In this section:
The SBC Core permits modification of the majority of provisioning attributes which influence the operational behavior of the SBC without impacting service in a production environment. A subset of provisioning attributes listed below cannot be changed without affecting service. Ribbon recommends modifying these attributes only during a maintenance window.
The following table details SBC Core configuration attributes which cannot be changed without first disabling operational state or setting a service to Out of Service (OOS) mode.
Table 1: Address Context Service-Impacting Configuration Attributes
Configuration Object | Attributes / Values | Configuration Restrictions |
---|---|---|
addressContext > dnsGourp > server | All | Cannot change any attribute unless operational state is disabled |
addressContext > intercept > callDataChannel |
| Cannot change the listed attribute unless secMode is placed OOS |
addressContext > ipInterfaceGroup > ipInterface |
|
|
addressContext > linkDetectionGroup | All | Cannot change any attribute unless operational state is disabled |
addressContext > linkDetectionGroup > linkMonitor | All | Cannot change any attribute unless operational state is disabled |
addressContext > diamNode |
| Cannot change the listed attributes unless operational state is disabled |
addressContext > diamNode > peer |
| Cannot change the listed attributes unless operational state is disabled |
addressContext > diamNode > realmRoute |
| Cannot change the listed attributes unless operational state is disabled |
addressContext > zone > gwSigPort |
|
|
addressContext > zone > h323 > sigPort |
| Cannot change the listed attributes unless operational state is disabled |
addressContext > zone > ipPeer |
|
|
addressContext > zone > ipPeer > pathCheck | profile <name> | Cannot modify the listed attribute unless pathCheck state is disabled |
addressContext > zone > ipPeer > surrogateRegistration | All | Cannot change any attribute unless surrogateRegistration state is disabled |
addressContext > zone > mtrmConnPort | All | Cannot change any parameter unless port is disabled. |
addressContext > zone > sipSigPort |
| Cannot change values of the listed attributes unless operational state is disabled |
profiles > security > ipSecProtectionProfile > encryption | All | Cannot change any attribute unless FIPS state is disabled |
profiles > security > tlsProfile > cipherSuite | All | Cannot change any attribute unless FIPS state is disabled |
profiles > services > transparencyProfile | All | Cannot change any attribute unless operational state is disabled |
profiles > services > surrogateRegistrationProfile | All | Cannot change any value unless operational state is disabled |
profiles > signaling > sipAdaptorProfile | All | Cannot change any attribute unless operational state is disabled |
system > logicalMgmtIpInterface | ipAddress | Cannot change the listed attribute unless operational state is disabled |
system > media > mediaPortRange | All | Cannot change any attribute unless all IP interfaces are OOS |
system > media > tcpPortRange | All | Cannot change any attribute unless all IP interfaces are OOS |
system > mgmtIpInterfaceGroup > mgmtIpInterface | All | Cannot change any attribute unless operational state is disabled |
FIPS-140-2 is not supported in SBC 10.1.3 and later releases, and it is automatically converted to FIPS-140-3 as part of the upgrade.
To verify the current status of FIPS certification, contact the Global Support Assistance Center:
Table 2: Global Service-Impacting Configuration Attributes
Configuration Object | Attributes / Values | Configuration Restrictions |
---|---|---|
global > monitorEndpoint > mct |
| Cannot modify the listed attributes unless operational state is disabled |
global > monitorTarget |
| Cannot modify the listed attributes unless operational state is disabled |
Table 3: OAM Service-Impacting Configuration Attributes
Configuration Object | Attributes / Values | Configuration Restrictions |
---|---|---|
oam > alarms > ipPolicingAlarmAdmin |
|
|
Table 4: Profiles Service-Impacting Configuration Attributes
Configuration Object | Attributes / Values | Configuration Restrictions |
---|---|---|
profiles > security > ipSecProtectionProfile > encryption | All | Cannot change any attribute unless FIPS state is disabled |
profiles > security > tlsProfile > cipherSuite | All | Cannot change any attribute unless FIPS state is disabled |
profiles > services > transparencyProfile | All | Cannot change any attribute unless operational state is disabled |
profiles > services > surrogateRegistrationProfile | All | Cannot change any value unless operational state is disabled |
profiles > signaling > sipAdaptorProfile | All | Cannot change any attribute unless operational state is disabled |
profiles > system > overloadProfile | All | Cannot change any attribute unless operational state is disabled NOTE this restriction is not service-impacting |
Table 5: System Service-Impacting Configuration Attributes
Configuration Object | Attributes / Values | Configuration Restrictions |
---|---|---|
system > logicalMgmtIpInterface | ipAddress | Cannot change the listed attribute unless operational state is disabled |
system > media > mediaPortRange | All | Cannot change any attribute unless all IP interfaces are OOS |
system > media > tcpPortRange | All | Cannot change any attribute unless all IP interfaces are OOS |
system > mgmtIpInterfaceGroup > mgmtIpInterface | All | Cannot change any attribute unless operational state is disabled |
Removing a license bundle is potentially service-affecting. If the removed license bundle contains unexpired licenses for features currently in use, the removal of the license bundle will cause those features to no longer work.