
Chapter 3: System planning
Security planning
Page 3-43
Encrypting downlink broadcasts
An AP can be enabled to encrypt downlink broadcast packets such as the following:
ARP
NetBIOS
broadcast packets containing video data on UDP.
The encryption used is DES for a DES-configured module and AES for an AES-configured module.
Before the Encrypt Downlink Broadcast feature is enabled on the AP, air link security must be
enabled on the AP.
Isolating SMs in PMP
In an AP, SMs in the sector can be prevented from directly communicating with each other. In
CMM4, the connected APs can be prevented from directly communicating with each other, which
prevents SMs that are in different sectors of a cluster from communicating with each other.
In the AP, the SM Isolation parameter is available in the General tab of the Configuration web
page. Configure the SM Isolation feature by any of the following selections from drop-down menu:
Disable SM Isolation (the default selection). This allows full communication between SMs.
Enable Option 1 - Block SM destined packets from being forwarded. This prevents both
multicast/broadcast and unicast SM-to-SM communication.
Enable Option 2 - Forward SM destined packets upstream. This not only prevents
multicast/broadcast and unicast SM-to-SM communication but also sends the packets, which
otherwise may have been handled SM to SM, through the Ethernet port of the AP.
In the CMM and the CMM4, SM isolation treatment is the result of how to manage the port-based
VLAN feature of the embedded switch, where all traffic can be switched from any AP to a specified
uplink port. However, this is not packet level switching. It is not based on VLAN IDs.
Filtering management through Ethernet
Configure the SM to disallow any device that is connected to its Ethernet port from accessing the
IP address of the SM. If the Ethernet Access Control parameter is set to Enabled, then:
No attempt to access the SM management interface (by http, SNMP, ftp, or tftp) through
Ethernet is granted.
Any attempt to access the SM management interface over the air (by IP address, presuming
that LAN1 Network Interface Configuration, Network Accessibility is set to Public, or by link
from the Session Status or Remote Subscribers tab in the AP) is unaffected.