User's Guide Part 1

Table Of Contents
Chapter 3: System planning Security planning
Security planning
This section describes how to plan for PTP 700 links to operate in secure mode.
Planning for SNTP operation
Note
PTP 700 does not have a battery-powered clock, so the set time is lost each time the
ODU is powered down. To avoid the need to manually set the time after each reboot,
use SNTP server synchronization.
Before starting to configure Simple Network Time Protocol (SNTP):
Identify the time zone and daylight saving requirements that apply to the system.
If SNTP server synchronization is required, identify the details of one or two SNTP servers:
IP address, port number and server key.
Decide whether or not to authenticate received NTP messages using an MD5 signature.
Planning for HTTPS/TLS operation
Before starting to configure HTTPS/TLS operation, ensure that the cryptographic material listed
in Table 59 is available.
Table 59
HTTPS/TLS security material
Item
Description
Quantity required
Key of Keys An encryption key generated using a
cryptographic key generator. The key length is
dictated by the installed license key. License keys
with AES-128 will require a key of keys of 128-
bits. License keys with AES-256 will require a key
of keys of 256-bits. The key output should be in
ASCII hexadecimal characters.
Two per link. For greater
security, each link end
should be allocated a
unique Key of Keys.
Page 3-51