
Chapter 17: Radio Configuration (CLI)
Configuring AES-256 Payload Encryption (CLI)
phn-3965_006v002
Page 17-14
Configuring AES-256 Payload Encryption (CLI)
Note
AES-256 is not supported with PTP 820F.
This feature requires:
•
Requires an activation key. If no valid AES activation key has been applied to the unit, AES will not operate on
the unit. See
Configuring the Activation Key
Note
In order for the AES activation key to become active, you must reset the unit after configuring a valid
AES activation key. Until the unit is reset, an alarm will be present if you enable AES. This is not the
case for other activation keys.
PTP 820G supports AES-256 payload encryption. AES is enabled and configured separately for each radio carrier.
PTP 820 uses a dual-key encryption mechanism for AES:
•
The user provides a master key. The master key can also be generated by the system upon user command. The
master key is a 32-byte symmetric encryption key. The same master key must be manually configured on both
ends of the encrypted link.
•
The session key is a 32-byte symmetric encryption key used to encrypt the actual data. Each link uses two
session keys, one for each direction. For each direction, the session key is generated by the transmit side unit
and propagated automatically, via a Key Exchange Protocol, to the other side of the link. The Key Exchange
Protocol exchanges session keys by encrypting them with the master key, using the AES-256 encryption
algorithm. Session keys are regenerated at user-configured intervals.
AES key generation is completely hitless, and has no effect on ACM operation.
To display the current payload encryption status for all available radio links on the unit, enter the following
command in root view:
root> payload encryption status show
The following is a sample output of this command in which payload encryption is enabled but not operational on
radio interface 1, and disabled on radio interface 2.
Summary of Contents for PTP 820 Series
Page 1: ...User Guide ...
Page 49: ...Chapter 1 Introduction Configuration Tips phn 3965_006v002 Page 1 3 ...
Page 162: ...Chapter 3 Configuration Guide System Configurations phn 3965_006v002 Page 3 4 ...
Page 294: ...Chapter 4 Unit Management Upgrading the Software phn 3965_006v002 Page 4 19 5 Select FTP ...
Page 713: ...Chapter 14 Getting Started CLI Configuring the Activation Key CLI phn 3965_006v002 Page 14 18 ...
Page 731: ...Chapter 14 Getting Started CLI Operating in FIPS Mode CLI phn 3965_006v002 Page 14 36 ...