Chapter 3: System planning
Security planning
Page
3-52
Table 92 Ports filtered per protocol selections
Port Configuration
450 Platform Family supports access to various communication protocols and only the ports required
for these protocols are available for access by external entities. Operators may change the port
numbers for these protocols via the radio GUI or SNMP.
Table 93 Device default port numbers
Port
Usage
Port Usage
Device
21
FTP
Listen Port
AP, SM
80
HTTP
Listen Port
AP, SM
443
HTTPS
Listen Port
AP, SM
161
SNMP port
Listen Port
AP, SM
162
SNMP trap port
Destination Port
AP, SM
514
Syslog Server port
Destination Port
AP, SM
1812
Standard RADIUS port
Destination Port
AP
1813
Standard RADIUS accounting port
Destination Port
AP, SM
Encrypting downlink broadcasts
An AP can be enabled to encrypt downlink broadcast packets such as the following:
Protocol Selected
Port Filtered (Blocked)
SMB
Destination Ports UDP: 137, 138, 139, 445, 3702 and 1900
Destination Ports TCP: 137, 138, 139, 445, 2869, 5357 and 5358
SNMP
Destination Ports TCP and UDP: 161 and 162
Bootp Client
Source Port 68 UDP
Bootp Server
Source Port 67 UDP
User Defined Port 1.3
User defined ports for filtering UDP and TCP
IPv4 Multicast
Block IPv4 packet types except other filters defined
IPv6 Multicast
Block IPv6 packet types except other filters defined
ARP
Filter all Ethernet packet type 806
Upstream
Applies packet filtering to traffic coming into the FEC interface
Downstream
Applies packet filtering to traffic destined to exit the FEC interface