PTP 800 Series User Guide
Syst em m anagem ent
phn- 2513_004v000 ( Oct 2012)
1- 57
View-based access control model
PTP 800 supports the SNMPv3 view-based access control model (VACM) with a single
context. The context name is the empty string. The context table is read-only, and cannot
be modified by users.
Access to critical security parameters
The SNMPv3 management interface does not provide access to critical security
parameters (CSPs). It is not possible to read or modify AES keys used to encrypt data
transmitted at the wireless interface.
MIB-based management of SNMPv3 security
PTP 800 supports a standards-based approach to configuring SNMPv3 users and views
through the SNMP MIB. This approach provides maximum flexibility in terms of defining
views and security levels appropriate for different types of user.
The system provides a default SNMPv3 configuration. This initial configuration is not
secure, but it provides the means by which a secure configuration can be created using
SNMPv3.
The secure configuration should be configured in a controlled environment to prevent
disclosure of the initial security keys necessarily sent as plaintext, or sent as encrypted
data using a predictable key. The initial security information should not be configured over
an insecure network.
The default configuration is restored when any of the following occurs:
•
All CMU configuration data is erased.
•
All SNMP users are deleted using the SNMP management interface.
•
The SNMP Engine ID Format has been changed.
•
The SNMP Engine ID Format is IP Address AND the IP Address has been changed.
•
The SNMP Engine ID Format is Text String AND the text string has been changed.
•
The SNMP Engine ID Format is MAC Address AND configuration has been restored
using a file saved from a different unit.
•
SNMPv3 Security Management is changed from web-based to MIB-based.
The default user configuration is specified in
SNMPv3 default configuration (MIB-based)
The system creates the
initial
user and template users with localized authentication and
privacy keys derived from the passphrase string
123456789
. Authentication keys for the
templates users are fixed and cannot be changed. Any or all of the template users can be
deleted.
Summary of Contents for PTP 800 Series
Page 1: ...Cambium PTP 800 Series User Guide System Release 800 05 02 ...
Page 40: ...Licensing requirements About This User Guide 10 phn 2513_004v000 Oct 2012 ...
Page 232: ...Limit of liability Chapter 3 Legal information 3 22 phn 2513_004v000 Oct 2012 ...
Page 322: ...Radiation hazard assessm ent Chapter 4 Reference information 4 90 phn 2513_004v000 Oct 2012 ...
Page 428: ...Replacing IRFU components Chapter 5 Installation 5 106 phn 2513_004v000 Oct 2012 ...
Page 630: ...Using recovery mode Chapter 7 Operation 7 78 phn 2513_004v000 Oct 2012 ...