Task 5: Configuring Security
PTP 450 Configuration and User
pmp-0815 (August 2015)
3-41
In the
Protocol Filtering
tab of the BHM, you may set the following parameters
Table 20
Protocol filtering tab attributes
Attribute
Meaning
Packet Filter Types
For any box selected, the Protocol and Port Filtering feature
blocks the associated protocol type.
To filter packets in any of the user-defined ports, you must do
all of the following:
Check the box for
User Defined Port
n (See Below)
in the
Packet Filter Types
section of this tab.
In the
User Defined Port Filtering Configuration
section of
this tab:
Provide a port number at
Port #
n
.
Enable
TCP
and/or
UDP
by clicking the associated radio
button
Filter Direction
Operators may choose to filter Upstream (uplink) RF packets
or Downstream (downlink) RF packets.
User Defined Port
Filtering Configuration
You can specify ports for which to block subscriber access,
regardless of whether NAT is enabled.
RF Telnet Access
RF Telnet Access restricts Telnet access to the BHM from a
device situated below a network BHS (downstream from the
BHM). This is a security enhancement to restrict RF-interface
sourced BHM access specifically to the LAN1 IP address and
LAN2 IP address (Radio Private Address, typically
192.168.101.[LUID]). This restriction disallows unauthorized
users from running Telnet commands on the BHM that can
change BHM configuration or modifying network-critical
components such as routing and ARP tables.
PPPoE PADI Downlink
Forwarding
Enabled
: the BHM allows downstream and upstream
transmission of PPPoE PADI packets. By default, PPPoE PADI
Downlink Forwarding is set to “Enabled”.
Disabled
: the BHM disallows PPPoE PADI packets from
entering the Ethernet interface and exiting the RF interface
(downstream to the BHS). PPPoE PADI packets are still
allowed to enter the BHM’s RF interface and exit the BHM’s
Ethernet interface (upstream).