Configuring Gtp Message Filtering; Configuring Subscriber Tracing (Lawful Interception); Example: Creating A Gtp Object - Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Configuring GTP Message Filtering

Configuring Subscriber Tracing (Lawful Interception)

Copyright © 2010, Juniper Networks, Inc.
By default, the security device permits all GTP message types. You can configure a security
device to filter GTP packets and drop them based on their message type.
A GTP message type includes one or many messages. When you drop a message type,
you automatically drop all messages of the specified type. For example, if you select to
drop the sgsn-context message type, you also drop " sgsn context request" , " sgsn
context response" , and " sgsn context acknowledge" messages.
You drop message types based on the GTP version number, enabling you to drop message
types for one version and permit them for another version.
You can configure a security device to identify subscribers based on IMSI prefixes or
Mobile Station-Integrated Services Data Network (MS-ISDN) identification, then log the
contents of their GTP-User Data (GTP-U) or GTP-Control (GTP-C) messages.
To enable subscriber tracing, you must configure the following:
Set Subscribers—Set the number of number of subscribers that the security device
actively traces concurrently. The default number of simultaneous active traces is three
(3).
Specify Log Bytes—Specify the number of bytes of data to log for a GTP-U packet.
The default value is zero, meaning that the device does not log any content from a
GTP-U packet. When you enter a number other than zero, the security device sends
the logged packets to an external server (such as Syslog) dedicated to Lawful
Interception operations.
Set ID—For each subscriber you want to trace, enter their ID number and select Based
on IMSI or Based on MSISDN.

Example: Creating a GTP Object

In Object Manager, select GTP Objects, then click the Add icon in the main display
1.
area. The New GTP Object dialog box appears.
In the Info tab, configure the following settings:
2.
For Name, enter GPRS1, then enter a color and comment for the object.
Select Sequence Number Validation.
Select GTP in GTP Denied.
Leave all other defaults.
In the GTP navigation tree, select Traffic Logging/Counting. Configure the following:
3.
Chapter 8: Configuring Objects
381

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents