In this section:
As user 'Calea', use the following commands to configure LI:
% set addressContext default intercept nodeNumber <integer>
As user 'Calea', use the following command to establish the LI call data channel configuration:
% set addressContext default intercept callDataChannel <callDataChannel_name> interceptStandard < etsi | packetcable | packetcablePlusEtsi | threeGpp> ipInterfaceGroupName <ipInterfaceGroup_Name> kaTimer <kaTimer_value> priIpAddress <IP_Address> priMode <active | outofservice | standby> priPort <priPort_number> priState <disabled | enabled> retries <value> secIpAddress <IP_Address> secMode <active | outofservice | standby> secState <disabled | enabled> vendorId <none | ss8 | utimaco | verint>
Example:
% set addressContext default intercept callDataChannel CDC_M ipInterfaceGroupName LIG1 interceptStandard packetcable kaTimer 5 priIpAddress 10.54.1.6 priMode active priPort 4560 priState enabled retries 3 secIpAddress 10.54.6.2 secMode standby secState enabled vendorId none [ok]
As user ''Admin'', use the following commands to configure IPsec:
localIdentity ipAddress – The SBC Interface Group IP associated with the LI CDC.
remoteIdentity ipAddress – The Mediation Server IP configured in the LI CDC.
The Recommended setting for LI IPsec mode is 'transport'.
For more information on IPsec configuration, refer to the section IP Security - CLI.
### create and configure IKE and IPsec protection profiles set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF saLifetimeTime 28800 set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms integrity hmacSha1,hmacMd5 set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms encryption aesCbc128,_3DesCbc set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF saLifetimeTime 28800 set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms encryption aesCbc128,_3DesCbc set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms integrity hmacSha1,hmacMd5 set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF dpdInterval noDpd ### create IKE peer set addressContext default ipsec peer PRGGSX2 ipAddress 10.54.78.20 preSharedKey 00000000000000000000000000000000 localIdentity type ipV4Addr ipAddress 10.220.41.161 set addressContext default ipsec peer PRGGSX2 remoteIdentity type ipV4Addr ipAddress 10.54.78.20 set addressContext default ipsec peer PRGGSX2 protocol ikev1 protectionProfile PRGGSX2_IKE_PROT_PROF ### create an SPD rule for this IKE peer set addressContext default ipsec spd PRGGSX2_SPD state enabled precedence 1001 set addressContext default ipsec spd PRGGSX2_SPD localIpAddr 10.220.41.161 localIpPrefixLen 32 remoteIpAddr 10.54.78.20 remoteIpPrefixLen 32 set addressContext default ipsec spd PRGGSX2_SPD action protect set addressContext default ipsec spd PRGGSX2_SPD protocol 0 set addressContext default ipsec spd PRGGSX2_SPD protectionProfile PRGGSX2_IPSEC_PROT_PROF set addressContext default ipsec spd PRGGSX2_SPD mode transport set addressContext default ipsec spd PRGGSX2_SPD peer PRGGSX2 ### enable IPsec on the IP interface group set addressContext default ipInterfaceGroup LIG1 enabled
As user 'Calea', use the following command in System-level mode to retrieve the LI statistics:
> show status addressContext default intercept interceptCallDataChannelStatistics interceptCallDataChannelStatistics default { primaryChannelStatus inService; secondaryChannelStatus outOfService; StartSuccess 0; StartFailures 0; StopSuccess 0; StopFailures 0; CallAnswerSuccess 0; CallAnswerFailures 0; CallDisconnectSuccess 0; CallDisconnectFailures 0; ServiceInstanceSuccess 0; ServiceInstanceFailures 0; IndicationSuccess 0; IndicationFailures 0; KeepAliveSuccess 1; KeepAliveFailures 0; RestartSuccess 1; RestartFailures 0; RadiusAckReceived 2; StartResponsesReceived 0; } [ok]