![Cambium PTP 450 Скачать руководство пользователя страница 184](http://html1.mh-extra.com/html/cambium/ptp-450/ptp-450_configuration-and-users-manual_3577514184.webp)
Security planning
PTP 450 Configuration and User
pmp-0815 (August 2015)
4-49
Allowing management from only specified IP addresses
The Security tab of the Configuration web page in the BHM and BHS includes the
IP
Access Control
parameter. You can specify one, two, or three IP addresses that must be
allowed to access the management interface (by HTTP, HTTPS, SNMP, FTP, or TFTP).
If you select
IP Access Filtering Disabled
, then management access is allowed from any IP
address, even if the
Allowed Source IP 1 to 3
parameters are populated.
IP Access Filtering Enabled
, and specify at least one address in the
Allowed Source
IP 1 to 3
parameter, then management access is limited to the specified address.
Configuring management IP by DHCP
The
IP
tab in the Configuration web page of every radio contains a
LAN1 Network
Interface Configuration, DHCP State
parameter that, if enabled, causes the IP
configuration (IP address, subnet mask, and gateway IP address) to be obtained through
DHCP instead of the values of those individual parameters. The setting of this DHCP state
parameter in the
Network Interface
tab of the Home page is Read-only.
Planning for airlink security
Cambium fixed wireless broadband IP systems employ the following encryption for
security of the wireless link:
DES (Data Encryption Standard)
: An over-the-air link encryption option that uses
secret 56-bit keys and 8 parity bits. DES performs a series of bit permutations,
substitutions, and recombination operations on blocks of data. DES encryption does
not affect the performance or throughput of the system.
AES (Advanced Encryption Standard):
An over-the-air link encryption option that
uses the Rijndael algorithm and 128-bit keys to establish a higher level of security than
DES. AES products are certified as compliant with the Federal Information Processing
Standards (FIPS 197) in the U.S.A.
The BHM is set to "None" by default. Ensure to select the encryption type on the BHM
and BHS that is needed for the link.
Planning for SNMP security
The SNMPv3 provides a more secure method to perform SNMP operations. This standard
provides services for authentication, data integrity and message encryption over SNMP.