In this section:

Related articles:


The SBC Core permits modification of the majority of provisioning attributes which influence the operational behavior of the SBC without impacting service in a production environment. A subset of provisioning attributes listed below cannot be changed without affecting service. Ribbon recommends modifying these attributes only during a maintenance window.

Configuration Objects

The following table details SBC Core configuration attributes which cannot be changed without first disabling operational state or setting a service to Out of Service (OOS) mode.

Address Context

Table 1: Address Context Service-Impacting Configuration Attributes

Configuration Object

Attributes / Values

Configuration Restrictions

addressContext > dnsGourp > server 

All

Cannot change any attribute unless operational state is disabled

addressContext > intercept > callDataChannel

  • priState
  • secState

Cannot change the listed attribute unless secMode is placed OOS

addressContext > ipInterfaceGroup > ipInterface

  • ipAddress or prefix (IPv4 and IPv6)
  • altIpAddress or altPrefix (IPv4 and IPv6)
  • ceName
  • portName
  • bandwidth
  • bwContingency
  • vlanTag
  • altMediaIpAddresses
  • Cannot change the listed attributes (except for altMediaIpAddresses) unless operational state is disabled
  • Cannot delete altMediaIpAddresses unless operational state is disabled

addressContext > linkDetectionGroup 

All

Cannot change any attribute unless operational state is disabled

addressContext > linkDetectionGroup > linkMonitor

All

Cannot change any attribute unless operational state is disabled

addressContext > diamNode

  • originRealm
  • ipV4Address
  • primaryOriginHost
  • secondaryOriginHost
  • transactionTimeout

Cannot change the listed attributes unless operational state is disabled

addressContext > diamNode > peer

  • ipAddress
  • tcpPort
  • fqdn
  • tcpPort

Cannot change the listed attributes unless operational state is disabled

addressContext > diamNode > realmRoute

  • realm
  • priority
  • peer

Cannot change the listed attributes unless operational state is disabled

addressContext > zone > gwSigPort

  • All attributes
  • gWSigPort
  • Cannot change any attribute (except mode) unless operational state is disabled
  • Cannot delete GW Sig Port unless operational state is disabled and mode is OOS

addressContext > zone > h323 > sigPort

  • h225IpAddress
  • h245IpAddress
  • ipInterfaceGroupName
  • portNumber

Cannot change the listed attributes unless operational state is disabled

addressContext > zone > ipPeer

  • ipAddress
  • ipPort
  • Cannot update the listed attributes unless operational state is disabled
  • Cannot modify the listed attributes unless surrogateRegistration and pathCheck states are enabled

addressContext > zone > ipPeer > pathCheck

profile <name>

Cannot modify the listed attribute unless pathCheck state is disabled

addressContext > zone > ipPeer > surrogateRegistration

All

Cannot change any attribute unless surrogateRegistration state is disabled

addressContext > zone > mtrmConnPort

All

Cannot change any parameter unless port is disabled.
(Disabling port does not affect current call, but will affect new call admission which reverts to local trunk group CAC logic)

addressContext > zone > sipSigPort

  • ipAddressV4
  • ipAddressV6
  • ipInterfaceGroupName
  • maskPortforRcb
  • recorder
  • portNumber
  • sctpProfileName
  • siprec
  • tcpConnectTimeout
  • tcpKeepaliveInterval
  • tcpKeepaliveProbes
  • tlsProfileName
  • transportProtocolsAllowed

Cannot change values of the listed attributes unless operational state is disabled

profiles > security > ipSecProtectionProfile > encryption

All

Cannot change any attribute unless FIPS state is disabled

profiles > security > tlsProfile > cipherSuite

All

Cannot change any attribute unless FIPS state is disabled

profiles > services > transparencyProfile

All

Cannot change any attribute unless operational state is disabled

profiles > services > surrogateRegistrationProfile

All

Cannot change any value unless operational state is disabled

profiles > signaling > sipAdaptorProfile

All

Cannot change any attribute unless operational state is disabled

system > logicalMgmtIpInterface

ipAddress

Cannot change the listed attribute unless operational state is disabled

system > media > mediaPortRange

All

Cannot change any attribute unless all IP interfaces are OOS

system > media > tcpPortRange

All

Cannot change any attribute unless all IP interfaces are OOS

system > mgmtIpInterfaceGroup > mgmtIpInterface

All

Cannot change any attribute unless operational state is disabled


FIPS Compliancy

The SBC 7.2.x release supports FIPS-140-2 and the 10.1.3 release supports FIPS-140-3. FIPS-140-2 is not supported in 10.1.3 and later releases and gets automatically converted to FIPS-140-3 as part of the upgrade.

To verify the current status of FIPS certification, contact the Global Support Assistance Center:

Global

Table 2: Global Service-Impacting Configuration Attributes

Configuration Object

Attributes / Values

Configuration Restrictions

global > monitorEndpoint > mct

  • ipAddress
  • trunkGroup
  • portNumber
Cannot modify the listed attributes unless operational state is disabled 
global > monitorTarget 
  • monitorEndpoint
  • duration
  • gcid
  • monitorLeg

Cannot modify the listed attributes unless operational state is disabled


OAM

Table 3: OAM Service-Impacting Configuration Attributes

Configuration Object

Attributes / Values

Configuration Restrictions

oam > alarms > ipPolicingAlarmAdmin

  • majorAlarmProfileName
  • minorAlarmProfileName
  • Cannot modify attribute unless majorAlarmMode is set to OOS
  • Cannot modify attribute unless minorAlarmMode is set to OOS


Profiles

Table 4: Profiles Service-Impacting Configuration Attributes

Configuration Object

Attributes / Values

Configuration Restrictions

profiles > security > ipSecProtectionProfile > encryption

All

Cannot change any attribute unless FIPS state is disabled

profiles > security > tlsProfile > cipherSuite

All

Cannot change any attribute unless FIPS state is disabled

profiles > services > transparencyProfile

All

Cannot change any attribute unless operational state is disabled

profiles > services > surrogateRegistrationProfile

All

Cannot change any value unless operational state is disabled

profiles > signaling > sipAdaptorProfile

All

Cannot change any attribute unless operational state is disabled

profiles > system > overloadProfile

All

Cannot change any attribute unless operational state is disabled

NOTE this restriction is not service-impacting


System

Table 5: System Service-Impacting Configuration Attributes

Configuration Object

Attributes / Values

Configuration Restrictions

system > logicalMgmtIpInterface

ipAddress

Cannot change the listed attribute unless operational state is disabled

system > media > mediaPortRange

All

Cannot change any attribute unless all IP interfaces are OOS

system > media > tcpPortRange

All

Cannot change any attribute unless all IP interfaces are OOS

system > mgmtIpInterfaceGroup > mgmtIpInterface

All

Cannot change any attribute unless operational state is disabled

Licenses

The removal of a license bundle is potentially service affecting. If the removed license bundle contains unexpired licenses for features currently in use, the removal of the license bundle will cause those features to no longer work.

Note
Licenses bundles may only be installed or removed using EMA or the EMS.