Principle Of Security Data Plan - Huawei SmartAX MA5603T Configuration Manual

Access module
Hide thumbs Also See for SmartAX MA5603T:
Table of Contents

Advertisement

SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
l
l
l
l
l
l
NOTE
l IPTV service is a closed service self-operated by carriers, and single-tagged S-VLAN is recommended.
l The same S-VLAN or different S-VLANs can be used as the M-VLAN and VoD VLAN. It is recommended
that you use different S-VLANs as M-VLAN and VoD VLAN so that the upper-level device easily
differentiates between the BTV service and VoD service.
l S-VLANs of VoD service can identify services and physical locations based on an entire network or an
OLT. It is recommended that you set different VoIP VLANs for the OLTs connected to one VoIP SR to
avoid an excessively large broadcast domain of the VoIP SR and convergence switch.

9.6.6 Principle of Security Data Plan

The security plan involves system security plan, user security plan, and service security plan.
Security policy ensures service security from different aspects.
NOTE
The device provides complete security measures, but not all security measures need to be deployed. Only the
security measures that meet the following requirements need to be deployed:
l The security measures can be used on the live network.
l The security measures are easy to deploy.
l The security measures are effective.
System Security
Security
Vulnerability
DoS attack
Issue 01 (2014-04-30)
C-VLAN: VLAN added based on the ONT/ONU port. For details, see the description of
the Double-tagged VLAN S+C.
Double-tagged VLAN S+C: C indicates the inner VLAN (C-VLAN) and S indicates the
outer VLAN (S-VLAN).
Double-layer VLAN S+C': C' indicates the translated inner VLAN (C'-VLAN) and S
indicates the outer VLAN (SVLAN).
Single-tagged S-VLAN: Single-tagged VLAN marked or translated by the OLT. It is
generally used in a single-tagged VLAN translation scenario.
C<->S+C': Bidirectional VLAN translation: translates the inner C-VLAN and then adds
one outer S-VLAN.
C<->S+C: Bidirectional VLAN translation: maintains the inner C-VLAN and adds one
outer S-VLAN.
Solution
Enable the anti-DoS-attack
function for OLT.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
9 FTTH Configuration
Description and Usage
Suggestion
After the anti-DoS-attack function is
enabled, control packets are
monitored and those exceeding the
number threshold are discarded.
Use this solution for new site
deployment.
575

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Smartax ma5600tSmartax ma5608t

Table of Contents