Security planning
ptp-450 (July 2014)
2-93
If you select
IP Access Filtering Disabled
, then management access is allowed from any IP address, even if the
Allowed
Source IP 1 to 3
parameters are populated.
IP Access Filtering Enabled
, and specify at least one address in the
Allowed Source IP 1 to 3
parameter, then
management access is limited to the specified address(es).
Configuring management IP by DHCP
The IP tab in the Configuration web page of every radio contains a
LAN1 Network Interface Configuration,
DHCP State
parameter that, if enabled, causes the IP configuration (IP address, subnet mask, and gateway IP
address) to be obtained through DHCP instead of the values of those individual parameters. The setting of this
DHCP state parameter is also viewable, but is not settable, in the Network Interface tab of the Home page.
In the BHS, this parameter is settable
in the NAT tab of the Configuration web page, but only if NAT is enabled.
in the IP tab of the Configuration web page, but only if the
Network Accessibility
parameter in the IP tab is set
to
Public
.
Planning for airlink security
Cambium fixed wireless broadband IP systems employ the following form of encryption for security of the wireless
link:
DES (Data Encryption Standard)
: An over-the-air link encryption option that uses secret 56-bit keys and 8
parity bits. DES performs a series of bit permutations, substitutions, and recombination operations on blocks of
data. DES encryption does not affect the performance or throughput of the system.
AES (Advanced Encryption Standard):
An over-the-air link encryption option that uses the Rijndael
algorithm and 128-bit keys to establish a higher level of security than DES. AES products are certified as
compliant with the Federal Information Processing Standards (FIPS 197) in the U.S.A.
Planning for RF Telnet Access Control
The RF Telnet Access feature restricts Telnet access to the BHM from a device situated below a network BHS
(downstream from the BHM). This is a security enhancement to restrict RF-interface sourced BHM access
specifically to the LAN1 IP address and LAN2 IP address (Radio Private Address, typically 192.168.101.[LUID]).
This restriction disallows unauthorized users from running Telnet commands on the BHM that can change BHM
configuration or modifying network-critical components such as routing and ARP tables.
Forwarding Downlink PPPoE PADI packets
The BHM supports the control of forwarding of PPPoE PADI (PPPoE Active Discovery Initiation) packets. This
forwarding is configured on the BHM GUI
Configuration
,
Radio
tab by parameter
PPPoE PADI Downlink
Forwarding
. When set to “Enabled”, the BHM allows downstream and upstream transmission of PPPoE PADI
packets. When set to “Disabled”, the BHM will NOT allow PPPoE PADI packets to be sent out of the BHM RF
interface (downstream) but will allow PPPoE PADI packets to enter the RF interface (upstream) and exit the
Ethernet interface.
Summary of Contents for PTP 450 series
Page 1: ...Cambium PTP 450 User Guide System Release 13 2...
Page 20: ......