Installation Guide

Table Of Contents
Task 5: Configuring security PMP 450i and PTP 450i Configuration and User
Guide
The following are example situations in which you can configure protocol filtering
where NAT is disabled:
If you block a subscriber from only PPPoE and SNMP, then the subscriber retains
access to all other protocols and all ports.
If you block PPPoE, IPv4, and Uplink Broadcast, and you also check the
All others selection, then only Address Resolution Protocol is not filtered.
For more information, see Protocol Filtering tab of the SM on Page 106.
Table 26 Ports filtered per protocol selection
Protocol Selected Port Filtered (Blocked)
SMB
Destination Ports UDP : 137, 138, 139, 445, 3702 and
1900
Destination Ports TCP : 137, 138, 139, 445, 2869,
5357 and 5358
SNMP Destination Ports TCP and UDP : 161 and 162
Bootp Client Source Port 68 UDP
Bootp Server Source Port 67 UDP
User Defined Port
1..3
User defined ports for filtering UDP and TCP
IPv4 Multicast Block IPv4 packet types except other filters defined.
IPv6 Multicast Block IPv6 packet types except other filters defined.
ARP Filter all Ethernet packet type 806
Upstream
Applies packet filtering to traffic coming into the FEC
interface
Downstream
Applies packet filtering to traffic destined to exit the
FEC interface
Encrypting downlink broadcasts
An AP can be enabled to encrypt downlink broadcast packets such as the following:
ARP
NetBIOS
broadcast packets containing video data on UDP.
The encryption used is DES for a DES-configured module and AES for an AES-
configured module. Before the Encrypt Downlink Broadcast feature is enabled on
the AP, air link security must be enabled on the AP.
pmp-0957 (April 2015) 87