User's Manual

7 of 47
Mesh Management Using ARCView Software
ARCView™ mesh management software provides live monitoring, as well as local and remote
management of MetroE wireless mesh networks. The software features an intuitive graphical user
interface and provides complete access to all mesh and individual node settings, including
security, VLANs, traffic prioritization, radio power controls, and Network Gateway Interconnects.
Live monitoring features include mesh and node statistics and a graphical view that uses node
icons to indicate active connections. Users can also import graphics of floor plans or maps. The
icons for each node can be moved over the graphics to show where they are physically located.
Security
The MetroE ODU mesh network includes several layers of security, including AES key and WEP
encryption.
AES (Advanced Encryption Standard) encryption can be used to protect data exchanged between
any two nodes in a wireless mesh. When AES encryption is enabled for a wireless mesh, all
payload data leaving the nodes in the mesh is encrypted using 128- or 256-bit keys. The data
remains encrypted as it passes through the intermediate nodes and is only decrypted at the end
node where it leaves the mesh network. This provides end-to-end security for the customer data
passing through the MetroE ODU wireless mesh.
WEP (Wired Equivalent Policy) supports 40/64- and 104/128-bit encryption to protect all traffic on
the mesh, including routing and management traffic. This can be used to protect traffic over the
wireless links.
For additional security, a proprietary mesh protocol prevents non-MetroE ODU devices from
participating on the mesh. Secure network access can also be provided for applications that do not
allow Wi-Fi client services by connecting computers to the mesh directly using cables connected to
the Ethernet ports on a MetroE ODU node.
Packet Filtering
MetroE ODU nodes can filter packets based upon the MAC address of the traffic. You can configure
each Ethernet port to deny or permit access for traffic coming from or to specific devices
(identified by the devices’ MAC addresses).
VLANs
The MetroE ODU mesh network includes support for virtual local area networks (VLANs) to enable
traffic to be separated into smaller groups and application-specific LANs. VLANs allow small
groups of users to operate within their own private space on the mesh, and they can also improve
mesh performance by directing traffic onto specific VLAN routes. The MetroE ODU mesh supports
802.1Q VLAN tagging of packets entering and exiting the mesh.
You can configure each Ethernet port to operate as part of a VLAN. A MetroE ODU wireless mesh
can support multiple VLANs. You can assign ports to different VLANs. Only ports belonging to the
same VLAN can switch traffic among themselves. You can create up to 16 logically separated
VLAN networks within a single mesh. The MetroE ODU mesh also supports VLAN trunks.