EDA 1200 System Overview
2.3 GPON Features
The EDA 1200 restrictions when using GPON technology are briefly described
in this section. For a complete description of the features and properties of the
GPON network and technology, please see the EDA 1500 Customer Product
Information.
The GPON network can be configured to be logically transparent (with the
exception of multicast) to the traffic of the EDA 1200 network.
The BLM sends group specific queries as unicast. The ESN204g can, however,
be configured to respond as if the group specific queries were sent as multicast,
in accordance with IGMP version 2.
2.4 Security in the Network
Various security measures can be deployed in order to protect the EDA 1200
system and the End-users connected to it. Some of the security settings may
overlap, but they can still be activated simultaneously to improve security:
Management Plan
Protection
The EDA 1200 nodes contain Access Control Lists
(ACL). The ACL is a filter which can be used to allow
or deny traffic from specific nodes or networks, and
specific types of traffic.
Filtering
The Line Termination Units can be configured to filter
out unwanted traffic based on a variety of parameters.
Forced Forwarding
Using Forced Forwarding towards the Service Provider’s
default gateway.
Number of CPE
Devices
It is possible to limit the maximum allowed number of
End-user devices for a specific service. This can be
used to ensure that the number of End-user MAC (or
VMAC) addresses connected to the network will not
cause switches overflow.
DHCP Relay Agent
Information Option
(Option 82)
Using DHCP Relay agent configuration (Option 82) to
authenticate End-users and to allow access to specific
services
Virtual MAC
Addresses
Using Virtual MAC addresses to prevent MAC spoofing.
The MAC Address Translation (MAT) can be used as
1:1 or N:1.
Separating Traffic
Using VLANs
VLANs can be used to create logically separated
networks within the Access Domain. Users in one VLAN
are totally separated (in layer 2) from users of another,
even though they share the same physical Ethernet. A
14
1/1551-LZA 101 464-V1 Uen C 2009-12-17
Kommentare zu diesen Handbüchern