In this section:

Overview


SBC SWe N:1 and SWe cloud-based systems communicate with the external PSX over the management interface and packet interface. The SBC can choose an alternate IP address attached to the packet interface to communicate with the external PSX over the management interface and/or packet interface.

The communication between the SBC and the external PSX follows a sequence, as described below:

  1. The SBC requests registration and receives a response from PSX.

  2. The SBC periodically sends a request to know the status of the external PSX.

  3. The SBC requests policy information and receives a response.

  4. The SBC requests de-registration and receives a response.

The global configuration of SBC SWe N:1 and SWe cloud-based systems include an optional metaVariable field (ipVar) to fetch an IP address from the PSX for use in connecting with the PSX. When the ipVar field is blank, the SBC picks a random IP address from the configured interface to connect with the PSX.

 Additionally, the interfaceIpAddress field is added to the policyServer 'show' command to identify the IP address the SBC uses to communicate with the PSX for the specified policy server.



Preliminary Steps

Log into the CLI and perform the following steps to view the current default ACL statistics and metaVariable data before configuring the SBC to use alternate IP addresses.

Note
Port number 3055 is used by default for D+ queries. In the following example, the source IP address is fd00:10:6b50:41c0::d/128 (3055) and the destination IP address are displayed as *, since the destination IP is not configured.
StepAction
1

Enter the following command to view the default ACL statistics (see Example 1 for example results):

show table addressContext default ipAccessControlList defaultAclStatistics

The Diameter Server (DS) protocol is used for communication between the SBC and the external PSX. The default Access Control List (ACL) for the DS process is created over Management (MGT).

2

Enter the following command to view the IP addresses associated with the corresponding metaVariables (see Example 2 for example results). 

show table system metaVariable


Example 1:

Click to view example...

Example 2:

Click to view example...

Procedure

StepAction
1

Configure use of an alternate IP address using a metaVariable

Enter the following command to assign the alternate IP address of a metaVariable to the ipVar configuration in globalConfig. This allows communication to the external PSX using the IP address that is provided by the metaVariable (ipVar).

set system policyServer globalConfig type ip addressContext default ipInterfaceGroup S_DsbcSig_IG3 ipVar PKT0_V03_ALT_IP_02.IP
[ok]
Commit complete
2

Configure the SBC for an external PSX

Enter the following commands to enable the external PSX.

set system policyServer localServer PSX_LOCAL_SERVER mode outOfService 
set system policyServer localServer PSX_LOCAL_SERVER state disabled 
set system policyServer remoteServer parrotpsx ipAddress fd00:10:6b50:41c0::d 
set system policyServer remoteServer parrotpsx ipAddress 10.54.28.13 
set system policyServer remoteServer parrotpsx action force state enabled mode active
[ok] 
Commit complete
3

Display the configured ipVar value

Enter the following command to view the default ACL statistics. The default ACL DS process entry contains the destination IP address with the IP address provided by the metaVariable configured in the ipVar field.

show table addressContext default ipAccessControlList defaultAclStatistics


Click to view example...

4

Display the external PSX global configuration

Enter the following command to view the external PSX global configuration:

show system policyServer globalConfig


Click to view example...

5

Display the PSX status

Once the external PSX is enabled, use the following command to view the PSX status:

show table system policyServer policyServerStatus


Click to view example...

6

Display the interface IP address over which the SBC communicates with the PSX

Enter the following command to view the new interfaceIpAddress entry and the associated IP address (configured in the ipVar field) provided by the metaVariable. In this example, interfaceIpAddress is associated with the IP address (fd00:10:6b50:4d71::75).


show status system policyServer policyServerStatus


Click to view example...

7

Verify successful communication between the SBC and PSX

Once the IP address is configured for SBC and PSX communication, perform the following verification steps.

  1. Log into the SBC as a root user.
  2. Execute the following TShark command:
    tshark -i pkt0.310 -f "port 3055"

    Click to view example...

  3. Execute the following command to verify the operational state of the remote server:
    show status system policyServer policyServerStatus

    Click to view example...

    The operState mode should always be displayed as Active/Standby/Alternate and not as Down when the policy server's state is enabled and mode is inservice.