System management Chapter 1: Product description
1-60
phn-2513_004v000 (Oct 2012)
AES license
PTP 800 provides optional encryption using the Advanced Encryption Standard (AES).
Encryption is not available in the standard system.
AES upgrades are supplied as an access key purchased from your Cambium Point-to-Point
distributor or solutions provider. The access key authorizes AES operation for one CMU.
Two access keys are needed to operate AES on a link. The upgrade is applied by entering
an access key together with the MAC address of the target CMU into the PTP License Key
Generator web page, which may be accessed from the support web page (see Contacting
Cambium Networks on page 2).
The License Key Generator creates a new license key that is delivered by email. The
license key must be installed on the CMU. When the license key is installed, the CMU must
be rebooted before AES can be enabled. Once applied, the AES upgrade is bound to a
single CMU and is not transferrable.
AES encryption may be used in the following ways:
• At the wireless port to encrypt data transmitted over the wireless link.
• At the SNMP management interface in the SNMPv3 mode.
• At the HTTPS/TLS management interface.
Two levels of encryption are available to purchase:
• 128-bit: This allows an operator to encrypt all traffic sent over the wireless link using
128-bit encryption.
• 256-bit: This allows an operator to encrypt traffic using either 128-bit or 256-bit
encryption.
Encryption must be configured with the same size key in each direction.
AES encryption at the wireless port is based on pre-shared keys. An identical key must be
entered at each end of the link.
AES encryption for SNMPv3 is always based on a 128-bit key, regardless of level enabled
in the license key.
For more information, see:
• Task 3: Installing license keys on page 6-21
• Task 5: Configuring security on page 6-28
Comments to this Manuals