Chapter 29: Security
STANDARD Revision 1.0
C4® CMTS Release 8.3 User Guide
© 2016 ARRIS Enterprises LLC. All Rights Reserved.
863
(OPTION_LQ_RELAY_DATA) which contains the CM MAC address. If the DHCPv6 server does not or cannot provide this
option, then these packets will be denied by the C4/c CMTS.
IPv6 Address Learning and Invalid IPv6 Prefixes — If Cable Source Verify is enabled, then any IPv6 source address using an
expired prefix will not be learned. If any IPv6 prefix expires or is deleted, the C4/c CMTS removes all of the learned IPv6
source addresses using that prefix from the MAC database and from the CAMs.
Note: If Source Verify is enabled in DHCP authoritative mode, and if an IPv6 prefix is advertised for auto-configuration,
then hosts attempting to auto-configure their IP addresses using that IPv6 prefix will be denied.
CLI Commands for Source Verification
The following commands apply to the source verification feature:
Table 108.
CLI Commands for Source Verification
Purpose
CLI Command
Enable source verification for all packets for the specified
mac-id
configure interface cable-mac <mac> cable source-
verify [dhcp [authoritative]]
Select the desired version of the DHCP lease query
protocol. (Default is draft-0.)
configure cable source-verify leasequery version
[draft-0|draft-2|draft-4|rfc-4388]
Select the DHCP lease query message type.
Note: When the C4/c CMTS is operating in RFC 4388
mode, the RFC-defined values are always used.
configure cable source-verify leasequery message-
type [type]
Determine how the C4/c CMTS is configured for cable
source verification
show running-config full verbose | include
source-verify
- or-
show ip interface cable-mac <mac-identifier>