Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Panel

...

borderColorgreen
bgColortransparent
borderWidth2

...

Noprint

Back to Table of Contents

Back to Configuring Various Features on SBC

Back to Configuring SBC For Lawful Interception

In this section:

Table of Contents
maxLevel4

...

width40%

Overview

Div
classexcerptdiv
Excerpt

Spacevars
0series4
acting as P-CSCF or I-BCF is configurable to intercept IMS sessions using Lawful Interception (LI)  techniques (legally sanctioned official access to private communications). This feature can also be used in non-IMS deployments to intercept audio, clear mode and fax streams.

At a high level, SBC Lawful Intercept functionality includes:

  • Support of Encapsulation mode (multimedia) for all signaling messages and media streams; Encapsulation mode signifies intercepting the received or sent signaling or media stream, by appending an header with extra information, towards the Mediation Server.
  • Support for SIP URI and DN based interception
  • Support for intercepting RTP media types such as audio, image (fax), clearmode
  • Support for intercepting any SIP signaling messages
  • Support for sending intercepted signaling messages over TCP, using an optional IPSec tunnel

Note

 Perform these steps if not already configured in EMS. The LI license is provisioned before interception, using EMS. For more details to provision LI license, refer to EMS User Guide.

Anchor
Configure the CDC
Configure the CDC
Configuring the Call Data Channel

To configure Call Data Channel (CDC)

...

:

...

...

...

...

Anchor
Configuring the Node Number
Configuring the Node Number
Configuring the Node Number

As user ''Calea'', use the following commands to configure LI:

Code Block
languagenone

...

set addressContext default intercept 

...

nodeNumber 7788

Include Page
CDC_Configured_through_EMS
CDC_Configured_through_EMS

Anchor
Configuring CDC for Intercept Flavor as IMS LI
Configuring CDC for Intercept Flavor as IMS LI

...

Creating CDC for Intercept Flavor as IMS LI

For other options of configuring the intercept flavor as IMS LI, refer to the section Configuring SBC For Lawful Interception.

Code Block
languagenone

...

set addressContext default intercept callDataChannel CDC interceptStandard etsi vendorId verint mediaIpInterfaceGroupName LIG1 ipInterfaceGroupName LIG1
commit
Info
titleNote

Mediation server’s ipInterfaceGroup must be different from other signaling ipInterface groups. This ensures that LI doesn't use signaling ipAddress to send intercepted traffic (media/signaling) towards Mediation Server.

Anchor
Configuring CDC for Media Interception Over TCP
Configuring CDC for Media Interception Over TCP
Configuring CDC for Media Interception Over TCP

Code Block
languagenone

...

set addressContext default intercept callDataChannel CDC mediationServer MS1 media tcp ipAddress 10.54.78.20 portNumber 65120 
commit

...

set addressContext default intercept callDataChannel CDC mediationServer MS1 media tcp state enabled mode inService
commit 
Note

Mediation server’s ipInterfaceGroup must be different from other signaling ipInterface groups. This ensures that LI doesn't use signaling ipAddress to send intercepted traffic (media/signaling) towards Mediation Server.

Anchor
Configuring CDC for Media Interception Over UDP
Configuring CDC for Media Interception Over UDP
Configuring CDC for Media Interception Over UDP

Code Block
languagenone

...

set addressContext default intercept callDataChannel CDC mediationServer MS1 media udp ipAddress 10.54.78.20 portNumber 65200
commit

...

set addressContext default intercept callDataChannel CDC mediationServer MS1 media udp state enabled mode inService
commit 
Note

The protocolType "udp" is not supported for Signaling interception in this release.

...

Anchor
Configuring CDC for Signaling Interception
Configuring CDC for Signaling Interception
Configuring CDC for Signaling Interception

Code Block
languagenone

...

set addressContext default intercept callDataChannel CDC mediationServer MS1 signaling ipAddress 10.54.78.

...

20 portNumber 65300 protocolType tcp
commit

...

set addressContext default intercept callDataChannel CDC mediationServer MS1 signaling state enabled mode inService
commit
Info
titleNote

The protocolType "udp" is not supported for Signaling interception.

Anchor
Configuring CDC for RTCP Interception
Configuring CDC for RTCP Interception
Configuring CDC for RTCP Interception

Code Block
languagenone

...

set addressContext default intercept callDataChannel CDC rtcpInterception enabled

...


commit
Info
titleNote

...

The rtcpInterception parameter is visible, when interceptStandard and vendorId is configured as IMS LI.

Anchor
Configuring CDC for "Li Pol Dip For Regd Ood Msg"
Configuring CDC for "Li Pol Dip For Regd Ood Msg"
Configuring CDC for "Li Pol Dip For Regd Ood Msg"

The parameter liPolDipForRegdOodMsg when enabled is used to indicate SBC to send policy request to PSX for registered Out-Of-Dialog requests(messages) to be intercepted. When this parameter is disabled, policy request is not sent to PSX for registered Out-Of-Dialog requests (messages).

Enable the support for Policy dip, for registered users out-of-dialog messages, to decide on interception, by executing the command

Code Block
languagenone

...

set addressContext default intercept callDataChannel CDC liPolDipForRegdOodMsg enabled

...


commit
Info
titleNote

...

The liPolDipForRegdOodMsg  parameter is visible, when interceptStandard and vendorId is configured as IMS LI.

Noprint

Back to Top

Viewing IMS LI Configuration

Enter the show commands to view the configurations.

View the Intercept Details

View the intercept details, by executing the command:

...

languagenone

Anchor
Configuring SBC Core IPsec
Configuring SBC Core IPsec
Configuring the SBC Core IPsec

As user ''Admin'', use the following commands to configure IPsec:

Info
titleNote
  •  This optional configuration is needed if secure connection is required between the
    Spacevars
    0product
    and the Mediation Server.  
  • The SBC does not support IPsec for media interception over UDP.
  • The SPD entry is required to create the following entries:
    • localIdentity ipAddress – The SBC Interface Group IP associated with the LI CDC.

    • remoteIdentity ipAddress – The Mediation Server IP configured in the LI CDC.

  • The Recommended setting for LI IPsec mode is 'transport'.

Info
titleInfo

For more information on IPsec configuration, refer to the section IP Security - CLI.

Code Block
### create and configure IKE and IPsec protection profiles
   
set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF saLifetimeTime 28800
set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms integrity hmacSha1,hmacMd5
set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms encryption aesCbc128,_3DesCbc
  
set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF saLifetimeTime 28800
set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms encryption aesCbc128,_3DesCbc
set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms integrity hmacSha1,hmacMd5
set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF dpdInterval noDpd
  
### create IKE peer
  
set addressContext default ipsec peer PRGGSX2 ipAddress 10.54.78.20 preSharedKey 00000000000000000000000000000000 localIdentity type ipV4Addr ipAddress 10.220.41.161
set addressContext default ipsec peer PRGGSX2 remoteIdentity type ipV4Addr ipAddress 10.54.78.20
set addressContext default ipsec peer PRGGSX2 protocol ikev1 protectionProfile PRGGSX2_IKE_PROT_PROF
  
### create an SPD rule for this IKE peer
  
set addressContext default ipsec spd PRGGSX2_SPD state enabled precedence 1001
set addressContext default ipsec spd PRGGSX2_SPD localIpAddr 10.220.41.161 localIpPrefixLen 32 remoteIpAddr 10.54.78.20 remoteIpPrefixLen 32
set addressContext default ipsec spd PRGGSX2_SPD action protect
set addressContext default ipsec spd PRGGSX2_SPD protocol 0
set addressContext default ipsec spd PRGGSX2_SPD protectionProfile PRGGSX2_IPSEC_PROT_PROF
set addressContext default ipsec spd PRGGSX2_SPD mode transport
set addressContext default ipsec spd PRGGSX2_SPD peer PRGGSX2
  
### enable IPsec on the IP interface group
  
set addressContext default ipInterfaceGroup LIG1 enabled
Info
titleNote

The SBC is enhanced to support IMS LI for PS-to-PS Handover scenarios. The enhancement has no impact on the IMS routing.

Viewing IMS LI Configuration

Enter the show commands to view the configurations.

Anchor
Viewing the Intercept Details
Viewing the Intercept Details
Viewing the Intercept Details

To view the intercept details, execute the following command:

Code Block
languagenone
show status addressContext default intercept callDataChannel
callDataChannel CDC {
    mediationServerMediaStatus MS1 {
        tcpChannelstatus inService;
        tcpPacketsSent   0;
        tcpPacketsLost   0;
        udpPacketsSent   0;
        udpPacketsLost   0;
    }
    mediationServerSignalingStatus MS1 {

...

        tcpChannelStatus 

...

inService;

...

        DSRSuccess       0;

...

        DSRFailures      0;

...

    

...

}
}
[ok]

...

Anchor
Viewing the CDC Configuration
Viewing the CDC Configuration
Viewing

...

the CDC Configuration

...

To view the CDC configuration,

...

execute the following command:

Code Block
languagenone

...

show addressContext default intercept
nodeNumber 7788;
callDataChannel CDC {
    interceptStandard     etsi;
    vendorId              verint;
    ipInterfaceGroupName  LIG1;
    liPolDipForRegdOodMsg enabled;
    rtcpInterception      enabled;
    mediaIpInterfaceGroupName LIG1;
    mediationServer MS1 {
        signaling {
            ipAddress    10.54.78.20;
            portNumber   65300;
            protocolType tcp;
            mode         inService;
            state        enabled;
        }
        media {
            tcp {
                ipAddress  10.54.78.20;
                portNumber 65120;
                mode       inService;
                state      enabled;
            }
            udp {
                ipAddress  10.54.78.20;
                portNumber 65200;
                mode       inService;
                state      enabled;
            }
        }
    }
}
[ok]

...



 

...

Pagebreak