Chapter 3: System planning
Security planning
Page
3-53
•
ARP
•
NetBIOS
•
broadcast packets containing video data on UDP.
The encryption used is AES for an AES-configured module. Before the Encrypt Downlink Broadcast
feature is enabled on the AP, air link security must be enabled on the AP.
Isolating SMs in PMP
In an AP, SMs in the sector can be prevented from directly communicating with each other. In CMM4,
the connected APs can be prevented from directly communicating with each other, which prevents SMs
that are in different sectors of a cluster from communicating with each other.
In the AP, the SM Isolation parameter is available in the General tab of the Configuration web page.
Configure the SM Isolation feature by any of the following selections from drop-down menu:
•
Disable SM Isolation (the default selection). This allows full communication between SMs.
•
Enable Option 1 - Block SM destined packets from being forwarded. This prevents both
multicast/broadcast and unicast SM-to-SM communication.
•
Enable Option 2 - Forward SM destined packets upstream. This not only prevents
multicast/broadcast and unicast SM-to-SM communication but also sends the packets, which
otherwise may have been handled SM to SM, through the Ethernet port of the AP.
In the CMM and the CMM4, SM isolation treatment is the result of how to manage the port-based VLAN
feature of the embedded switch, where all traffic can be switched from any AP to a specified uplink
port. However, this is not packet level switching. It is not based on VLAN IDs.
Filtering management through Ethernet
Configure the SM to disallow any device that is connected to its Ethernet port from accessing the IP
address of the SM. If the Ethernet Access Control parameter is set to Enabled, then:
•
No attempt to access the SM management interface (by http, SNMP, ftp, or tftp) through Ethernet is
granted.
•
Any attempt to access the SM management interface over the air (by IP address, presuming that
LAN1 Network Interface Configuration, Network Accessibility is set to Public, or by link from the
Session Status or Remote Subscribers tab in the AP) is unaffected.
Allowing management from only specified IP addresses
The Security sub-menu of the Configuration web page in the AP/BHM and SM/BHS includes the IP
Access Control parameter. Specify one, two, or three IP addresses that must be allowed to access the
management interface (by HTTP, SNMP, FTP or TFTP).
If the selection is:
•
IP Access Filtering Disabled, then management access is allowed from any IP address, even if the
Allowed Source IP 1 to 3 parameters are populated.