PMP 450 Configuration and User Guide
Task 5: Configuring security
pmp-0050 (May 2012)
2-65
Filtering management through Ethernet
You can configure the SM to disallow any device that is connected to its Ethernet port from accessing the IP
address of the SM. If you set the
Ethernet Access Control
parameter to
Enabled
, then
no attempt to access the SM management interface (by http, SNMP, telnet, ftp, or tftp) through Ethernet
can succeed.
any attempt to access the SM management interface over the air (by IP address, presuming that
LAN1
Network Interface Configuration, Network Accessibility
is set to
Public
, or by link from the Session Status
or Remote Subscribers tab in the AP) is unaffected.
Allowing management only from specified IP addresses
The Security tab of the Configuration web page in the AP and SM includes the
IP Access Control
parameter.
You can specify one, two, or three IP addresses that should be allowed to access the management interface (by
http, SNMP, telnet, ftp, or tftp).
If you select
IP Access Filtering Disabled
, then management access is allowed from any IP address, even if the
Allowed
Source IP
1 to 3
parameters are populated.
IP Access Filtering Enabled
, and specify at least one address in the
Allowed Source IP
1 to 3
parameter,
then management access is limited to the specified address(es). If you intend to use Prizm to manage the
element, then you must ensure that the IP address of the Prizm server is listed here.
Configuring management IP by DHCP
The IP tab in the Configuration web page of every radio contains a
LAN1 Network Interface Configuration,
DHCP State
parameter that, if enabled, causes the IP configuration (IP address, subnet mask, and gateway IP
address) to be obtained through DHCP instead of the values of those individual parameters. The setting of this
DHCP state parameter is also viewable, but is not settable, in the Network Interface tab of the Home page.
In the SM, this parameter is settable
in the NAT tab of the Configuration web page, but only if NAT is enabled.
in the IP tab of the Configuration web page, but only if the
Network Accessibility
parameter in the IP tab
is set to
Public
.
Denying All Remote Access
Wherever the No Remote Access feature is enabled by the following procedure, physical access to the module is
required for
any change in the configuration of the module.
any software upgrade in the module.
Содержание PMP 450
Страница 1: ...Cambium PMP 450 Configuration and User Guide System Release 12 0...
Страница 6: ......
Страница 22: ......
Страница 172: ......
Страница 173: ...PMP 450 Configuration and User Guide pmp 0050 May 2012 3 1 Chapter 3 Reference information...
Страница 178: ......