Got it

GPON Security

Created: Feb 24, 2021 20:13:53Latest reply: Feb 25, 2021 19:11:09 484 6 0 0 0
  Rewarded HiCoins: 0 (problem resolved)


Which is recommend security for OLT in GPON system?

I usualy use anti-macspoofing, anti-ipspoofing, anti-macduplicate, anti-dos, anti-rogue autodetect on, AES128 and ip-firewall.

Featured Answers

Best answer

Recommended answer

liqiang185
Admin Created Feb 25, 2021 01:46:54

Hi there!

macspoofing: To prevent malicious users from forging MAC addresses to send packets to attack the device(Optional).

anti-ipspoofing: To prevent malicious users from forging IP addresses to send packets to attack the device(Optional).

anti-macduplicate: After anti-MAC-duplicate is enabled, the system records the first MAC address learned from the port and bound to the port and VLAN. It can prevent users from forging MAC address to perform malicious attack(Mandatory).

anti-dos: Anti-DoS attack alarm function of the device(Mandatory).

anti-rogue autodetect on: Used to enable or disable the function of automatically isolating the rogue optical network terminal (ONT) detected by the system. When this function is enabled, the rogue ONT detected by the system will be automatically isolated. An isolated rogue ONT can only receive information and cannot send information(Optional).

aes128: An encryption algorithm(Optional).

ip-firewall: The firewall that filters the source address(Mandatory).

For more information, click the following link:

https://support.huawei.com/enterprise/en/doc/EDOC1100168771/293be000/security-hardening

If you do not have the permission to open the link, please click How do we upgrade our account

Thanks!



View more
  • x
  • convention:

All Answers
Hello User. we are reviewing your question and we will answer you shortly. Thanks.
View more
  • x
  • convention:

Hi there!

macspoofing: To prevent malicious users from forging MAC addresses to send packets to attack the device(Optional).

anti-ipspoofing: To prevent malicious users from forging IP addresses to send packets to attack the device(Optional).

anti-macduplicate: After anti-MAC-duplicate is enabled, the system records the first MAC address learned from the port and bound to the port and VLAN. It can prevent users from forging MAC address to perform malicious attack(Mandatory).

anti-dos: Anti-DoS attack alarm function of the device(Mandatory).

anti-rogue autodetect on: Used to enable or disable the function of automatically isolating the rogue optical network terminal (ONT) detected by the system. When this function is enabled, the rogue ONT detected by the system will be automatically isolated. An isolated rogue ONT can only receive information and cannot send information(Optional).

aes128: An encryption algorithm(Optional).

ip-firewall: The firewall that filters the source address(Mandatory).

For more information, click the following link:

https://support.huawei.com/enterprise/en/doc/EDOC1100168771/293be000/security-hardening

If you do not have the permission to open the link, please click How do we upgrade our account

Thanks!



View more
  • x
  • convention:

Vlada85
Vlada85 MVE Author Created Feb 25, 2021 19:11:09

Hi,
I know these explanations.
Mandatory GPON security are: anti-macduplicate, anti-dos and ip-firewall.
All other GPON security are optional?
View more
  • x
  • convention:

liqiang185
liqiang185 Created Feb 26, 2021 01:34:01 (0) (0)
Yes, but for the sake of the normal operation of the equipment and network, I suggest that you do as much as you can for other optional measures without affecting users' access to the Internet.  
Vlada85
Vlada85 Reply liqiang185  Created Feb 26, 2021 20:28:07 (0) (0)
Ok. I understand.  
Vlada85
Vlada85 Reply Vlada85  Created Feb 26, 2021 20:28:18 (0) (0)
Thank you  

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.