Other Security Features - Alcatel-Lucent 7302 Information Manual

Intelligent services access manager
Table of Contents

Advertisement

Regardless of the authentication mode of the corresponding PON, the operator must
specify either the physical identifier or the logical identifier of the ONT when
configuring the ONT. The system ensures the uniqueness of the identifier on the
PON based on the authentication mode of the PON. The password does not need to
be unique if used in combination with a MAC address or ONT ID. However, the
password must be unique if authentication is based on a password alone.
The operator can change the authentication mode of a PON interface if the ONT
MAC address is not statically provisioned. However, all ONT MAC addresses under
the modified PON interface will be removed and all ONTs under the PON interface
will deregister.
In the logical ID authentication mode, the operator does not need to pre-provision an
EPON ONT with its logical ID. However, because of a limitation with the EPON
MAC chipset, the operator must pre-provision an EPON ONT with its MAC address
so that the MPCP process can be completed. If an unknown ONT MAC address is
discovered, the MAC address is added to the white list of acceptable EPON MAC
addresses. In this case, the MPCP process is completed when the ONT tries to
reregister. However, the logical ID authentication starts regardless of whether the
ONT MAC address is pre-provisioned. If the authentication is successful, the SLA is
enabled immediately and services start running. If the authentication fails, the ONT
MAC address is removed from the white list.
In logical ID authentication mode, the ONT can be authenticated either locally on the
OLT or remotely at a centralized RADIUS server.

Other security features

In addition to authentication, ISAM also provides the following security features to
avoid unlawful attacks and interceptions:
filtering
anti-spoofing
CPU overloading protection
Alcatel-Lucent 7302 ISAM | 7330 ISAM FTTN | 7360 ISAM FX ONT R04.06.02
3FE 55873 AAAA TCZZA
Edition 01
ONT Product Information Guide
Note —
Conflicting passwords may occur if the authentication mode
is changed from ONT ID plus password to password only. If a conflict
is detected, the system will reject the request to change the
authentication mode of the PON.
Note —
Release 4.2.30 of the EPON system does not support
centralized remote authentication through a RADIUS server.
7 — EPON ONT overview
November 2013
7-13

Advertisement

Table of Contents
loading

This manual is also suitable for:

73607330

Table of Contents