You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

In this section:


These objects specify the IP interfaces that the SBC will utilize for telephony, management, and system debugging traffic.

IP Interface Groups are a primary tool for accomplishing disjoint networks (administrative network separation). An IP Interface Group is the local manifestation of a segregated network domain.

Note

For the SBC 52x0 platform, the IP Interface on the media ports 0 and 1 are considered as the first set (example: set 1) and the IP Interfaces on media ports 2 and 3 are considered as second set (Example: set 2). While associating the interfaces to an IP Interface Group, the IP Interfaces associated to the group must be from the same set (set 1 or set 2). This should be set at the configuration level.

Note

When calculating bandwidth size, keep in mind that an IPv6 header size (40 bytes) is twice as large as IPv4 header (20 bytes), thus reducing the number of messages when using IPv6.


Note

Each signaling port within an Address Context must use a unique IP address and port number combination.


Note

The  SBC 7000 system supports creating IP Interface Groups containing sets of IP interfaces that are not "processor friendly" (i.e. carried on physical Ethernet ports served by separate processors). However, restrictions exist regarding the usage of such Interface Groups.

(This ability does not apply to the SBC 5400, which has only two physical media ports. You may configure the IP interfaces from the two physical ports within the same IP Interface Groups without restrictions.)

For complete details, refer to Configuring IP Interface Groups and Interfaces.

View an IP Interface Group

From the main menu, go to Configuration > System Provisioning > Category: Base Provisioning > IP Interface Group  to open the IP Interface Group window.

System Provisioning - IP Interface Group


The IP Interface Group can be checked for each Address Context or for all the Address Contexts created. Use the drop-down box to select the desired Address Context.

Edit an IP Interface Group

To edit any of the IP Interface Groups in the list, click the radio button next to the specific IP Interface Group name.

The Edit Selected IP Interface Group window is displayed below.

IP Interface Group Edit Window


Make the required changes and click Save at the right hand bottom of the panel to save the changes made.

Create an IP Interface Group

To create a new IP Interface Group, click New IP Interface Group tab on the IP Interface Group List panel.

Figure 3: Ip Interface Group fields


The Create New IP Interface Group window is displayed.

IP Interface Group Create Window

The following fields are displayed:

IP Interface Group Parameters

Parameter

Description

Name

The name of the IP interface group.

IPsec

The administrative state of a resource. Administrative state of the IPsec support for this interface group.

  • Disabled – (default) IPsec support is turned off for all interfaces in the group.
  • Enabled – IPsec support is turned on for all interfaces in the group.

Note: PING does not work when IPSec is enabled on the IP interface.

IPsec For Media


Note

This feature applies to SBC 7000 only.

The parameter IPsec For Media  in the IP Interface Group EMA screen supports media over IPsec. The IPsec For Media parameter works in conjunction with the IPsec state parameter already available in the same screen. The IPsec Admin State field enables or disables IPsec on the LIF Group as a whole. 

  • You must enable the existing IPsec parameter for any use of IPsec.

  • You must also enable the IPsec For Media parameter to support media over IPsec.

Note

To support media over IPsec, you must enable both the IPsec and IPsec for Media parameters. Calls using this IP Interface Group will only succeed if the media packets match a media SPD entry.

Whenever IPsec For Media is disabled, only media SAs are deleted. If only IPsec is disabled, then only the signaling/LI SAs are deleted.

Currently, whenever IPsec is disabled on a LIF group, isakmp ports on the interfaces belonging to the LIF group are closed. If IPsec is disabled on LIF group but IPsec for Media is enabled, then isakmp ports are not closed, and vice versa.

To establish IPsec SAs for media traffic, enable IPsec For Media of a media IP Interface Group as well as the  administrative "state" of media IPsec SPD.  

  • Disable (default)
  • Enable

Enter all the required fields. You can click Show only required fields at the left hand bottom of the panel to view and enter only the required fields to create a IP Interface Group.

Delete an IP Interface Group

To delete any of the created IP Interface Group, click the radio button next to the specific IP Interface Group which you want to delete.

Click Delete at the end of the highlighted row. This will open a delete confirmation message.

Click Yes to remove the specific IP Interface Group from the list.


  • No labels