Page 1
Administration for the Avaya G450 Media Gateway 03-602055 Issue 1 January 2008...
Page 2
Avaya support Avaya provides a telephone number for you to use to report problems or to ask questions about your product. The support telephone number is 1-800-242-2121 in the United States. For additional support telephone numbers, see the Avaya website: http://www.avaya.com/support...
Page 4
Accessing the CLI via a modem connection to the S8300 ... Accessing Avaya IW ........
Page 5
Configuring the Primary Management Interface (PMI) ....Setting the PMI of the G450 ......
Page 6
Summary of configuration file backup and restore commands ..Listing the files on the Avaya G450 Media Gateway ....Summary of file listing commands ..... .
Page 7
SLS service........Avaya phones supported in SLS ......
Page 8
Chapter 7: Configuring Ethernet ports ....193 Ethernet ports on the G450......
Page 9
Contents Disabling logging system messages to a log file ....Deleting current log file and opening an empty log file ... Displaying log file messages .
Page 10
Contents Chapter 10: Configuring the G450 for modem use ... . 239 Configuring the USB-modem interface......
Downloading this book and updates from the web You can download the latest version of the Administration for the Avaya G450 Media Gateway from the Avaya website. You must have access to the Internet, and a copy of Acrobat Reader must be installed on your personal computer.
6. Click the book title. Your browser downloads the book. Related resources Title Number Overview for the Avaya G450 Media Gateway 03-602058 Quick Start for Hardware Installation for the Avaya G450 Media 03-602053 Gateway Installing and Upgrading the Avaya G450 Media Gateway 03-602054 Avaya G450 CLI Reference...
Toll fraud, call Avaya Toll Fraud Intervention at 1-800-643-2353 ● International For all international resources, contact your local Avaya authorized dealer for additional help. Trademarks All trademarks identified by the ® or ™ are registered trademarks or trademarks, respectively, of Avaya Inc. All other trademarks are the property of their respective owners.
Westminster, CO 80234 USA E-mail, send your comments to: ● document@avaya.com Fax, send your comments to: ● 1-303-538-1741 Mention the name and number of this book, Administration for the Avaya G450 Media Gateway, 03-602055. 26 Administration for the Avaya G450 Media Gateway...
The G450 can support up to 450 users when deployed as a branch gateway in a mid to large branch office of a large enterprise or a call center, and can serve up to 2400 users when deployed as a campus gateway.
Introduction The G450 is a modular device, adaptable to support different combinations of endpoint devices. While fixed front panel ports support the connection of external LAN switches, network data ports, Ethernet WAN lines and external routers, eight slots are provided for plugging in optional media modules.
Page 29
G450 support information E1/T1 trunks ● ISDN PRI trunks ● ISDN BRI trunks ● E1/T1 and USP WAN data lines ● On board ports ● Issue 1 January 2008...
Page 30
Introduction 30 Administration for the Avaya G450 Media Gateway...
Basic configuration The G450 can be deployed in the LAN with a basic configuration that includes no redundancy. The G450 is connected to an external LAN switch using one of the two Ethernet LAN ports located on the G450’s front panel.
Supported LAN deployments Port redundancy configuration The G450 can be deployed in the LAN using port redundancy to provide redundancy. The G450 is connected to an external LAN switch using both of the Ethernet LAN ports located on the G450’s front panel.
Configuring port redundancy on page 358. When the G450 senses a link down failure on the primary port or failure of the switch to which the primary link is attached, it automatically enables the secondary link to the backup switch.
Supported LAN deployments STP configuration The G450 can be deployed in the LAN using STP to provide redundancy. The G450 is connected to an external LAN switch using both of the Ethernet LAN ports located on the G450’s front panel.
Configuring spanning tree on page 362. When the G450 senses a link down failure on the active port or failure of the switch to which the active link is attached, it automatically enables the blocked link to the backup switch. Both ports need to be administratively enabled on the LAN switch peer.
Page 36
Supported LAN deployments 36 Administration for the Avaya G450 Media Gateway...
43. Defining the Console interface The first thing you should do when configuring a new G450 is to assign an IP address to the Console interface. It is not necessary to include a subnet mask. 1. Enter interface console to enter the Console context.
Configuration overview Defining the USB-modem interface If you intend to use a USB modem to connect to the G450, you should also assign an IP address to the USB-modem interface. It is not necessary to include a subnet mask. 1. Enter interface usb-modem to enter the USB-modem context.
Configuration using CLI Configuration using CLI You can use the Avaya G450 Media Gateway CLI to manage the G450. The CLI is a command prompt interface that enables you to type commands and view responses. For instructions on how to access the G450 CLI, see Accessing the CLI on page 43.
When you change the configuration of the G450, your changes affect only the running configuration. Your changes are lost when the G450 resets if you do not save your changes.
If it becomes necessary to use the older version, you can enter set boot bank bank-x and then reset the G450 to use the older version. This is particularly important when uploading new versions.
Page 42
Configuration overview 42 Administration for the Avaya G450 Media Gateway...
Chapter 4: Accessing the Avaya G450 Media Gateway You can access the Avaya G450 Media Gateway using the CLI, the IW, the GIW, the PIM, and the Avaya Communication Manager. You can manage login permissions by using and configuring usernames and passwords, and by configuring the G450 to use SSH, SCP, RADIUS authentication.
In the following example, the user enters the vlan 1 interface context and displays help for the bandwidth command. G450-001(super)# interface vlan 1 G450-001(super-if:VLAN 1)# bandwidth ? Bandwidth commands: ---------------------------------------------------------------------- Syntax: bandwidth <kilobytes size> <kilobytes size> : integer (1-10000000) Example: bandwidth 1000 44 Administration for the Avaya G450 Media Gateway...
Accessing CLI via local network Access the CLI from a computer on the same local network as the Avaya G450 Media Gateway by using SSH or, if telnet is active, any standard telnet program. Use the IP address of any G450 interface for the host address.
PPP network connection from a modem at the remote location. You can use either a USB modem connected to the USB port on the front panel of the G450 or a serial modem connected to the Console port on the front panel of the G450. You must only use an approved Avaya serial cable.
Accessing the CLI via a serial modem 1. Connect a modem to the Console port on the front panel of the Avaya G450 Media Gateway. Use an RJ-45 serial cable to connect the modem. 2. Make sure the Console port is properly configured for modem use.
Accessing the CLI via a modem connection to the S8300 If the Avaya G450 Media Gateway includes an S8300 Server, you can access the CLI from a remote location. This is done by establishing a PPP network connection from a modem at the remote location to a USB modem connected to one of the USB ports on the front panel of the S8300.
Accessing Avaya IW Access and run the Avaya IW using a laptop computer 1. Connect a laptop computer to the Services port of the S8300, using a crossover cable. 2. Make sure the laptop is configured as described in Connecting a console device to the Services port on page 45.
Page 50
18. Click the Launch Installation Wizard link on the home page. The Avaya IW Overview screen appears. Figure 6: Avaya IW Overview screen For step-by-step instructions on how to configure the G450 using the Avaya IW, see Installing and Upgrading the Avaya G450 Media Gateway, 03-602054. 50 Administration for the Avaya G450 Media Gateway...
G450 that does not include an S8300 Server. You can use the GIW to perform initial configuration of the G450 and to upgrade software and firmware. Specifically, you can perform the following tasks with the GIW:...
Accessing the Avaya G450 Media Gateway Figure 7: GIW Overview screen For step-by-step instructions on how to configure the G450 using the GIW, see Installing and Upgrading the Avaya G450 Media Gateway, 03-602054. Accessing PIM The Provisioning and Installation Manager (PIM) enables you to remotely configure devices, primarily Avaya media gateways, on a network-wide basis.
G450 security mechanism. When the user enters a username, the G450 first searches its own database for the username. If the G450 does not find the username in its own database, it establishes a connection with the RADIUS server, and the RADIUS server provides the necessary authentication services.
Privilege level When you start to use Avaya G450 Manager or the CLI, you must enter a username. The username that you enter sets your privilege level. The commands that are available to you during the session depend on your privilege level. If you use RADIUS authentication, the RADIUS server sets your privilege level.
Direct connection to the front panel Console port or Services port using the "craft" login ● When ASG authentication is enabled on the G450, the G450 recognizes any login attempts using Avaya Services reserved usernames as service logins, and requests ASG authentication from the user, instead of a static user password.
ASG authentication can be enabled and disabled on the gateway and requires an ASG authentication file. The ASG authentication file contains Avaya Services accounts for authenticating users at login as members of Avaya Services. The G450 is shipped with an ASG authentication file. For information about replacing the authentication file, refer to...
Page 57
● filename ip, where filename is the name of the authentication file, including the full path and ip is the IP address of the host. The G450 prompts you for a username and password after you enter the command. To download an authentication file from a remote SCP server:copy scp auth-file ●...
Use no login authentication lockout to return the lockout time and lockout attempt threshold to their default values (180 and 3). For example, to lockout Avaya Services access to the device for 360 seconds following five failed login attempts:...
Switch between modem operation modes, including rasaccess and ppp modes, using ppp ● authentication {pap|chap|none|ras}. ASG authentication is enabled when ras is selected. For example: G450-001(super)# ppp authentication ras Displaying ASG authentication information Display login authentication settings and information, using show login ●...
Accessing the Avaya G450 Media Gateway Summary of ASG authentication CLI Commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 3: ASG authentication CLI command Command Description copy auth-file ftp Upload the authentication file from the gateway to an...
● fingerprint). The public key is always 16 bytes long. This public key is displayed. The G450 sends the public key to the client computer. This public key is used by the client ● to encrypt the data it sends to the G450. The G450 decrypts the data using the private key.
The client chooses a random number that is used to encrypt and decrypt the information ● sent. This random number is sent to the G450, after encryption based on the G450’s public key. ● When the G450 receives the encrypted random number, it decrypts it using the private ●...
61, except that the roles of the G450 and the client computer are reversed. To perform file transfers secured by SCP, the G450 launches a local SSH client via the CLI. This establishes a secured channel to the secured file server. The G450 authenticates itself to the server by providing a username and password.
When you use RADIUS authentication, you do not need to configure usernames and passwords on the G450. When you try to access the G450, the G450 searches for your username and password in its own database first. If it does not find them, it activates RADIUS authentication.
3. Use the set radius authentication server command to set the IP address of the primary or secondary RADIUS Authentication server. For more information about these commands, see Avaya G450 CLI Reference, 03-602056. Changing RADIUS parameters The following commands are optional: Use the set radius authentication retry-number command to set the number ●...
Accessing the Avaya G450 Media Gateway Summary of RADIUS authentication configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 6: RADIUS authentication configuration command Command Description Clear the primary or secondary RADIUS server IP address...
The G450 includes a special recovery password. The purpose of the recovery password is to enable the system administrator to access the G450 in the event that the regular password is forgotten. You can only use the recovery password when accessing the G450 via a direct connection to the Console port or Services port.
Initiate a login session via telnet to a network host telnet Managing gateway secrets The G450 provides a mechanism for storage, backup, and restore of sensitive materials (passwords and keys) maintained in the Media Gateways. All sensitive materials are encrypted using a Master Configuration Key (MCK), derived from a passphrase entered by an administrator.
Enabling SYN cookies The G450 provides various TCP/IP services and is therefore exposed to a myriad of TCP/IP based DoS attacks. DoS (Denial of Service) attacks refers to a wide range of malicious attacks that can cause a denial of one or more services provided by a targeted host.
1. Enter tcp syn-cookies. 2. Copy the running configuration to the start-up configuration using the copy running-config startup-config command. 3. Reset the device using the reset command. SYN cookies are now enabled on the device. 70 Administration for the Avaya G450 Media Gateway...
Special security features SYN attack notification When the SYN cookies feature is enabled, the G450 alerts the administrator to a suspected SYN attack as it occurs by sending the following syslog message: SYN attack suspected! Number of unanswered SYN requests is greater...
MSS notifications are intercepted and, if certain conditions are met, may be forwarded to the Avaya Security Operations Center (SOC) as INADS alarms. The SOC is an Avaya service group that handles DoS alerts, responding as necessary to any DoS attack or related security issue.
Page 73
3. Use the set mss-notification rate command to modify the MSS reporting rate, if necessary. The default is 300 seconds. The G450 counts events for each DoS class for the duration of the interval. At the end of each interval, if the count of each class of DoS events surpasses a defined threshold, the G450 generates an MSS notification, reporting on the event type, event parameters, and the number of occurrences.
For all routable packets, the Gateway report reception of IP spoofed packets UNKNOW_L4_IP_PROTOCOL Packets with unknown (unsupported or administratively closed) protocol in IP packet with TO-ME interface as a destination UNATHENTICATED_ACCESS Failure to authenticate services 74 Administration for the Avaya G450 Media Gateway...
For example, you can use destination-ip to specify that the rule applies to packets with a specific destination address and you can use ip-protocol to specify that the rule applies to packets with a specific protocol: G450-001(super-ACL 301/ip rule 1)# destination-ip 255.255.255.255 0.0.0.0 Done! G450-001(super-ACL 301/ip rule 1)# ip-protocol icmp Done! 5.
Page 76
8. Enter the configuration mode of the interface on which you want to activate the ACL. For example: G450-001(super)# interface vlan 203 9. Activate the configured ACL for incoming packets on the desired interface. For example: G450-001(super-if:vlan 203)# ip access-group 301 in Done! 76 Administration for the Avaya G450 Media Gateway...
G450-001(super-ACL 301)# composite-operation Deny-Notify Done! //specify that the ip rule applies to packets with this destination ip address. G450-001(super-ACL 301/ip rule 1)# destination-ip 255.255.255.255 0.0.0.0 Done! //Specify that the ip rule applies to ICMP packets G450-001(super-ACL 301/ip rule 1)# ip-protocol icmp...
Accessing the Avaya G450 Media Gateway Summary of MSS configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 12: MSS configuration CLI commands Command Description Edit the specified composite operation. If the composite...
● Defining an interface All interfaces on the G450 must be defined by the administrator, after installation of the G450. 1. Use the interface command to enter the interface context. Some types of interfaces require an identifier as a parameter. Other types of interfaces require the interface’s module and port number as a parameter.
Sending messages from the G450 using FTP and TFTP protocol ● You can designate any of the G450’s interfaces to serve as the G450’s PMI. The PMI must be an IP address that the MGC recognizes. If you are not sure which interface to use as the PMI, check with your system administrator.
Configured PMI. The PMI that the G450 is configured to use after reset, as defined in ● the startup configuration file If you use this command after you reset the G450, both the Active and the Configured PMI should be the same IP address. 7. Use the following commands to configure other identification information: Use the set system contact command to set the contact information for the G450 ●...
G450 supports both External Call Controllers (ECC) and Internal Call Controllers (ICC). An ICC is an Avaya S8300 Server that you install in the G450 as a media module. An ECC is an external server that communicates with the G450 over the network.
Several options exist to minimize network disruption in the event that connectivity between the G450 and the server or media gateway controller (MGC) is lost. MGC list. You must register the G450 with at least one, and up to four, MGCs. The first ●...
Setting the G450’s MGC Use the set mgc list command to set the G450’s MGC. You can enter the IP addresses of up to four MGCs with the set mgc list command. The first MGC on the list is the primary MGC.
In the following example of the set mgc list command, if the MGC with the IP address 132.236.73.2 is available, that MGC becomes the G450’s MGC. If that server is not available, the G450 searches for the next MGC on the list, and so on.
In this example, in the event of a connection loss with the registered MGC, the G450 searches for the primary MGC on its MGC list for 20 minutes. If the G450 does not establish a connection with the primary MGC within this time, it searches for the other MGCs on the list for a total of 40 minutes.
MGC’s IP address, and then enter session mgc to access the MGC If the G450 includes a local S8300, enter session icc to access the S8300. You can use this command whether or not the local S8300 is the G450’s registered MGC.
Basic device configuration Summary of MGC list configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 16: MGC list configuration commands Command Description Remove one or more MGCs from the MGC list clear mgc list...
- Dialer interface - Serial interface The most common application of this configuration is for connecting the G450 to the Internet and getting the DNS server information from the ISP. Therefore, interfaces configured to automatically learn the DNS servers in the system are usually the FastEthernet with PPPoE interface and the Dialer interface.
3. Add a DNS server to the DNS servers list using the name-server command. Configure the following: Assign an index number that ranks the DNS server by priority ● Specify the IP address of the DNS server ● 90 Administration for the Avaya G450 Media Gateway...
Page 91
Specify the domain name ● 6. Repeat Step 5 to configure additional domain names. You can configure up to six domain names. G450-001(config)# ip domain list 1 avaya.com Done! G450-001(config)# ip domain list 2 emea.avaya.com Done! 7. Optionally, configure the number of DNS query retries, using the ip domain retry command.
Page 92
Basic device configuration Important: If either DHCP Client or PPP are configured in the G450, you do not need to Important: configure DNS resolver because the DNS resolver is enabled by default. In addition, the DHCP Client and PPP discover DNS servers automatically, so the list of DNS servers will include the automatically-learned DNS servers.
G450, see Configuring logging on page 209. Summary of DNS resolver configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 17: DNS resolver configuration commands Root level Command Description command Clear the DNS resolver’s statistics counters...
2 of 2 Viewing the status of the device To view the status of the Avaya G450 Media Gateway, use the following commands:For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Enter show faults to view information about currently active faults.
Page 96
Use the show mm command to view information about media modules that are installed on ● the G450. To view information about a specific media module, include the slot number of the media module as an argument. For example, to view information about the media module in slot 2, enter show mm v2.
Viewing the status of the device Summary of device status commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 18: Device status commands Command Description Enable CPU utilization measurements set utilization Display information about currently active faults...
● File transfer The Avaya G450 Media Gateway can be a client for the FTP and TFTP protocols. Use either a USB device or the FTP or TFTP protocols to transfer files between the Avaya G450 Media Gateway and other devices. You can use file transfer to: Install software and firmware upgrades on the G450 ●...
Loading firmware from the non-default bank You can use the ASB button on the G450 front panel to load firmware from a bank other than the default bank during startup: 1. Press and hold the reset button.
FTP or TFTP server. Then, use one of the following commands to upload the file to the G450. For each of these commands, include the full path of the file and the IP address of the FTP or TFTP host as parameters. When you enter the command, the CLI prompts you for a username and password.
USB mass storage device. 3. Remove the USB storage device from the PC, and insert it in the G450 USB port. 4. Copy the software or firmware file(s) to the G450 using one of the following commands: Use the copy usb SW_imageA command to upgrade the G450 firmware into Bank A ●...
Copy media modules’ firmware files to the MM subdirectory. d. Copy IP phone firmware files to the IPPHONE subdirectory. 4. Remove the USB mass storage device from the PC, and insert it in the G450 USB port. 5. Enter restore usb usbdevice0 backup-name, where backup-name is the root directory path and name on the USB mass storage device.
Page 103
Software and firmware management phone-scriptA. Phone script bank A in the gateway’s TFTP directory ● phone-scriptB. Phone script bank B in the gateway’s TFTP directory ● license-file. The VPN license file ● startup-config. The startup configuration file ● capture-file. The packet sniffing buffer ●...
Basic device configuration Summary of software and firmware management commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 19: Software and firmware management CLI commands Command Description Upload a specific file from the gateway to an FTP server...
CLI commands for backing up and restoring files to or from a USB mass storage device enable you to use a USB port for efficient restoration or replication of a G450 media gateway and for replacing and upgrading media modules. Using the USB port you can back up or restore multiple files with one CLI command, which is simpler than the alternative TFTP/FTP/SCP method, in which files are copied and restored individually.
USB mass storage device. Another single command restores all of the backed up files. If you need to completely replicate a media gateway, you can also download the G450 firmware, media modules’ firmware, IP phone firmware, and Device Manager firmware to the USB mass storage device, and use the restore usb command to restore these files as well as the administration and configuration files.
Page 107
Software and firmware management Note: Before unplugging the USB mass storage device, use the safe-removal usb Note: command to safely remove the USB mass storage device. A backup directory is created on the USB mass storage device, with the following sample structure and file types: Table 20: Backup file and directory structure on a USB mass storage device Root directory...
Table 21, to enable a successful restore. 1. Make sure you have a backup of the faulty G450 on a USB mass storage device. Refer to Backing up administration and configuration files using a USB mass storage device page 106.
Page 109
IP address of the FTP server. Alternatively, enter copy tftp sw_imageA filename ip if you are downloading from a TFTP server. 6. If the new G450 firmware version is 26.x.y or above, add a G450 firmware to the USB mass storage device, as follows: a.
Page 110
Embedded web image g450_emweb_3_0_5.bin IP phone scripts and IPPHONE images directory 46xxupgrade.scr 46xxsettings.txt 4601dape1_82.bin 4601dbte1_82.bin Media modules file directory mm722v2.fdl mm714v67.fdl mm711h20v67.fdl mmanalogv67.fdl Gateway announcements GWANNC and music-on-hold file directory DanAnncouncement.wav DanaAnncouncement.wav 110 Administration for the Avaya G450 Media Gateway...
16. Obtain and install a VPN license. For information on obtaining a VPN license, see Installing and Upgrading the Avaya G450 Media Gateway, 03-602054. 17. Update the S8300 on the new G450 with the serial number of the new gateway, otherwise the gateway is not able to register in the Avaya Communication Manager. See Administrator’s Guide for Avaya Communication Manager, 555-233-506.
4. Insert the USB mass storage device into a G450 USB port. 5. Enter restore usb usbdevice0 backup-name, where backup-name is the backup directory path and file name on the USB mass storage device.
● and a server on the network. Use a USB mass storage device connected to a G450 USB port to upload or download the ● startup configuration file of the G450. You can use either the USB copy commands, or use...
Use the copy ftp startup-config command to restore a configuration file from an ● FTP server. The configuration file becomes the startup configuration on the G450. Use the copy tftp startup-config command to restore a configuration file from a ●...
Software and firmware management Summary of configuration file backup and restore commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 23: Configuration file backup and restore CLI commands Command Description Download a G450 configuration file from an FTP server to the...
Listing the files on the Avaya G450 Media Gateway Use the dir command to list all G450 files. When you list the files, you can see the version numbers of the software components. The dir command also shows the booter file, which cannot be changed.
Configuring SLS on page 132. Media module compatibility with SLS SLS works on the G450 and its media modules only if they satisfy the minimum hardware vintage and firmware version requirements listed in Table Table 25: G450 media module firmware version required...
Configuring Standard Local Survivability (SLS) Table 25: G450 media module firmware version required (continued) Media module Minimum firmware version required MM717 Vintage 8 MM720 Vintage 7 MM722 Vintage 7 G450 gateway MG 4.1, build 27_x 2 of 2 SLS service Call capability for analog, DCP, and IP phones ●...
Configuring Standard Local Survivability (SLS) The new Avaya 96xx IP phone family is not directly referenced in the G450 CLI. When you administer these phones via the CLI, use the following mapping: Table 27: Mapping Avaya 96xx IP phones for CLI administration...
Acts as an H.323 Gatekeeper that enables IP endpoints to register simultaneously ● Direct Inward Dialing ● Multiple call appearances ● Hold and Call Transfer functions ● Contact closure feature ● Call Detail Recording (CDR, see SLS logging activities on page 130) ●...
Configuring Standard Local Survivability (SLS) Provisioning data SLS requires that the G450 has connected to an MGC at least once and has received provisioning information, including: Avaya Communication Manager port information sent through the H.248 control channel: ● - Tone sources, including a distinctly different dial tone to inform users that the system is...
RAM (NVRAM) on the G450. After the initial data collection, PIM retains a copy of the data set for each G450. This set is compared with subsequent data sets to determine if anything has changed: If the data set changes, the newer data set is pushed down to the media gateway ●...
The G450 closes the SLS socket after maintenance determines that it has completed an ● H.248 registration with the primary MGC. SLS determines that it needs to unregister with the G450 due to internal error conditions. ● Teardown state activities 1.
MGC list for a controller. SLS interaction with specific G450 features SLS interacts differently with the various G450 features. Direct Inward Dialing in SLS mode Direct Inward Dial (DID) is a service offered by telephone companies that enables callers to dial directly into an extension on a PBX without the assistance of an operator or automated call attendant.
Pressing the held Call Appearance button ● Analog phones Newer analog phones (for example, Avaya 62xx series) have buttons with specific functions for placing a call on Hold: Hold button. A hold function that is local to the phone ●...
Using the Flash button 1. Press the Flash button on the analog phone. You hear a dial tone; the other party hears nothing. You can leave the call on Hold or transfer the call. Press the Flash button twice to return to the call.
Page 128
Transferring an established call from an analog phone Newer analog phones (for example, Avaya 62xx series) have buttons with specific functions for transferring a call. The switchhook (receiver on/off hook) sends a disconnect signal to the server, and the Transfer/Flash button sends a transfer message to the server.
Note: Displays are not supported on analog phones unless they are supported locally Note: by an analog phone. Using contact closure in SLS mode When the media gateway is in survivable mode, contact closure works as follows: 1. Lift the phone receiver and listen for the survivability dial tone. 2.
The SLS mode supports shared administrative identity with the Avaya Softphone application, but requires specific station administration. 1. Access the CM administrative SAT interface. For instructions on accessing the Avaya Communication Manager through the G450, see Accessing the registered MGC page 87.
Example of CDR log entries and format Figure 11: CDR log example G450-SLS(super)# show logging cdr file content 02/18/2005,10:46:35:CDR-Informational: 10:46 00:00 A 700 50029555 52001 v301 02/18/2005,10:45:46:CDR-Informational: 10:45 00:00 A 700 50029 52001 v301 02/18/2005,10:45:14:CDR-Informational: 10:45 00:00 A 700 52 52001 v301...
Using PIM to manage SLS administration on the gateway on page 138. If PIM is not available, the G450 can be manually configured for SLS and Auto Fallback via the CLI. See Using the CLI to manually configure SLS administration on the gateway page 144.
Configuring Communication Manager for SLS You must configure the Avaya Communication Manager for SLS whether you will be using PIM provisioning or manual CLI entry of SLS administration. Perform the configuration during the initial administration of the host CM server.
Page 134
Note: The immediately field value is only one of the four possible choices. See the Note: Administrator Guide for Avaya Communication Manager, 03-300509 for more information on the values for this field. 9. Submit the form. 134 Administration for the Avaya G450 Media Gateway...
Page 135
(see Step 2 of Configuring the SLS data through the CLI on page 159). Max Survivable IP Ext field only appears when the Type field is G450. The current ● maximum product limits enforced by the SLS gateway’s firmware module is 240.
Page 136
Survivable ARS Analysis Table - Unrestricted. This station can place a call to any number defined in the Survivable ARS Analysis Table. Those strings administered as deny are also denied to these users as well. 136 Administration for the Avaya G450 Media Gateway...
Page 137
Configuring SLS Figure 13 shows the hierarchical relationship among the calling-restriction categories. Figure 13: Inherited Class of Restriction (COR) permissions Emergency Internal Local Toll Unrestricted cydsetru LAO 031405 Figure notes: 1. Unrestricted: Users can dial any 3. Local: Users can only dial these call valid routable number, except an types: ARS pattern specifically administered...
Using PIM to manage SLS administration on the gateway Before enabling SLS, you must gather provisioning data from PIM and deliver it to the G450. Run PIM’s Device Profile Wizard to perform this task. The Device Profile Wizard gathers a subset of the Communication Manager translations (dial plan analysis and destination routing instructions) and delivers them to the G450.
Page 139
Configuring SLS Figure 14: SLS / ARS page 8. Optionally click the following buttons: View Extract displays the current SLS administration data set for this gateway. ● Perform Extract extracts the SLS information from the controlling Communication ● Manager server for this Media Gateway. Actions enables you to edit or delete a previously-administered entry: ●...
Page 140
The number of dialed digits to be deleted from the beginning of the dialed string. Default: 0. Inserted Digits The digit string to be inserted at the beginning of the dialed string. Default: blank. 1 of 2 140 Administration for the Avaya G450 Media Gateway...
Page 141
Configuring SLS Table 29: SLS ARS Entry page field options (continued) Field Description Call Type Can be one of the following: emer (emergency call) fnpa (10-digit NANP call) hnpa (7-digit NANP call) intl (public-network international number call) iop (international operator call) locl (public-network local number call) natl (non-NANP call) op (operator)
Page 142
Set as many as six Daily Updates. Note: The Daily Updates must be at least four hours apart. Note: c. Click Submit. 12. Use the Backup/Restore page (Figure 17) to backup the PIM database backup schedule. 142 Administration for the Avaya G450 Media Gateway...
PIM wizard screens. Enabling and disabling SLS To enable SLS on the G450, enter set sls enable. The G450 responds with the message Survivable Call Engine is enabled. To disable SLS on the G450, enter set sls disable. The G450 responds with the message Survivable Call Engine is disabled.
The SLS is enabled on the G450 through its CLI ● S8300 is not serving as an LSP ● G450 is not subtending to another external server (including ESS or another LSP in ● another gateway) Planning and preparing the SLS data set...
Page 145
* 340 stations maximum (all types) You can collect the Communication Manager data using the CM administrative SAT interface. For instructions on accessing the Avaya Communication Manager through the G450, see Accessing the registered MGC on page 87.
Page 146
G450 MM712 MM717 4. At the SAT, enter display port port-number, where port-number is the DCP station port on the gateway. The system displays the extension number assigned to the port. 146 Administration for the Avaya G450 Media Gateway...
Page 147
Configuring SLS 5. Once you know the extension, enter display station extension to display the Station form for this extension. 6. Gather the necessary information from Table Table 34: DCP station form data to assemble for SLS Page Field Name Notes Extension Port...
Page 148
Field Name Notes Extension Security Code (IP only) This value is the shared secret between Communication Manager and the media gateway used for the registration of the IP endpoint 1 of 2 148 Administration for the Avaya G450 Media Gateway...
Page 149
4. Identify the analog trunk ports. Refer to Table 5. Identify the BRI trunk ports. Refer to Table 6. Identify the digital DS1 trunk ports. Refer to Table 7. Identify the G450 modules and check for provisioned trunk ports. Issue 1 January 2008...
Page 150
Note that this does not apply to DS1 PRI tie trunks. Digits This field contains a value only when the Digit Treatment field is set to insert1, insert2, insert3, or insert4 1 of 3 150 Administration for the Avaya G450 Media Gateway...
Page 151
Configuring SLS Table 36: Trunk group data to assemble for SLS (continued) Page Field Name Notes Trunk Type Depends on trunk signaling type: Analog trunks: ● - Loop-start - Ground-start - DID In-Band DS1 trunks with CO Group-Type: ● - Loop-start - Ground-start In-Band DS1 trunks with Tie Group-Type: ●...
Page 152
This field appears when Signaling Mode = isdn-pri Bit Rate = 2.048 Connect = pbx Connect Specifies what is connected at the far-end of the DS1 facility Interface Determines glare handling 1 of 2 152 Administration for the Avaya G450 Media Gateway...
Page 153
Configuring SLS Table 37: DS1 circuit pack data to assemble for SLS (continued) Page Field Name Notes Side Specifies QSIG glare handling when the Interface field is set to peerslave Country Protocol Specifies the Layer 3 signaling protocol used by the country-specific service provider Protocol Version Used in countries whose public networks allow multiple...
Page 154
Specifies the companding mode used by the far end switch LAPD address assignment for the TEI field Directory Number A Channel B1’s directory number Directory Number B Channel B2’s directory number 1 of 2 154 Administration for the Avaya G450 Media Gateway...
Page 155
Configuring SLS Table 39: ISDN-BRI administration data to assemble for SLS (continued) Page Field Name Notes SPID-A Service Profile Identifier required for Country Code (USA) SPID-B Service Profile Identifier required for Country Code (USA) Endpt Init Determines whether the far end supports endpoint initialization Layer 1 Stable Determines whether to expect the network to drop...
Page 156
6. At the SAT, enter display system-parameters features to display the Feature Related System Parameters form. 7. Scroll to page 10 and read the value of the Date Format on Terminals field (summarized Table 41). 156 Administration for the Avaya G450 Media Gateway...
Page 157
Configuring SLS 8. At the SAT, enter display media-gateway n, where n is the administered number of the media gateway of interest, to display the Media Gateway form. 9. Read the Max Survivable IP Ext field value (summarized in Table 41).
Page 158
1. At the SAT, enter display inc-call-handling-trmt trunk-group n, where n is an administered trunk group. 2. For each entry, read the values of the following fields (see Table 43): Called Number ● Called Length ● ● Insert ● 158 Administration for the Avaya G450 Media Gateway...
Configuring SLS Table 43: Incoming call handling data to gather for SLS CM Form Page Field Name Notes Incoming Call Called Number Dial string entry that is used to Handling Treatment match a pattern on inbound trunk calls Incoming Call Called Len Maximum length of the Handling Treatment...
Page 160
6. Use the set date-format command to set a date format for the SLS data set. 7. Use the set ip-codec-set command to select the country-specific G.711 codec set within the SLS data set: g.711mu or g.711a. 160 Administration for the Avaya G450 Media Gateway...
Page 161
8. Administer the slot configuration information by entering set slot-config slot-number board-type, where slot-number is the slot where the Media Module is located and board-type is the Media Module type (see Table 44). Table 44: Media Modules supporting SLS for the G450 Media Module Description Permitted Slots MM710...
Page 162
This will cause the SLS application to resynchronize its administrative database with the gateway's CLI command database. 21. At the gateway command prompt, enter copy running-config startup-config to save the changes. 162 Administration for the Avaya G450 Media Gateway...
Configuring SLS Administering Station parameters 1. At the gateway command prompt, enter station extension class to enter a second-level sub-context to administer each phone that you want covered by SLS. In this command, extension is a 1-13 digit numeric string that may begin with 0, and class is analog, dcp, or ip.
Page 164
8 possible ports MM714 4 possible ports G450 (ports 1-4) MM716 24 possible ports MM717 24 possible ports * You cannot select these modules/ports if they are already assigned as DID trunks. 164 Administration for the Avaya G450 Media Gateway...
Page 165
Configuring SLS Examples If an MM711 is inserted into slot V3 and an analog station is to be administered for ● port #5, then set port v305 sets the previously-administered analog station "1234567" to the fifth physical analog station port on the gateway’s media module. If an MM712 is inserted into slot V4 and a DCP station is to be administered for ●...
● transmission robbed bit. In-band signaling for T1 service, yielding twenty-four 56 kbps ● B-channels for voice transmission isdnpri. T1 or E1 ISDN Primary Rate service (supports both FAS and NFAS) ● 166 Administration for the Avaya G450 Media Gateway...
Page 167
Configuring SLS isdnext. NFAS T1 or E1 ISDN service for: ● T1 facility, in which all 24 channels are for bearer transport ● E1 facility, in which all 31 channels are for bearer transport ● 5. Enter set channel-numbering method to select the channel-numbering method for B-channels on an E1 interface, where method is one of the following values: seq.
Page 168
Australia (Australia National PRI) Japan Italy Netherlands Singapore Mexico Belgium Saudi Arabia United Kingdom (ETSI) Spain France (ETSI) Germany (ETSI) Czech Republic Russia Argentina Greece China Hong Kong Thailand Macedonia Poland Brazil 1 of 2 168 Administration for the Avaya G450 Media Gateway...
Page 169
Configuring SLS Table 47: ISDN Layer 3 country codes (continued) Country Country Code Nordic countries South Africa ETSI (no use of RESTART message) etsi QSIG qsig 2 of 2 10. For countries whose public networks allow for multiple ISDN Layer 3 country protocols for ISDN Primary Rate service, enter set protocol-version option to specify the mode (see Table...
Page 170
---- ---- --------- ------- ------- --------- ---- -------- --- ------ ---- --- v4 1544 isdnpri seq network user a country1 a speech ulaw 15. Enter exit to leave the ds1 context in SLS. 170 Administration for the Avaya G450 Media Gateway...
Configuring SLS Administering BRI parameters 1. Enter bri slot-address, where slot-address is any permitted port. The command line prompt changes to sls-bri <slot-address>. If you want to remove the BRI link from the SLS administration, enter exit to leave the second-level bri context and return to the (super-sls)# context, and then enter clear bri slot-address.
Page 172
-------- ------ ------- ---------- ------------- v401 user country1 speech ulaw Dir-NumberA Dir-NumberB Spid-A Spid-B ----------- ----------- -------------- -------------- 3033234567 3033234568 30332345671111 30332345681111 16. Enter exit to leave the bri context in SLS. 172 Administration for the Avaya G450 Media Gateway...
DID trunk, but not both. The maximum limits for a given trunk type are defined by the slot-configuration assignment for the G450. The maximum number of ports allowed per interface module is defined in Table...
Page 174
Configuring Standard Local Survivability (SLS) Table 49: G450 SLS group type assignments (continued) Group type Media module Number of Description of trunks that may be ports/channels assigned loop-start MM714 Ports 5, 6, 7, 8 ground-start MM714 Ports 1, 2, 3, 4...
Page 175
Configuring SLS 4. Enter add port module port sig-group to specify the G450 port or media module port that is compatible with the device and/or media module (see Table 50 for G450 analog trunks, and Table 51 for G450 digital trunks).
Page 176
Configuring Standard Local Survivability (SLS) Table 51: Trunk port values in SLS trunk-group context for the G450 (Digital Trunks) (continued) Group Type Media Module Maximum Ports/Channels e1-isdn MM710 30 (FAS) 31 (NFAS) t1-inband MM710 e1-inband MM710 2 of 2 Example If an MM711 is inserted into slot V3 and an analog loop-start trunk is to be ●...
Page 177
Configuring SLS auto-auto ● auto-wink ● 7. For an analog DID trunk group or DS1 non-ISDN tie trunk group, enter set digit-treatment digit-treat, where digit-treat can be one of the following values: blank (use this value to prevent any absorb or insert digit treatment from being ●...
Page 178
● restricted. The number is sent to the network as ”Presentation restricted” ● Note: For this release, specify method as no, since sending a Calling Party Number is Note: a future feature. 178 Administration for the Avaya G450 Media Gateway...
Page 179
Configuring SLS 17. For ISDN trunks, enter set numbering-format type to specify the numbering plan for this trunk in Standard Local Survivability (SLS). The numbering plan encodes the Numbering Plan Indicator and Type of Number fields in the Calling/Connected Party Number IE in the ISDN protocol.
3-digit gateway identifier, module is the 2-character slot identifier, and interface-id is the DS1 circuit number associated with the NFAS group. The value of interface-id is received from the network service provider. 180 Administration for the Avaya G450 Media Gateway...
Configuring SLS Note: The North American Public Network Service Providers do not allow any part of a Note: T1 to be shared outside of this NFAS-trunk group. In other words, they do not allow one of the T1 interfaces (of this NFAS group) to be fractionalized into two or more uses.
Note: Since the PIM application does not automatically extract this information from the Note: CM's SAT screen for Incoming-Digit-Treatment-Handling, you must enter this SLS information via the gateway CLI interface. 182 Administration for the Avaya G450 Media Gateway...
Page 183
Configuring SLS 1. Enter incoming-routing tgnum mode, where tgnum is an existing ISDN trunk group number and mode is the protocol used for receiving incoming digits. mode can be either enbloc or overlap. The command line prompt changes to sls-incoming-routing <tgnum>. If you want to remove the incoming routing treatment from the SLS administration, enter exit to leave the second-level incoming-routing context and return to the (super-sls)# context, and then enter clear internal-routing tgnum mode.
Configuring Standard Local Survivability (SLS) Summary of SLS configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 52: SLS CLI command hierarchy Root Level First Level Context Second Level Context Description Commands Commands Commands...
Page 185
Delete the administration for a given ISDN signaling group in SLS clear slot-config Delete the slot and the board administration in the G450 for SLS clear survivable-config Set the SLS parameters to their default values clear station Delete a particular extension number...
Page 186
Set the interface to agree with the companding method used by the far-end of the DS1 circuit for SLS mode set long-timer Increase the duration of the T303 (call establishment) timer in SLS 3 of 8 186 Administration for the Avaya G450 Media Gateway...
Page 187
Configuring SLS Table 52: SLS CLI command hierarchy (continued) Root Level First Level Context Second Level Context Description Commands Commands Commands set name Identify the user name for a DS1 facility in SLS set protocol-version Specify country protocol for countries whose public networks allow for multiple ISDN Layer 3 country protocols for ISDN Primary Rate service in SLS...
Page 188
List all administered signaling groups in SLS show slot-config Define the slot and the board administration in the G450 for SLS show station Display extension-specific SLS data parameters 5 of 8 188 Administration for the Avaya G450 Media Gateway...
Page 189
Configuring SLS Table 52: SLS CLI command hierarchy (continued) Root Level First Level Context Second Level Context Description Commands Commands Commands show trunk-group Display trunk group administration in sig-group Administer signaling groups for SLS add nfas-interface Identify a list of DS1 modules that are controlled by the primary D-channel in SLS remove nfas-interface...
Page 190
Elements to the user phone in SLS set dial Define the method for sending outbound digits in SLS set digit-handling Define how the inbound/outbound calls handle the transmission/reception of the dialed pattern in SLS 7 of 8 190 Administration for the Avaya G450 Media Gateway...
Page 191
Configuring SLS Table 52: SLS CLI command hierarchy (continued) Root Level First Level Context Second Level Context Description Commands Commands Commands set digits Define the inserted dial string that is added to the beginning of the received DID incoming dial string for analog DID trunks or for DS1 TIE trunks using in-band signaling in set digit-treatment...
Page 192
Configuring Standard Local Survivability (SLS) 192 Administration for the Avaya G450 Media Gateway...
Use a crossover network cable when you connect a computer or other endpoint device to the fixed router port. For all other Ethernet ports on the G450, you can use either a standard network cable or a crossover network cable to connect any device.
333. Switch Ethernet port commands Use the following commands for basic configuration of switch Ethernet ports. For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Use the set port auto-negotiation-flowcontrol-advertisement command ● to set the flow control advertisement for the specified port when performing auto-negotiation.
- force-false. The port is treated as if it were connected to shared media - auto. The G450 tries to automatically detect the connection type of the port Use the set port speed command to configure the speed of a port or range of ports. In ●...
Primary Management Interface (PMI). For more information, see Configuring the Primary ● Management Interface (PMI) on page 80. Advanced router features. For more information, see Configuring the router on page 443. ● 196 Administration for the Avaya G450 Media Gateway...
Configuring the WAN Ethernet port VoIP queuing. For more information, see Configuring QoS parameters on page 232. ● Access control policy lists and QoS policy lists. For more information, see Configuring ● policy on page 591. SNMP Link Up and Link Down traps. For more information, see Configuring SNMP ●...
Use the speed command to set the port speed. ● Summary of WAN Ethernet port configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 54: WAN Ethernet port configuration CLI commands Root level command...
The Avaya G450 Media Gateway can be configured to function as a DHCP (Dynamic Host Configuration Protocol) client. DHCP client enables the G450 to receive an IP address from a DHCP server, according to the DHCP client-server protocol. The DHCP server grants the G450 DHCP client an IP address for a fixed amount of time, called the lease.
Use the ip dhcp client client-id command to set the client identifier for the ● DHCP client. By default, the client identifier is usually the MAC address of the G450 FastEthernet interface. Use the ip dhcp client hostname command to set the hostname for the DHCP ●...
Page 201
01:00:04:0D:29:DC:68 Done! G450-001(config-if:FastEthernet 10/2)# ip dhcp client hostname “G450-A“ Done! G450-001(config-if:FastEthernet 10/2)# ip dhcp client lease 1 4 15 Done! G450-001(config-if:FastEthernet 10/2)# no ip dhcp client request domain-name Done! 3. Optionally, use the ip dhcp client route track command to apply an object tracker to monitor the DHCP client’s default route.
Use the renew dhcp command to renew a DHCP lease for an interface. This is ● effectively a request to renew an existing IP address, or the start of a new process of allocating a new IP address. For example: G450-001(super)# renew dhcp FastEthernet 10/2 Done! 202 Administration for the Avaya G450 Media Gateway...
Interface FastEthernet 10/2 assigned DHCP address 193.172.104.161, mask 255.255.255.0 Maintaining DHCP client For a full description of the commands and their output fields see Avaya G450 CLI Reference, 03-602056. Use the show ip dhcp-client command to show the configuration of the DHCP ●...
Configuring Ethernet ports Summary of DHCP client configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 55: DHCP client configuration CLI commands Root level Command Description command Clear the DHCP client statistics counters...
Configuring LLDP Table 55: DHCP client configuration CLI commands (continued) Root level Command Description command Display the configuration of the DHCP client show ip dhcp-client Display the DHCP client statistics counters show ip dhcp-client statistics 2 of 2 Configuring LLDP IEEE 802.1AB Link Layer Discovery Protocol (LLDP) simplifies troubleshooting of enterprise networks and enhances the ability of network management tools to discover and maintain accurate network topologies in multi-vendor environments.
1. Enable the LLDP agent globally using the set lldp system-control command. For example: G450-001(super)# set lldp system-control enable Done! The device’s global topology information, including all mandatory TLVs, is now available to neighboring devices supporting LLDP. 206 Administration for the Avaya G450 Media Gateway...
This allows you to advertise additional data about the device’s and port’s VLAN information, VLANs, and system capabilities. Additional TLVs are disabled by default. For example: G450-001(super)# set port lldp tlv 10/3 enable all Done! The device now advertises all mandatory and optional TLVs to neighboring network devices supporting LLDP.
Configuring Ethernet ports Summary of LLDP configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 56: LLDP configuration CLI commands Command Description Set the delay from when a port is set to LLDP "disable"...
System logging is a method of collecting system messages generated by system events. The Avaya G450 Media Gateway includes a logging package that collects system messages in several output types. Each of these types is called a sink. When the system generates a logging message, the message can be sent to each sink that you have enabled.
IP address of the Syslog server. If you do not define an access level, the default read-write level is used. For example: G450-001(super)# set logging server access-level read-only 147.2.3.66 Done! Only messages with the appropriate access level are sent to the Syslog output.
A header (Oct 11 22:14:15 host LINKDOWN in this example), providing the date ● and time, the hostname, and a message mnemonic. A message (SWICHFABRIC-Notification: Port 10/3 Link in this example), ● detailing the application being logged, the severity level, and the message text. 212 Administration for the Avaya G450 Media Gateway...
A log file is a file of data concerning a system event, saved in the flash memory. The log files serve as the system logging database, keeping an internal record of system events. 1. Enter set logging file enable. G450-001(super)# set logging file enable Done! 2. Optionally, define filters to limit the types of messages received (see...
Displaying conditions defined for the file output sink Enter show logging file condition. For example: G450-001(super)# show logging file condition ****************************************************** *** Message logging configuration of FILE sink *** Sink Is Enabled Sink default severity: Informational 214 Administration for the Avaya G450 Media Gateway...
A session log is the display of system messages on the terminal screen. It is automatically deleted when a session ends. 1. Enter set logging session enable. G450-001(super)# set logging session enable Done! Note: If the device is connected to several terminals, a separate session log is Note: established for each terminal.
The user enabling the log will only see entered commands with a user-level no Note: higher than the user’s own privileges. For example, a user with read-write privileges will not see entered commands having an admin user level. 216 Administration for the Avaya G450 Media Gateway...
218. ip address is the IP address of the Syslog server. ● For example: G450-001(super)# set logging server condition dialer critical 147.2.3.66 Done! G450-001(super)# set logging file condition dhcps warning Done! G450-001(super)# set logging session condition ISAKMP Information...
Informational message only debugging Message that only appears during debugging Sinks default severity levels Syslog. Warning ● Log file. Informational ● Session ● - Session from terminal. Informational - Session from telnet/ssh. Warning 218 Administration for the Avaya G450 Media Gateway...
Configuring logging filters Applications to be filtered Filters can be defined for any application listed in Table Table 59: Logging applications Application Description System startup failures boot Stack CASCADE mechanism cascade Call Detail Recording. Registers the active calls in SLS mode.
The following example defines a Syslog server with the following properties: IP address 147.2.3.66 ● Logging of messages enabled ● Output to the Kernel facility ● Only messages that can be viewed by read-write level users are received ● 220 Administration for the Avaya G450 Media Gateway...
G450-001(super)# set logging server facility kern 147.2.3.66 Done! G450-001(super)# set logging server access-level read-write 147.2.3.66 Done! G450-001(super)# set logging server condition all error 147.2.3.66 Done! Log file example The following example enables the logging of system messages to a log file in the flash memory...
! Severity Override ------------------------------------------- ISAKMP ! Informational Summary of Logging configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 60: Logging configuration CLI commands Command Description Delete the message log file being stored in non-volatile...
Page 223
Summary of Logging configuration CLI commands Table 60: Logging configuration CLI commands (continued) Command Description Define a new Syslog output server for remote logging of set logging server system messages Set the access level associated with a Syslog server set logging server sink access-level Set a filter for messages sent to the specified Syslog...
Page 224
Configuring logging 224 Administration for the Avaya G450 Media Gateway...
Configuring RTP and RTCP on page 225. You can use many types of telephones and trunks that do not directly support VoIP. The Avaya G450 Media Gateway translates voice and signalling data between VoIP and the system used by the telephones and trunks.
Configuring VoIP QoS The G450 offers both RTP header compression, for reducing the amount of bandwidth needed for voice traffic, and TCP and UDP header compression, for reducing the amount of bandwidth needed for non-voice traffic. For header compression purposes, any UDP packet with an even destination port within a user-configurable range of ports, is considered an RTP packet.
Configuring header compression Note: Non-IETF encapsulation is compatible with other vendors. Note: Configuring IPHC IHPC applies to RTP, TCP, and UDP headers. Note: You cannot specify IPHC for a Frame Relay non-IETF interface. Note: 1. Optionally, configure header compression parameters. If you do not configure these parameters, their default values are used.
Summary of IPHC header compression CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 62: IPHC configuration CLI commands Root level command First level command...
Configuring header compression Table 62: IPHC configuration CLI commands (continued) Root level command First level command Description Enter the Dialer or Serial interface context interface (dialer|serial) Control the number of Real-Time Transport ip rtp Protocol (RTP) connections supported on the compression- current interface connections...
Page 230
Once header compression is enabled, any change to a header compression Note: parameter is effective immediately. 3. To disable VJ TCP header compression on an interface, use the no ip tcp header-compression command in the interface context. 230 Administration for the Avaya G450 Media Gateway...
Displaying and clearing header compression statistics For a full description of the commands and their output fields, see Avaya G450 CLI Reference, 03-602056. Use the show ip rtp header-compression command to display the RTP header ●...
Use this command regardless of which compression method is employed. Configuring QoS parameters The G450 uses MGCP (H.248) protocol for call signalling and call routing information. Use the following commands to configure QoS for signalling and VoIP traffic. Use the set qos control command to define the source for QoS control parameters.
Use the show qos-rtcp command to display QoS, RSVP, and RTCP parameters. ● Summary of QoS, RSVP, and RTCP configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 64: QoS, RSVP and RTCP configuration CLI commands Command...
Use the show queueing command to display WFVQ configuration. ● Use the show queue command to display information about the real-time status of output ● queues for the current interface. 234 Administration for the Avaya G450 Media Gateway...
Priority queueing Summary of WFVQ configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 65: WFVQ configuration CLI commands Root level Command Description command Enter the Serial, FastEthernet, or interface Dialer interface configuration context...
Use the voip-queue-delay command to set the maximum queue delay for which to ● estimate the high priority queue size necessary to meet the queuing delay for a specific VoIP codec. Use the show queueing command to display the queueing configuration. ● 236 Administration for the Avaya G450 Media Gateway...
Priority queueing Summary of priority queueing configuration CLI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 66: Priority queueing configuration CLI commands Root level Command Description command Enter the Serial, FastEthernet, or interface Dialer interface configuration context...
Page 238
Configuring VoIP QoS 238 Administration for the Avaya G450 Media Gateway...
Chapter 10: Configuring the G450 for modem use You can connect either a USB or a serial modem to the Avaya G450 Media Gateway. A USB modem must be connected to the USB port on the G450 chassis. A serial modem must be connected to the Console port (CONSOLE) on the G450 chassis.
Page 240
- chap. Challenge Handshake Authentication Protocol. An encrypted password is sent for authentication. To configure this password, use the ppp chap-secret command. Note: If the G450 firmware is replaced by an earlier firmware version, the ppp Note: chap-secret is erased, and must be re-configured.
Configuring the USB port for modem use Summary of CLI commands for configuring the USB port for modem use For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 67: USB port configuration for modem use, CLI commands Root level...
Enter async mode interactive to set the Console port to use modem mode every time an Avaya proprietary modem cable is plugged into the Console port. If you do not want the Console port to automatically detect when a modem is connected to it, enter async mode terminal to disable interactive mode.
Use the load-interval command to set the load calculation interval for the interface. ● Summary of CLI commands for configuring the Console port for modem use For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 68: Console port configuration for modem use, CLI commands Root level Command...
Console port. The Console port uses the following settings: baud = 9600 ● data bits = 8 ● parity = none ● stop bits = 1 ● flow control = hardware ● 244 Administration for the Avaya G450 Media Gateway...
You can use an MM340 E1/T1 media module or an MM342 USP media module as an endpoint for a WAN line on the G450. You can also use a Fast Ethernet port on the G450 chassis as the endpoint for a WAN line by configuring the FastEthernet interface for PPP over Ethernet (PPPoE).
QoS lists change the DSCP and 802.1p priority of routed packets according to the packet characteristics. For more information, see Configuring policy on page 591. Each interface on the G450 can also have an active policy-based routing list. For more information, see Configuring policy-based routing on page 619.
Serial interface overview E1/T1 port channel group Figure 20 illustrates an E1/T1 port channel group. All data from the channel group is encapsulated using frame relay protocol. The data is sent via a frame relay Serial interface and sub-interfaces over the multiple IP interfaces defined using Data Link Connection Identifier (DLCI).
The Avaya G450 Media Gateway supports point-to-point frame relay connections. To enable you to use the G450 as an endpoint in a Point to Multi-Point (PTMP) topology, the G450 supports inverse ARP replies. The G450 responds to inverse ARP queries received on frame relay sub-interfaces with the proper inverse ARP replies.
2. Enter show ds-mode to check whether the G450 is configured for E1 or T1 operation. 3. Use the ds-mode command to set the mode of the G450 to E1 or T1. Changing the line type requires resetting the module. The default value is T1.
Page 250
8. Use the interface serial command to enter the Serial interface context. Specify the slot number of the media module, the port number, the channel group number, and optionally, the IP interface number. 250 Administration for the Avaya G450 Media Gateway...
Page 251
If you do not specify an IP interface number for the first Serial interface that you define on a channel group, the G450 automatically assigns IP interface number 0. For each additional Serial interface that you define on the channel group, use a different IP interface number.
Use the loopback diag command to activate or deactivate an inward diagnostic ● loopback signal on the controller interface. Use the loopback local command to activate or deactivate a local line or payload ● loopback signal on the controller interface. 252 Administration for the Avaya G450 Media Gateway...
This command is applicable only to a T1 line. Summary of E1/T1 ports configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 70: E1/T1 port configuration CLI commands Root level...
If you do not specify an IP interface number for the first Serial interface that you define on a port, the G450 automatically assigns IP interface number 0. For each additional Serial interface that you define on the port, use a different IP interface number. For example: - interface serial 3/1.
Page 255
G450, or the router on the WAN have a receive buffer that is not large enough to hold the traffic sent by the G450. In this case, configure transmitter-delay on the DCE equipment or the remote router in order to preserve the high performance that you had when transmitter-delay was configured to 0 on the G450.
Encoding Bandwidth 2,048 kbps Line-up indicator signal Summary of USP port configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 72: USP port configuration CLI commands Root level command Command Description Enter Serial interface or sub interface...
- ppp timeout ncp. Set the maximum time to wait for the network layer to negotiate. If this time is exceeded, the G450 restarts the PPP session. - ppp timeout retry. Set the maximum time to wait for a response during PPP negotiation.
A PPPoE client can establish a tunnel that carries PPP frames between a dialing host (the G450) and an access concentrator. This enables the use of PPP authentication protocols (CHAP and PAP). Unlike other tunneling protocols such as L2TP and PPTP, PPPoE works directly over Ethernet rather than IP.
Initial WAN configuration A typical broadband access network is based on ADSL modems configured as transparent Ethernet bridges. ADSL modems use ATM protocol, and the transparent bridging is done to a well known ATM VC. On the other side of the telephone line is a device called a DSLAM. The DSLAM terminates the ADSL physical layer, collects the ATM cells from the various ADSL subscribers, and places them on the SP ATM infrastructure.
Page 260
4. Configure an authentication method and parameters: - For PAP authenticating, enter ppp pap-sent username followed by a user name and password. For example: G450-001(super-if:FastEthernet 10/2)# ppp pap-sent username avaya32 password 123456 Done! - For CHAP authentication, enter ppp chap hostname followed by a hostname, and ppp chap password followed by a password.
Page 261
For more information on the PPoE commands, see Table 6. If the G450 is connected to the Internet via the FastEthernet interface configured for PPPoE, and you define a VPN tunnel which specifies remote hosts by name, it is recommended to use the ppp ipcp dns request command. The command requests the list of available DNS servers from the remote peer during the PPP/IPCP session.
Configuring WAN interfaces Summary of PPPoE commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 74: PPPoE CLI commands Root level command Command Description Enter the FastEthernet interface interface context fastethernet Change the encapsulation to PPPoE...
Configuring frame relay 1. Ensure that the port is configured on the media module: - For an E1/T1 port, see Configuring the Avaya MM340 E1/T1 WAN media module page 249 - For a USP port, see Configuring the Avaya MM342 USP WAN media module page 254 2.
Page 264
11. Enter exit to return to general context. The prompt returns to: G450-001(super)# 12. If needed, repeat Step 7 through Step 11 to configure additional frame relay sub-interfaces on the same Serial interface. 264 Administration for the Avaya G450 Media Gateway...
Use the show interfaces command to display interface configuration and statistics for a specific interface or for all interfaces. Summary of frame relay commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 75: Frame relay CLI commands Root level command...
DCD = up DSR = up DTR = up RTS = up CTS = up Use the show frame-relay pvc command to view detailed PVC information, or show ● frame-relay pvc brief for a brief summary of PVC configuration. 266 Administration for the Avaya G450 Media Gateway...
● Enter show startup-config to display the configuration loaded at startup. ● Use the ping command to send ICMP echo request packets from the G450 to the ● interface Serial peer IP address and verify that it responds. Use the ping command to send ICMP echo request packets to another node on the ●...
Serial interface on the same module, including interfaces on different serial ports. Note: A frame relay interface in a primary or backup role overrides the role of its Note: sub-interfaces. 268 Administration for the Avaya G450 Media Gateway...
For example, you can use the following command to switch over immediately to the backup interface in case of failure, and pause 60 seconds before reverting to the primary interface: G450-001(super)# interface fastethernet 10/2 G450-001(super-if:FastEthernet 10/2)# backup delay 0 60 Done! G450-001(super-if:FastEthernet 10/2)# Interface backup relations rules Each interface can have only one backup interface.
You can also use this command to set a delay before reverting back to the primary interface. For example, the following command causes the G450 to switch immediately to the backup interface in the event of primary interface failure, and to delay 60 seconds before...
Modem dial backup Modem dial backup The modem dial backup feature allows the Avaya G450 Media Gateway to utilize a modem to provide redundant connectivity between a G450 and IP phones in a small branch office and their primary Media Gateway Controller (MGC) at the headquarters or a regional branch office.
Page 272
Modem dial backup uses a modem connected directly to the G450’s USB or Console port. The modem can also be used to access the G450 CLI from a remote location. The modem cannot do both at the same time. For information about remote access to the G450 via modem, see Accessing the CLI via modem on page 46.
RAS server can use passive-OSPF-interface and the G450 can use static via routes. The G450 can call an ISP RAS (which is likely to assign it a dynamic IP address) and open ●...
When the Dialer interface is activated, the Dialer first attempts to dial the number associated with dialer string 1. If that attempt fails, the Dialer attempts to connect to the number associated with the next dialer string, and so on. 274 Administration for the Avaya G450 Media Gateway...
Page 275
5. Enter dialer persistent initial delay, with the value 30 seconds, to prevent dialup after boot, before the WAN link is fully functional. For example: G450-001(if:dialer 1)# dialer persistant initial delay 30 Done! 6. If needed, set any of the following parameters: Use the dialer persistent max-attempts command to set the maximum ●...
Page 276
7. Configure an authentication method and parameters (if required): - For PAP authenticating, enter ppp pap sent-username followed by a username and password. For example: G450-001(if:dialer 1)# ppp pap sent-username avaya32 password 123456 Done! - For CHAP authentication, enter ppp chap hostname followed by a hostname, and ppp chap password followed by a password.
Page 277
Dialer interface dials the number associated with the first dialer string. 10. From the general context, use the ip default-gateway dialer command to configure backup routing. The following example configures a simple low priority via static route: G450-001(super)# ip default-gateway dialer 1 1 low Done! Issue 1 January 2008...
Backup interfaces on page 268. The G450’s Console port is an RJ-45 asynchronous port that can be used to support the ● modem for dial backup. Thus, the Dialer can utilize the same serial modem that is used for remote access to the device.
The branch office is connected to the corporate network using a G450. IP phone users in the branch office connect to an MGC located in the headquarters data center, and an RAS is located in the headquarters data center, with multiple phone lines available for dial access.
Page 280
Configuring WAN interfaces Figure 24 shows the network topology. Figure 24: Modem dial backup configuration example 280 Administration for the Avaya G450 Media Gateway...
The initial delay prevents the Dialer from dialing out unnecessarily on reboot. The primary WAN interface often requires a few moments to register itself as up, and during that period, the initial delay prevents the device from activating the Dialer. 282 Administration for the Avaya G450 Media Gateway...
Page 283
The only modems supporting modem dial backup are the MultiTech ZBA series modems. For more information on configuring the Console and USB-modem interfaces to support modems, see Configuring the G450 for modem use on page 239.
Configuring WAN interfaces Modem dial backup maintenance The G450 generates specific log messages for Dialer interface activity when configured to do so. Certain dialer-related log messages are generated to aid you in troubleshooting problems with modem dial backup. In addition, messages generated by the modem and the PPP session are available to help with troubleshooting modem dial backup issues.
Page 285
Modem dial backup Table 78: Modem dial backup logging messages Log Message Severity Possible cause Action Dialer Messages – Messages generated by the Dialer interface Dialer 1 state is Debug The Dialer interface generates a None required. <state> message when a change in its operational state has been detected.
Page 286
When the timer expires, the Dialer 1 timer expired message is sent, and the Dialer begins attempting to connect to the remote modem again. 2 of 6 286 Administration for the Avaya G450 Media Gateway...
Page 287
Modem dial backup Table 78: Modem dial backup logging messages (continued) Log Message Severity Possible cause Action Dialer 1 Modem Warning This message is generated Troubleshooting steps: is not ready when the Dialer interface has Check modem ● been triggered and the cable connection operational state of the Dialer is to serial port.
Page 288
Initialization when the USB modem attempts Check modem ● string error to dial and has an incorrect configuration for initialization string. The attempt proper initialization to dial fails. string. 4 of 6 288 Administration for the Avaya G450 Media Gateway...
Page 289
Modem dial backup Table 78: Modem dial backup logging messages (continued) Log Message Severity Possible cause Action PPP Messages – Messages generated by the PPP session LCP Up/Down Informational LCP is used by PPP to initiate None required. and manage sessions. LCP is responsible for the initial establishment of the link, the configuration of the session, the...
Page 290
PPP as a static address session cannot begin passing IP or through traffic. Dynamic IP addressing or through IP unnumbered. 6 of 6 290 Administration for the Avaya G450 Media Gateway...
Modem dial backup Summary of modem dial backup commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 79: Modem dial backup CLI commands Root level Command Description command Enter the Dialer interface configuration interface context...
WAN, FastEthernet, Loopback, PPPoE, and Dialer PPP interfaces and Frame relay sub-interfaces. ICMP keepalive is still supported for backward compatibility. For information about object tracking, see Object tracking on page 298. 292 Administration for the Avaya G450 Media Gateway...
Page 293
Figure 25: G450 with T1 and xDSL lines For example, your branch office may have a G450 that connects to the Headquarters over a T1 line and via an xDSL connection to the Internet. The T1 line is used for voice traffic, while data packets are sent over the xDSL line.
Defining the ICMP keepalive parameters Use the following commands to define the ICMP keepalive parameters. For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Use the keepalive-icmp timeout command to set the timeout (in seconds) for ●...
Dynamic Call Admission Control (CAC) provides enhanced control over WAN bandwidth. When Dynamic CAC is enabled on an interface, the G450 informs the MGC of the actual bandwidth of the interface and instructs the MGC to block calls when the bandwidth is exhausted.
(optional). If dynamic CAC is activated on more than one active ● interface, the G450 reports the bearer bandwidth limit of the interface with the highest activation priority. You can set the activation priority to any number from 1 to 255. The default activation priority is 50.
Configuring WAN interfaces Summary of dynamic CAC configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 81: Dynamic CAC CLI commands Root level Command Description command Enter the Dialer, Serial, Loopback, interface FastEthernet, Tunnel, or VLAN interface...
Note: You can register either a VPN tunnel or an interface with an object tracker. For Note: more information see the definition of the keepalive-track command in the Avaya G450 CLI Reference, 03-602056. Issue 1 January 2008...
4. Optionally, use the dscp command to set the DSCP value in the IP header of the probe packet, thus setting the packets’ priority. If you do not configure this parameter, the default value of 48 is used. For example: G450-001(config-rtr icmp 5)# dscp 43 Done! 300 Administration for the Avaya G450 Media Gateway...
Page 301
The next-hop command is disabled by default. Use the next-hop command when the G450 is connected to a remote device via more than one interface, and you wish to monitor the state of one specific interface. When you specify the next-hop as the interface you wish to monitor, you ensure that the RTR will probe that interface.
50 as the unique ID for this object tracker. For example: G450-001(config)# track 1 rtr 5 G450-001(config-track rtr 1)# 2. Use the description command to enter a description for the object tracker. For example: G450-001(config-track rtr 1)# description "track rtr-5" Done! 302 Administration for the Avaya G450 Media Gateway...
Page 303
2. Use the description command to enter a description for the track list. For example: G450-001(config-track list 10)# description "track list rtr-5 and rtr-6" Done! 3. Use the object command to add an object tracker to the list.
Use the show rtr operational-state command to display the global operational ● status of the RTR feature, for a specific RTR operation or for all RTR operations. Use the show track command to display tracking information. ● 304 Administration for the Avaya G450 Media Gateway...
CLI-Notification: write: set logging session enable 2. Use the set logging session condition saa to view all RTR messages of level Info and above. For example: G450-001# set logging session condition saa Info Done! CLI-Notification: write: set logging session condition saa Info 3.
2. The second step is to configure an object tracker which tracks the state of RTR 5. For example: G450-001(config)# track 1 rtr 5 G450-001(config-track rtr 1)# description "track rtr-5" Done! G450-001(config-track rtr 1)# exit 306 Administration for the Avaya G450 Media Gateway...
1. The first step is to configure several RTRs. In this case, RTR 5 tracks the device at IP address 10.0.0.1, and RTR 6 tracks the device at IP address 20.0.0.1. For example: G450-001(config)# rtr 5 G450-001(config-rtr 5)# type echo protocol ipIcmpEcho 10.0.0.1 G450-001(config-rtr icmp 5)# wait-interval 2 seconds Done!
In this case, a Boolean OR argument is used. This means that the track list is up if either object tracker 1 or object tracker 2 is up. For example: G450-001(config)# track 10 list boolean or G450-001(config-track list 10)# description "track list rtr-5 and rtr-6" Done! G450-001(config-track list 10)# object 1...
Typical application – VPN failover using object tracking In this application, the G450 is connected to a remote site through an IPSec VPN tunnel. The remote site can be reached through two or more VPN gateways that can back each other up, such as a main gateway and a backup gateway.
Page 310
6.0.0.202 next-hop interface fastethernet 10/2 exit rtr-schedule 3 start-time now life forever rtr 4 type echo protocol ipIcmpEcho 6.0.0.203 next-hop interface fastethernet 10/2 exit rtr-schedule 4 start-time now life forever 310 Administration for the Avaya G450 Media Gateway...
Page 311
Object tracking ! Define four object trackers to track the four RTRs. track 1 rtr 1 exit track 2 rtr 2 exit track 3 rtr 3 exit track 4 rtr 4 exit ! Define a track list consisting of the four object trackers. ! Define a threshold calculation such that if all four object trackers ! are up, the list is up, and if 2 or less are up, the list is down.
WAN Fast Ethernet running DHCP client. It is necessary to define static routes in order to prevent loops. Therefore, the IP route command allows configuration of static routes over WAN Fast Ethernet running DHCP client. 312 Administration for the Avaya G450 Media Gateway...
Object tracking When the WAN Fast Ethernet is up, policy-based routing routes this traffic via the WAN FastEthernet interface. When the track list defined in the previous typical application is down, policy-based routing routes this traffic through the Serial interface 3/1:1. When the track list is up again, the traffic is again routed through the WAN FastEthernet interface.
10/2 ip dhcp client route track 2 exit Summary of object tracking configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 82: Object tracking CLI commands Root level First level Second level...
Page 315
Object tracking Table 82: Object tracking CLI commands (continued) Root level First level Second level Description command command command Set the DSCP value for the packets of dscp the RTR probes Set how many consecutive fail-retries unanswered probes change the status of an RTR operation device from up to down Set the frequency of the RTR probes...
Configuring WAN interfaces Frame relay encapsulation features The Avaya G450 Media Gateway supports the following frame relay encapsulation features: Frame relay traffic shaping and FRF.12 fragmentation ● Priority DLCI ● Note: The terms PVC (Permanent Virtual Circuit) and DLCI (Data Link Connection Note: Identifier) describe the same entity and are interchangeable.
Use the show map-class frame-relay command to display a table of all configured map-classes. Summary of frame relay traffic shaping commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 83: Frame relay traffic shaping CLI commands Root level command...
DLCI, it is recommended to verify that the primary DLCI is set as the High Priority DLCI in the Priority DLCI group. On the Avaya G450 Media Gateway, OSPF is mapped by default to the High Priority DLCI. For better network reliability, it is recommended to verify that the same configuration exists on the other side of the frame relay connection.
Priority DLCI Summary of priority DLCI commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 84: Priority DLCI CLI commands Root level Command Description command Enter the Serial interface or sub interface interface configuration context...
Configuring WAN interfaces Site A connection details Site A contains four IP phones and a G450 with S8300 and one MM342 media module. The MM342 media module connects the G450 to the WAN via a USP 128 Kbps V.35 interface. The...
Priority DLCI Configuration Example for Site A You can configure PPP VoIP on the G450 at Site A. Commands with footnotes are described at the end of the configuration procedure. Loopback and PMI interfaces configuration: ● G450-001# interface loopback 1 G450-001(if:Loopback 1)# ip address 149.49.54.82 24...
(4) At this stage the number of connections (20) depends on the number of phones. (5) At this stage you are matching the RTP port range to that of the G450. (6) At this stage the default queue size is 6, and since RTP is enabled you can double the VoIP queue size.
Page 323
Priority DLCI VoIP configuration: ● G450-001(if:Serial 4/1:1)# ip rtp header-compression G450-001(if:Serial 4/1:1)# ip rtp compression-connections 20 G450-001(if:Serial 4/1:1)# ip rtp port-range 2048 3028 G450-001(if:Serial 4/1:1)# exit Static routes configuration: ● G450-001# ip route 1.1.1.0 24 serial 4/1:1 G450-001# ip route 11.11.11.0 24 serial 4/1:1...
Page 324
Configuring WAN interfaces 324 Administration for the Avaya G450 Media Gateway...
(MM711, MM714, or MM716). The ETR panel provides up to five incoming Central Office (CO) trunk loops to 5 selected G450 analog lines. Thus, one ETR panel supports up to five emergency lines. You can cascade a second ETR panel, providing support for up to 10 emergency analog phones.
● Line status (off hook or on hook) ● Summary of ETR commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 85: ETR configuration CLI commands Command Description Enable Emergency Transfer Relay (ETR) mode, or allow the...
They allow SNMP managers to communicate with agents to configure, get statistics and information, and receive alerts from network devices. You can use any SNMP-compatible network management system to monitor and control a G450. Agent and manager communication There are several ways that the SNMP manager and the agent communicate.
● SNMPv3 ● The G450 supports all three versions. The implementation of SNMPv3 on the G450 is backwards compatible. That is, an agent that supports SNMPv3 will also support SNMPv1 and SNMPv2c. 328 Administration for the Avaya G450 Media Gateway...
SNMP versions SNMPv1 SNMPv1 uses community strings to limit access rights. Each SNMP device is assigned to a read community and a write community. To communicate with a device, you must send an SNMP packet with the relevant community name. By default, if you communicate with a device using only the read community, you are assigned the security name ReadCommN.
Use the no form of the snmp-server user command to remove a user and its mapping to a specified group. If you do not specify a group, the no form of the snmp-server user command removes the user from all groups. 330 Administration for the Avaya G450 Media Gateway...
The group maps its users to views based on the security model and level with which the user is communicating with the G450. Within a group, the following combinations of security model and level can be mapped to views: SNMPv1 security model and NoAuthNoPriv security level ●...
OIDs to the list or exclude OIDs from a list of all of the OIDs in the G450’s MIB tree. You can use wildcards to include or exclude an entire branch of OIDs in the MIB tree, using an asterisk instead of the specific node. For a list of MIBs...
You can add and remove addresses from the trap receivers table. In addition, you can limit the traps sent to specified receivers. You can also enable and disable link up/down traps on specified G450 interfaces. Use the following commands to configure the trap receivers table: Note: You need an Admin privilege level to use the SNMP commands.
ITC proprietary link down notifications ● supply. Main and backup power supply notifications ● Summary of SNMP trap configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 87: SNMP trap configuration CLI commands Root level command Command Description...
2 of 2 Configuring SNMP access Use the ip snmp command to enable SNMP access to the G450. Use the no form of this ● command to disable SNMP access to the G450. Use the set snmp retries command to set the number of times to attempt to ●...
Note: You need an Admin privilege level to use the SNMP commands. Note: Summary of SNMP access configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 88: SNMP access configuration CLI commands Command Description...
2 of 2 Configuring dynamic trap manager Dynamic trap manager is a special feature that ensures that the G450 sends traps directly to the currently active MGC. If the MGC fails, dynamic trap manager ensures that traps are sent to the backup MGC.
Use the clear dynamic-trap-manager command to remove administration of the dynamic trap manager. Summary of dynamic trap manager configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 89: Dynamic trap manager configuration CLI commands Command...
G450-001(super-if:FastEthernet 10/2)# no snmp trap link-status Done! The following example creates a read-only user: G450-001# snmp-server user joseph ReadOnlyG v3 auth md5 katmandu priv des56 ktamatan The following example creates a read-write user: G450-001# snmp-server user johnny ReadWriteG v3 auth md5 katmandu priv des56...
Page 341
The following example sets the SNMPv1 read-write community: G450-001(super)# set snmp community read-write write SNMP read-write community string set. The following example enables Link Up and Link Down traps on a LAN port on the G450: G450-001(super)# set port trap 6/5 enable Port 6/5 up/down trap enabled...
Page 342
Configuring SNMP 342 Administration for the Avaya G450 Media Gateway...
1. Connect an Avaya Partner Contact Closure Adjunct™ to the Contact Closure port on the Avaya G450 Media Gateway front panel. The Contact Closure port is labeled CCA on the G450 front panel. Use a telephone cable with standard RJ-11 connectors.
1. Enter the set contact-closure admin command. In the following example, the command sets contact closure to work in relay 1 of the Avaya Partner Contact Closure Adjunct™ when activated by the call controller. set contact-closure admin 10/1:1 mgc 2.
Showing contact closure status In the following example, the command deactivates contact closure in relay 2 of the Avaya Partner Contact Closure Adjunct™. Contact closure will not operate, even automatically, until you use the set contact-closure admin command to change the status of contact closure to mgc or manual-trigger.
Page 346
Configuring contact closure 346 Administration for the Avaya G450 Media Gateway...
Avaya Voice Announcement Manager (VAM) can be used to centrally manage announcement files for multiple voice systems, including G450 media gateways. VAM is designed to be installed on a customer-provided platform at a remote location. For information about VAM, see Avaya Voice Announcement Manager Reference, 14-300613.
Page 348
● announcement-file ftp command. Specify the file name of the announcement file in the G450 announcement directory, followed by the IP address of the remote FTP server, and, optionally, a destination file name, including the full path. For example: G450-001(super)# copy announcement-file ftp local_announcement2.wav 192.168.49.10 remote_announcement2.wav...
Page 349
Announcement file operations Display the announcements files stored in the G450 announcement directory, using the ● show announcements-files command. Optionally add the keyword brief to display less detail. For example: G450-001(super)# show announcements files Mode: FTP-SERVER/SCP-CLIENT File Description Size (Bytes) Date ---- ---------------- ------------- ------------ ----------------- 46xxupgrade.scr...
Transferring and managing announcement files Summary of announcement files commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 92: Announcement file CLI commands Command Description Upload an announcement file to a remote FTP copy announcement-file ftp...
Chapter 16: Configuring advanced switching You can configure advanced switching on the switch ports of the Avaya G450 Media Gateway. These are the ETH LAN ports located on the front panel. Configuring VLANs A VLAN is made up of a group of devices on one or more LANs that are configured so the devices operate as if they form an independent LAN.
VLAN for privacy. The whole building has a shared high-speed connection to the ISP. In order to accomplish this, the G450 enables multiple VLANs per port. The available Port Multi-VLAN binding modes are: Bound to Configured.
Configuring VLANs G450 VLAN table The G450 VLAN table lists all VLANs configured on the G450. You can configure up to 64 VLANs. To display a list of VLANs, use the show vlan command. When the VLAN table reaches its maximum capacity, you cannot configure any more VLANs. If this occurs, use the clear vlan command, followed by the name or number of the VLAN you want to delete, to free space in the VLAN table.
Use the show vlan command to display the VLANs configured in the switch ● VLAN configuration examples The following example deletes a statically bound VLAN from a port: G450-001(super)# clear port static-vlan 10/3 34 VLAN 34 is unbound from port 10/3 354 Administration for the Avaya G450 Media Gateway...
Page 355
G450-001(super)# no interface vlan 66 Done! The following example statically binds a VLAN to a port: G450-001(super)# set port vlan-binding-mode 10/3 static Set Port vlan binding method:10/3 The following example sets a port’s VLAN ID: G450-001(super)# set port vlan 54 10/3 Port 10/3 added to VLAN 54 The following example sets a port’s VLAN binding mode:...
Page 356
10/3 is bind to all configured VLANs The following example displays VLAN tagging information: G450-001(super)# show trunk Port Mode Binding mode Native VLAN ------ ----- ------------------------- ----------- 10/3 dot1q bound to configured VLANs 54 356 Administration for the Avaya G450 Media Gateway...
VLAN ID VLAN-name ------- -------------------------------- Marketing 2121 Training Total number of VLANs: 4 Summary of VLAN commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 93: VLAN CLI commands Root level First level Description command Command...
The secondary port takes over within one second and is activated when the primary port link stops functioning. Subsequent switchovers take place after the minimum time between switchovers has elapsed. To set the minimum time between switchovers, use the set port redundancy-intervals command. 358 Administration for the Avaya G450 Media Gateway...
Port redundancy CLI commands The following commands are used to configure port redundancy. For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Use the set port redundancy enable/disable command to globally enable or ●...
10/6 primary Minimum Time between Switchovers: 60 Switchback interval: 30 Summary of port redundancy commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 94: Port redundancy CLI commands Command Description Define or remove redundancy pairs...
(Tx), or transmitted and received (both) traffic. Port mirroring constraints You cannot use the LAN port on the G450 front panel or the WAN Fast Ethernet port on the G450 front panels in port mirroring. Port mirroring CLI commands The following commands are used to configure port mirroring on the G450.
Mirroring both Rx and Tx packets from port 10/5 to port 010/6 is enabled The following example disables port mirroring: G450-001(super)# clear port mirror Summary of port mirroring commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 95: Port mirroring CLI commands Command Description...
Spanning tree can take up to 30 seconds to open traffic on a port. This delay can cause problems on ports carrying time-sensitive traffic. You can, therefore, enable or disable spanning tree in the G450 on a per-port basis to minimize this effect. Rapid Spanning Tree Protocol (RSTP) The enhanced feature set of the 802.1w standard includes:...
Page 364
– to specify whether or not a port is considered an edge port. For example, the following command specifies that ports 10/5 and 10/6 are edge ports: G450-001(super)# set port edge admin state 10/5-6 edge-port The following command specifies that port 10/5 is not an edge port:...
For example, the following command specifies that ports 10/5 and 10/6 are treated as if they were connected point-to-point: G450-001(super)# set port point-to-point admin status 10/5-6 force-true All ports. Enter show port point-to-point status, followed by the module and ●...
Spanning tree default path costs is set to common spanning tree. The following example configures the time used when transferring the port to the forwarding state: G450-001(super)# set spantree forward-delay 16 bridge forward delay is set to 16. 366 Administration for the Avaya G450 Media Gateway...
Page 367
The following example configures the time interval between the generation of configuration BPDUs by the root: G450-001(super)# set spantree hello-time 2 bridge hello time is set to 2. The following example configures the amount of time an information message is kept before...
Configuring advanced switching Summary of spanning tree commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 96: Spanning tree CLI commands Command Description Assign or de-assign RSTP edge-port admin state to a set port edge admin state port for Rapid Spanning Tree Protocol (RSTP) treatment Specify a port’s connection type...
Port classification With the G450, you can classify any port as either regular or valuable. Classifying a port as valuable means that a link fault trap is sent in the event of a link failure. The trap is sent even when the port is disabled.
Configuring advanced switching The following example displays the port classification of all ports on the G450: G450-001(super)# show port classification Port Port Classification -------- ------------------------- 10/5 valuable 10/6 regular Summary of port classification commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437.
RMON agent on the management station. You can configure RMON for switching on the Avaya G450 Media Gateway. The G450 uses RMON I, which analyzes the MAC layer (Layer 2 in the OSI seven-layer model). You can also configure a port to raise an SNMP trap whenever the port fails.
1 was created successfully The following example creates an RMON event entry: G450-001(super)# rmon event 32 log description “Change of device” owner root event 32 was created successfully The following example creates an RMON history entry with an index of 80 on port 10/2, recording activity over 60 intervals (buckets) of 20 seconds each.
Page 373
Configuring RMON The following example displays information about an RMON alarm entry: G450-001(super)# show rmon alarm 1 alarm alarm 1 is active, owned by root Monitors ifEntry.1.16777216 every 20 seconds Taking delta samples, last value was 0 Rising threshold is 10000, assigned to event # 32...
Configuring monitoring applications Summary of RMON commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 98: RMON CLI commands Command Description Clear RMON statistics clear rmon statistics Create or delete an RMON alarm entry rmon alarm...
Configuring and analyzing RTP statistics Note: The gateway performs traceroutes whenever RTP statistics is enabled. Note: The RTP statistics application provides the following functionality: Collects QoS data from the gateway VoIP engine(s), including Real-Time Control Protocol ● (RTCP) data, traceroute reports, and information from the DSP regarding jitter buffer, internal delays, and so on Note: RTCP is a standard QoS report companion protocol to RTP.
The RTP statistics application samples the VoIP engine every RTCP interval, which is configured in Avaya Communication Manager, where it is called “RTCP Report Period”. The RTCP interval is typically 5 to 8 seconds. For information about configuring the RTCP interval (RTCP report period), see Administrator Guide for Avaya Communication Manager, 03-300509.
Page 377
Configuring and analyzing RTP statistics Viewing the configured thresholds 1. Enter show rtp-stat thresholds. For example: G450-001(super)# show rtp-stat thresholds Item Threshold Event Threshold -------------------- ------------- ----------------- Codec Loss 6.0% Average Codec Loss 3.0% Codec RTT 700mS Echo Return Loss Loss 6.0%...
Codec RTT metric indicates the overall delay experienced by the user. If you configure a meaningful threshold on the Codec RTT metric, metrics such as Local Jitter, Remote Jitter, and rtt metrics may help you identify causes when Codec RTT exceeds its threshold. 378 Administration for the Avaya G450 Media Gateway...
RTP session, the echo-return-loss event counter increments. 2. Use the rtp-stat event-threshold command to set thresholds on QoS events. For example: G450-001(super)# rtp-stat event-threshold echo-return-loss 2 Done! With this example configuration, if echo-return-loss is sampled over its threshold more than twice during an RTP session, the application considers the session to have QoS faults.
QoS fault and clear traps. Fault The QoS fault trap boundary. That is, the minimum number of active sessions with QoS faults that triggers a QoS fault trap. 1 of 2 380 Administration for the Avaya G450 Media Gateway...
Page 381
Configuring and analyzing RTP statistics Table 100: RTP statistics application configuration (continued) Name Description Clear The QoS clear trap boundary. That is, the reduced number of active sessions with QoS faults that triggers a QoS clear trap to be sent after a QoS fault trap was sent.
3. To configure an additional trap destination, such as an external trap manager, use the command snmp-server host. For example: G450-001(super)# snmp-server host 136.9.71.47 traps v1 public 382 Administration for the Avaya G450 Media Gateway...
QoS fault traps appear in the Network Management Console Event Log Browser, Note: indicating to the user that there are QoS problems in a specific network device. See the Avaya Network Management Console User Guide, 14-300169. Use the rtp-stat fault command. For example: ●...
G450-001(super)# show rtp-stat summary Total QoS traps: 23 QoS traps Drop : 0 Qos Fault Engine Active Total Mean Description Uptime Session Session Duration -------------- ----------- ------- ------- -------- ---- internal 04,18:15:15 35/24 01:04:44 384 Administration for the Avaya G450 Media Gateway...
See Configuring QoS fault and clear traps on page 383. Engine ID The ID of the VoIP engine. Since the G450 has one VoIP engine, one line appears in the table. Description Description of the VoIP engine Uptime The uptime of the RTP statistics application.
Page 386
, DSCP 184 , L2Pri 6 , RTCP 62 Remote-Statistics: Loss 0.0% , Avg-Loss 0.0% , Jitter 0mS , Avg-Jitter 0mS Echo-Cancellation: Loss 45dB , Len 32mS RSVP: Status Disabled , Failures 0 386 Administration for the Avaya G450 Media Gateway...
Page 387
● the session. Faulted. There are QoS ● problems in the session. EngineId The ID of the VoIP engine. The G450 EngineId: 0 has one VoIP engine. Start-Time The date of the RTP session 2004-10-20 The start time of the RTP session...
Page 388
The sampling interval Samples: 54 (5 sec) Codec: The codec used for the session G723 The RTP packet size, in bytes The RTP packet interval, in ms 30mS The encryption method 2 of 6 388 Administration for the Avaya G450 Media Gateway...
Page 389
Configuring and analyzing RTP statistics Table 102: Detailed CLI output per RTP session (continued) Field Label Description From the CLI example Silence The received silence suppression Silence-suppression (Tx/Rx) suppression method Disabled /Not-Supp (Tx/Rx) orted The transmitted silence suppression Silence-suppression (Tx/Rx) method Disabled/Not-Suppor Play-Time...
Page 390
Duplicates 0 consecutive RTP packets with the sample RTP sequence number are received. A large number of duplicates may indicate problems in the Layer 2/Ethernet topology (for example, loops). 4 of 6 390 Administration for the Avaya G450 Media Gateway...
Page 391
Configuring and analyzing RTP statistics Table 102: Detailed CLI output per RTP session (continued) Field Label Description From the CLI example Seq-Fall This counter increments each time an Seq-Fall 0 RTP packet with a sequence number less than the last known sequence is received.
The syslog messages are stored in the messages file on the MGC hard disk. You can view the syslog messages through the Avaya Maintenance Web Interface to debug the QoS problems. 1. In the Avaya Maintenance Web Interface, enter the Setup log viewing screen.
Configuring and analyzing RTP statistics Figure 32: Viewing syslog messages Analyzing QoS trap output The following is an example of the syslog message for the QoS trap sent upon termination of RTP session 35 (see the session ID in bold), which terminated at 11:13:40 on Oct. 20: Oct 20 11:13:40 LZ-SIT-SR1 snmptrapd[9407]: 135.8.118.252...
Page 394
This is also displayed by the show rtp-stat summary command. The number of times the application sampled the Stats{S 54} VoIP engine (RTP receiver) statistics 2 of 4 394 Administration for the Avaya G450 Media Gateway...
Page 395
Configuring and analyzing RTP statistics Table 103: QoS Trap output fields (continued) Label Description From the trap example The total number of received RTCP packets Stats{S 54 RTCP 54 9236} The total number of received RTP packets Stats{S 54 RTCP 54 RX 9236 The codec used for the session g723...
Page 397
Configuring and analyzing RTP statistics Table 104 describes the fields in the QoS fault and clear traps according to the numbered labels on the example above. Table 104: QoS fault and clear trap output fields Label Description From the QoS fault trap From the QoS clear trap example example...
The round trip time per probe packet. Three probe packets are sent per hop address, and the displayed value is the average of the three round-trip times. An asterisk (*) indicates that the probe packet timed out. 398 Administration for the Avaya G450 Media Gateway...
Figure 33 shows the locations of four telephone extensions in an example network. Telephones with extensions 2004 and 2111 are connected to the local gateway G450-001. Extensions 2002 and 2101 are connected to the remote gateway G450-002. Figure 33: Four telephones in a sample network...
Page 400
Configuring monitoring applications At the site of the local gateway “G450-001”, the administrator enabled and configured the RTP-MIB application as follows: //to enable the RTP statistics application: G450-001(super)# rtp-stat-service //to view the configuration of the application: G450-001(super)# show rtp-stat config...
Page 401
//to configure the minimum statistics window for evaluating packet loss: G450-001(super)# rtp-stat min-stat-win 50 //to configure an external trap manager as a trap destination in addition to the active MGC: G450-001(super)# snmp-server host 136.9.71.47 traps v1 public Issue 1 January 2008...
Page 402
QoS Trap: Enabled QoS Fault Trap: Enabled Fault: 2 Clear: 0 QoS Trap Rate Limiter: Token Interval: 10.00 seconds Bucket Size: 5 Session Table: Size: 128 Reserved: 64 Min Stat Win: 50 402 Administration for the Avaya G450 Media Gateway...
Configuring and analyzing RTP statistics A call over the WAN from an analog phone to an IP phone At 00:39 on December 7, 2004, a call is placed from analog extension 2111 to IP phone extension 2002 (see Figure 34) in the network described in Configuring the RTP statistics application for a sample network on page 399.
Page 404
Transmitted-RTP: VLAN 1, DSCP 46, L2Pri 6, RTCP 17 Remote-Statistics: Loss 11.6% #14 , Avg-Loss 8.9%, Jitter 33mS #0, Avg-Jitter 26mS Echo-Cancellation: Loss 49dB #0, Len 32mS RSVP: Status Disabled, Failures 0 404 Administration for the Avaya G450 Media Gateway...
Configuring and analyzing RTP statistics A few points to note: The asterisk in the show rtp sessions output indicates that session 1 has QoS faults ● The QoS is described as Faulted because there were QoS faults [2] ● QoS faults that can be seen in the output are: ●...
Page 406
All average metric values are below the average thresholds [4] [5] [6] [8] [10] [12] [14] [16] ● All event counters are zero [3] [5] [7] [9] [11] [13] [15] [17] ● 406 Administration for the Avaya G450 Media Gateway...
2004-12-07,01:02:50 01:05:15 G711U 30.30.30.2 Sessions 13 and 14 both belong to the call, since two VoIP channels are used by an unshuffled call between two IP phones: one channel between each telephone and the G450 VoIP engine. Issue 1 January 2008...
Page 408
Transmitted-RTP: VLAN 1, DSCP 46, L2Pri 6, RTCP 27 Remote-Statistics: Loss 0.4% #17 , Avg-Loss 6.5%, Jitter 3mS #0, Avg-Jitter 22mS Echo-Cancellation: Loss 49dB #0, Len 32mS RSVP: Status Disabled, Failures 0 408 Administration for the Avaya G450 Media Gateway...
Page 409
Configuring and analyzing RTP statistics Session 14 is free of QoS problems: //to display details of session 14: G450-001(super)# show rtp-stat detailed 14 Session-ID: 14 Status: Terminated, QOS: Ok, EngineId: 0 Start-Time: 2004-12-07,01:02:50, End-Time: 2004-12-07,01:05:15 Duration: 00:02:25 CName: gwp@30.30.30.1 Phone: 202:2002 Local-Address: 30.30.30.1:2165 SSRC 247950253...
//to display the RTP sessions: G450-001(super)# show rtp sessions QoS Start date and time End Time Type Destination ----- --- ------------------- -------- --------------- --------------- 00001 2004-12-23,09:55:17 G729 16.16.16.101 00002 2004-12-23,09:55:20 G711U 149.49.41.50 410 Administration for the Avaya G450 Media Gateway...
Page 411
Loss 0.0% #0, Avg-Loss 0.0%, Jitter 2mS #0, Avg-Jitter 1mS Echo-Cancellation: Loss 49dB #0, Len 0mS RSVP: Status Reserved, Failures 0 //to display details of session 2: G450-001(super)# show rtp detailed 2 Session-ID: 2 Status: Active, QOS: Ok, EngineId: 0 Start-Time: 2004-12-23,09:55:20, End-Time: - Duration: 00:00:50 CName: gwp@33.33.33.33...
The conference ID that appears in the Phone string for session 1 and for session 2 is identical, which identifies the two sessions as belonging to the same conference call [1] [2]. Summary of RTP statistics commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 106: RTP statistics application CLI commands Command...
In addition, the G450’s packet sniffing service is capable of capturing non-Ethernet packets, such as frame-relay and PPP. Non-Ethernet packets are wrapped in a dummy Ethernet header to allow them to be viewed in a libpcap format. Thus, the G450 allows you to analyze packets on all the interfaces of the device.
Configuring monitoring applications The G450’s packet sniffing service gives you full control over the memory usage of the sniffer. You can set a maximum limit for the capture buffer size, configure a circular buffer so that older information is overwritten when the buffer fills up, and specify a maximum number of bytes to capture for each packet.
Enabling packet sniffing Since the packet sniffing service presents a potential security breach, the administrator must first enable the service on the G450 before a user can start capturing packets. Enter capture-service to enable the packet sniffing service. Note:...
A capture list contains an ordered list of rules and actions. A rule specifies criteria against which packets are tested. The action tells the G450 whether to capture or not capture packets matching the rule criteria. Only packets that match the specified criteria and have an action of capture are captured to the capture file.
Page 417
For example, the following commands create a rule (rule 10 in capture list 510) that determines that TCP packets are not captured: G450-001(super)# ip capture-list 510 G450-001(super-Capture 510)# ip-rule 10 G450-001(super-Capture 510/ip rule 10)# composite-operation no-capture Done! G450-001(super-Capture 510/ip rule 10)# ip-protocol tcp Done!
Page 418
Use the source-ip command to apply the rule to packets from the specified IP address or range of addresses. Use the destination-ip command to apply the rule to packets going to the specified IP address or range of addresses. 418 Administration for the Avaya G450 Media Gateway...
Page 419
To apply the rule to all source or destination IP addresses except the specified address or range of addresses, use the not form of the applicable command. For example: G450-001(super-Capture 520/ip rule 20)# not destination-ip 135.64.102.0 0.0.255.255 Done! G450-001(super-Capture 520/ip rule 20)#...
Page 420
Range. Type range, followed by two port numbers, to set a range of port numbers to ● which the rule applies. For example: G450-001(super-Capture 520/ip rule 20)# tcp destination-port range 1 3 Done! G450-001(super-Capture 520/ip rule 20)# Equal. Type eq, followed by a port name or number, to set a port name or port number to ●...
Page 421
G450-001(super-Capture 520/ip rule 20)# To apply the rule to all ICMP packets except the specified type and code, use the not form of this command. For example: G450-001(super-Capture 520/ip rule 20)# not icmp 1 2 Done! G450-001(super-Capture 520/ip rule 20)# Fragment To apply the rule to non-initial fragments, enter fragment.
Page 422
G450-001(super-Capture 511/ip rule 10)# composite-operation no-capture Done! G450-001(super-Capture 511/ip rule 10)# ip-protocol tcp Done! ! You can use a port number instead of "telenet" (23). G450-001(super-Capture 511/ip rule 10)# tcp destination-port eq telnet Done! G450-001(super-Capture 511/ip rule 10)# exit G450-001(super-Capture 511)# G450-001(super-Capture 511)# ip-rule 15...
Applying a capture list To apply a capture list, use the capture filter-group command from the general context. For example, to set the G450 to use capture list 511 on interfaces in which packet sniffing is enabled, specify the following command:...
- do you want to continue (Y/N)? y Done! G450-001(super)# Note: When you change the maximum frame size, the G450 clears the capture buffer. Note: Enter clear capture-buffer to clear the capture buffer. ● 424 Administration for the Avaya G450 Media Gateway...
If you do not use the capture filter-group command, the packet sniffing service captures all packets. If packet sniffing has been enabled by the administrator, the following appears: G450-001(super)# capture start Starting the packet sniffing process G450-001(super)#...
You can use the show capture-buffer hex command to view a hex dump of the captured packets. However, for a proper analysis of the captured packets, you should upload the capture file and analyze it using a sniffer application, as described in the following sections. 426 Administration for the Avaya G450 Media Gateway...
Configuring and analyzing packet sniffing The following is an example of the show capture-buffer hex command: G450-001> show capture-buffer hex Frame number: 1 Time relative to first frame (D H:M:S:Micro-S): 0, 0:0:0.0 Packet time: 14/01/1970-13:24:55.583598 Frame length: 60 bytes Capture Length: 60 bytes 00000000:ffff ffff ffff 0040 0da9 4201 0806 0001 ..@..B..
Page 428
2. Open the Avaya Maintenance Web Interface. For instructions on accessing the Avaya Maintenance Web Interface, see Installing and Upgrading the Avaya G450 Media Gateway, 03-602054. 3. In the Avaya Maintenance Web Interface, select FTP under Security in the main menu. 4. Click Start Server. 5. Log into the G450.
Configuring and analyzing packet sniffing 9. Optionally, enter show upload status 10 to view upload status. For example: G450-001(super)# show upload status 10 Module #10 =========== Module : 10 Source file : sniffer Destination file : pub/capfile.cap Host : 149.49.43.96...
Page 430
Figure 38: Sample Ethereal screen Identifying the interface The G450’s packet sniffing service can capture also non-Ethernet packets, such as frame-relay and PPP, into the capture file. This is achieved by wrapping non-Ethernet packets in a dummy Ethernet header to allow the packets to be stored in a libpcap format. This enables you to analyze packets on all the device interfaces.
Note: Ethernet packets received on a VLAN interface are identified by their VLAN tag. Note: However, decrypted IPSec packets received on a VLAN interface are stored with a dummy header. G450-001> show capture-dummy-headers Description ----------------- ---------------------------------------------------- 00:00:01:00:00:00 Src/dst address of Packet to/from frame-relay or PPP...
Configuring monitoring applications Summary of packet sniffing commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 107: Packet sniffing CLI commands Root level First level Second level Description command command command Set the capture buffer to cyclic...
Page 433
Configuring and analyzing packet sniffing Table 107: Packet sniffing CLI commands (continued) Root level First level Second level Description command command command Upload the packet sniffing buffer to copy a file on a remote TFTP server capture-file tftp Upload the capture file to a USB copy mass storage device capture-file...
FastEthernet 10/2 is up, line protocol is down However, if normal keepalive reports that the connection is up but ICMP keepalive fails, the following is displayed: FastEthernet 10/2 is up, line protocol is down (no KeepAlive) 434 Administration for the Avaya G450 Media Gateway...
For detailed specifications of CLI commands, refer to Avaya G450 CLI Reference, 03-602056. Summary of interface status commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 109: Interface status CLI commands...
Performs the specified test using the parameter values passed in the test request ● Upon successful completion of the test, sends the test results to the analyzer of the ● chatterbox whose IP address is designated in the test request 436 Administration for the Avaya G450 Media Gateway...
Configuring the G450 test plug for registration From the G450 CLI, you can configure the G450 test plug to register with a CNA scheduler. 1. Use the cna-testplug command to enter the testplug context. For example: G450-001# cna-testplug 1...
Page 438
The test plug attempts to register with the first scheduler on the scheduler list. You can use the show cna testplug command to see if the test plug is registered and to view test plug statistics counters. 438 Administration for the Avaya G450 Media Gateway...
//to enter the test plug context: G450-001(super)# cna testplug 1 //to configure entries 3 and 1 on the scheduler list: G450-001(super-cna testplug 1)# scheduler 3 135.64.102.76 Done! G450-001(super-cna testplug 1)# scheduler 1 1.1.1.1 Done! //to change the configuration of scheduler 1: G450-001(super-cna testplug 1)# scheduler 1 1.1.1.2...
Page 440
Test rate limiter: Maximum 60 tests in 10 seconds Last Test: traceroute to 135.64.103.107 Result: ip1=149.49.75.178 ip2=135.64.103.107 ttl_len = 4 Test Count Failed Cancelled ---------- ------ ------ --------- traceroute ping tcpconnect merge 440 Administration for the Avaya G450 Media Gateway...
G450-001(cna-testplug 1)# clear counters All CNA test plug counters are cleared. Summary of CNA test plug commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 111: CNA test plug CLI commands Root level command Command...
Page 442
Configuring monitoring applications 442 Administration for the Avaya G450 Media Gateway...
Chapter 18: Configuring the router The Avaya G450 Media Gateway has an internal router. You can configure the following routing features on the router: Interfaces ● Unnumbered IP interfaces ● Routing table ● GRE tunneling ● DHCP and BOOTP relay ●...
VLAN (Vlan 1). When you configure the G450 without an external VPN or firewall, Vlan 1 is used to connect the internal G450 router to the internal G450 switch. If an external firewall or VPN is connected to the Fast Ethernet port, it is important to disable Vlan 1 to prevent a direct flow of packets from the WAN to the LAN.
VLAN (on the Switching Interface). The G450 switch can have multiple VLANs defined ● within its switching fabric. The G450 router supports up to 64 VLANs that can be configured over their internal switching interface connections. Serial Interface. The Serial interface is a virtual interface that is created over a portion of ●...
Use the show interface brief command to display a summary of the configuration information for a specific interface or for all of the interfaces. Summary of basic interface configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 112: Basic interface configuration CLI commands Root level...
Page 447
Configuring interfaces Table 112: Basic interface configuration CLI commands (continued) Root level Command Description command Assign an IP address and mask to an interface ip address or delete an interface Set the administrative state of an IP interface ip admin-state Update the interface broadcast address ip broadcast- address...
Modem dial-backup requires unnumbered IP to be configured on the Dialer interface of the branch gateway and at both the default and the backup dialing destinations. 448 Administration for the Avaya G450 Media Gateway...
LOCAL 180.0.0.0 Loopback 1 180.0.0.1 LOCAL Summary of unnumbered IP interface configuration commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 113: Unnumbered IP interface configuration CLI commands Root level Command Description command Enter the Dialer, Serial, or Tunnel...
Routing sources Routing sources The G450 router supports both static and dynamic routing per interface. You can configure static routes with two levels of priority, high and low, and you can enable and configure Open Shortest Path First (OSPF) and Routing Information Protocol (RIP) dynamic routing protocols.
Next-hop IP address. Specifies the IP address of a router as a next hop. The next hop ● router must belong to one of the directly attached networks for which the Avaya G450 Media Gateway has an IP interface. Static route types Two kinds of static routes can be configured: High Preference static routes.
Configuring the routing table Note: If you apply tracking to a static route, you can only configure one next hop for the Note: route. Next hops can only be added to an existing static route if they have the same preference and metric as the currently defined next hops.
199. Permanent static route The Avaya G450 Media Gateway enables you to configure a static route as a permanent route. Configuring this option prevents the static route from becoming inactive when the underlying Layer 2 interface is down. This prevents routing table updates from being sent each time an interface goes up or down when there is a fluctuating Layer 2 interface on the static route.
Enter traceroute, followed by an IP address, to trace the route an IP packet would ● follow to the specified IP address. The G450 traces the route by launching UDP probe packets with a small TTL, then listening for an ICMP time exceeded reply from a gateway.
Configuring the router Summary of routing table commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 114: Routing table CLI commands Command Description Delete all the dynamic routing entries from the routing table clear ip route...
Configuring GRE tunneling A GRE tunnel is set up as an IP interface, which allows you to use the GRE tunnel as a routing destination. A GRE tunnel can transport multicast packets, which allows it to work with routing protocols such as RIP and OSPF. To set up a GRE tunnel, you must create the interface and assign it an IP address, a tunnel source address, and a tunnel destination address.
In addition to checking for nested tunneling, the G450 prevents loops in connection with GRE tunnels by preventing the same packet from being encapsulated more than once in the G450.
2 and activate it on the router RIP with the matching interface: G450-001(super)# ip distribution access-list-name 1 "list #1" Done! G450-001(super)# ip distribution access-default-action 1 default-action-permit Done! G450-001(super)# ip distribution access-list 1 10 "deny" 192.68.1.0 0.0.0.255 Done! G450-001(super)# router rip G450-001(super router:rip)# distribution-list 1 out FastEthernet 10/2 Done!
1 and activate it on the router RIP with the matching interface: G450-001(super)# ip distribution access-list-name 1 "list #1" Done! G450-001(super)# ip distribution access-default-action 1 default-action-permit Done! G450-001(super)# ip distribution access-list 1 10 "deny" 192.68.1.0 0.0.0.255 Done! G450-001(super)# router rip G450-001(super router:rip)# distribution-list 1 in FastEthernet 10/2 Done!
G450-001# interface tunnel 1 G450-001(if:Tunnel 1)# keepalive 20 3 Done! Note: You do not have to configure tunnel keepalive on both sides of the tunnel.
The Avaya G450 Media Gateway does not check whether the configured tunnel Note: source IP address is an existing IP address registered with the G450 router. 4. In most cases, it is recommended to configure keepalive in the tunnel so that the tunnel’s source interface can determine and inform the host if the tunnel is down.
Additional GRE tunnel parameters Use the following commands to configure additional GRE tunnel parameters. For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Use the tunnel checksum command in the GRE Tunnel interface context to add a ●...
Internet. Instead, Router 1 receives the packet from host 1, looks up the packet’s destination address in its routing table, and determines that the next hop to the destination address is the remote end of the GRE tunnel. 464 Administration for the Avaya G450 Media Gateway...
Configuring the router Summary of GRE tunneling commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 115: GRE tunneling CLI commands Root level Command Description command Enter tunnel interface configuration context, interface create a Tunnel interface if it does not exist, or...
DHCP and BOOTP packets. The router also relays replies from the server back to the client. The G450 can alternatively function as a DHCP server, providing DHCP service to local devices. For information about configuring DHCP server on the G450, see...
Note: protocols. When there is more than one IP interface on a VLAN, the G450 chooses the lowest IP address on this VLAN when relaying DHCP/BOOTP requests. The DHCP/BOOTP server then uses this address to decide the network from which to allocate the address. When there are multiple networks configured, the G450 performs a round-robin selection process.
Use the no form of this command to remove a server. You must be in an interface context to use this command. Summary of DHCP and BOOTP relay commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 116: DHCP and BOOTP relay CLI commands Root level...
DHCP requests by data devices are routed to a central remote DHCP server using DHCP relay. The Avaya G450 Media Gateway can function as a DHCP server or as a DHCP client, or both simultaneously. For information about configuring DHCP client on the G450, see...
Create a minimum of two dynamic pools: at least one pool for data devices (PCs) and at least one pool for voice devices (IP phones). The G450 also supports reservation pools, which map hardware addresses/client identifiers to specific IP addresses. Reservation pools may be required for security issues or VPN appliances.
256 IP addresses, you must first use the no start ip address and no end ip address commands before configuring the new start and end IP addresses. 472 Administration for the Avaya G450 Media Gateway...
Configuring DHCP server Configuring Options DHCP options are various types of network configuration information that the DHCP client can receive from the DHCP server. The G450 supports all DHCP options. The most common options used for IP phones are listed in Table 117.
Use the next-server command to specify the IP address of the next server in the boot ● process of a DHCP client. Use the server-name command to specify the optional server name in the boot process ● of a DHCP client. 474 Administration for the Avaya G450 Media Gateway...
Page 476
The following example configures a vendor-specific option for DHCP pool 5: G450-001(super-DHCP 5)# vendor-specific-option 1 G450-001(super-DHCP 5/vendor specific 1)# class-identifier "ccp.avaya.com" Done! G450-001(super-DHCP 5/vendor specific 1)# value raw ascii "gfdgfd" Done! G450-001(super-DHCP 5/vendor specific 1)# exit G450-001(super-DHCP 5)# 476 Administration for the Avaya G450 Media Gateway...
Configuring DHCP server The following example defines a reservation pool for data devices: G450-001(super)# ip dhcp pool 3 G450-001(super-DHCP 3)# name "Data 1 Server" Done! G450-001(super-DHCP 3)# start-ip-addr 135.64.20.61 Done! G450-001(super-DHCP 3)# end-ip-addr 135.64.20.61 Done! G450-001(super-DHCP 3)# subnet-mask 27 Done!
Configuring the router Summary of DHCP Server commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 118: DHCP server CLI commands Root level First level Second level Description command command command Delete IP address binding...
Page 479
Configuring DHCP server Table 118: DHCP server CLI commands (continued) Root level First level Second level Description command command command Set the end IP address of the end-ip-addr range of available IP addresses that the DHCP server may assign to clients Configure the lease period for IP lease address assignment...
For each interface on the Avaya G450 Media Gateway, you can configure whether the G450 forwards directed broadcast packets to the network address or subnet mask address of the interface.
Network Basic Input Output System (NetBIOS) is a protocol for sharing resources among desktop computers on a LAN. You can configure the Avaya G450 Media Gateway to relay NetBIOS UDP broadcast packets. This feature is used for applications such as WINS that use broadcast but might need to communicate with stations on other subnetworks or VLANs.
Static ARP table entries do not expire. You add static ARP table entries manually using the arp command. For example, to add a static ARP table entry for station 192.168.7.8 with MAC address 00:40:0d:8c:2a:01, use the following command: G450-001# arp 192.168.7.8 00:40:0d:8c:2a:01 482 Administration for the Avaya G450 Media Gateway...
Page 483
ARP table entries: Use the no arp command to remove static and dynamic entries from the ARP table. For example, to remove the ARP table entry for the station 192.168.13.76: G450-001# no arp 192.168.13.76 Issue 1 January 2008...
Use the show ip reverse-arp command to display the IP address of a host, based on ● a known MAC address. Summary of ARP table commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 120: ARP table CLI commands Command Description...
2 of 2 Enabling proxy ARP The G450 supports proxy ARP. Proxy ARP is a technique by which a router provides a false identity when answering ARP requests intended for another device. By falsifying its identify, the router accepts responsibility for routing packets to their true destination.
492. You can configure route redistribution between OSPF, RIP, and static routes. With route redistribution, you can configure the G450 to redistribute routes learned from one protocol into the domain of the other routing protocol. For more information, see Route redistribution page 497.
Internet. However the very simplicity of RIP has a disadvantage. This protocol does not take into account network bandwidth, physical cost, and data priority. The Avaya G450 Media Gateway supports two versions of RIP: RIPv1 ●...
You can assign the rules per interface and per direction. Up to 99 RIP distribution access lists can be configured on the Avaya G450 Media Gateway. For example, to configure RIP distribution access list number 10 permitting distribution and learning of network 10.10.0.0, do the following:...
That is, RIPv1 and RIPv2 routers should not be configured on the same subnetwork. However, you can configure different IP interfaces of the G450 with different RIP versions. This configuration is valid as long as all routers on the subnet are configured with the same version.
Use the timers basic command to set RIP timers. Use the no form of this command to ● set the RIP timers to their default values. Summary of RIP commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 124: RIP CLI commands Root level command Command...
Page 491
Configuring RIP Table 124: RIP CLI commands (continued) Root level command Command Description Set the authentication string used ip rip on the interface authentication Specify the type of authentication ip rip used in RIP v2 packets authentication mode Enable learning of the default route ip rip received by the RIP protocol.
(topography). You can configure route redistribution between OSPF, RIP, and static routes. With route redistribution, you can configure the G450 to redistribute routes learned from one protocol into the domain of the other routing protocol. For more information, see Route redistribution page 497.
Configuring OSPF OSPF dynamic Cost An OSPF interface on the G450 can dynamically set a Cost. The Cost represents the price assigned to each interface for purposes of determining the shortest path. By default the OSPF interface Cost is calculated based on the interface bandwidth, according to...
Page 494
Use the show ip ospf database command to display lists of information related to the ● OSPF database for a specific router. Use the show ip ospf interface command to display the OSPF-related interface ● information. 494 Administration for the Avaya G450 Media Gateway...
Use the timers spf command to configure the delay between runs of OSPFs (SPF) ● calculation. Use the no form of this command to restore the default value. Summary of OSPF commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 125: OSPF CLI commands Root level command Command...
Page 496
Display the OSPF-related interface show ip ospf information interface Display OSPF neighbor show ip ospf information on a per-interface neighbor basis Display OSPF parameters and show ip protocols statistics 2 of 2 496 Administration for the Avaya G450 Media Gateway...
OSPF. Export default metric The Avaya G450 Media Gateway enables you to configure the metric to be used in updates that are redistributed from one routing protocol to another. In RIP, the default is 1 and the maximum value is 16. In OSPF, the default is 20.
Router RIP or Router OSPF contexts. This value is used for all types of redistributed routes, regardless of the protocol from which the route was learned. Summary of route redistribution commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 126: Route redistribution CLI commands Root level...
Configuring VRRP The concept underlying VRRP is that a router can back up other routers, in addition to performing its primary routing functions. This redundancy is achieved by introducing the concept of a virtual router. A virtual router is a routing entity associated with multiple physical routers.
Configuring the router There is one main router on IP subnet 20.20.20.0, such as a G450, C363T, C364T, or any router that supports VRRP, and a backup router. You can configure more backup routers. The G450 itself must have an interface on the IP subnetwork, for example, 20.20.20.2 ●...
● VRRP routing. Use the show ip vrrp command to display VRRP information. ● Summary of VRRP commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 127: VRRP CLI commands Root level Command Description command...
2 of 2 Configuring fragmentation The G450 supports IP fragmentation and reassembly. The G450 router can fragment and reassemble IP packets according to RFC 791. This feature allows the router to send and receive large IP packets where the underlying data link protocol constrains the Maximum Transport Unit (MTU).
Enter show fragment to display information regarding fragmented IP packets that are ● destined to a router. Summary of fragmentation commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 128: Fragmentation CLI commands Command Description...
Page 504
Configuring the router 504 Administration for the Avaya G450 Media Gateway...
IPSec SAs secure the actual traffic between the protected networks behind the peers, while the IKE SA only secures the key exchanges that generate the IPSec SAs between the peers. The G450 IPSec VPN feature is designed to support site-to-site topologies, in which the two peers are gateways.
The basic IPSec VPN building blocks define how to secure packets, as follows: ISAKMP policies. Define parameters for IKE phase 1 negotiation ● Transform-sets. Define parameters for IKE phase 2 negotiation ● 506 Administration for the Avaya G450 Media Gateway...
Page 507
Once the building blocks are defined, IPSec VPN is implemented using a crypto list. The crypto list defines, for the interface to which it applies, which packets should be secured and how, as follows: Each rule in the crypto list points to a crypto-map. A crypto-map points to a transform-set, and to a peer or peer-group.
4. Enter copy running-config startup-config to save your current configuration. 5. Reset using the reset command. Configuring IPSec VPN Prerequisites As a prerequisite to configuring IPSec VPN, a valid VPN license must be installed on the G450. For details, see Installing the VPN license file on page 510.
Configuring a site-to-site IPSec VPN IPSec VPN configuration overview To configure a site-to-site IPSec VPN, two devices (the G450 and a peer Gateway) must be configured symmetrically. In some cases, you may wish to configure global VPN parameters (see Configuring global parameters on page 524).
● comp-lzs. For example: G450-001# crypto ipsec transform-set ts1 esp-3des esp-md5-hmac comp-lzs G450-001(config-transform:ts1)# 2. You can use the following commands to set the parameters of the transform-set: Use the set pfs command to specify whether each IKE phase 2 negotiation ●...
If you wish to specify the ISAKMP peer by its FQDN name, you must configure Note: the G450 as a DNS client (see DNS resolver on page 88), and verify that the peer’s name is listed in a DNS server. 514 Administration for the Avaya G450 Media Gateway...
Page 515
Do not specify an ambiguous ISAKMP peer; that is, do not configure an FQDN Note: that translates to an IP address which is already associated with another ISAKMP peer. For example: G450-001# crypto isakmp peer address 149.49.70.1 G450-001(config-peer:149.49.70.1)# G450-001# crypto isakmp peer fqdn vpn.lnd.ny.avaya.com G450-001(config-peer:vpn.lnd.ny.avaya.com)# 2.
Page 516
GNpi1odGNBrB5z4GJL G450-001(config-peer:149.49.70.1)# pre-shared-key Done! Alternatively, you can obtain a cryptographic-grade random key from the G450 with the suggest-key command, and then enter it using the pre-shared-key command. The suggested key-length can vary from 8-127 alphanumeric characters, or from 8-64 bytes represented in hexadecimal notation.
Page 517
Configuring a site-to-site IPSec VPN 7. Specify the branch device (G450) by its address or by the FQDN name that identifies the G450 in the remote peer, using the self-identity command. For example: G450-001(config-peer:149.49.70.1)# self-identity address Done! G450-001(config-peer:149.49.70.1)# self-identity fqdn vpn.avaya.com...
For example: G450-001(config-peer-grp:NY-VPN-group)# set peer 149.49.52.135 1 Done! 4. Repeat Step 3 for every peer you want to add to the list. 518 Administration for the Avaya G450 Media Gateway...
G450-001# crypto map 1 G450-001(config-crypto:1)# 2. Use the description command to enter a description for the crypto map. For example: G450-001(config-crypto:1)# description "vpn lincroft branch" Done! 3. Specify the remote peer, using the set peer command. For example: G450-001(config-crypto:1)# set peer 149.49.60.60 Done! Specify a peer-group, using the set peer-group command.
A crypto list is an ordered list of ip-rules that control which traffic requires IPSec protection and which does not, based on IP groups (source and destination IP addresses and wildcard). A crypto list is activated on an interface. The G450 can have multiple crypto lists activated on different interfaces.
Page 521
536. 3. Specify the name of the crypto list using the name command. For example: G450-001(Crypto 901)# name “Public Network via ADSL” Done! 4. Use the ip-rule command, followed by an index number from 1 to 1000, to enter the context of an ip-rule (and to create the ip-rule if it does not exist).
Page 522
● match this rule by using the following commands. For a full description of the commands see Avaya G450 CLI Reference, 03-602056. Note that this fine-tuning is not applicable for rules whose action is protect crypto map. - ip-protocol. Specify the IP protocol to match.
For example: G450-001# interface serial 3/1 G450-001(if: Serial 3/1)# no ip crypto-group Done! After modifying IPSec VPN parameters as desired, re-activate the crypto list on the interface using the ip crypto-group crypto-list-id command. For example:...
4500; to find out the port number, use the show crypto ipsec sa command. The G450 IPSec VPN feature supports NAT Traversal. If your installation includes one or more NAT devices between the local and remote VPN peers, NAT Traversal should be enabled, although in some rare cases it may not be required.
NAT translation alive in the NAT device, and not let it age-out due to periods of inactivity. Set the NAT Traversal keepalive interval on the G450 to be less than the NAT translation aging time on the NAT device. For example:...
Page 526
The crypto ipsec minimal-pmtu command is intended for advanced users only. ● It sets the minimal PMTU value which can be applied to an SA when the G450 participates in Path MTU Discovery (PMTUD) for the tunnel pertaining to that SA.
Displaying IPSec VPN configuration You can use the following show commands to display IPSec VPN configuration. For a full description of the commands and their output fields see Avaya G450 CLI Reference, 03-602056. Use the show crypto ipsec transform-set command to display configuration for a ●...
For more information about logging, see Configuring logging on page 209. Note: 1. Use the set logging session enable command to enable session logging. G450-001# set logging session enable Done! CLI-Notification: write: set logging session enable 528 Administration for the Avaya G450 Media Gateway...
Page 529
IPSec VPN maintenance 2. Use the set logging session condition ISAKMP command to view all ISAKMP messages of Info level and above. For example: G450-001# set logging session condition ISAKMP Info Done! CLI-Notification: write: set logging session condition ISAKMP Info 3.
There is a VPN tunnel from each spoke to the VPN hub over the Internet ● Only VPN traffic is allowed via the Internet connection ● Figure 45: Simple VPN topology: VPN hub and spokes 530 Administration for the Avaya G450 Media Gateway...
Typical installations Configuring the simple VPN topology 1. Configure each branch as follows: The default gateway is the Internet interface ● VPN policy is configured on the Internet interface egress as follows: ● Traffic from the local subnets to any IP address is encrypted, using tunnel mode ●...
Page 532
This enables the PMTUD application to work Egress All allowed services Permit This traffic is tunnelled from any IP address using VPN to any local subnet Egress Default Deny 2 of 2 532 Administration for the Avaya G450 Media Gateway...
The G450 IPSec VPN feature provides dynamic local peer IP address support. To work with dynamic local peer IP, you must first configure some prerequisites and then instruct the G450 to learn the IP address dynamically using either PPPoE or DHCP client.
Page 537
PPP over Ethernet (PPPoE) is a client-server protocol used for carrying Note: PPP-encapsulated data over Ethernet frames. You can configure PPPoE on the G450’s ETH WAN Fast Ethernet port. For more information about PPPoE on the G450, see Configuring PPPoE on page 259.
However, there are advantages to keeping the connection continuously alive, such as eliminating the waiting time necessary to construct a new IPSec VPN connection. The G450 IPSec VPN feature supports continuous channel, which maintains a continuous IPSec VPN connection. That means that when you activate the ip crypto-group command on the defined interface, the IPSec VPN tunnel is immediately started, even if no traffic is traversing the interface and the timeouts have expired.
There is a VPN tunnel from each spoke to the VPN hub over the Internet ● There is a VPN tunnel from one spoke to another spoke ● Only VPN traffic is allowed via the Internet connection ● Figure 46: Full or partial mesh 540 Administration for the Avaya G450 Media Gateway...
Page 541
Typical installations Configuring the mesh VPN topology 1. Configure Branch Office 1 as follows: The default gateway is the Internet interface ● VPN policy is configured on the Internet interface egress as follows: ● Traffic from the local subnets to the second spoke subnets -> encrypt, using tunnel ●...
Page 542
Table 131: Configuring the mesh VPN topology – Branch Office 2 Traffic ACL parameter Description direction value Ingress IKE from Main Office IP to Permit Branch IP Ingress ESP from Main Office IP to Permit Branch IP 1 of 2 542 Administration for the Avaya G450 Media Gateway...
Page 543
Typical installations Table 131: Configuring the mesh VPN topology – Branch Office 2 (continued) Traffic ACL parameter Description direction value Ingress IKE from First Branch IP to Permit Branch IP Ingress ESP from First Branch IP to Permit Branch IP Ingress ICMP from any IP address to Permit...
The local hosts access the Internet directly through the local broadband connection ● The PSTN connection backs up the voice bearer ● Figure 47: Full solution: hub-and-spoke with VPN for data and VoIP control backup 552 Administration for the Avaya G450 Media Gateway...
Page 553
Typical installations Configuring hub-and-spoke with VPN for data and VoIP control backup 1. Configure the Branch Office as follows: The default gateway is the Internet interface ● VPN policy is configured on the Internet interface egress as follows: ● Traffic from the local GRE tunnel endpoint to the remote GRE tunnel endpoint -> encrypt, using IPSec tunnel mode, with the remote peer being the Main Office.
Page 554
- Destination IP = branch VoIP subnet(s) or GW address (PMI), DSCP = control -> Route: 1. WAN 2. DBR ACM is configured to route voice calls through PSTN when the main VoIP trunk is ● down 554 Administration for the Avaya G450 Media Gateway...
Page 555
Typical installations Configuration example crypto isakmp policy 1 encryption aes hash sha group 2 authentication pre-share exit crypto isakmp peer address <Main Office Internet public Static IP Address> pre-shared-key <key1> isakmp-policy 1 exit crypto ipsec transform-set ts1 esp-3des esp-sha-hmac exit crypto map 1 set peer <Main Office Internet public Static IP Address>...
Page 556
<Branch voice Subnet> <Branch voice Subnet Mask> composite-operation Permit exit ip-rule default composite-operation deny exit exit ip access-control-list 302 ip-rule 10 source-ip any destination-ip any ip-protocol udp udp destination-port eq Ike composite-operation Permit exit 556 Administration for the Avaya G450 Media Gateway...
Page 557
Typical installations ip-rule 11 source-ip any destination-ip any ip-protocol udp destination-port eq Ike-nat-t composite-operation permit exit ip-rule 12 source-ip any destination-ip any ip-protocol udp destination-port eq Ike-nat-t-vsu composite-operation permit exit ip-rule 20 source-ip any destination-ip any ip-protocol esp composite-operation Permit exit ip-rule 30 source-ip any...
Page 558
! The following command specifies the Voice bearer dscp 46 next-hop list 1 exit ip-rule 20 ! The following command specifies the Voice Control dscp 34 next-hop list 2 exit ip-rule default next-hop PBR exit exit 558 Administration for the Avaya G450 Media Gateway...
IP address before establishing an IKE connection. Your DNS server should be able to provide an IP address of a living host. The G450 will perform a new DNS query and try to re-establish the VPN connection to the newly provided IP address whenever it senses that the currently active remote peer stops responding.
● Failover using GRE A branch with a G450 can connect to two or more VPN hub sites, in a way that will provide either redundancy or load sharing. In this topology, the G450 is connected through its 10/100 WAN Ethernet port to a DSL modem.
Page 561
Typical installations Figure 48: Hub and spoke with hub redundancy/load sharing using GRE Configuring VPN hub redundancy and load sharing topologies using GRE 1. Configure the Branch Office as follows: VPN policy is configured on the Internet interface egress as follows: ●...
Page 562
The ACL portion for the branch is a mirror image of the branch, with some minor ● modifications The GRE Tunnel interface is configured for the branch ● Dynamic routing (OSPF or RIP) is configured to run over the GRE interface to the ● branch 562 Administration for the Avaya G450 Media Gateway...
Page 563
Typical installations Configuration example crypto isakmp policy 1 encryption aes hash sha group 2 authentication pre-share exit crypto isakmp peer address <Primary Main Office Internet public Static IP Address> pre-shared-key <key1> isakmp-policy 1 exit crypto isakmp peer address <Backup Main Office Internet public Static IP Address>...
Page 564
Permit exit ip-rule 50 source-ip any destination-ip host <Branch Office Public Internet Static IP Address> ip-protocol icmp composite-operation Permit exit ip-rule 60 source-ip any destination-ip any composite-operation Permit exit 564 Administration for the Avaya G450 Media Gateway...
Page 565
Typical installations ip-rule 70 source-ip host <Backup Main Office GRE Tunnel end point IP Address> destination-ip host <Branch GRE Tunnel end point IP Address> composite-operation Permit exit ip-rule default composite-operation deny exit exit ip access-control-list 302 ip-rule 30 source-ip any destination-ip any ip-protocol udp udp destination-port eq Ike...
Page 566
Tunnel 2 keepalive 10 3 tunnel source <Branch GRE Tunnel end point IP Address> tunnel destination <Backup Main Office GRE Tunnel end point IP Address> ip address 20.20.20.1 255.255.255.252 exit 566 Administration for the Avaya G450 Media Gateway...
VPN peers. On the G450 configure that hostname as your remote peer. The G450 will perform a DNS query in order to resolve the hostname to an IP address before establishing an IKE connection. Your DNS server should be able to provide an IP address of a living host.
Page 568
Permit IKE Traffic (UDP port 500) for VPN control traffic (IKE) ● Permit ESP traffic (IP Protocol ESP) for VPN data traffic (IPSEC) ● Permit ICMP traffic, to support PMTU application support, for a better fragmentation ● process 568 Administration for the Avaya G450 Media Gateway...
Page 569
Typical installations For each private subnet, add a permit rule, with the destination being the private ● subnet and the source being any. This traffic will be allowed only if it tunnels under the VPN, because of the crypto list. Define all other traffic (default rule) as deny in order to protect the device from ●...
Page 570
! that is accessible without VPN. ip domain name-server-list 1 name-server 1 123.124.125.126 exit ! Define the IKE Entity crypto isakmp policy 1 encryption aes hash sha group 2 authentication pre-share exit 570 Administration for the Avaya G450 Media Gateway...
Page 571
Typical installations ! Define the remote peer as FQDN (DNS Name) crypto isakmp peer fqdn main-vpn.avaya.com pre-shared-key <key1> isakmp-policy 1 exit ! Define the IPSEC Entity crypto ipsec transform-set ts1 esp-3des esp-sha-hmac exit ! Define the VPN Tunnel crypto map 1 set peer main-vpn.avaya.com...
Page 573
Typical installations ip-rule default composite-operation deny exit exit ! Define the Egress access control list for the public interface ip access-control-list 302 ip-rule 5 source-ip destination-ip ip-protocol udp destination-port eq dns composite-operation Permit exit ip-rule 10 source-ip destination-ip ip-protocol udp destination-port eq Ike composite-operation Permit exit...
Page 574
! Activate the crypto list and the access control list on the public interface interface fastethernet 10/2 ip crypto-group 901 ip access-group 301 in ip access-group 302 out exit 574 Administration for the Avaya G450 Media Gateway...
Typical installations Failover using a peer-group The failover VPN topology utilizes a peer-group which lists a group of redundant peers. At any point in time, only one peer is active and acting as the remote peer. An object tracker monitors the state of the active peer.
Page 576
Define a track list that will monitor (by ICMP) five hosts behind the specific peer. If two or more hosts are not working then the object tracker is down. The G450 will then pass on to the next peer in the peer group list.
Page 577
Typical installations Permit ICMP traffic, to support PMTU application support, for a better fragmentation ● process For each private subnet, add a permit rule, with the destination being the private ● subnet, and the source being any. This traffic will be allowed only if it tunnels under the VPN, because of the crypto list.
Page 578
"Branch Subnet2" ip address 10.0.20.1 255.255.255.0 exit ! Define the Public Subnet interface fastethernet 10/2 ip address 100.0.0.2 255.255.255.0 exit ! Define the default gateway the public interfce ip default-gateway 100.0.0.1 578 Administration for the Avaya G450 Media Gateway...
Page 579
Typical installations ! We wish to check 5 hosts in the Corporate intranet behind the current VPN ! remote peer, and if 2 or more hosts don’t work then keepalive-track will fail , ! and we will move to the next peer in the peer-group rtr 1 type echo protocol ipIcmpEcho <host1 IP>...
Page 580
901 local-address "Fast Ethernet 10/2.0" ip-rule 10 source-ip 10.0.10.0 0.0.0.255 destination-ip any protect crypto map 1 exit ip-rule 20 source-ip 10.0.20.0 0.0.0.255 destination-ip any protect crypto map 1 exit exit 580 Administration for the Avaya G450 Media Gateway...
Page 581
Typical installations ! Define the Ingress access control list for the public interface ip access-control-list 301 ip-rule 10 source-ip destination-ip ip-protocol udp destination-port eq Ike composite-operation Permit exit ip-rule 11 source-ip any destination-ip any ip-protocol udp destination-port eq Ike-nat-t composite-operation permit exit ip-rule 12 source-ip any...
301 in ip access-group 302 out exit Checklist for configuring site-to-site IPSec VPN Table 134 to gather the information for simple G450 site-to-site IPSec VPN. Table 134: Checklist for configuring site-to-site IPSec VPN Parameter Possible values Actual value 1.
Page 584
- Lifetime kilobytes 2,560 to 536,870,912 ● default: 4,608,000 kb disable ● 6. Which packets should be secured a. Protect rules matching IP source address ● options IP destination address ● 2 of 3 584 Administration for the Avaya G450 Media Gateway...
Page 585
Checklist for configuring site-to-site IPSec VPN Table 134: Checklist for configuring site-to-site IPSec VPN (continued) Parameter Possible values Actual value b. Bypass rules matching IP source address ● options IP destination address ● ● ● dscp ● fragment ● icmp ●...
Configuring IPSec VPN Summary of VPN commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 135: VPN CLI commands Root level command First level Second level Description command command Flush a specific ISAKMP SA or all...
Page 587
Summary of VPN commands Table 135: VPN CLI commands (continued) Root level command First level Second level Description command command Enable continuous-channel IKE, continuous- which keeps the IKE phase1 channel session always up and running, even if there is no traffic Enter a description for the ISAKMP description peer...
Page 588
Attach a peer to a crypto map set peer Attach a peer-group to a crypto set peer-group Configure the transform-set transform-set Enter the FastEthernet, interface Dialer, Serial, or VLAN (fastethernet| interface context dialer|serial| vlan) 3 of 5 588 Administration for the Avaya G450 Media Gateway...
Page 589
Set the minimal PMTU value that crypto ipsec can be applied to an SA when the minimal-pmtu G450 participates in PMTUD for the tunnel pertaining to that SA Activate a crypto list in the context of the interface on which the crypto...
Page 590
Display all or specific crypto map show crypto map configurations Display information about a show ip specific policy list or all lists active-lists Display all or specific crypto list show ip configurations crypto-list 5 of 5 590 Administration for the Avaya G450 Media Gateway...
Global rules. A set of rules that are executed before the list is evaluated ● Rule list. A list of filtering rules and actions for the G450 to take when a packet matches ● the rule. Match actions on this list are pointers to the composite operation table.
IP addresses, protocols, ports, IP fragments, or DSCP values. Figure 51 illustrates how access control lists are used to control traffic into and out of your network. Figure 51: Network security using access control lists 592 Administration for the Avaya G450 Media Gateway...
DSCP values or CoS values, and can be based on specific values or groups of IP addresses, protocols, ports, IP fragments, or DSCP values. When a packet matches a rule on the QoS list, the G450 sets one or both of the QoS fields in the packet. The following table shows these QoS fields:...
Configuring policy Managing policy lists You can manage policy lists on the Avaya G450 Media Gateway with CLI commands. You can also manage policy lists throughout your network with Avaya QoS Manager. Avaya QoS Manager is part of Avaya Integrated Management.
Defining policy lists To create or edit a QoS list, enter ip qos-list followed by a list number in the range 400-499. The G450 includes one pre-configured QoS list. The pre-configured QoS list is list number 400. For example, to create a new QoS list 401, enter the following command:...
Configuring policy Default actions When no rule matches a packet, the G450 applies the default action for the list. The following table shows the default action for each type of policy list: List Default action Access control list Accept all packets...
Device-wide policy lists You can attach a policy list (other than a policy-based routing list) to every interface on the G450 using one command. To do this, attach a list to the Loopback 1 interface. For more information, Attaching policy lists to an interface on page 596.
Defining rules on page 599. The G450 applies global rules before applying individual rules. 1. Enter the context of the access control list in which you want to define the rule. 2. Enter one of the following commands, followed by the name of a composite command: - ip-fragments-in.
Rules work in the following ways, depending on the type of list and the type of information in the packet: Layer 4 rules in an access control list with a Permit operation are applied to non-initial ● fragments 600 Administration for the Avaya G450 Media Gateway...
The following command specifies any IP protocol except IGMP for rule 3 in access control list 302: G450-001(ACL 302/ip rule 3)# no ip-protocol igmp Source and destination IP address To specify a range of source and destination IP addresses to which the rule applies, use the commands source-ip and destination-ip, followed by the IP range criteria.
The following command specifies a source IP address outside the range 64.236.24.0 through 64.236.24.255 for rule 7 in access control list 308: G450-001(ACL 308/ip rule 7)# no source-ip 64.236.24.0 0.0.0.255 The following command specifies a source IP address in the range 64.<any>.24.<any> for rule 6 in access control list 350: G450-001(ACL 350/ip rule 6)# source-ip 64.*.24.*...
The following command specifies any destination TCP port in the range 5000 through 5010 for rule 1 in access control list 301: G450-001(ACL 301/ip rule 1)# tcp destination-port range 5000 5010 The following command specifies any source TCP port except a port named http for rule 7 in...
DSCP value is set to 56: G450-001(ACL 301/ip rule 5)# dscp 56 Composite Operation For instructions on assigning a composite operation to an ip rule, see Adding composite operation to an ip rule on page 607. 604 Administration for the Avaya G450 Media Gateway...
Composite operations Composite operations A composite operation is a set of operations that the G450 can perform when a rule matches a packet. Every rule in a policy list has an operation field that specifies a composite operation. The operation field determines how the G450 handles a packet when the rule matches the packet.
CoS field to 3.) If the composite operation is set to Trust-DSCP-CoS, the operation uses the greater of the CoS or the DSCP value. If the composite operation is set to No Change, the operation makes no change to the packet’s QoS tags. 606 Administration for the Avaya G450 Media Gateway...
Composite operations Configuring composite operations You can configure additional composite operations for QoS lists. You can also edit composite operations that you configured. You cannot edit pre-configured composite operations. Note: You cannot configure additional composite operations for access control lists, Note: since all possible composite operations are pre-configured.
The following commands create a new composite operation called dscp5 and assign the new composite operation to rule 3 in QoS list 402. If the packet matches a rule, the G450 changes the value of the DSCP field in the packet to 5.
QoS rules on the list take precedence over the DSCP table. If a QoS rule other than the default matches the packet, the G450 does not apply the DSCP table to the packet. The G450 applies only the operation specified in the QoS rule.
- show dscp-table. Displays the current list’s DSCP table - show ip-rule. Displays a list of all rules configured for the list - show list. Displays the parameters of the current list, including its rules 610 Administration for the Avaya G450 Media Gateway...
For example, the following command simulates the effect of applying QoS list number 401 to a packet entering the G450 through interface VLAN 2: G450-001(if:VLAN 2)# ip simulate 401 in CoS1 dscp46 10.1.1.1 10.2.2.2 tcp 1182 20 The simulated packet has the following properties: CoS priority is 1 ●...
Configuring policy When you use the ip simulate command, the G450 displays the effect of the policy rules on the simulated packet. For example: G450-001(super-if:VLAN 2)# ip simulate 401 in CoS1 dscp46 10.1.1.1 10.2.2.2 tcp 1182 20 Rule match for simulated packet is the default rule...
Page 613
Summary of access control list commands Table 139: Access control list CLI commands (continued) Root level Command Command Description command Specify the action taken on ip-fragments-in incoming IP fragmentation packets for the current access control list Specify the action taken on ip-option-in incoming packets carrying an IP option for the current access...
Page 614
Copy an existing policy list to a new list policy-list- copy Display the attributes of a show ip specific access control list or of access-control all access control lists -list 3 of 3 614 Administration for the Avaya G450 Media Gateway...
Summary of QoS list commands Summary of QoS list commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 140: QoS list CLI commands Root level Command Command Description command Enter the Dialer, Serial, interface {dialer|...
Page 616
ICMP packet Apply the current rule to packets ip-protocol with the specified IP protocol Display the parameters of the show composite operation assigned to composite- the current rule operation 2 of 3 616 Administration for the Avaya G450 Media Gateway...
Page 617
Summary of QoS list commands Table 140: QoS list CLI commands (continued) Root level Command Command Description command Display the current list’s DSCP show table dscp-table Display the attributes of the show ip-rule current rule Apply the current rule to packets source-ip from the specified source IP address...
Page 618
Configuring policy 618 Administration for the Avaya G450 Media Gateway...
Each PBR list includes a set of rules, and each rule includes a next hop list. Each next hop list contains up to 20 next hop destinations to which the G450 sends packets that match the rule. A destination can be either an IP address or an interface.
NULL interface to drop packets when the primary next hop fails. For example, voice packets are usually sent over a WAN line, and not the Internet. You can configure a PBR list to drop voice packets when the WAN line is down. 620 Administration for the Avaya G450 Media Gateway...
In general context, enter ip pbr-list followed by a list number in the range ● 800-899. For example: G450-001(super)# ip pbr-list 802 G450-001(super-PBR 802)# To assign a name to the list, use the name command, followed by a text string, in the ●...
Page 622
Configuring DHCP client on page 199. A next hop list can include the value NULL0. When the next hop is NULL0, the G450 drops the packet. However, you cannot apply tracking to NULL0. 622 Administration for the Avaya G450 Media Gateway...
Page 623
The third entry is NULL, which means the packet is dropped ● G450-001(super)# ip next-hop-list 1 G450-001(super-next hop list 1)#name "Data_to_HQ" Done! G450-001(super-next hop list 1)#next-hop-ip 1 172.16.1.221 track 3 Done! G450-001(super-next hop list 1)#next-hop-interface 2 Serial 3/1:1 Done! G450-001(super-next hop list 1)#next-hop-interface 3 Null0...
It is recommended to leave a gap between rule numbers, in order to leave room Note: for inserting additional rules at a later time. For example, ip-rule 10, ip-rule 20, ip-rule 30. 624 Administration for the Avaya G450 Media Gateway...
Next hop lists PBR rules include a next hop list. When the rule matches a packet, the G450 routes the packet according to the specified next hop list. Each next hop list can include up to 20 entries. An entry in a next hop list can be either an IP address or an interface.
3 deletes the third entry from the next hop list. Canceling tracking and keeping the next hop 1. Enter the context of the next hop list. 2. Use the next-hop-ip or next-hop-interface command again, without the track keyword. 626 Administration for the Avaya G450 Media Gateway...
To remove a list from an interface, use the no form of the ip pbr-group command in the interface context. The following example removes the PBR list from the VLAN 2 interface. G450-001(super)# interface vlan 1 G450-001(super-if:VLAN 1)# no ip pbr-group Done! G450-001(super-if:VLAN 1)# To modify a PBR list, enter ip pbr-list, followed by the number of the list you want to modify, to enter the list context.
- show ip pbr-list list number detailed. Displays all the parameters of the specified PBR list - show ip active-lists. Displays a list of each G450 interface to which a PBR list is attached, along with the number and name of the PBR list - show ip active-lists list number.
Page 629
Figure 55: Sample policy-based routing application This example includes a voice VLAN (6) and a data VLAN (5). The PMI is on VLAN 6. The G450 is managed by a remote Media Gateway Controller (MGC) with the IP address 149.49.43.210.
G450-001(super-PBR 801/ip rule 40)# next-hop list 1 Done! G450-001(super-PBR 801/ip rule 40)# destination-ip 149.49.123.0 0.0.0.255 Done! G450-001(super-PBR 801/ip rule 40)# dscp 46 Done! G450-001(super-PBR 801/ip rule 40)# exit G450-001(super-PBR 801)# exit G450-001(super)# 630 Administration for the Avaya G450 Media Gateway...
Page 631
G450 itself are routed via the E1/T1 line. The Loopback interface is a logical interface that is always up. Packets sent from the G450, such as signaling packets, are sent via the Loopback interface. In this example, applying PBR list 801 to the Loopback interface ensures that signaling packets originating from voice traffic are sent via the T1/E1 line.
Page 632
(for more information on object tracking, refer to Object tracking on page 298). Note that the GRE tunnel itself has keepalive and can detect the status of the interface and, therefore, modify the next hop status. 632 Administration for the Avaya G450 Media Gateway...
Policy-based routing supports the ip simulate command for testing policies. Refer to Simulating packets on page 611. Summary of policy-based routing commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 141: Policy-based routing CLI commands Root level First level...
Page 634
Assign a name to the specified list or name operation Specify the owner of the current list owner Display the attributes of a specific show ip-rule rule or all rules 2 of 3 634 Administration for the Avaya G450 Media Gateway...
Page 635
Summary of policy-based routing commands Table 141: Policy-based routing CLI commands (continued) Root level First level Second level Description command command command Display information about the show list specified list Display information about a specific show ip policy list or all lists active-lists Display details about a specific PBR show ip...
Page 636
Configuring policy-based routing 636 Administration for the Avaya G450 Media Gateway...
If neither primary nor secondary sources are identified, the local clock becomes the active source. The following example sets the MM710 media module located in slot 2 of the G450 chassis as the primary clock synchronization source for the Avaya G450 Media Gateway.
Setting synchronization If the Avaya G450 Media Gateway includes a second MM710 media module, enter the following additional command: set sync interface secondary v3 set sync source secondary If, for any reason, the primary MM710 media module cannot function as the clock synchronization source, the system uses the MM710 media module located in slot 3 of the Avaya G450 Media Gateway chassis as the clock synchronization source.
Configured when a source has not been defined, for example, when there are no T1 cards installed. Summary of synchronization commands For more information about these commands, see Avaya G450 CLI Reference, 03-300437. Table 142: Synchronization CLI commands Command Description...
Page 640
Setting synchronization 640 Administration for the Avaya G450 Media Gateway...
Appendix A: Traps and MIBs This appendix contains a list of all G450 traps and all MIBs. G450 traps Name Parameters Class Severity Trap Name/ Format Description (MIB variables) Facility Mnemonic coldStart Boot Warning coldStart Agent Up with A coldStart trap indicates...
Page 642
FABRIC ndancyTrap Redundancy $1 manager of the deletion Trap Status definition deleted of the specified redundant link, which is identified by the softRedundancyId. It is enabled/disabled by chLntAgConfigChangeTr aps. 2 of 9 642 Administration for the Avaya G450 Media Gateway...
Page 643
G450 traps Name Parameters Class Severity Trap Name/ Format Description (MIB variables) Facility Mnemonic createSW soft P330 SWITCH Info createSWRedu Software The trap is generated on Redundancy Redundancy FABRIC ndancyTrap Redundancy $1 the creation of the Trap Status definition created redundant links for the specified ports.
Page 644
Notification InlinePwr Module $2 Inline This trap reports the FaultMask, FltOK Power Supply correction of a failure on genGroupId, failure was cleared an inline power supply. genGroup BUPSActivity Status 4 of 9 644 Administration for the Avaya G450 Media Gateway...
Page 645
G450 traps Name Parameters Class Severity Trap Name/ Format Description (MIB variables) Facility Mnemonic WanPhysical ifIndex, Critical Cable Problem on An E1/T1/serial cable AlarmOn ifAdminStatus, Physical port $4 was disconnected. ifOperStatus, AlarmOn ifName, ifAlias, dsx1Line Status wanPhysical ifIndex, Notification wan...
Page 646
This trap reports a PwrFlt Index, NTITY PwrFlt power supply Fault problem with a 3.3V entPhysical power supply. Descr, entPhySensor Value, avEntPhy SensorHi Warning, avEntPhy SensorLo Warningent Physical ParentRelPos 6 of 9 646 Administration for the Avaya G450 Media Gateway...
Page 647
G450 traps Name Parameters Class Severity Trap Name/ Format Description (MIB variables) Facility Mnemonic avEnt2500mv entPhysical AVAYA-E SUPPLY avEnt2500mv 2.5V (2500mv) This trap reports a PwrFlt Index, NTITY PwrFlt power supply Fault problem with a 2.5V entPhysical power supply. Descr,...
Page 648
PwrFltOk Index, NTITY wrFlt power supply Fault correction of a problem entPhysical Cleared with a 1.8V power supply. Descr, entPhySensor Value, avEntPhy SensorHi Warning, avEntPhy SensorLo Warningent Physical ParentRelPos 8 of 9 648 Administration for the Avaya G450 Media Gateway...
G450 MIB files MIB File MIB Module Supported by G450 SNMPv2-MIB.my SNMPv2-MIB USM-MIB.my USM-MIB VACM-MIB.my VACM-MIB OSPF-MIB.my OSPF-MIB Tunnel-MIB.my TUNNEL-MIB 3 of 3 MIB files in the Load.MIB file The following table provides a list of the MIBs in the Load.MIB file that are supported by the...
MIB files in the RFC1315-MIB.my file The following table provides a list of the MIBs in the RFC1315-MIB.my file that are supported by the G450 and their OIDs: Object frDlcmiIfIndex 1.3.6.1.2.1.10.32.1.1.1 frDlcmiState 1.3.6.1.2.1.10.32.1.1.2 1 of 3 652 Administration for the Avaya G450 Media Gateway...
1.3.6.1.2.1.17.7.1.4.5.1.4 dot1qPortGvrpFailedRegistrations 1.3.6.1.2.1.17.7.1.4.5.1.5 dot1qPortGvrpLastPduOrigin 1.3.6.1.2.1.17.7.1.4.5.1.6 MIB files in the ENTITY-MIB.my file The following table provides a list of the MIBs in the ENTITY-MIB.my file that are supported by the G450 and their OIDs: Object entPhysicalIndex 1.3.6.1.2.1.47.1.1.1.1.1 entPhysicalDescr 1.3.6.1.2.1.47.1.1.1.1.2 entPhysicalVendorType 1.3.6.1.2.1.47.1.1.1.1.3 entPhysicalContainedIn 1.3.6.1.2.1.47.1.1.1.1.4...
G450 MIB files MIB files in the VRRP-MIB.my file The following table provides a list of the MIBs in the VRRP-MIB.my file that are supported by the G450 and their OIDs: Object vrrpNodeVersion 1.3.6.1.2.1.68.1.1.1 vrrpOperVrId 1.3.6.1.2.1.68.1.1.3.1.1 vrrpOperVirtualMacAddr 1.3.6.1.2.1.68.1.1.3.1.2 vrrpOperState 1.3.6.1.2.1.68.1.1.3.1.3 vrrpOperAdminState 1.3.6.1.2.1.68.1.1.3.1.4...
Traps and MIBs MIB files in the UTILIZATION-MANAGEMENT-MIB.my file The following table provides a list of the MIBs in the UTILIZATION-MANAGEMENT-MIB.my file that are supported by the G450 and their OIDs: Object genCpuIndex 1.3.6.1.4.1.6889.2.1.11.1.1.1.1.1 genCpuUtilizationEnableMonitoring 1.3.6.1.4.1.6889.2.1.11.1.1.1.1.2 genCpuUtilizationEnableEventGeneration 1.3.6.1.4.1.6889.2.1.11.1.1.1.1.3 genCpuUtilizationHighThreshold 1.3.6.1.4.1.6889.2.1.11.1.1.1.1.4 genCpuAverageUtilization 1.3.6.1.4.1.6889.2.1.11.1.1.1.1.5...
G450 MIB files MIB files in the ENTITY-SENSOR-MIB.my file The following table provides a list of the MIBs in the ENTITY-SENSOR-MIB.my file that are supported by the G450 and their OIDs: Object entPhySensorType 1.3.6.1.2.1.99.1.1.1.1 entPhySensorScale 1.3.6.1.2.1.99.1.1.1.2 entPhySensorPrecision 1.3.6.1.2.1.99.1.1.1.3 entPhySensorValue 1.3.6.1.2.1.99.1.1.1.4 entPhySensorOperStatus 1.3.6.1.2.1.99.1.1.1.5...
The following table provides a list of the MIBs in the DS1-MIB.my file that are supported by the G450 and their OIDs: Object dsx1LineIndex 1.3.6.1.2.1.10.18.6.1.1 dsx1IfIndex 1.3.6.1.2.1.10.18.6.1.2 dsx1TimeElapsed 1.3.6.1.2.1.10.18.6.1.3 dsx1ValidIntervals 1.3.6.1.2.1.10.18.6.1.4 1 of 3 660 Administration for the Avaya G450 Media Gateway...
G450 MIB files MIB files in the PPP-IP-NCP-MIB.my file The following table provides a list of the MIBs in the PPP-IP-NCP-MIB.my file that are supported by the G450 and their OIDs: Object pppIpOperStatus 1.3.6.1.2.1.10.23.3.1.1.1 pppIpLocalToRemoteCompressionProtocol 1.3.6.1.2.1.10.23.3.1.1.2 pppIpRemoteToLocalCompressionProtocol 1.3.6.1.2.1.10.23.3.1.1.3 pppIpRemoteMaxSlotId 1.3.6.1.2.1.10.23.3.1.1.4 pppIpLocalMaxSlotId 1.3.6.1.2.1.10.23.3.1.1.5...
Traps and MIBs MIB files in the AVAYA-ENTITY-MIB.my file The following table provides a list of the MIBs in the AVAYA-ENTITY-MIB.my file that are supported by the G450 and their OIDs: Object avEntPhySensorHiShutdown 1.3.6.1.4.1.6889.2.1.99.1.1.1 avEntPhySensorHiWarning 1.3.6.1.4.1.6889.2.1.99.1.1.2 avEntPhySensorHiWarningClear 1.3.6.1.4.1.6889.2.1.99.1.1.3 avEntPhySensorLoWarningClear 1.3.6.1.4.1.6889.2.1.99.1.1.4 avEntPhySensorLoWarning 1.3.6.1.4.1.6889.2.1.99.1.1.5...
G450 MIB files MIB files in the XSWITCH-MIB.my file The following table provides a list of the MIBs in the XSWITCH-MIB.my file that are supported by the G450 and their OIDs: Object scGenPortGroupId 1.3.6.1.4.1.81.28.1.4.1.1.1 scGenPortId 1.3.6.1.4.1.81.28.1.4.1.1.2 scGenPortVLAN 1.3.6.1.4.1.81.28.1.4.1.1.3 scGenPortPriority 1.3.6.1.4.1.81.28.1.4.1.1.4 scGenPortSetDefaults 1.3.6.1.4.1.81.28.1.4.1.1.5...
1.3.6.1.4.1.81.31.3.1.1.2 vlConfStatus 1.3.6.1.4.1.81.31.3.1.1.3 4 of 4 MIB files in the RS-232-MIB.my file The following table provides a list of the MIBs in the RS-232-MIB.my file that are supported by the G450 and their OIDs: Object rs232Number 1.3.6.1.2.1.10.33.1 rs232PortIndex 1.3.6.1.2.1.10.33.2.1.1 rs232PortType 1.3.6.1.2.1.10.33.2.1.2...
G450 MIB files MIB files in the RIPv2-MIB.my file The following table provides a list of the MIBs in the RIPv2-MIB.my file that are supported by the G450 and their OIDs: Object rip2GlobalRouteChanges 1.3.6.1.2.1.23.1.1 rip2GlobalQueries 1.3.6.1.2.1.23.1.2 rip2IfStatAddress 1.3.6.1.2.1.23.2.1.1 rip2IfStatRcvBadPackets 1.3.6.1.2.1.23.2.1.2 rip2IfStatRcvBadRoutes 1.3.6.1.2.1.23.2.1.3...
The following table provides a list of the MIBs in the DS0-MIB.my file that are supported by the G450 and their OIDs: Object dsx0Ds0ChannelNumber 1.3.6.1.2.1.10.81.1.1.1 dsx0RobbedBitSignalling 1.3.6.1.2.1.10.81.1.1.2 dsx0CircuitIdentifier 1.3.6.1.2.1.10.81.1.1.3 dsx0IdleCode 1.3.6.1.2.1.10.81.1.1.4 dsx0SeizedCode 1.3.6.1.2.1.10.81.1.1.5 dsx0ReceivedCode 1.3.6.1.2.1.10.81.1.1.6 dsx0TransmitCodesEnable 1.3.6.1.2.1.10.81.1.1.7 dsx0Ds0BundleMappedIfIndex 1.3.6.1.2.1.10.81.1.1.8 dsx0ChanMappedIfIndex 1.3.6.1.2.1.10.81.3.1.1 680 Administration for the Avaya G450 Media Gateway...
G450 MIB files MIB files in the POLICY-MIB.my file The following table provides a list of the MIBs in the POLICY-MIB.MY file that are supported by the G450 and their OIDs: Object ipPolicyListSlot 1.3.6.1.4.1.81.36.1.1.1 ipPolicyListID 1.3.6.1.4.1.81.36.1.1.2 ipPolicyListName 1.3.6.1.4.1.81.36.1.1.3 ipPolicyListValidityStatus 1.3.6.1.4.1.81.36.1.1.4 ipPolicyListChecksum 1.3.6.1.4.1.81.36.1.1.5...
1.3.6.1.4.1.81.36.11.3.1.7 ipPolicyValidDSCPErrMsg 1.3.6.1.4.1.81.36.11.3.1.8 7 of 7 MIB files in the BRIDGE-MIB.my file The following table provides a list of the MIBs in the BRIDGE-MIB.my file that are supported by the G450 and their OIDs: Object dot1dBaseBridgeAddress 1.3.6.1.2.1.17.1.1 dot1dBaseNumPorts 1.3.6.1.2.1.17.1.2 dot1dBaseType 1.3.6.1.2.1.17.1.3...
G450 MIB files MIB files in the CONFIG-MIB.my file The following table provides a list of the MIBs in the CONFIG-MIB.MY file that are supported by the G450 and their OIDs: Object chHWType 1.3.6.1.4.1.81.7.1 chNumberOfSlots 1.3.6.1.4.1.81.7.2 chReset 1.3.6.1.4.1.81.7.7 chLntAgMaxNmbOfMngrs 1.3.6.1.4.1.81.7.9.3.1 chLntAgPermMngrId 1.3.6.1.4.1.81.7.9.3.2.1.1...
G450 MIB files MIB files in the G700-MG-MIB.my file The following table provides a list of the MIBs in the G700-MG-MIB.MY file that are supported by the G450 and their OIDs: Object cmgHWType 1.3.6.1.4.1.6889.2.9.1.1.1 cmgModelNumber 1.3.6.1.4.1.6889.2.9.1.1.2 cmgDescription 1.3.6.1.4.1.6889.2.9.1.1.3 cmgSerialNumber 1.3.6.1.4.1.6889.2.9.1.1.4 cmgHWVintage 1.3.6.1.4.1.6889.2.9.1.1.5...
1.3.6.1.4.1.6889.2.9.1.8.2 cmgDynCacLastUpdate 1.3.6.1.4.1.6889.2.9.1.8.3 5 of 5 MIB files in the FRAME-RELAY-DTE-MIB.my file The following table provides a list of the MIBs in the FRAME-RELAY-DTE-MIB.my file that are supported by the G450 and their OIDs: Object frDlcmiIfIndex 1.3.6.1.2.1.10.32.1.1.1 frDlcmiState 1.3.6.1.2.1.10.32.1.1.2 frDlcmiAddress 1.3.6.1.2.1.10.32.1.1.3...
G450 MIB files MIB files in the IP-MIB.my file The following table provides a list of the MIBs in the IP-MIB.my file that are supported by the G450 and their OIDs: Object ipForwarding 1.3.6.1.2.1.4.1 ipDefaultTTL 1.3.6.1.2.1.4.2 ipInReceives 1.3.6.1.2.1.4.3 ipInHdrErrors 1.3.6.1.2.1.4.4 ipInAddrErrors 1.3.6.1.2.1.4.5...
G450 MIB files MIB files in the WAN-MIB.my file The following table provides a list of the MIBs in the WAN-MIB.my file that are supported by the G450 and their OIDs: Object ds0BundleMemmbersList 1.3.6.1.4.1.6889.2.1.6.1.1.2.1.1 ds0BundleSpeedFactor 1.3.6.1.4.1.6889.2.1.6.1.1.2.1.2 ds1DeviceMode 1.3.6.1.4.1.6889.2.1.6.2.1.1 ifTableXtndIndex 1.3.6.1.4.1.6889.2.1.6.2.2.1.1.1 ifTableXtndPeerAddress 1.3.6.1.4.1.6889.2.1.6.2.2.1.1.2...
G450 MIB files MIB files in the SNMPv2-MIB.my file The following table provides a list of the MIBs in the SNMPv2-MIB.my file that are supported by the G450 and their OIDs: Object sysDescr 1.3.6.1.2.1.1.1 sysObjectID 1.3.6.1.2.1.1.2 sysUpTime 1.3.6.1.2.1.1.3 sysContact 1.3.6.1.2.1.1.4 sysName 1.3.6.1.2.1.1.5...
The following table provides a list of the MIBs in the OSPF-MIB.my file that are supported by the G450 and their OIDs: Object ospfRouterId 1.3.6.1.2.1.14.1.1 ospfAdminStat 1.3.6.1.2.1.14.1.2 ospfVersionNumber 1.3.6.1.2.1.14.1.3 ospfAreaBdrRtrStatus 1.3.6.1.2.1.14.1.4 ospfASBdrRtrStatus 1.3.6.1.2.1.14.1.5 ospfExternLsaCount 1.3.6.1.2.1.14.1.6 1 of 4 706 Administration for the Avaya G450 Media Gateway...
1.3.6.1.2.1.14.12.1.6 ospfExtLsdbAdvertisement 1.3.6.1.2.1.14.12.1.7 4 of 4 MIB files in the TUNNEL-MIB.my file The following table provides a list of the MIBs in the TUNNEL-MIB.my file that are supported by the G450 and their OIDs: Object tunnelIfLocalAddress 1.3.6.1.2.1.10.131.1.1.1.1.1 tunnelIfRemoteAddress 1.3.6.1.2.1.10.131.1.1.1.1.2 1 of 2...
Page 714
......packet sniffing dialer interface 714 Administration for the Avaya G450 Media Gateway...
Page 715
Index ......E1/T1 ports ip ospf priority ....
Page 716
........nslookup rtp-stat fault 716 Administration for the Avaya G450 Media Gateway...
Page 717
Index ......rtp-stat min-stat-win set interface (bri) ....
Page 718
... . . set snmp trap disable frame-relay show cna testplug ... . set snmp trap enable auth show composite-operation 718 Administration for the Avaya G450 Media Gateway...
Page 719
Index ..... . . access control list show ip crypto-lists ....
Page 720
......show snmp retries start-ip-addr 720 Administration for the Avaya G450 Media Gateway...
Page 722
....when not necessary ....maintaining 722 Administration for the Avaya G450 Media Gateway...
Page 723
Index ..DNS servers setting flowcontrol advertisements requesting list of DNS servers during a PPP/IPCP WAN Ethernet port ....session see WAN Ethernet port requesting list of DNS servers from a DHCP...
Page 724
....CLI commands ... preventing recursive routing Interfaces 724 Administration for the Avaya G450 Media Gateway...
Page 725
Index ........adjusting bandwidth policies ....
Page 726
... . . configuration example ....configuring 726 Administration for the Avaya G450 Media Gateway...
Need help?
Do you have a question about the G450 and is the answer not in the manual?
Questions and answers