![Cambium PTP 670 Series User Manual Download Page 45](http://html.mh-extra.com/html/cambium/ptp-670-series/ptp-670-series_user-manual_485665045.webp)
Chapter 1: Product description
Wireless operation
Page 1-21
HCMP topology
In the HCMP wireless topology, PTP 670 always uses the Group Access method. The Master
and Slave ODUs must all share the same Group ID.
Note
The configured Access Method provides effective protection against an accidental
attempt to form a link with the wrong remote unit. Use wireless encryption to protect
against a malicious attempt to connect an unauthorized ODU to the wireless network.
Further reading
For information about…
Refer to…
General description of Wireless encryption
Configuring Access Method
Configuring Target MAC Address
Authorization Control page
Wireless encryption
The PTP 670 supports optional encryption for data transmitted over the wireless link using a
choice of three different encryption algorithms:
•
TLS RSA: The ODUs exchange RSA certificates to authorize the remote unit and agree a
randomly-generated master secret. The TLS RSA option supports unencrypted operation of
the wireless link, or encryption with 128-bit or 256-bit AES.
•
TLS PSK 128-bit: Both ends of the link are configured with the same 128-bit pre-shared key
as a master secret. The wireless link is encrypted using 128-bit AES.
•
TLS PSK 256-bit: Both ends of the link are configured with the same 256-bit pre-shared key
as a master secret. The wireless link is encrypted using 256-bit AES.
The Advanced Encryption Standard (AES) is a symmetric encryption algorithm approved by
U.S. Government organizations (and others) to protect sensitive information. The AES
implementation in PTP 670 is approved to FIPS 197.
The use of AES encryption in PTP 670 is controlled by the AES license and enabled through the
purchase of a capability upgrade.
Note
Encryption Algorithm cannot be configured as TLS RSA when Access Method is Link
Name Access. In this case, only the TLS PSK algorithms are supported.