|
Slimjim100 DOCSIS Engineer
Blog...
(Disclaimer:
No information or writing on this site should be used as
a basis of buying, investing, or anything else to do with any of
the equipment discussed on this site. The information on this
site is just the opinion of "Slimjim100" and other
DOCSIS Engineer's.)
Slimjim100
no longer posts to this Blog but other skilled DOCSIS Engineers
will be posting so stay tuned!
-
Archive of posts 1 2 3 4 5
|
July
28th 2008 (2:30PM By DOCSIS-Paul)
The forum is now
active but understand it is a work in progress at this time.
Please feel free to go and join up. Registration is free and
will allow you to post to the forums.
forum link
http://docsishelp.do.funpic.de/board
Regards,
DOCSIS-Paul |
|
July
28th 2008 (1:00PM By DOCSIS-Paul)
We are now working on
adding a forum to this blog to allow for more real-time
DOCSIS support and we hope to build a community of DOCSIS
Engineers to help each other out. At this time we are
building the forums from a free hosting site in Germany
(sorry ad supported) but if the idea takes off we may buy
hosting some where. Once it goes live please stop by and
post a quick hello so we get an idea of the number of people
interesting in this idea.
Thanks,
DOCSIS-Paul |
| June
27th 2008 (5:00PM By docsisdude)
This post was
made after docsisdude spent some time doing a password
recovery on a BSR and could not find any documentation for
the BSR online.... Sound familiar???
One of the
best things about Cisco is how well they document things.
I don't know how many times I've gone to www.cisco.com
and found exactly what I was looking for.
Sometimes it can take a little longer than I had
hoped, but that's only because they have so much
documentation to sift through. You
often have to be pretty specific when doing the search,
and when you find something good…. Bookmark it.
Stuff like load balancing configs, RFSW setup, CWDM
SFPs, the list is endless. Like
all websites Cisco moves things around, so don't get angry
when you get dead linked to the apologetic Cisco page not
found error. This brings up an
interesting point. On one hand
Cisco has gone to the infinite degree to document
EVERYTHING. This has pros and
cons as having all that info often makes finding things
difficult. The other side of the
coin is that the other vendors often have very little as
far as public documentation. I
know you can't really expect that from everyone, but it
can slow you down when you don't have that PDF you need or
are learning on a new box. Either
way it would be helpful if the other vendors could put
more info up. It also wouldn't
hurt if Cisco trimmed some of the documentation, or
removed that eight year doc about DOCSIS1.0 ;)
docsisdude |
| June
11th 2008 (4:00PM By docsisdude)
So your a DOCSIS
Engineer and you compete with AT&T's U-Verse VDSL
service. They're taking some of your single play subs and
turning them into triple play subs, but hey you've been
turning their single play subs into triple plays subs for
years. The problem begins after they take the subs, but
before those subs disconnect (or if those subs
keep your service). What is the problem? HPNA On the HPNA
wiki they brush over the topic and state some of the
disadvantages of HPNA3.x are "Doesn't coexist
with DOCSIS". Well I'll expand on that
a little further. This has gotten some news as Comcast
outside Chicago has been battling with AT&T and
complained to them. This has for the most part been
ignored but I'm sure AT&T is burning the midnight
oil trying to come up with a solution to allow HPNA to
work without disrupting DOCSIS. (right) HPNA works in the
frequencies above DSL and voice, but below broadcast
television. Sound familiar? Well it should because that's
your DOCSIS return path. When somebody hooks up a 2Wire
HPNA router/gateway to a coax line still connected to
active cable plant, that HPNA signal leaves the house and
gets into our return plant. I saw this first hand, and it
forced me in at my previous job to vacate my preferred
frequency of 35MHz. I had to use 25MHz which isn't a bad
frequency, but again this is a competitors product that
actively interferes with your product. The HPNA signal
looks like a static "haystack" its not bursty like a TDMA based DOCSIS carrier. It can and will destroy
your return path and make large swathes of said spectrum
completely unusable. Is the solution for the us to high
pass filter subs that switch to Uverse? Or should
Uverse use the 43-50MHz range we can't use? This is
barring strange mid-split systems and assuming standard
diplex filters of 5-45 which roll off at @43Mhz.
Everything past ~40MHz has pretty hardcore group delay
issues anyway so I'd be happy to give them 40-50MHz. If
that was the case they could work, we could work and we
could go back to competing fairly...... Or I could just
drive around with an unlicensed AM transmitter, or go pee
on a VRAD.... something makes me think Harry Potter... err
Kevin Martin wouldn't like that, let alone MaBell (or the
Engineers at AT&T that would have to fix it).
Till next time
docsisdude
(this post was made by
"DOCSIS_Dude" |
|
April 14th 2008 (10:00PM By Slimjim100)
Well now I am in a new
job but still in the DOCSIS CMTS work area. Due to my new
position I will not be able to continue posting to this
BLOG. Now this is not the end of this BLOG as I will have a
few other DOCSIS Engineers take over with posts and updates.
Sorry to have to leave this way but I have taken a very good
job and feel in my new position I do not want to risk any
kind of perceived conflicts. So from this point on any post
to this BLOG will be made by other DOCSIS Engineers. When a
post is made it will state the posters online name. Thanks
for all your support and feel free to e-mail me any
questions to slimjim100(at)gmail.com.
Thanks,
Slimjim100 |
|
March 4 2008
(11:00AM By Slimjim100)
DOCSIS Engineer
Must Read Book

PacketCable
Implementation
Jeff Riddel CCIE#12798
Since I
recently talked with Jeff and I own this book I figured I
would share my thought of the book with you. I highly recommend this book
for any DOCSIS Engineer working in a Packetcable Voice
network. Even if you plan on deploying a SIP or third party
voice service this book will be your new bible. With over
1100 pages of true technical information with many charts,
graphs, & diagrams to help explain the flow of data this
book will help bring all the complexity to a understandable
level. Lets face it there is not a good single source of
information out there to support DOCSIS engineers in there
jobs but I think with this book you get the full view.
Anyway I highly recommend it and make sure to jet over to
Cisco Press or Amazon and read the description. This is also
a Safari book so online access for 45 days comes with the
book too.
Links
for the book:
Cisco Press
Amazon |
|
February 27 2008
(10:00AM By Slimjim100)

BlackHat 2008 DC
Last week I was in DC for BlackHat 2008. I had a great time
and seen some interesting talks on security, Hacking,
Pen-testing, Networking, and much more. I have to say my
favorite talk was from Felix "FX" Lindner titled
"Developments in Cisco IOS Forensics. I would highly
recommend you to visit his site and read the white paper he
released (found
here)
on his companies site "Recurity Labs". Slides and
presentations from BlackHat should be on there site soon for
download. In other news I have heard of routers getting
hijacked due to poor ACL's and SNMP traffic being sent over
public networks in plain-text. It is important to keep your
router locked down and protected. If your router got
accessed and changed by an unauthorized person the first
thing they might do is to lock you out. I have heard of
reports where this is happened to a large multi-site company
and they where blackmailed for money to get access back to
there routers. With networks expanding over many miles,
cities, and countries it's important to keep you
network safe. In the case of this reported company, the cost of
sending people out to password recover the routers was a lot
more than the blackmailer's offer so the company paid them and then
locked down the devices after they regained access. This
could of been avoided and the skills needed to lock down a
router is not CCIE level stuff! just using ACL's and a
understanding of how the network is designed can prevent
this kind of attack. Other issues
with "unauthorized access" is even if you can regain access it's
best to reload the IOS and review you config's. I say this
since I have learned from Felix's
presentation at BlackHat that some attackers load non-Cisco
patches to the IOS. If an unauthorized IOS patch was made to
your devices it is very difficult to identify the
malicious code. With infected IOS code your
routers you risk them becoming members of bot-nets, reset unexpectedly,
or relay/hide unwanted traffic or tunnels.
My recommendation is to only trust IOS code you get directly
from Cisco. In the end of the day it does pay to keep you
Cisco contracts up to date so when you need that clean IOS
fix your CCO login can save the day.
References in this post:
http://www.blackhat.com/html/bh-dc-08/bh-dc-08-speakers.html#FX
www.recurity-labs.com
www.cisco.com |
|
February 11 2008
(10:00AM By Slimjim100)
Motorola DOCSIS 3.0
Ultra-Broadband Site Online
http://business.motorola.com/ultrabroadbandsolutions/home.html
 
Click on the pictures to enlarge
them
It’s
good to see Motorola releasing technical information to the
web without the forced login. It looks like they still have plans
for both I-CMTS & M-CMTS to support the MSO’s with there
DOCSIS 3.0 rollout. It would be nice to see more whitepapers
listed and maybe some CLI guides too. One of the issues I
have had in the past with Motorola’s Broadband Products is
that there is no real public documentation available (just
marketing stuff). Where
Cisco has way too much available and can cause an
informational overload or confuse an engineer because
features in one version of IOS might not work in another.
Anyway check out Moto’s site and let me know what you think.
DOCSIS 3.0 is coming and the big boys are getting ready to
test the waters (some already are now) are you ready to jump
in?
|
|
February 7 2008
(10:00AM By Slimjim100)
When the 10K meets
an older Acterna DSAM….
+
Recently during an ISO upgrade I found (well a fellow
engineer I work with found) that the older Acterna (now JDSU)
DSAM meters failed BPI registration. It was interesting
because all the modems on the CMTS worked fine and other
meters did not have this issue. Well after a lot of trouble
shooting from myself and other engineers it was found that
the newer JDSU meters did not have the same issue. In the
end it was that the older meters did not have a valid self
signed Certificate and they had to be upgraded via JDSU TAC.
Now the prior IOS was 12.3(17b)BC and we upgraded to
12.3(21a)BC and noticed the issue. So just as a warning to
other Engineers you may want to test your older Acterna
meters if you upgrade your IOS. If they do not pass BPI/BPI+
just call JDSU and have them add valid certs to the meters.
This can be done via hooking the DSAM up to an Ethernet
connect with a public IP for the JDSU TAC to access the
meter. Basically your meter is fine and even if you have the
BPI fail issue your meter can still work fine with all your
normal RF testing and you could just use a modem to test
DOCSIS with till you upgrade the meter. |
|
February 7 2008
(9:00AM By Slimjim100)
Cisco 10012uBR CMTS: Wiring the Beast…
Installing a new Cisco 10k can be a pain in it’s own but
with the micro (MCX) RF cabling and the DIY cable kits your
frustration can peak out. I wanted to make a post with links
and info on wiring the Cisco 10K for those that may of not
had the fun of this special experience.
What cable set did I order or do I need?
Here are some of the choices:
-
Dual-shielded cables
-
Quad-shielded cables
Now when you order your cable you will hopefully get the 10
color kit but some time you will end up with the 5 color kit
which is harder to get use too.

This is a
picture from Cisco’s site of the 10 color cable
The back of the 10K with line cards looks like this:

Here is a picture of how the cable connects to the 10K
 
Now for the recommended wiring of the cable kits:
10 color cable kits
|
Universal Cable Holder (1) |
Universal Cable Holder (2) |
Universal Cable Holder (3) |
|
Line Card Port |
Cable Color |
RF Switch User Defined |
Line Card Port |
Cable Color |
RF Switch User Defined |
Line Card Port |
Cable Color |
RF Switch
User Defined |
|
US0 |
Red |
|
US10 |
Grey |
|
DS0 |
Red |
|
|
US1 |
White |
|
US11 |
Brown |
|
DS1 |
White |
|
|
US2 |
Blue |
|
US12 |
Red |
|
DS2 |
Blue |
|
|
US3 |
Green |
|
US13 |
White |
|
DS3 |
Green |
|
|
US4 |
Yellow |
|
US14 |
Blue |
|
DS4 |
Yellow |
|
|
US5 |
Violet |
|
US15 |
Green |
|
— |
— |
|
|
US6 |
Orange |
|
US16 |
Yellow |
|
— |
— |
|
|
US7 |
Black |
|
US17 |
Violet |
|
— |
— |
|
|
US8 |
Gray |
|
US18 |
Orange |
|
— |
— |
|
|
US9 |
Brown |
|
US19 |
Black |
|
— |
— |
|
5 color
cable kits
|
Universal Cable Holder (1) |
Universal Cable Holder (2) |
Universal Cable Holder (3) |
|
Line Card Port |
Cable Color |
RF Switch User Defined |
Line Card Port |
Cable Color |
RF Switch User Defined |
Line Card Port |
Cable Color |
RF Switch
User Defined |
|
US0 |
Red |
|
US10 |
Red |
|
DS0 |
Red |
|
|
US1 |
White |
|
US11 |
White |
|
DS1 |
White |
|
|
US2 |
Blue |
|
US12 |
Blue |
|
DS2 |
Blue |
|
|
US3 |
Green |
|
US13 |
Green |
|
DS3 |
Green |
|
|
US4 |
Yellow |
|
US14 |
Yellow |
|
DS4 |
Yellow |
|
|
US5 |
Red |
|
US15 |
Red |
|
— |
— |
|
|
US6 |
White |
|
US16 |
White |
|
— |
— |
|
|
US7 |
Blue |
|
US17 |
Blue |
|
— |
— |
|
|
US8 |
Green |
|
US18 |
Green |
|
— |
— |
|
|
US9 |
Yellow |
|
US19 |
Yellow |
|
— |
— |
|
All
information in this post is from Cisco’s website and the
full document can be found here:
http://www.cisco.com/univercd/cc/td/doc/product/cable/ubr10k/ubr10012/frus/ubrmc520.htm
This
post in
PDF Here |
|
January 28 2008
(10:00AM By Slimjim100)
(Note this article was
written 3 months ago and since there has been rumor that
some vendors have a sub $100[in bulk] DOCSIS 3.0 modem)
Is DOCSIS 3.0 Really Here?

Author: Brian Wilson
CISSP, CCNA, CCSE, CCAI,
MCP, JNCIA, Network+, Security+
Slimjim100@slimjim100.com
Co-Author: Owen Parsons
CCNA, CCCS, A+,
Network+, NCTI Senior Master Technician
docsisdude@gmail.com
So you’re an MSO with a DOCSIS
network and want to know when you can start moving to DOCSIS
3.0 to gain all the new bells and whistles to include
bandwidth, IPv6, & advanced security. DOCSIS 3.0 has the
ability to give you over 100+Mbps to the customer, new
security features, and support for IPv6 so you can save the
internet’s IP resources. A rather important question
remains, are there any vendors already selling DOCSIS 3.0
networks and devices? The answer is not the quick “yes” a
vendor’s PowerPoint presentation may lead you to believe.
The
most profound issue with DOCSIS 3.0 revolves around the
modems themselves. There are no true DOCSIS 3.0 modems on
the market at this time. All of the vendors have a
3.0(D)ownsteam only modems. This just gives you the
downstream channel bonding, but does not have the upstream
channel bonding IPv6, or the security features that makes
DOCSIS 3.0 so enticing. The other issue that arises is “do
the modems they’re selling today, have the ability to be
upgraded to full DOCSIS 3.0”? Well in a short the answer is
“no” they will not. The reason for this lack of upgrade
ability is the Broadcom chipset supporting the 256-bit AES
encryption and the additional upstream tuners are not
available today. This chipset is needed to implement the
security functions required in the DOCSIS 3.0
specification. At this point the chips are not 100% ready
or at least not in mass production. So no matter how bad you
want to get your network to DOCSIS 3.0 you are faced with
the lack of true DOCSIS 3.0 modems. If you do decide on
using Pre-DOCSIS 3.0 downstream only modems you need to make
sure the modems you buy are not proprietary and bound to a
specific brand of CMTS. If that is the case you would be in
a predicament if you ever choose to switch CMTS vendors. Not
only would this cause a headache for your customers, but it
would create an unnecessary capital investment as you would
have to forklift all the proprietary modems and replace them
with newer 100% DOCSIS 3.0 modems.
With
these new DOCSIS 3.0 modems slated to cost multiple
hundreds of dollars each, this would be an unwelcome PO in
your accounting department. So choose your modem carefully
and make sure they can be upgraded or you may be regretting
your decision to arrive early at the DOCSIS 3.0 party.
Another large obstacle will be the price of the modem.
Currently you can buy DOCSIS 2.0 modems in bulk for roughly
$40.00USD. These newer DOCSIS 3.0 modems are rumored to
initially cost anywhere from $100-$250 each. With a DOCSIS
3.0 modem costing that much it is prohibitively expensive to
put one in every home. It’s very likely that these modems
won’t make it to the residential customer anytime soon. The
DOCSIS model is built around standards so nothing is going
to stop a power user from going to their local WalMart or
BestBuy and paying $250.00USD for a new DOCSIS 3.0 modem. On
the other hand, not many users have that kind of money to
spend on a modem and there is little justification for
stores to even carry them. Why as a consumer would you pay
hundreds of dollars more for a modem when the old modem
works and is basically free in comparison.
So
the question is, how do you transition from your current
DOCSIS 1.x/DOCSIS 2.0 network to a full 3.0 network? I don’t
see the move to DOCSIS 3.0 happening nearly as fast as the
industry is buzzing and it will most likely start with
business customer first. These business customers have a
more attractive ROI and can justify the capital being spent
on them. Once the efficiency of manufacturing gets in place
these modems will cost less, but the raw cost of multiple
tuners and brand new chips will always make them more
expensive than a DOCSIS 2.0 modem. The true cost
breakthroughs will come when the raw materials come down in
cost. Single chips that can replace multiple tuners, more
chips being produced thus further lowering the initial cost
to the manufacturer. This is years away but once it happens
the cost per modem will drop, also an MSO’s ability to
negotiate pricing and buy in bulk will further expedite this
process.
I
think once the modems are around $60.00 wholesale you will
see the MSO’s stocking up on them and installing them in
residential “power user” homes. The cable industry is in a
period of growth with many new technologies providing never
before seen opportunities. If they want to party it’s going
to cost them billions to get to the next level, but when
they do get there the customer experience will be amazing.
Hopefully we will catch up with many of the Asian MSO’s and
be able to make a 100+Mbps just a simple mouse click away.

The 3 Major Players
DOCSIS 3.0
Pros:
-
IPv6
-
Bandwidth
(Downstream 100mbps+ & Upstream 50+mbps)
-
256 bit AES
encryption
-
SNMP v3
-
Channel
Bonding (Upstream & Downstream)
-
IPDR
-
Support
IGMPv3
-
Multicast
QoS
-
Improved
ability to monitor DOCSIS devices
Cons:
-
Availability
-
Complexity
-
Cost
-
Number of
vendors
-
Having to
replace parts of network
-
RF
bandwidth needed
-
RF plant
conditions to support higher QAMs
-
2-4 DS
carriers have to be adjacent to each other
-
Only one of
the bonded channels has the MAC/scheduling info inside it
-
VoIP
Protection currently only on one downstream (not in the
edge QAM)
References:
Many vendor
presentations (Cisco, Motorola, Bigband, Arris)
Cablelabs listed
public specs (www.cablelabs.com)
Google (www.google.com)
Link to this
Article in
PDF
Here
 |
|
January 24 2008
(1:00PM By Slimjim100)
Review:
uCertify
Network+ PrepKit
By Brian Wilson
CISSP, CCAI, CCNA,
CCSE, JNCIA, Security+, Network+, MCP
Slimjim100@slimjim100.com
This is a review on uCertify’s Network+ Prepkit available
over at
www.ucertify.com.
The uCertify Prepkit is a quick download from their site.
Once you install it on your computer, you have access to the
demo version which gives you some practice questions and
limited use of the Prepkit. Upon buying the full Prepkit,
you will be sent a license key that will unlock all the
questions and features. Now you can get started learning.
Some of the major advantages with the Network+ Prepkit is
the fact that it is more than just a simple study guide.
Inside the Prepkit you will find:
-
Diagnostic test
-
7
large Practice tests
-
Final exam, an Adaptive test
-
Ability to create custom tests
-
Interactive quiz with 154 questions
-
Study notes
-
Flash cards
-
Articles
-
Ability to track your Progress
I
recently reviewed the Security+ PrepKit from uCertify and
was asked to review the Network+ Guide also. I decided this
time I would put it to the test by getting 2 free copies of
the PrepKit and having some associates try their hands at
the actual CompTIA Network+ Exam. I figured the only real
way to test the quality of the PrepKit was to put it to use
with 2 people that I knew wanted to study for the CompTIA
exam. I recruited the 2 subjects and asked that they only
use the uCertify PrepKit to study for there exams. Now I
already felt impressed about uCertify’s guides (based on my
recent review of the Security+ guide), but it was now time
to see how it would fair in a live test.
The 2
subjects sat for the exam and both passed with decent
scores. I do want to add that both of the test subjects had
over 3 years of networking experience. With their experience
and the uCertify Network+ PrepKit, they were able to pass
the exam and attain the CompTIA Network+ certifications. I
would also like to note that this was the first IT
Certification that either of the two candidates had ever
attempted. With the proof on the table, I have to endorse
the uCertify Network+ PrepKit as it has proven itself to be
the right study guide to pass the Network+ Exam.
This Review
uCertify Network+ in PDF
BTW if you would like
to buy any of the Prepkits from uCertify use this discount code
"BRISON" for
10% off! Thanks for reading my review and look forward as I
plan on reviewing uCertify's Network+ PrepKit very soon.
|
|
January 3 2008
(10:00PM)
Update
(4 January 2008
By Slimjim100)
Time to stop the attach of the MAC Clones
First…
Happy New Year!!! I have been busy lately chatting with
other DOCSIS engineers and assisting/brainstorming with them
on newer ways to ID and prevent modem cloning (theft of
service). I am sure all DOCSIS Engineers out there know
about the different cable modem hacking sites and have there
own little ways of minimize the impact of these criminal
services. Now not to get on a soap box since I think Hacking
in it’s real form is a good thing but using advanced
knowledge to assist others to break the law and steel in not
cool at all. Anyway to the point While talking with one
Engineer friend in particular I found his method to work
around flaws in the CMTS’s he has to deal with a great idea.
Now if your in a Cisco, Motorola, or an Arris CMTS world you
are good to go because they actually enforce BPI+ but some
of the other bastard CMTS’s (no longer made or supported
models) might not implicitly apply DOCSIS 1.1 standards and
this can lead to crackers abusing flaws in DOCSIS 1.0’s BPI.
I will explain in a later post the neat trick my friend did
to reduce cloning and theft but I would like to cover some
of the basics to reduce theft of service.
DOCSIS 1.0
-
Configure network to only allow TFTP from Authorized
server to avoid rouge config files.
-
Set
modem filter to only allow HFC interface to pull TFTP from
your servers.
-
Set
your SNMP access to only respond to your management
network from source IP’s on the HFC interface of the modem
(not the CPE address space).
-
Monitor your devices via SNMP and make sure you track the
config file names to the correct MAC addresses.
-
Test
all DOCSIS devices to make sure they respond to SNMP (if
they fail to respond block the MAC via an ACL)
DOCSIS 1.1
-
Do
all of the above steps listed.
-
If
possible and all devices are DOCSIS 1.1 or above (no
DOCSIS 1.0 modems) use the CMTS’s vendor command to
“Enforce BPI+” and “TFTP Source Verify” (this will not let
hacked firmware force the modem to DOCSIS 1.0 BPI).
-
Make
sure to upgrade all modem firmware to a ECN RFI 02030 load
and maintain few version load to make rouge modem
identification easier.
-
Enable and setup “Cable Shared Secret” on your DOCSIS
interfaces of the CMTS (change your shared secret often if
not monthly).
-
If
using a Cisco CMTS enable “Dynamic Shared Secret” so that
a dynamic secret key is established at the time the config
file is requested.
There are many other methods of preventing hack, cracked,
modified, & cloned modems from steeling service on your
network. It is important to try to force BPI+ (DOCSIS 1.1)
if possible on your Network. With BPI+ the modems
certificates and keys are linked to it’s MAC address so a
clone can not match the key value. When the keys fail you
will see the cloned modems in a state of Reject(pk),
Reject(kek) or Reject(tek) keep in mind that there is other
reasons for a failed BPI+ modem to not come online and if
you have a large number of modems in Reject(pk) first check
to make sure the CA root-cert is installed (Cisco the cert
should be 996 sized cert if the root-cert is 958 you have a
corrupted or incorrect root-cert) and a working NTP server
is configure as the encryption for BPI+ like any encryption
is time sensitive. Other benefits to BPI+ is the fact that
the data transmitted from the modems is encrypted so RF
sniffing will be unable to recompile your customers data and
assist to protect there privacy and reduce you liability for
there privacy getting breached.
Last but not least you should have scripts available to
detect cloned modems and ACL’s to block devices not running
BPI+. This will eliminate most if not all theft of service
on your network and also improve your paying customer
experience.
Other non MSO direct ways to prevent theft of service is to
push the vendors to remove all diagnostic ports and access
from the modems internal motherboards and to sign the boot
code of the mode to a chipset SN number so if the boot code
was changed the modem would no longer work. This is a very
good idea and with the cost of DOCSIS 2.0 modems so cheap it
would be worth the modem costing a few dollars more is it
prevented the chances of hacked modems on the plant.
I would say the very last step is to go down hard on cable
theft of service and make sure to prosecute as this will
make an example and be a deterrent for others not to try to
modify there DOCSIS devices to steel service.
If you have any other idea on how to prevent and stop theft
of service please feel free to e-mail also feel free to
contact me for questions and comments you may have.
slimjim100(at)slimjim100.com
Update
(4 January 2008)
Cisco IOS
Release 12.3(21)BC introduces a
DOCSIS 1.1-compliant and above security enhancement that
helps to eliminate denial-of-service (DOS) attacks that are
caused by cloned cable modems.
commands:
Router#
cable privacy bpi-plus-enforce
More
info linked below:
http://www.cisco.com/univercd/cc/td/doc/product/cable/cab_rout/cmtsfg/ufg_ccmd.htm |
|
December 31 2007 (12:00PM
By Slimjim100)
Ok so I decided to try a new
banner. Since I am not good with Photoshop or any graphical
software I will seek help from any of my readers that would
like to give it a shot. I am looking for a more professional
looking banner. I also want to hear from you! E-mail me to
let me know what topics you want covered here and also send
me a quick note on what CMTS's you are running and where
your cable plant is. I have networked with many DOCSIS
Engineers from all over the world and I hope to start
posting there lessons learned in hopes this site might be
able to assist even more users. So e-mail me @
slimjim100(at)slimjim100.com and tell me a little about
yourself. |
|
December 30 2007 (4:00PM
By Slimjim100)
First I would like
to say Happy New Year and I hope the best to everyone! I
have been very busy here on my time off from work with all
of the holiday stuff but I wanted to add a few comments
here. One thing I have noticed is that the headhunters like
to recruit during the holidays as I got bothered a few times
via my phone and e-mail. I had stated in a past post I was
thinking about leaving the DOCSIS world for a different
gig... Well so far nothing panned out with that so I might
be around for a bit longer. You also may of noticed the
"Need Help Call me" thing at the top of this page... Well
lets just say I am trying it out to see if anyone will call.
If you need help and can't afford to pay feel free to e-mail
me and I will try to help. I also decided to revamp my
Modem status guide (info in guide is
from Cisco's documentation). I still have a new
review coming for uCertfiy's Network+ Exam guide. After I
finished my Review of the Security+ Guide they asked if I
could review there Network+ guide and I agreed too on the
terms they let me pick a few people to just use there Prep
Guide to study for the test and write my review based on a
true exam takers point of view. Well so far one the guys
that I asked to try the network+ with uCertify's guides has
done very well but I will save the rest for my up and coming
review. Also to let everyone that read the blog now I did
not take any favors or money from uCeritfy to review there
guides I am an advocate to people gaining knowledge and
bettering them selves and certification is one way of doing
this and after looking at there price and quality I decided
to review there products free. |
|
December 4 2007 (8:00AM
By Slimjim100)
(updated
December 19th 2007 with coupon code)
Review:
uCertify Security+ PrepKit
By Brian Wilson
CISSP, CCAI, CCNA,
CCSE, JNCIA, Security+, Network+, MCP
Slimjim100@slimjim100.com
I recently had a chance to try out
uCertify’s
Security+ PrepKit. I was asked to try it out and see what I
thought of it. Seeing as I took the self study route for the
Security+ Certification last year and passed it with a very
high score I figured I could make a fair and honest
assessment of this test preparation kit. In the past I have
used the different vendor’s books and brain dumps and found
some are well written While most are just not worth your
time or money. In fact instead of helping with your study
efforts they can often frustrate you with poor organization
and usability. In this case not only is the preparation kit
well written and easy to use I was also pleasantly surprised
to see the simple layout of the uCertfiy’s Test Prep.

Features
worth mentioning:
-
Diagnostic tests
-
Many
practice tests
-
Adaptive
tests
-
Ability
to make custom test
-
Flash
Cards
-
Notes &
Objectives for review
-
Progress
tracker
-
Online
Prepkit updater
-
Ability
to bookmark test questions
-
Very
easy to navigate GUI
I feel
compelled to inform you that this is not a brain dump. You
get a full study guide and a nice progress chat to help you
gauge where you are in your study process. I enjoyed the
Objectives and Notes that fully examined the content and
allowed you to fully understand the objectives of the
Security+ exam. I also found the flash cards and ability to
bookmark questions in the practice tests helpful. uCertify
has been around since 1997 and there pass rate for exam
takers using there content is around 97% (according to their
marketing info). I have to believe that if you followed this
Prep-Guide you would have a very good chance of passing the
exam and truly understanding the content. In the end I was
very satisfied and would recommend it to anyone wanting to
take CompTIA’s Security+ exam.
CompTIA
will most likely be seeing an increase in people taking the
Network+ & Security+ certification because of DoD directive
8570.1. Which will soon require many personnel that work for
the Department of Defense to have networking and security
related certifications if they hold the role of Information
Assurance Technician or Information Assurance Manager. With
this new directive requiring certification I feel it further
adds industry value to the CompTIA certs among other
required certifications per the new directive. If you are a
contractor or employee for the US government now you may
want to start taking the certifications as it’s only a
matter of time be for it might be a requirement for many
other positions in the government. With that said I would
highly recommend the uCertify Prepkits for your exam
perpetration needs.
More information
on
DoD
Directive 8570.1
This Review
uCertify Security+ in PDF
Link to
uCertify
BTW if you would like
to buy any of the Prepkits from uCertify use this discount code
"BRISON" for
10% off! Thanks for reading my review and look forward as I
plan on reviewing uCertify's Network+ PrepKit very soon. |
|
November 21 2007 (11:00AM
By Slimjim100)
Questions, questions,
questions.... I have seen a lot of hits to this BLOG with
interesting search terms and I would like to extend out my
knowledge to other DOCSIS Engineers out there that might have
a question about DOCSIS, CMTS setup, or lessons learned. I
chat with many other DOCSIS Engineers throughout the week
and always see new and interesting bugs and issues out in
the plant so feel free to fire your questions this way. I
can't say that I will always have the answer but I can
take a shoot at it.
Jobs... Yes I am
looking at a few places to advance my career and at this
time I have not made a 100% commitment ether way. But I can
say I have had a lot of Job offers sent my way that did not
fit what I was looking for or where I wanted to live. With
that said I would like to extend the job offers I get to any
other DOCSIS Engineers out there. If you are a DOCSIS
Engineer or a Technical MSO Engineer and would like to be in
the loop on current job openings with many MSO's and other
companies serving the Cable industry let me know as I can
add you resume to my resume page on this site and I can
assure you the recruiters and companies will e-mail you. I
get around 5-10 e-mails per week with job offers. I wish
some of the job offers where in Georgia :p. < | |