GB/T 38797-2020 in English
VALIDTest method for security of broadband customer network equipment based on public telecommunication network—Broadband customer gateway
- Issued on:2020-04-28
- Implemented on:2020-11-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$243.00
《GB/T 38797-2020基于公用电信网的宽带客户网络设备安全测试方法 宽带客户网关》由TC485(全国通信标准化技术委员会)归口,主管部门为工业和信息化部(通信)。
Introduction
Interpretation of the core content of the standard
| Test dimensions | Test items | Reference standards | Key indicators |
|---|---|---|---|
| User plane security | Firewall function | YD/T1440-2006 | Support MAC/IP/Port three-level filtering |
| VPN function | YD/T1440-2006 | Support tunnel encryption and access control | |
| Anti-DoS attack | 4.6.1 of this standard | No service interruption under high traffic impact | |
| WLAN security | 4.8 of this standard | Support WPA-PSK encryption |
Analysis of key technical requirements
1. User plane security
The standard requires that the Broadband Customer Gateway must implement the following:
- Password policy: The administrator password must contain two of the following: numbers + letters + special characters, with a length of ≥8 characters
- Firewall classification: Three levels of protection: high/medium/low, supporting deep packet inspection based on protocol type
- Anti-port scanning: Silently discard unopened ports, with response delay ≤500ms
2. Control plane security
Take identification and authentication test as an example: The device is required to support:
- Separation of permissions between administrator account and ordinary account
- Five consecutive incorrect password attempts will trigger a 15-minute lock
- Configurable session timeout (30 minutes by default)
Standard Implementation Recommendations
Enterprise Implementation Guide
| Implementation Phase | Suggested Measures | Reference Clauses |
|---|---|---|
| Procurement Acceptance | Require manufacturers to provide third-party test reports | Chapter 4-7 |
| Daily operation and maintenance | Perform anti-DoS stress testing | every quarter4.6.1 |
| Verification of remote diagnostic function compatibility | 7.3 |
Technology evolution analysis
Compared with YD/T1440-2006, this standard adds:
- WLAN security test: Add detection requirements for SSID hiding and MAC filtering
- Electrical safety test: Clarify that overvoltage protection must meet YD/T1082-2011
- Management plane test: Add encryption storage requirements for remote diagnostic logs

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 46882-2025 in English
Test methods for access network equipment—Interoperability of 10-Gigabit-capable passive optical network (XG-PON) and 10-Gigabit-capable symmetric passive optical networks (XGS-PON)
2025-12-31 -

GB/T 37083-2018 in English
Technical requirements for access network-Interoperability of ethernet passive optical network(EPON)system
2018-12-28