels of
security for their Data-over-Cable Service Interface Specifications (DOCSIS) cable networks, by using
randomized, single-use shared secrets to verify the DOCSIS configuration files that are downloaded to
each cable modem. The Dynamic Shared Secret feature is enabled using the cable dynamic-secret
interface configuration command.
The Dynamic Shared Secret feature automatically creates a unique DOCSIS shared secret on a per-modem
basis, creating a one-time use DOCSIS configuration file that is valid only for the current session. This
ensures that a DOCSIS configuration file that has been downloaded for one cable modem can never be used
by any other modem, nor can the same modem reuse this configuration file at a later time.
This patent-pending feature is designed to guarantee that all registered modems are using only the
quality of service (QoS) parameters that have been specified by the DOCSIS provisioning system for
that particular modem at the time of its registration.
OL-2239-05
Dynamic port mapping that maps the default port numbers for well-known applications to other port
numbers. This can be done on a host-by-host basis or for an entire subnet, providing a large degree
of control over which users can access different applications.
Configurable alerts and audit trail.
Intrusion Detection System (IDS) that recognizes the signatures of 59 common attack profiles.
When an intrusion is detected, IDS can either send an alarm to a syslog server or to NetRanger
Director, drop the packet, or reset the TCP connection.
User-configurable audit rules.
Configurable real-time alerts and audit trail logs.
Cisco IOS Firewall Feature Set
In particular, refer to the
http://www.cisco.com/en/US/docs/ios/11_3/security/configuration/guide/secur_c.html
http://www.cisco.com/en/US/docs/ios/cable/command/reference/cbl_book.html
Cisco uBR7200 Series Universal Broadband Router Software Configuration Guide
documentation
"Security Configuration Guide, Traffic Filtering"
cops tcp window-size
chapter:
1-105

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents