Loader

EMS Features Packages

For example, users with Admin privileges can view and use configuration menu options, such as the Profiles menu; while other users with Read-only access can only view menu options, but cannot create or modify network elements using the Profiles menu selection. Refer to "User Manager" for details about user roles and permission settings.

Considering the different user permissions and roles, feature packages, examples are depicted for: (a) Base (b) Security, (c) Availability and (d) Operations license key as they might appear in the EMS when the license key file is uploaded and activated. 

Base

Base Feature Package - is the default package that provides a limited set of features. Additional features, only available through the purchase of one or more software license keys, are grayed out in menu options and fields. 

Security 

Security Feature Package - Advanced Security contains the features needed to restrict access to network resources. The example displays options in the Feature package that are available for Security.

The following license key for Security makes up this package:

  • 802.1x Port Authentication allows users to restrict access to switch ports until the user has authenticated to RADIUS. The system administrator can prevent unauthorized devices or users from accessing a port on the system. Only authenticated users are allowed access to the port.
  • MAC Authentication Bypass (MAB) allows devices to be authenticated by RADIUS by using their MAC address. The OLT acts as a proxy and authenticates to RADIUS using the device’s MAC.
  • ACL - Access Control Lists allows the ability to drop specific traffic types or restrict access to a particular MAC, IP or Subnet. ACL lists assist in protecting the network by filtering unwanted traffic and also allow features such as Sticky MAC and Static MAC.
  • User-installed Certificates enable encryption on OLT and ONT Voice ports using an installed certificate for all communications. The system is configured by default to trust Tellabs stock certificates. This feature allows the installation of administrator-defined certificates. The administrator can build a network where only devices that have a certificate from a trusted certificate authority talk to the system.
  • RADIUS Craft Support allows an administrator to configure the OLTs to use a RADIUS server to authenticate users attempting to log into the OLT remotely or at the serial console port. Users can logon using their network login and be authenticated to gain access to the system.
  • ICMP Host rate limiting allows the system to rate limit the number of ICMP Destination Unreachable messages sent by the system. It also allows the user to configure whether the system responds to ping requests (ICMP Echo Request/Reply messages). This makes it more difficult for attackers to locate the system and determine that there is an active device at a given IP address.
  • Dynamic ARP Inspection thwarts unauthorized attacks from occurring on subscriber ports, for the purpose of learning the MAC to IP address binding originating from sent DHCP acknowledgment messages, thereby avoiding DHCP snooping threats.

Redundancy

Redundancy - the Redundancy feature provides greater reliability using PON Protection. is the PON Protection icon, the only Redundancy feature.


 

The license key for Redundancy consists of:

  • Type B PON Protection allows the use of a 2:1 splitter to allow the attachment of two uplink PON ports. This lets the standby or secondary PON port to take over and drives the PON if the primary PON fails.

Operations

Operations Feature Package - Advanced Operations simplifies day-to-day operations, by streamlining network applications. In the example below, the menu options reflect the functions available to the user from the menu options.


 

The license key for Operations makes up this package:

  • ISP 1 to 1
  • SNMP Agent at the OLT level allows third-party SNMP tools to get access to status, statistics and alarms. This method is used to consolidate all the surveillance of the network into a few workstations. SNMP allows many different systems to be viewed in a generic way.
  • Multiple Spanning Tree (MSTP) is an extension of the RSTP and allows for multiple spanning tree instances to be active on a device.
  • Network Access Control (NAC) enables many methods to control access to network resources. It supports default VLANs, and fallback to a Guest VLAN. It also supports integration with RADIUS and 802.1x to allow RADIUS to define the configured VLAN or the entire policy for a given service. It also supports the configuration of a VLAN to quarantine a user when the user is rejected by RADIUS due to an authentication failure.
  • Syslog Support allows the logging of many types of status information to a standard syslog server. All configuration changes, alarms, security violations and abnormal conditions can be logged to one or more syslog servers.
  • PON TCA allows for thresholds to be set for configured bandwidth and utilization of the PON interface. This allows for an early warning system to define PONs that might be reaching their limits and should be split.
  • Link Layer Discover Protocol (LLDP) allows the users to obtain inventory from any attached device that supports LLDP. This provides great visibility into what devices are attached to your network. The LLDP protocol also allows for finely grained negotiation of PoE power levels with LLDP aware devices.
  • Web Client allows the user to perform daily operations in the EMS GUI with an easy-to use Web interface.
  • Web Troubleshooter examines and monitors the system for network elements for problems and attempts to resolve the source.
  • ONT Auto-configuration allows the system to be set up for plug-and-play ONT installation.
  • Commissioning Wizard is run at the time of EMS installation and configures all the default profiles to match local network policy. The Commissioning Wizard is used to prepare the system to run the Add OLT Wizard.
  • Add OLT Wizard adds a new OLT to the EMS using the OLT’s IP address. It allows the user to define rules for the assignment of VLANs to port and supports incrementing VLANs on a PON blade or port basis.

Previous   |    

FEEDBACK: Are you happy with this material?