Cisco Systems uBR7200 Network Router User Manual


 
1-106
Cisco uBR7200 Series Universal Broadband Router Software Configuration Guide
OL-2239-05
Chapter1 Overview of Cisco uBR7200 Series Software
cops tcp window-size
For additional information, refer to the following document on Cisco.com:
Configuring a Dynamic Shared Secret for the Cisco CMTS document:
http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122newft/122limit/122bc/
122bc_15/ubrdmic.htm
Note The Dynamic Shared Secret feature does not affect the use of the original shared secret or secondary
shared secrets that are configured using the cable shared-secondary-secret and cable shared-secret
commands. If these shared secrets are configured, the Cisco CMTS continues to use them to validate the
original DOCSIS configuration file that is downloaded from the TFTP server. If the DOCSIS
configuration file fails to pass the original or secondary shared secret verification checks, the cable
modem is not allowed to register, and the Dynamic Shared Secret feature is not invoked for that
particular cable modem.
Tip Verify that a cable modem is able to register with the Cisco CMTS before enabling the Dynamic Shared
Secret feature.
Dynamic Shared Secret (DMIC) with OUI Exclusion for DOCSIS
Cisco IOS Release 12.3(9a)BC introduces the option of excluding the Organizational Unique Identifiers
(OUIs) from being subjected to the DMIC check. The new cable dynamic-secret exclude command
allow specific cable modems to be excluded from the Dynamic Shared Secret feature on the following
Cisco CMTS platforms:
Cisco uBR7246VXR universal broadband router
Cisco uBR10012 universal broadband router
The Dynamic Shared Secret feature automatically creates a unique DOCSIS shared secret on a
per-modem basis, creating a one-time use DOCSIS configuration file that is valid only for the current
session. This ensures that a DOCSIS configuration file that has been downloaded for one cable modem
can never be used by any other modem, nor can the same modem reuse this configuration file at a later
time.
This patent-pending feature is designed to guarantee that all registered modems are using only the
quality of service (QoS) parameters that have been specified by the DOCSIS provisioning system for
that particular modem at the time of its registration.
For additional command information, refer to the following document on Cisco.com:
Configuring a Dynamic Shared Secret for the Cisco CMTS
http://www.cisco.com/en/US/products/hw/cable/ps2217/products_feature_guide09186a00801b17cc.html
Cisco Broadband Cable Command Reference Guide
http://www.cisco.com/univercd/cc/td/doc/product/cable/bbccmref/index.htm
HTTP Security
Cisco IOS Release 12.2(4)BC1 includes the HTTP security solution introduced for earlier Cisco IOS releases
and router platforms. For additional information, refer to the document titled Cisco IOS HTTP Server Query
Vulnerability, Revision 1.3 on Cisco.com:
http://www.cisco.com/warp/public/707/ioshttpserverquery-pub.shtml