User's Guide Part 1

Table Of Contents
Chapter 1: Product description System management
Installation:
The Installation Wizard is used to install license keys, configure the PTP 700
wireless interface and to arm the unit ready for alignment.
Management:
These web-pages are used to configure the network management interfaces.
Security:
The Security Wizard is used to configure the HTTPS/TLS interface and other
security parameters such as the AES wireless link encryption key and the key of keys for
encrypting CSPs on the ODU. The Security Wizard is disabled until AES encryption is
enabled by license key.
Change Password
: The Change Password web page changes the web interface password of
the active user. The User Accounts page is also used to change passwords.
Logout:
Allows a user to log out from the web-based interface.
Transport layer security
The HTTPS/TLS interface provides the same set of web-pages as the HTTP interface, but allows
HTTP traffic to be encrypted using Transport Layer Security (TLS). PTP 700 uses AES
encryption for HTTPS/TLS. Operation of HTTPS/TLS is enabled by purchase of an optional AES
upgrade.
HTTPS/TLS requires installation of a private key and a public key certificate where the common
name of the subject in the public key certificate is the IP address or host name of the PTP 700
unit. PTP 700 supports certificates with 2048-bit key size.
HTTPS/TLS operation is configured through the web-based interfaces using the Security
Wizard.
Note
The PTP 700 has no default public key certificate, and Cambium Networks is not able
to generate private keys or public key certificates for specific network applications.
Note
PTP 700 supports a single public key certificate for HTTPS. This certificate must be
based on an IPv4 or IPv6 address as the Common Name. Any attempt to use HTTPS
without a certificate for the associated IP address will not be secure, and will trigger
browser security warnings. It follows from this that the Dual IPv4/IPv6 interface should
not normally be used when HTTPS is required.
User account management
PTP 700 allows a network operator to configure a policy for login attempts, the period of
validity of passwords and the action taken on expiry of passwords.
Identity-based user accounts
The PTP 700 web-based interface provides two methods of authenticating users:
Role-based user authentication allows the user, on entry of a valid password, to access all
configuration capabilities and controls. This is the default method.
Identity-based user authentication supports up to 10 users with individual usernames and
passwords.
Page 1-41