![Cambium PTP 450 Скачать руководство пользователя страница 93](http://html1.mh-extra.com/html/cambium/ptp-450/ptp-450_configuration-and-users-manual_3577514093.webp)
PTP 450 Configuration and User Guide
Task 5: Configuring Security
3-36
pmp-0815 (August 2015)
In the
Security
tab of the BHM, you may set the following parameters
Table 19
BHM security tab attributes
Attribute
Meaning
Authentication Mode
Operators may use this field to select from among the following
authentication modes:
Authentication Required
- The BHM acts as the
authentication server to its BHS and makes use of a user-
configurable pre-shared authentication key. The operator
enters this key on both the BHM and all BHSs desired to
register to that BHM. Due to the nature of the authentication
operation, if you want to set a specific authentication key, then
you MUST configure the key on all of the BHSs and reboot them
BEFORE enabling the key and option on the BHM. Otherwise,
if you configure the BHM first, none of the BHSs will register.
Authentication Disabled
—the BHM requires no BHS to
authenticate.
Authentication Key
The authentication key is a 32-character hexadecimal string
used when
Authentication Mode
is set to BHM
PreShared
Key
. By default, this key is set to
0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF.
24 Hour Encryption
Refresh
A BHM that has encryption enabled forces its BHS to re-
register once every 24 hours, during which the BHM refreshes
the encryption key. This provides a level of security, but results
in a brief but daily downtime. Since the refresh occurs in 24
hour increments that begins when the link is established, the
only way to set a favorable time of the day (for example, 2:00
AM) for the key refresh is to reboot either the BHM or BHS at
the favorable time.
When this feature is
Disabled
, the key is refreshed upon only
other re-registration events, such as a reboot.
The default status of this feature is
Enabled
.
The algorithm used in Advanced Encryption Standard (AES)
encryption-capable radios is certified by the National Institute
of Standards and Technology (NIST) to meet government
Federal Information Processing Standard-197 (FIPS-197) for
ensuring secure data communication. Refreshing the key at 24-
hour intervals is not needed for AES radios to meet FIPS 197,
but provides a level of security above the algorithm itself.
In any BH link where encryption is enabled, the BHS briefly
drops registration and re-registers in the BHM every 24 hours
to change the encryption key.