CABH-SEC-MIB

MIB Reference — IPNetwork Monitor · Updated September 14, 2026

All MIBsCABH-SEC-MIB

Organization: CableLabs Broadband Access Department

Last Updated: 2004-08-06

Category: DOCSIS and Cable

Description: Manages CableLabs CableHome security features including firewall policies and access control for residential gateway devices on cable networks.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is CABH-SEC-MIB?

CABH-SEC-MIB is a CableLabs CableHome specification MIB that governs the Security Portal Services of a residential cable gateway device, sitting in the cable/DOCSIS technology area alongside other CableHome MIBs. It exposes configuration data for firewall policy file management (URL, hash, enable state), firewall event logging/enable flags, and intrusion/attack alert thresholds. In monitoring terms, this MIB is primarily used to check the operational and software status of the gateway's security subsystem: whether the current firewall policy file was successfully downloaded and applied (operational status, current version, last successful URL), and whether attack-detection thresholds and event types have tripped. It builds on the broader CableHome (CABH) MIB family and DOCSIS/cable modem management framework, and typically depends on associated CableHome device and event MIBs for full context. It is deployed on residential/small-business cable gateway (eRouter/eSAFE) devices managed by an MSO's provisioning and monitoring back office. Engineers can download the CABH-SEC-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in CABH-SEC-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • CableHome residential cable gateway
  • DOCSIS eRouter/cable modem gateway

Monitoring Examples

An operator can poll cabhSecFwPolicyFileOperStatus and cabhSecFwPolicyFileCurrentVersion to confirm that a pushed firewall policy (identified by cabhSecFwPolicyFileURL and validated via cabhSecFwPolicyFileHash) was successfully applied on the gateway, falling back to cabhSecFwPolicySuccessfulFileURL to see the last known-good policy if the newest push failed. Enabling cabhSecFwEventType1Enable/Type2/Type3 lets the operator control which classes of firewall events are logged, while cabhSecFwEventAttackAlertThreshold and cabhSecFwEventAttackAlertPeriod define when a burst of blocked packets escalates to an attack notification. A sudden change in operational status to a failure value, or a spike in attack alerts within the configured period, signals a misconfigured policy push or an active intrusion attempt against the subscriber's gateway.

What Can Be Monitored

  • firewall policy file operational status
  • firewall policy file current version
  • firewall event type enable flags
  • attack alert threshold
  • attack alert period
  • last successful policy file URL
Imported Objects

From CLAB-DEF-MIB

clabProjCableHomeOBJECT-IDENTITY

From DOCS-BPI2-MIB

X509Certificate

From DOCS-CABLE-DEVICE-MIB

docsDevFilterIpEntryOBJECT-TYPE

From IF-MIB

InterfaceIndexOrZero

From INET-ADDRESS-MIB

InetAddress
InetPortNumber

From RMON2-MIB

ZeroBasedCounter32

From SNMP-FRAMEWORK-MIB

SnmpAdminString

From SNMPv2-CONF

MODULE-COMPLIANCE
OBJECT-GROUP

From SNMPv2-SMI

Counter32
MODULE-IDENTITY
OBJECT-TYPE
Unsigned32
zeroDotZero

From SNMPv2-TC

DateAndTime
RowStatus
TimeStamp
TruthValue
VariablePointer

How to Use in IPNetwork Monitor

Example using cabhSec2FwLocalFilterIpMatches OID:

Select a CableHome-compliant residential gateway (cable modem/router) as the target host to create a monitor — the SNMP service should be up and running on it. Click New Monitor, then check SNMP Custom on the Favorites tab, click Next, and confirm the host. On the next page, click Select... to open the built-in SNMP MIB Browser and type cabhSec2FwLocalFilterIpMatches into the Find box to locate it in the OID tree, selecting the specific row/instance you want to monitor since this is a table column, then select it and click OK. Counts the number of times this filter was matched. On the monitor's Main parameters page you can set the target's SNMP port (default 161), credentials, polling interval, and other settings — see the SNMP Monitor help for details. On the State conditions and Alerting tabs, configure when the monitor should change state and trigger an alert; since this is a Counter32-type OID, Value bounds is the most useful condition here — trigger an alert if the counter increases sharply between polls relative to its normal baseline, since an unexpected spike often reflects a real change in traffic or activity. Click Finish to create the monitor; you can adjust any parameter later.
OIDs

RFC description

CableHome security portal firewall, certificate, and Kerberos management for cable broadband gateways.

Start monitoring CableHome-compliant residential gateways (cable modem/router) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download CABH-SEC-MIB