Chapter 3: System planning
178
The encryption used is AES for an AES- configured module. Before the Encrypt Downlink Broadcast
feature is enabled on the AP, air link security must be enabled on the AP.
Isolat ing SMs in PMP
In an AP, SMs in the sector can be prevented from directly communicating with each other. In CMM4, the
connected APs can be prevented from directly communicating with each other, which prevents SMs that
are in different sectors of a cluster from communicating with each other.
In the AP, the SM Isolation parameter is available in the General tab of the Configuration web page.
Configure the SM Isolation feature by any of the following selections from drop-down menu:
l
Disable SM Isolation (the default selection). This allows full communication between SMs.
l
Enable Option 1 - Block SM destined packets from being forwarded. This prevents both
multicast/broadcast and unicast SM-to-SM communication.
l
Enable Option 2 - Forward SM destined packets upstream. This not only prevents
multicast/broadcast and unicast SM-to-SM communication but also sends the packets, which
otherwise may have been handled SM to SM, through the Ethernet port of the AP.
In the CMM and the CMM4, SM isolation treatment is the result of how to manage the port-based VLAN
feature of the embedded switch, where all traffic can be switched from any AP to a specified uplink port.
However, this is not packet level switching. It is not based on VLAN IDs.
Filt er ing m anag em ent t hr oug h Et her net
Configure the SM to disallow any device that is connected to its Ethernet port from accessing the IP
address of the SM. If the Ethernet Access Control parameter is set to Enabled, then:
l
No attempt to access the SM management interface (by http, SNMP, ftp, or tftp) through Ethernet
is granted.
l
Any attempt to access the SM management interface over the air (by IP address, presuming that
LAN1 Network Interface Configuration, Network Accessibility is set to Public, or by link from the
Session Status or Remote Subscribers tab in the AP) is unaffected.
A llow ing m anag em ent f r om only sp ecif ied IP ad d r esses
The Security sub-menu of the Configuration web page in the AP/BHM and SM/BHS includes the IP Access
Control parameter. Specify one, two, or three IP addresses that must be allowed to access the
management interface (by HTTP, SNMP, FTP or TFTP).
If the selection is:
l
IP Access Filtering Disabled, then management access is allowed from any IP address, even if the
Allowed Source IP 1 to 3 parameters are populated.
l
IP Access Filtering Enabled, and specify at least one address in the Allowed Source IP 1 to 3
parameter, then management access is limited to the specified address(es).
Conf ig ur ing m anag em ent IP b y DHCP
The Configuration > IP web page of every radio contains a LAN1 Network Interface Configuration, DHCP
State parameter that, if enabled, causes the IP configuration (IP address, subnet mask, and gateway IP
address) to be obtained through DHCP instead of the values of those individual parameters. The setting of
Summary of Contents for PMP 450 Series
Page 92: ...Chapter 2 System hardware 92 Figure 29 MicroPoP Omni antenna implementation pattern Vertical...
Page 134: ...Chapter 3 System planning 134 Figure 51 Mast or tower installation...
Page 135: ...Chapter 3 System planning 135 Figure 52 Wall installation...
Page 136: ...Chapter 3 System planning 136 Figure 53 Roof installation...
Page 137: ...Chapter 3 System planning 137 Figure 54 GPS receiver wall installation...
Page 158: ...Chapter 3 System planning 158 Figure 61 cnMedusa Antenna...