CM Config File-Network Access Control Object.

1: The CM MUST NOT forward frames between the RF port and CPE ports if the CM config file sets Network

Access Control Object (NACO) to 0. 

2: The CM MUST forward frames between the CPE ports and CM IP stack even if NACO is 0. 

3: The CM MUST forward frames between the RF port and CM IP stack even if NACO is 0.


If the value field is a 1, CPEs attached to this CM are allowed access to the network, based on CM provisioning. If
the value of this field is a 0, the CM MUST continue to accept and generate traffic from the CM itself and not
forward traffic from an attached CPE to the RF MAC Network. The value of this field does not affect CMTS
service flow operation and does not affect CMTS data forwarding operation.

Type Length Value

3 1 1 or 0

The intent of "NACO = 0" is that the CM does not forward traffic from any attached CPE onto the cable network (a
CPE is any client device attached to that CM, regardless of how that attachment is implemented). However, with
"NACO = 0", management traffic to the CM is not restricted. Specifically, with NACO off, the CM remains
manageable, including sending/receiving management traffic such as (but not limited to):
• ARP: allow the modem to resolve IP addresses, so it can respond to queries or send traps.
• DHCP: allow the modem to renew its IP address lease.
• ICMP: enable network troubleshooting for tools such as "ping" and "trace-route."
• ToD: allow the modem to continue to synchronize its clock after boot.
• TFTP: allow the modem to download either a new configuration file or a new software image.
• SYSLOG: allow the modem to report network events.
• SNMP: allow management activity

HTTP (if supported): allow the modem to download new a software image.


In DOCSIS v1.1, with NACO off, the primary upstream and primary downstream service flows of the CM remain
operational only for management traffic to and from the CM. With respect to DOCSIS v1.1 provisioning, a CMTS
should ignore the NACO value and allocate any service flows that have been authorized by the provisioning server.


你可能感兴趣的:(NACO)