Aperto PacketMax 120 User manual

10009436 Rev B
Aperto PacketMax
PacketMax 120/320
(November 2008)
Installation and Operation User Manual

©Copyright 2007-08 by Aperto Networks
All rights reserved.
Specifications subject to change.
Aperto, PacketMax, and WaveCenter are trademarks of Aperto Networks.
All other trademarks used herein are the property of their respective owners.
Aperto Networks
598 Gibraltar Drive
Milpitas, CA 95035 USA
Phone: 408.719.9977
Fax: 408.719.9970
www.apertonet.com

Aperto WaveCenter
Regulatory Information
CE Notice
Declaration of Conformity
Aperto Networks Inc. of 598 Gibraltar Drive, Milpitas CA 95037, USA, declare under our sole respon-
sibility that the following product models, PM120/320-3G and PM120/320-5G, to which this declara-
tion relates, are in conformity with the following standards and/or other normative documents.
• EN 301 753
• EN 301 489
• EN 60950
We hereby declare that all essential radio test suites have been carried out and that the above named
product is in conformity to all the essential requirements of Directive 1999/5/EC.
The conformity assessment procedure referred to in Article 10 and detailed in Annex [III] or [IV] of
Directive 1999/5/EC has been followed.

Aperto WaveCenter
UL Information
CAUTION: For the CATV system, the CATV installer should install in accordance with Article 820-
40 of the NEC which provides guidelines for proper grounding and, in particular, specifies
that the cable ground shall be connected to the grounding system of the building, as
close as possible to the point of cable entry as practical.
CAUTION: The external exposed (outdoor) run of the cables, from the exit of the building to the
antenna/radio assembly, should be less than 140ft, while the total cable run is as
described in this manual.
CAUTION: For Model PM 120/320, the Power Over Ethernet box is intended to be installed
indoor only and the Radio/Antenna is intended to be installed outdoors.

Aperto WaveCenter
Waste Electrical and Electronic Equipment (WEEE) Directive Compliance
Aperto Network products sold within the European Union (EU) are subject to the requirements of
the Waste Electrical and Electronic Equipment (WEEE) Directive; as implemented by national
legislation in each EU country. The objective of the Directive is to reduce the environmental
impacts of WEEE by promoting re-use and recycling, as an alternative to disposal.
From 13 August 2005, product placed on the EU market is required to be marked with the symbol
shown below. This symbol indicates that end-of-life electronic equipment generated within the
EU should not be mixed with other types of waste or placed in the general waste stream; but
should be segregated for the purpose of re-use or recycling.


–i
PacketMax 120/320 User Manual
Table Of Contents
Scope of This Manual . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . -i
Conventions Used in This Manual . . . . . . . . . . . . . . . . . . . . . . . . . . . . -i
Intended Audience for this Manual . . . . . . . . . . . . . . . . . . . . . . . . . . . -ii
General Cautions and Warnings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . -ii
List of References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . -iv
Chapter 1. Overview Of PacketMAX 120/320 Subscriber Station
PacketMAX 120/320 Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
PM 120/320 Hardware Features . . . . . . . . . . . . . . . . . . . . . . . 1-2
PM 120/320 Software Features . . . . . . . . . . . . . . . . . . . . . . . 1-2
Bridge Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
VLAN Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-2
Point-to-Point Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-3
Management, Configuration and Diagnostic Functions . . . . . . . . . . . . 1-3
Upgrades . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
SS Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
MIB . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
Event Reporting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-4
3 DES Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-5
Certificates and Management . . . . . . . . . . . . . . . . . . . . . . . . . 1-6
IP Filtering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-7
Automatic Frequency Scanning (AFS) . . . . . . . . . . . . . . . . . 1-8
PM 120/320 Package Content . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-9
Components of PM 120/320 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1-10
PacketMax 120/320 Outdoor Unit (ODU) . . . . . . . . . . . . . . . 1-10
PacketMax Indoor Unit - PoE (IDU) . . . . . . . . . . . . . . . . . . . 1-10
Chapter 2. Installation of PacketMAX 120/320 Subscriber Station
Installation Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-2
Cables and Connector Requirements . . . . . . . . . . . . . . . . . . . 2-2
Additional Items Required . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-3
Before Installation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-3
Installation Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-4
Installing the Ethernet Cable and Boot Cover. . . . . . . . . . . . . 2-4
Mounting PM 120/320: Pole Mounting . . . . . . . . . . . . . . . . . 2-6
Positioning the Outdoor Unit. . . . . . . . . . . . . . . . . . . . . . . . . 2-7
Grounding the Outdoor Unit (Radio/Antenna) . . . . . . . . . . . 2-8
Connecting the Outdoor Unit to the Power Over Ethernet . . 2-11
Configure the PM 120/320 Using the HTTP Configurator . . 2-12
Align the PM 120/320 ODU . . . . . . . . . . . . . . . . . . . . . . . . . 2-14
Rebooting the Subscriber Station and Connecting to the
PacketMAX Network . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2-15
Table Of
Contents

Table Of Content
–ii
PacketMax 120/320 User Manual
Chapter 3. Configuring PacketMAX 120/320 Using Configurator
PacketMAX 120/320 Configurator . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-2
Logging in to the Configurator . . . . . . . . . . . . . . . . . . . . . . . . 3-2
Understanding the Pages in the Configurator . . . . . . . . . . . . 3-3
Specifying Wireless Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-4
Automatic Frequency Scanning (AFS) . . . . . . . . . . . . . . . . . 3-6
Specifying Network Setup Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-7
Viewing Status Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-8
Information Page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-9
Wireless Information Page . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-10
System Information Page . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-12
Statistics Information Page . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-13
ARP Information Page . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-15
System Log . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-16
Configuring Administrative Settings . . . . . . . . . . . . . . . . . . . . . . . . . . 3-17
Returning to Factory Default Settings . . . . . . . . . . . . . . . . . . 3-18
Rebooting the PM 120/320 Unit . . . . . . . . . . . . . . . . . . . . . . 3-18
Changing the Device Name and Location . . . . . . . . . . . . . . . 3-19
Enabling or Disabling Web, SSH, and Telnet Access . . . . . . 3-19
Enabling or Disabling the Status LEDs . . . . . . . . . . . . . . . . . 3-20
Changing Log In Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-20
Throughput Test . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-20
Upgrading Firmware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3-22
Appendix A. Specifications
General Specifications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A-1
Models . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A-1
Interfaces . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A-1
Power requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A-1
RF and Antenna Specifications . . . . . . . . . . . . . . . . . . . . . . . A-2
PM 120 General Specifications . . . . . . . . . . . . . . . . . . . . . . . A-2
Receiver Threshold Specifications . . . . . . . . . . . . . . . . . . . . . A-3
Performance and capacities . . . . . . . . . . . . . . . . . . . . . . . . . . A-4
Mechanical Specifications . . . . . . . . . . . . . . . . . . . . . . . . . . . A-4
Environmental Specifications . . . . . . . . . . . . . . . . . . . . . . . . A-5
Mounting and Brackets . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A-5
Regulatory Standards . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A-5
Appendix B. Event Reporting
PacketMax 120/320 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . B-1
Appendix C. Cables, Spares and Accessories
PacketMax 120/320 CPEs, Cables and Spares . . . . . . . . . . . . . . . . . . . C-1
PacketMax 120/320 CPEs . . . . . . . . . . . . . . . . . . . . . . . . . . . C-2

–iii
PacketMax 120/320 User Manual
Table Of Contents
PacketMax 120 Cables . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . C-2
PacketMAX 120/320 Spares . . . . . . . . . . . . . . . . . . . . . . . . . C-3
Appendix D. Virtual Local Area Network
Bridge and VLAN Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D-2
Out of band Management with Management VLAN . . . . . . . . . . . . . . D-2
Inband Management with Management VLAN . . . . . . . . . . . . . . . . . . D-3
VLAN Classifiers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D-4
VLAN Application Example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D-5
Looping Prevention . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D-6
Behavior of SS VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D-6
Appendix E. Troubleshooting
Troubleshooting Issues and Tips . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F-1
Appendix F. LIMITED EQUIPMENT WARRANTY (“Agreement”)
WARRANTY COVERAGE . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G-1
REMEDIES . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G-2
LIMITED LIABILITY . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . G-3

Table Of Content
–iv
PacketMax 120/320 User Manual

Preface - i
PacketMax 120/320 User Manual
Preface
This manual is part of the documentation for the PacketMax broadband wireless sys-
tem for delivering high-speed subscriber services.
Scope of This Manual
This manual documents the installation and operation of the PacketMax 120/320
Series subscriber equipment.
This manual provides the following information:
•Chapter 1 Overview of Subscriber Station: Provides an overview of the
Aperto Subscriber Station, its components, and functions.
•Chapter 2 Installation of Subscriber Station: Provides step-by-step proce-
dure for installing the Aperto Subscriber Station.
•Chapter 3 Configuring PM120/320 Using Configurator: Walks you through
the steps of configuring PacketMAX 120/320 subscriber stations using the
HTTP Interface.
•Appendixes: Provide additional information on System Specifications, Events
and Alarms, Cables, Spares, and Accessories, VLAN, and Troubleshooting tips.
Conventions Used in This Manual
PacketMax manuals represent special kinds of text as follows:
• File names and URLs are represented in italics, with variables described inside
angle brackets. For example, if the URL http://<IP address>/BS.htm is referenced,
you will replace the variable <IP address> with the appropriate real IP address.
Preface

Preface
Preface - ii
PacketMax 120/320 User Manual
• Management interface text is represented in a bold font: for example, the
Generate Config File button.
• Labels on equipment are represented in a bold font: for example, the Control
connector.
WARNING: This format is used to indicate the possibility of personal injury or
damage to equipment.
CAUTION: This format is used to indicate the possibility of system or equipment
operation problems.
NOTE: Items of special importance will be marked by a pointing-hand icon, as this
paragraph is.
For conceptual discussions, PacketMax 120/320 is used interchangeably with SS or
Subscriber Stations in many places of this user manual. Similarly, PacketMax 5000
and PM 3000 is used interchangeably with BS or Base Station in may places of this
user manual.
Further, Subscriber Station and Subscriber Equipment have been used interchange-
ably.
Intended Audience for this Manual
This manual is intended primarily for subscriber equipment installers. It also presents
information of use to subscribers, including a discussion of tools used for configura-
tion.
Installation of radio equipment involves numerous factors requiring considerable
expertise. It is assumed that equipment installers are professionals with a full under-
standing of the principles, standard practices and procedures of cell site installation,
with all relevant safety requirements, and with applicable local building codes.
General Cautions and Warnings
Observe the following when installing or operating any PacketMax System compo-
nents.
Carefully follow all local building and electrical codes, especially the latest revision
of the National Electrical Code (NEC) and standard safety procedures for install-
ing and working with this type of equipment. Improper procedures or installation
can result in damage to the equipment or the building, and injury or death. If you

Preface
Preface - iii
PacketMax 120/320 User Manual
are not sure about whether the installation follows these codes, contact a licensed
building inspector or electrician in the area for assistance.
Always use quality components—including cables, connectors, mounts, etc.—
specifically rated for your particular environmental conditions and system perfor-
mance requirements.
Always use appropriate tools, and follow the instructions of the tool
manufacturers.
All outdoor installation, including equipment mounting and cabling, should be per-
formed by trained microwave radio technicians familiar with usual and customary
practices and procedures.
Take extreme care to avoid contacting any overhead power lines, lights, and
power circuits while you are installing the Outdoor Unit. Contact with any of these
objects could cause injury or death. Do not install the Outdoor Unit near power
lines.
Make sure that the outdoor radio/antenna is grounded in accordance with local,
state, federal, and National Electrical Code (NEC) requirements. Pay special
attention to NEC sections 810 and 820. See the instructions in Chapter 4 of this
manual.
For the PacketMax 120 Series Indoor Unit, use an outlet that contains surge pro-
tection and ground fault protection, or use a surge protection device. This will
protect the Indoor Unit and equipment connected to it from damage resulting from
AC current surges, lightning, etc. For complete protection, all connections to the
Indoor Unit (i.e., from radio/antenna and PC/hub) should be connected to a surge
protection device. To ensure the best signal, use surge protectors designed for
the specific application.
RF Exposure Guidelines
In order to comply with FCC and Industry Canada requirements for maximum RF
exposure levels to persons, the antenna must be mounted in such a way that dur-

Preface
Preface - iv
PacketMax 120/320 User Manual
ing operation, a minimum separation distance of 21 cm is maintained between the
antenna and all persons.
Prohibition against Unauthorized Modifications
The user is cautioned that changes or modifications not expressly approved by
Aperto Networks could void the user’s authority to operate the equipment.
PM120/320-5G units sold in the United States can only be used in the FCC spec-
ified band of 5.725 to 5.850 GHz.
PM120/320-3G units sold in the United States can only be used in the FCC spec-
ified band of 3.650 to 3.675GHz.
Because Aperto Networks cannot be responsible for improper installation or use of its
equipment, failure to follow these and other published cautions and warnings may
void your equipment warranty.
List of References
WaveCenter EMS Pro User Manual
PacketMax 5000 Installation and Operation User Manual
PacketMax 3000 Installation and Operation User Manual

1–1
PacketMax 120/320 User Manual
Overview Of PacketMAX 120/320
Subscriber Station
As part of Aperto Networks' PacketMaxTM Broadband Multiservice Wireless Access
System, the PacketMax 120/320 Series Subscriber Station delivers high-speed,
always-on Internet access to small and medium-sized businesses, small offices/home
offices (SOHO), and residences. The PacketMax System can be deployed in the stan-
dard frequency bands, licensed or unlicensed, for wireless broadband networking. For
the PacketMAX 120/320 System specifications, see General Specifications.
This Chapter covers the following topics:
PacketMAX 120/320 Features
PM 120/320 Package Content
Components of PM 120/320
VLAN Mode
Management, Configuration and Diagnostic Functions
1

1–2
PacketMax 120/320 User Manual
Chapter 1. Overview Of PacketMAX 120/320 Subscriber Station
1.1 PacketMAX 120/320 Features
The PacketMAX 120/320 is designed for quick installation. The following list summa-
rizes the key features of PM 120/320.
1.1.1 PM 120/320 Hardware Features
Power-over-Ethernet (PoE) capabilities allow data and power to be supplied to
the unit using a single Ethernet cable.
Includes an external or embedded antenna with multiple antenna gain options.
External signal strength LEDs allow the antenna to be aligned for optimal
received signal strength from the base station, without having to use a com-
puter to log in to the unit
1.1.2 PM 120/320 Software Features
Standards-Based:Compliant with IEEE 802.16-2004 for communication with
WiMAX base stations that support this standard.
Extensive Frequency Bands Coverage: Operates in licensed and unlicensed
bands including 3.3 GHz, 3.4GHz, 3.65GHz, 5.1GHz, 5.4GHz, 5.8GHz.
Industry’s leading Quality of Service:Supports configurable QoS on UL and DL,
including UGS support for latency-sensitive applications.
Popular Channel Bandwidths supported: Supports 3.5, 5 and 7 MHz.
Network Stack: Both bridge and VLAN modes supported. IP filtering for Layer
2, 3 and 4 supported.
Security:X.509/3DES encryption mode supported.
Management: HTTP Interface for configuration; Support for Secondary Man-
agement using WaveCenter EMS Pro.
1.2 Bridge Mode
The default setting of the PM 120/320 Subscriber Stations is Bridge mode.
1.3 VLAN Mode
The operation of the PM 120/320 in VLAN mode has been discussed in Virtual Local
Area Network section. Please refer to Virtual Local Area Network, for information on SS
in VLAN Mode and different user scenario examples.

1–3
PacketMax 120/320 User Manual
Chapter 1. Overview Of PacketMAX 120/320 Subscriber Station
1.4 Point-to-Point Mode
The PacketMAX 5000/3000 Base Stations in combination with PacketMAX 320 Sub-
scriber Stations provide high-speed, cost-effective links for point-to-point applications.
With unprecedented interference resilience and minimal spectrum usage, they are
ideal for such applications as high-speed backhaul of Wi-Fi hotspot networks, higher-
capacity alternatives to T1/E1 connections, and building-to-building connections in the
enterprise environments.
Features of Point-to-Point applications include:
Support for 3.3, 3.5, 3.65, and 5.8 GHz frequency bands
High interference immunity
Exceptional wireless range (up to approximately 35 to 50 miles/ 55 to 80 km,
depending on the frequency band)
Outdoor radio units with connectorized output for high-gain antennas to extend
the range of the wireless link.
Synchronization between units
Management via SNMP-based Element Management System.
Point-to-Point Mode allows you to increase the number of supported hosts up to 7500
(from 250 supported in PM 320). You can enable or disable the Point-to-Point Mode
from the SS Configuration screen in the WaveCenter EMS Pro.
Point-to-point mode is supported only for PM 320.
1.5 Management, Configuration and Diagnostic
Functions
The PacketMax 120/320 includes a number of features which provide management,
configuration, and diagnostic functions. They range from back-panel LEDs to HTTP
Interface and include:
LEDs — LED indicators on the back-panel of the ODU show status of the LAN,
wireless interfaces as well as power to the unit, and RSSI status.
HTTP Interface— This utility initializes newly-installed subscriber equipment
and displays the system parameters.
SNMP Agent — Each PacketMax 120/320 includes an SNMP agent which can
be accessed via a standard SNMP manager, either directly or through the Base
Station Unit’s proxy agent.

1–4
PacketMax 120/320 User Manual
Chapter 1. Overview Of PacketMAX 120/320 Subscriber Station
1.5.1 Upgrades
The bulk upgrade feature of EMS allows the users to upgrade the BS/SS in batches
efficiently (multiple CPEs together). You can also upgrade the Subscriber Station
using the HTTP Interface.
1.5.2 SS Configuration
SS configuration can be done in Secondary Management mode using the Wave-
Center EMS Pro. When you configure the CPE using HTTP Interface, ensure that
Secondary Management (Default) option is selected.
1.5.3 MIB
Each PacketMax 120/320 includes a SNMP agent supporting the following MIBs:
MIB II (RFC 1213)
Aperto private MIB
Wimax-IF-MIB (objects for 802.16 based SS and BS)
The complete MIBs are provided on the PacketMax CD-ROM.
SNMP can be used to read configuration, status, and performance data from Sub-
scriber Units. In addition, SNMP can be used to change some configuration parame-
ters (those which can be changed via the Configuration Manager in EMS), and to
upload the configuration changes to the TFTP server (if the TFTP server is configured
to accept uploads).
The SNMP agents support trap reporting. Trap-reporting parameters can be specified
via the Configuration Manager as well as via SNMP.
1.5.4 Event Reporting
PacketMax 120/320 Series Subscriber Units offer several means of reporting sub-
scriber equipment events:
SNMP traps — The Subscriber Station’s SNMP agent supports trap reporting.
Trap-reporting parameters can be specified via the EMS (WaveCenter Config-
uration Manager), or SNMP.
Syslog — The Subscriber Station supports logging of event messages to a des-
ignated server according to the Syslog protocol. If Syslog is employed, the Sys-
log server must be identified in the Subscriber Station configuration file created
using the WaveCenter Configuration Manager.
NOTE: Use of Syslog is strongly recommended as a means of providing a
record of system events for performance management and troubleshooting.

1–5
PacketMax 120/320 User Manual
Chapter 1. Overview Of PacketMAX 120/320 Subscriber Station
1.5.5 3 DES Encryption
Security is a required feature in the current network, to ensure that the Base Station
and Subscriber Station communicate with each other. An encryption scheme is used
to secure the BS and SS communication channel by encrypting the data between the
two.
The Encryption procedure is as follows:
1. At first, the SS initiates the authorization process and sends message to the
BS indicating that it is capable of encryption.
2. The BS authorizes the SS by verifying the device and Vendor Certificate of the
SS during the Privacy Key Management (PKM) Message Exchange.
3. An Authorization Key (AK) is used to decrypt the Traffic Encryption Keys
(TEKs) using PKM protocol. The AK is periodically refreshed and is encrypted
using 3DES.
4. In the BS, the TEKs are generated and send to SS using the 3DES encryption
format. The SS decrypts these TEKs using a Key Encryption Key (KEK) gen-
erated from the AK. If the BS encrypts the TEK using the RSA Public Key of
SS, then the SS decrypts it using its Private Key.
5. The TEKs are used for encrypting data on different Service Flows (SF) between
the BS and SS.
6. All the Service Flows for one SS will have the same key in both upstream and
downstream.
NOTE: To enable encryption on every service flow, please refer to the WaveCenter
EMS User Manual.
7. The traffic between the BS and SS can now be encrypted/decrypted using the
TEK keys.
8. If the CPE fails authentication, the CPE can re-try authentication.

1–6
PacketMax 120/320 User Manual
Chapter 1. Overview Of PacketMAX 120/320 Subscriber Station
Figure 1-1 3-DES Encryption
NOTE: TEK is encrypted using KEK derived from Authorization key and 3DES
Algorithm, while data is encrypted using TEK and DES Algorithm.
1.5.6 Certificates and Management
WiMax forum prescribes X.509 based digital-certificate for authorization process.
which is part of the negotiation process as described in the above section. The cer-
tificates are used to strengthen the security process.
The Aperto WiMax Root Certificate, is a Self-Signed certificate issued by the Aperto
Certifying Authority (CA). The CA is stored in the BS. The X.509 certificates are
injected into the base station devices at manufacturing time and can later be upgraded
from the EMS.
The Root Certificate is the same across all Base Stations and shall be available on
MSC, as the Certificate Verification happens on MSC. In the case, when primary and
redundant MSCs are installed, the Certificates need to be available on both the MSC
Authorization Key
Traffic Encryption Key
3-DES Encryption
SS uses PK to
decrypt
SS uses KEK
from AK
SS Initiates
Authorization BS validates
Certificates
Privacy Key Management — PKM
Private Key — PK
Key Encryption Key — KEK
Traffic Encryption Key — TEK
BS
SS
Traffic Encryption Key
3-DES Encryption
Authorization Key
This manual suits for next models
3
Table of contents