In this section:

The provisioning example in this section applies to both Gateway Screening and MSU Tracing. However, if you want to provision the system for only MSU Tracing, make sure to set Screening Test Mode to ENABLED in the Web UI (see Screening Table Features). Any other differences between the two application are clearly indicated in the section.

In mated pair configurations, both STPs must be configured for GWST separately.

Before you start gateway screening or MSU tracing provisioning, make sure that the system-wide attributes are defined as required for your network configuration. For more information, see Configuring GWST Configuration.

The following figure shows a typical network for the example in this section.

Typical Network to Illustrate Gateway Screening or MSU Tracing Provisioning

The provisioning criteria is as follows:

  • Block all user traffic from 110.3.*

  • Block all user traffic with SI=5 from 110.2.2 to all DPCs

  • Allow user traffic with SI=3 from 110.2.2 to 200.1.1

The GWST tables must be provisioned as follows in the order indicated (see the following table).

GWST Tables to be Provisioned for the Example in this Section

Table EPR Criteria Next Screening Step
Allowed DPC 1 PC=200.1.1 STOP
Allowed SIO   1 SI=0&&2 STOP
 SI=3 Allowed DPC (EPR1)
 SI=5 FAIL
Allowed OPC  1 PC=110.3.* FAIL
 PC=110.2.2 Allowed SIO (EPR1)
Incoming Linkset 1 (NA) PC=110.1.1 Allowed OPC (EPR1)
PC=110.1.2 Allowed OPC (EPR1)

The following procedures must be completed in the order indicated to meet the provisioning criteria for the network illustrated in Figure Typical Network to Illustrate Gateway Screening or MSU Tracing Provisioning.

To configure the GWST to ensure that all messages to 200.1.1 are allowed

Click to read more...

To configure the GWST to ensure that all SIOs are screened properly

Click to read more...

To link the Allowed SIO table with the Allowed DPC table (All traffic with SI=3 to DPC 200.1.1 allowed)

Click to read more...

To trace MSUs in Allowed SIO SI 3

Click to read more...

To fail all traffic with SI=5 to all destinations from 110.2.2

Click to read more...

To trace MSUs in Allowed SIO SI 5

Click to read more...

To link the Allowed OPC with Allowed SIO table

Click to read more...

To block all traffic from OPC 110.3.*

Click to read more...

To trace MSUs in Allowed OPC 110.5*

Click to read more...

To link the Incoming Linkset with the Allowed OPC table

Click to read more...

  • No labels