...
Panel | ||||||
---|---|---|---|---|---|---|
| ||||||
|
...
Panel | ||||
---|---|---|---|---|
In this section:
|
...
width | 40% |
---|
Info | ||
---|---|---|
| ||
For PCSI LI configuration, refer to Configuring the SBC for Lawful Interception as it is supported only on the D-SBC. |
To configure PCSI LI:
Anchor | ||||
---|---|---|---|---|
|
As user 'Calea', use the following commands to configure LI:
Code Block | ||
---|---|---|
| ||
% set addressContext <default> intercept
nodeNumber <integer> |
Include Page | ||||
---|---|---|---|---|
|
Anchor | ||||
---|---|---|---|---|
|
Code Block |
---|
### create and configure IKE and IPsec protection profiles
set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF saLifetimeTime 28800
set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms |
...
integrity hmacSha1,hmacMd5 set profiles security ipsecProtectionProfile PRGGSX2_IPSEC_PROT_PROF espAlgorithms encryption aesCbc128,_3DesCbc set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF saLifetimeTime 28800 set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms encryption aesCbc128,_3DesCbc set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF algorithms |
...
integrity hmacSha1,hmacMd5 set profiles security ikeProtectionProfile PRGGSX2_IKE_PROT_PROF dpdInterval noDpd |
...
...
### create IKE peer set addressContext default ipsec peer PRGGSX2 ipAddress 10.220.11.8 |
...
preSharedKey 00000000000000000000000000000000 |
...
|
...
localIdentity type ipV4Addr ipAddress 10.220.41.161 set addressContext default ipsec peer PRGGSX2 remoteIdentity type ipV4Addr ipAddress 10.220.11.22 set addressContext default ipsec peer PRGGSX2 protocol ikev1 protectionProfile PRGGSX2_IKE_PROT_PROF |
...
### create an SPD rule for this IKE peer
set addressContext default ipsec spd PRGGSX2_SPD state enabled precedence 1001
set addressContext default ipsec spd PRGGSX2_SPD localIpAddr 10.220.41.161 localIpPrefixLen 32 remoteIpAddr 10.220.11.22 remoteIpPrefixLen 32
set addressContext default ipsec spd PRGGSX2_SPD action protect
set addressContext default ipsec spd PRGGSX2_SPD protocol |
...
0 set addressContext default ipsec spd PRGGSX2_SPD protectionProfile PRGGSX2_IPSEC_PROT_PROF set addressContext default ipsec spd PRGGSX2_SPD mode transport set addressContext default ipsec spd PRGGSX2_SPD peer PRGGSX2 |
...
...
### enable IPsec on the IP interface group set addressContext default ipInterfaceGroup LIG1 enabled |
...
Anchor | ||||
---|---|---|---|---|
|
...
To configure the IP Interface Group, execute the following command:
Code Block | ||
---|---|---|
| ||
set addressContext default intercept callDataChannel CDC ipInterfaceGroupName LIG1
commit |
Anchor | ||||
---|---|---|---|---|
|
For other options of configuring the intercept flavor as IMS LI, refer to the section Configuring SBC For Lawful Interception.
Code Block |
---|
set addressContext default intercept callDataChannel CDC interceptStandard packetCable vendorId ss8
commit |
Anchor | ||||
---|---|---|---|---|
|
Note |
---|
The PCSI LI supports configuring up to 8 mediation servers under the CDC. |
Code Block | ||
---|---|---|
| ||
set addressContext default intercept callDataChannel CDC interceptStandard mediationServer MS1
commit |
Anchor | ||||
---|---|---|---|---|
|
Code Block | ||
---|---|---|
| ||
set addressContext default intercept callDataChannel CDC mediationServer MS1 media tcp ipAddress fc22:3200::230:7 portNumber 8765 dscpValue 0
commit
set addressContext default intercept callDataChannel CDC mediationServer MS1 media tcp mode inService state enabled
commit |
Anchor | ||||
---|---|---|---|---|
|
Code Block |
---|
set addressContext default intercept callDataChannel CDC rtcpInterception enabled
commit |
Enter the show commands to view the configurations.
Anchor | ||||
---|---|---|---|---|
|
To view the intercept details, execute the following command:
Code Block |
---|
> show status addressContext default intercept callDataChannel
callDataChannel CDC {
mediationServerMediaStatus MS1 {
tcpChannelstatus inService;
tcpPacketsSent 0;
tcpPacketsLost 0;
udpPacketsSent 0;
udpPacketsLost 0;
}
}
[ok] |
Anchor | ||||
---|---|---|---|---|
|
To view the CDC configuration, execute the following command:
Code Block |
---|
show addressContext default intercept callDataChannel CDC
interceptStandard packetcable;
vendorId ss8;
ipInterfaceGroupName LIG1;
mediationServer MS1 {
media {
tcp {
ipAddress 10.54.6.1;
portNumber 8765;
dscpValue 0;
mode inService;
state enabled;
}
}
}
[ok] |
Pagebreak |
---|