![Cirronet CR-SEH User Manual Download Page 21](http://html1.mh-extra.com/html/cirronet/cr-seh/cr-seh_user-manual_2608455021.webp)
CR-SEH
CR-SEH Operation
Overview
CR-SEH devices are wireless Ethernet modems that perform bridging functions in point-to-point or point-
to-multipoint configurations. CR-SEH products are designed to connect remote network segments
together while keeping the data traffic between the network segments to a minimum. CR-SEH products
use MAC-layer addresses to learn on which network segment a device is located.
A master CR-SEH can connect up to 60 remote slave CR-SEHs. The CR-SEH is a single channel device
with an over-the-air data rate of 1.23Mbps providing up to 500Kbps full duplex data throughput. The
radio modems in the CR-SEHs are factory configured with optimum settings for typical point-to-point
applications. The radio parameters can be configured to optimize data throughput, latency and range for
whatever the application. In addition, the radios in the CR-SEHs can be configured to allow multiple CR-
SEH networks to be co-located.
Security Modes
The CR-SEH provides several security modes that protect against unauthorized control of the CR-SEH
and unauthorized access to the network to which the CR-SEH is connected.
The first security feature is the need for a password to connect to a CR-SEH remotely through a telnet
session. The password is enabled and cannot be disabled. When a telnet session is initiated, a password
must be entered to gain access to the command line mode of the CR-SEH. The default password is
“Cirronet” (no quotes, case sensitive) but should be changed immediately. When you change the
password, please make note of it and save it in a secure location as there is no way to recover lost
passwords. Another feature is available to limit the ability to initiate telnet and web sessions with the CR-
SEH. The
access ip add
command is used to add specific IP addresses from which telnet sessions will
be allowed. Up to 10 IP addresses can be entered. This featured is defaulted OFF and is enabled through
the
access ip enable
command.
The same password required for a telnet session may also be required for a serial connection to the
console port. The default for this feature is Off. It is set using the
access console enable
command.
When enabled, the same password used for the telnet session will be required to gain access to the
command line interface of the CR-SEH through the console port.
Similar to the telnet/console password is the FTP password. This password is always required and cannot
be disabled. The default password is “Cirronet” (no quotes, case sensitive) but should be changed
immediately. When you change the password, please make note of it and save it in a secure location as
there is no way to recover lost passwords.
To provide security from unauthorized CR-SEHs gaining access to a CR-SEH network, an access
code/password feature is available. This features requires slave CR-SEHs to authenticate with the master
before being granted access to the network. This feature is defaulted OFF and is set up using the
bridge
login
,
bridge access
and
bridge password
commands.
Details of all the security-related commands are found in the
Bridge Commands
and
Security Commands
sections of this manual.
Point-to-Point Mode
In point-to-point operation, one CR-SEH is configured as the Master and the other is configured as a
Slave. While this is necessary for operation, it does not matter which CR-SEH is the master and which is
the slave. The radio in the master operates as the base radio. Configuring the CR-SEH as the master
automatically configures the radio in the master as a base radio. Similarly, configuring a CR-SEH as a
slave automatically configures the slave radio as a remote radio.
2000- 2004 Cirronet
Inc
16
M-2411-0013 Rev A