User Guide for FibeAir® IP-20 All-Outdoor Products, CeraOS 10.5
Page 240 of 825
Ceragon Proprietary and Confidential
5.5
Configuring AES-256 Payload Encryption
Notes
:
This feature is only relevant for IP-20C, IP-20C-HP, and IP-20S units.
This feature is not supported with MIMO or Space Diversity links.
This feature requires:
•
Requires an activation key per radio. If no valid AES activation key has been
applied to the unit, AES will not operate on the unit. See
Note:
In order for the AES activation key to become active, you must reset
the unit after configuring a valid AES activation key. Until the unit is
reset, an alarm will be present if you enable AES. This is not the case
for other activation keys.
FibeAir IP-20C, IP-20C-HP, and IP-20S support AES-256 payload encryption. AES is
enabled and configured separately for each radio carrier.
IP-20 uses a dual-key encryption mechanism for AES:
•
The user provides a master key. The master key can also be generated by the
system upon user command. The master key is a 32-byte symmetric
encryption key. The same master key must be manually configured on both
ends of the encrypted link.
•
The session key is a 32-byte symmetric encryption key used to encrypt the
actual data. Each link uses two session keys, one for each direction. For each
direction, the session key is generated by the transmit side unit and
propagated automatically, via a Key Exchange Protocol, to the other side of
the link. The Key Exchange Protocol exchanges session keys by encrypting
them with the master key, using the AES-256 encryption algorithm. Session
keys are regenerated at user-configured intervals.
AES key generation is completely hitless, and has no effect on ACM operation.
To configure payload encryption:
1 Verify that both the local and remote units are running with no alarms. If any
alarm is present, take corrective actions to clear the alarms before
proceeding.
2 If the link is using in-band management, identify which unit is local and which
unit is remote from the management point of view.
3
In a protected link, enable protection lockout, first on the remote and then on
the local unit. See
Disabling Automatic Switchover to the Standby Unit
4
On the remote unit, select
Radio > Payload Encryption
. The Payload
Encryption page opens.
◦
For multi-carrier units, the Payload Encryption page initially displays a
table as shown in
◦
For IP-20S units, a page appears, similar to
(which shows an IP-
20C/IP-20C-HP page).