Re: [c-nsp] CMs security

2018-07-29 Thread Aaron Gould
My cable modem mgmt and mta (voice) ip's are on different subnet than CPE. And we have an ACL on the CMTS to not allow customer ip's to communicate with those cm ip's Aaron > On Jul 29, 2018, at 5:38 PM, ring...@mail.com wrote: > > Hi all, > > Wondering what do you guys prefer as best

[c-nsp] CMs security

2018-07-29 Thread ringbit
Hi all, Wondering what do you guys prefer as best practice to block connectivity like ping, http and everything else between CMs (docsis plant)? How do you do and manage it? ton ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

[c-nsp] ASR9000 ABF/ePBR

2018-07-29 Thread Curtis Piehler
So I have been attempting to use IOS-XR ABF (Access List Based Forwarding) to implement a "catch-all" next-hop of a destination within the same LAN (back out the same interface the packet arrived on). Cisco documentation indicates this would fall under the "for-us" rule and not work by default.