...
Panel |
---|
...
borderColor | green |
---|---|
bgColor | transparent |
borderWidth | 2 |
...
Noprint |
---|
In this section:
|
...
...
width | 40% |
---|
Anchor | ||||
---|---|---|---|---|
|
To configure Call Data Channel (CDC):
...
...
...
|
As user ''Calea'', use the following commands to configure LI:
Code Block | ||
---|---|---|
|
...
set addressContext default intercept |
...
Note |
---|
Mediation server’s |
nodeNumber |
...
7788 |
Include Page | ||||
---|---|---|---|---|
|
Anchor | ||||
---|---|---|---|---|
|
...
For other options of configuring the intercept flavor as IMS LI, refer to the section Configuring SBC For Lawful Interception.
Code Block | ||
---|---|---|
|
...
set addressContext default intercept callDataChannel CDC interceptStandard etsi vendorId verint mediaIpInterfaceGroupName LIG1 ipInterfaceGroupName LIG1 commit |
Info | ||
---|---|---|
| ||
Mediation server’s |
Anchor | ||||
---|---|---|---|---|
|
Code Block | ||
---|---|---|
|
...
set addressContext default intercept callDataChannel CDC mediationServer MS1 media tcp ipAddress 10.54.78.20 portNumber 65120 commit |
...
set addressContext default intercept callDataChannel CDC mediationServer MS1 media tcp state enabled mode inService
commit |
Anchor | ||||
---|---|---|---|---|
|
Code Block | ||
---|---|---|
|
...
set addressContext default intercept callDataChannel CDC mediationServer MS1 media udp ipAddress 10.54.78.20 portNumber 65200
commit
|
...
set addressContext default intercept callDataChannel CDC mediationServer MS1 media udp state enabled mode inService
commit |
...
Anchor | ||||
---|---|---|---|---|
|
Code Block | ||
---|---|---|
|
...
set addressContext default intercept callDataChannel CDC mediationServer MS1 signaling ipAddress 10.54.78. |
...
20 portNumber 65300 protocolType tcp commit |
...
set addressContext default intercept callDataChannel CDC mediationServer MS1 signaling state enabled mode inService
commit |
...
Info | ||
---|---|---|
| ||
The |
...
. |
Anchor | ||||
---|---|---|---|---|
|
Code Block | ||
---|---|---|
|
...
set addressContext default intercept callDataChannel CDC rtcpInterception enabled |
...
commit |
Info | ||
---|---|---|
|
...
The |
Anchor | ||||
---|---|---|---|---|
|
The parameter liPolDipForRegdOodMsg
when enabled is used to indicate SBC to send policy request to PSX for registered Out-Of-Dialog requests(messages) to be intercepted. When this parameter is disabled, policy request is not sent to PSX for registered Out-Of-Dialog requests (messages).
Enable the support for Policy dip, for registered users out-of-dialog messages, to decide on interception, by executing the command
Code Block | ||
---|---|---|
|
...
set addressContext default intercept callDataChannel CDC liPolDipForRegdOodMsg enabled |
...
commit |
Info | ||
---|---|---|
|
...
The |
Anchor | ||||
---|---|---|---|---|
|
As user ''Admin'', use the following commands to configure IPsec. This optional configuration is needed if secure connection is required between the
Spacevars | ||
---|---|---|
|
Info | ||
---|---|---|
| ||
|
Info | ||
---|---|---|
| ||
The Recommended setting for LI IPsec mode is 'transport'. For more information on IPsec configuration, refer to the section IP Security - CLI. |
Code Block |
---|
### create and configure IKE and IPsec protection profiles set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF saLifetimeTime 28800 set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms integrity hmacSha1,hmacMd5 set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms encryption aesCbc128,_3DesCbc set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF saLifetimeTime 28800 set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms encryption aesCbc128,_3DesCbc set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms integrity hmacSha1,hmacMd5 set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF dpdInterval noDpd ### create IKE peer set addressContext default ipsec peer PRGGSX2 ipAddress 10.54.78.20 preSharedKey 00000000000000000000000000000000 localIdentity type ipV4Addr ipAddress 10.220.41.161 set addressContext default ipsec peer PRGGSX2 remoteIdentity type ipV4Addr ipAddress 10.54. |
...
78.20
set addressContext default ipsec peer PRGGSX2 protocol ikev1 protectionProfile PRGGSX2_IKE_PROT_PROF
### create an SPD rule for this IKE peer
set addressContext default ipsec spd PRGGSX2_SPD state enabled precedence 1001
set addressContext default ipsec spd PRGGSX2_SPD localIpAddr 10.220.41.161 localIpPrefixLen 32 remoteIpAddr 10.54.78.20 remoteIpPrefixLen 32
set addressContext default ipsec spd PRGGSX2_SPD action protect
set addressContext default ipsec spd PRGGSX2_SPD protocol 0
set addressContext default ipsec spd PRGGSX2_SPD protectionProfile PRGGSX2_IPSEC_PROT_PROF
set addressContext default ipsec spd PRGGSX2_SPD mode transport
set addressContext default ipsec spd PRGGSX2_SPD peer PRGGSX2
### enable IPsec on the IP interface group
set addressContext default ipInterfaceGroup LIG1 enabled |
Info | ||
---|---|---|
| ||
The SBC is enhanced to support IMS LI for PS-to-PS Handover scenarios. The enhancement has no impact on the IMS routing. |
...
Enter the show commands to view the configurations.
Anchor | ||||
---|---|---|---|---|
|
To view the intercept details, execute the following command:
Code Block | ||
---|---|---|
|
...
show status addressContext default intercept callDataChannel
callDataChannel CDC {
mediationServerMediaStatus MS1 {
tcpChannelstatus |
...
inService; tcpPacketsSent 0; tcpPacketsLost 0; udpPacketsSent 0; udpPacketsLost 0; } mediationServerSignalingStatus MS1 { tcpChannelStatus |
...
inService; DSRSuccess 0; DSRFailures 0; } } [ok] |
Anchor | ||||
---|---|---|---|---|
|
To view the CDC configuration, execute the following command:
Code Block | ||
---|---|---|
|
...
show addressContext default intercept nodeNumber 7788; callDataChannel CDC { interceptStandard |
...
etsi; vendorId |
...
verint; ipInterfaceGroupName LIG1; liPolDipForRegdOodMsg enabled; rtcpInterception enabled; mediaIpInterfaceGroupName LIG1; mediationServer MS1 { signaling { ipAddress 10. |
...
54. |
...
78. |
...
20; portNumber |
...
65300; protocolType tcp; mode inService; state enabled; } media { tcp { ipAddress 10. |
...
54. |
...
78. |
...
20; portNumber |
...
65120; mode inService; state enabled; } udp { ipAddress 10. |
...
54. |
...
78. |
...
20; portNumber |
...
65200; mode inService; state enabled; } } } } [ok] |
...
Noprint |
---|
...
|