Chapter 29: Security
STANDARD Revision 1.0
C4® CMTS Release 8.3 User Guide
© 2016 ARRIS Enterprises LLC. All Rights Reserved.
865
If other source verify checks fails, then the MAC/IP binding is denied for those other reasons. One of those other
checks performed ensures that a less secure source does not take away an address from a more secure source. CPE
Host Authorization is considered more secure than DHCP, for example. So when a match with host authorization table
occurs, the IP type is changed to IPTYPE_PROVISIONED. This prevents the less secure/more secure check from
retracting that IP address.
If a CPE IP learning event occurs for an IPv4 address that has been provisioned for host authorization, and host
authorization is enabled, the learning event indicates the correct CM and CPE that have been provisioned, all other
source verify check pass, and the MAC is currently assigned an IP address, then the IP learning will be allowed, but
instead of assigning the MAC address the new IP address, the new IP address will be added behind the MAC as a /32
subnet in the CAM hardware.
When a host authorization IP address is removed from the provisioning, if that IP address is currently assigned to a
MAC address, that IP address for that MAC address is cleared. Because adding and removing IPs is expected to be rare,
a situation in which a MAC address does not have primary addresses but does have secondary addresses is permitted.
When a host authorization IP address is removed from the provisioning, if that IP address is currently not assigned to a
MAC address, the /32 subnet for that IP address is deleted from the CAM hardware.
When a host authorization IP address is added to the provisioning and host authorization is enabled, that IP address is
checked to see if is entered in the MAC Database (MACDB) behind the wrong CM or CPE. If a mismatch is found, the IP
address in the MACDB is invalidated.
When host authorization is enabled, each entry in the host authorization table is checked to see if an entry exists in the
MACDB associating that IP address with the wrong CM or CPE. If a mismatch is found, the IP address in the MACDB is
invalidated.
When a host authorization MIB table entry is created, a check will be made to see if any other entries have been made
with the same CPE MAC address, and if so, the new entry’s CM MAC address will be the same as the existing entry’s
CM MAC address. If it is not the same, then the new creation is rejected.
When a host authorization MIB table entry is created, a check is made to see if there are other entries using the same
IP address. If the same IP address is already used, the new creation is rejected.
The C4/c CMTS supports a maximum of 1000 MIB entries in the Host Authorization table and up to 32 entries for a single
CPE/MAC address.
CLI Commands
The CPE Host Authorization feature is enabled or disabled with the following command: