Chapter 29: Security
STANDARD Revision 1.0
C4® CMTS Release 8.3 User Guide
© 2016 ARRIS Enterprises LLC. All Rights Reserved.
864
CPE Host Authorization
The CPE Host Authorization feature provides an alternative or a supplement to DHCP Lease Query, also known as Cable
Source Verify. It is another means of preventing the spoofing of IP addresses. It permits the CMTS operator to provision
multiple IP addresses to a single MAC address.
When the CAM receives a packet from an unknown source MAC address or from a known MAC address having an IP
address that differs from the previous MAC-IP binding, a learning event is generated by the hardware. This new
information is forwarded to the RCM. There, the MAC Data Manager (MACDM) performs several checks for source
verification before assigning an IP address to a MAC address. If the request satisfies all the checks, the new learned
information is added to internal databases of the C4/c CMTS and copied into the CAM hardware.
Note: CPE Host Authorization is not supported for IPv6 addresses.
The following list describes the additional checks used by this feature to govern the flow of CPE traffic through the system:
When the host authorization feature is turned on, packets from an unknown source will be dropped.
Packets from unknown sources currently are dropped only if Cable Source Verify is on or if subscriber management cpe
control is on for the particular modem. This feature adds one additional condition to cause packets from an unknown
source to be dropped.
If a CPE MAC learning event indicates that a MAC address has moved from being active behind one modem to being
active behind another where it has been provisioned as having authorized IP addresses behind the new modem, the
movement is not denied.
Currently, the MAC learning event prohibits an active MAC from being moved to a new modem if source verify is on.
This requirement supersedes that check if host authorization has been provisioned for a CPE behind a modem.
If host authorization is enabled and a CPE IP learning event occurs for an IP address that has been provisioned for host
authorization, and the learning event indicates a different CM or CPE than the one provisioned, then the IP learning
will be denied. The C4/c CMTS issues an error message:
IP address authorized for use by CM xx:xx:xx:xx:xx:xx/CPE xx:xx:xx:xx:xx:xx.
If host authorization is enabled and a CPE IP learning event occurs for an IP address that has been provisioned for host
authorization, and the learning event indicates that the correct CM and CPE have been provisioned, and furthermore, if
other source verify checks pass, and the MAC is not currently assigned an IP address, then the IP learning is allowed
and the IP address is assigned with the type IPTYPE_PROVISIONED.