![Cambium Networks PTP 820 Series User Manual Download Page 338](http://html.mh-extra.com/html/cambium-networks/ptp-820-series/ptp-820-series_user-manual_485676338.webp)
Chapter 5: Radio Configuration
Configuring AES-256 Payload Encryption
phn-3965_006v002
Page 5-24
Configuring AES-256 Payload Encryption
Note
AES-256 is not supported with PTP 820F
This feature requires:
•
Requires an activation key. If no valid AES activation key has been applied to the unit, AES will not operate on
the unit. See
Configuring the Activation Key
Note
In order for the AES activation key to become active, you must reset the unit after configuring a valid
AES activation key. Until the unit is reset, an alarm will be present if you enable AES. This is not the
case for other activation keys.
PTP 820G supports AES-256 payload encryption. AES is enabled and configured separately for each radio carrier.
PTP 820 uses a dual-key encryption mechanism for AES:
•
The user provides a master key. The master key can also be generated by the system upon user command. The
master key is a 32-byte symmetric encryption key. The same master key must be manually configured on both
ends of the encrypted link.
•
The session key is a 32-byte symmetric encryption key used to encrypt the actual data. Each link uses two
session keys, one for each direction. For each direction, the session key is generated by the transmit side unit
and propagated automatically, via a Key Exchange Protocol, to the other side of the link. The Key Exchange
Protocol exchanges session keys by encrypting them with the master key, using the AES-256 encryption
algorithm. Session keys are regenerated at user-configured intervals.
AES key generation is completely hitless, and has no effect on ACM operation.
To configure payload encryption:
1.
Verify that both the local and remote units are running with no alarms. If any alarm is present, take corrective
actions to clear the alarms before proceeding.
2.
If the link is using in-band management, identify which unit is local and which unit is remote from the
management point of view.
3.
In a link with radio protection, enable protection lockout, first on the remote and then on the local unit. See
4.
On the remote unit, Select
Radio > Payload Encryption
. The Payload Encryption page opens.
Summary of Contents for PTP 820 Series
Page 1: ...User Guide ...
Page 49: ...Chapter 1 Introduction Configuration Tips phn 3965_006v002 Page 1 3 ...
Page 162: ...Chapter 3 Configuration Guide System Configurations phn 3965_006v002 Page 3 4 ...
Page 294: ...Chapter 4 Unit Management Upgrading the Software phn 3965_006v002 Page 4 19 5 Select FTP ...
Page 713: ...Chapter 14 Getting Started CLI Configuring the Activation Key CLI phn 3965_006v002 Page 14 18 ...
Page 731: ...Chapter 14 Getting Started CLI Operating in FIPS Mode CLI phn 3965_006v002 Page 14 36 ...