
58
9.
Ethernet Features
The SkyWay-LM system includes a multi-port Ethernet switch that provides Layer2 interconnection
between the four front panel ports, the local (IDU internal) CPU port and the radio port. The switch is
capable of providing normal, unrestricted address learning and frame forwarding functions between these
six ports. The switch is also configurable via the IDU user interface to provide the following enhanced
functionality:
VLAN-based security features restrict the forwarding of frames between the management and
transport ports, protecting the near and far-side CPUs and management Ethernet ports from
unauthorized access via the transport ports.
Port-based QoS Priority provides for setting the priority of each port, determining the QoS level
assigned to all frames entering that port.
Port-based rate limiting allows the assignment of a maximum ingress bit rate allowed for each
port.
Ethernet flow control for managing data overflows in the network by halting transmissions for
specified periods of time.
A more detailed discussion of each of these features is given below.
9.1. VLAN-based Security Features
The SkyWay-LM platform includes VLAN-based security features designed to protect the near and far-
side CPUs and management Ethernet ports from unauthorized access via the transport ports. The design
is depicted in Figure 7-1. When VLAN Security is enabled, Ethernet frames ingressing into either of the
two transport ports at each IDU are allowed to egress from only the corresponding transport port at the
far-side IDU. (E.g., frames ingressing into P0 at the near-side egress only from P0 on the far side.)
Frames ingressing from either of the transport ports are not allowed to egress to the local switch’s CPU
port or management ports, nor to the far-side switch’s CPU or management ports. Ethernet frames
ingressing from either of the management ports are allowed to egress to the other local management port,
the local CPU port, the far-side management ports, or the far side CPU port, as determined by the
switches’ address lookup and forwarding functions. Frames ingressing from either of the management
ports are not allowed to egress the local or far-side transport ports.
This VLAN Security feature operates by adding a VLAN tag to all ingressed frames for internal processing
within the Ethernet switches. The VLAN security feature can accommodate traffic traversing the link that
is already VLAN tagged. VLAN-tagged frames that ingress to the switch will be double-tagged. VLAN
tags added by the switch are removed upon egress from the link. Therefore, frames that ingress to the
switch with a single VLAN tag egress from the terminal with their original VLAN tag intact. However,
frames that ingress to the link double-tagged will have their 2nd tags removed. Both terminals of a link
must have VLAN Security enabled for protection to be in effect.
Also note that both terminals of a link must have the same VLAN Security setting (enabled or disabled) in
order to have remote management access to the far-side terminal. Therefore, if VLAN Security is to be
Summary of Contents for SKYWAY-LM Series
Page 1: ...1 SKYWAY LM SERIES PTP Microwave Radio System User s Guide APRIL 2010 Rev 1 6 PN 1552601 ...
Page 21: ...21 Figure 5 2 The backside of the ODU rectangular waveguide version shown ...
Page 25: ...25 Figure 5 9 Loosened plate Figure 5 10 Rotating the antenna waveguide by 90 degrees ...
Page 50: ...50 Figure 6 19 System Reboot Screen ...
Page 57: ...57 Figure 8 3 Serial Interface Menu Structure ...