Radius-Based Lawful Intercept; Enabling Radius-Based Lawful Intercept - Cisco ASR 9000 Series Configuration Manual

Aggregation services router broadband network gateway
Hide thumbs Also See for ASR 9000 Series:
Table of Contents

Advertisement

Radius-based Lawful Intercept

Radius-based Lawful Intercept
Radius-based Lawful Intercept feature provides mechanisms for interception of the BNG subscriber traffic
by using the RADIUS attributes. This is a preferred method over SNMP user-connection MIB, as SNMP-based
method prevents a session to be tapped until an IP address has been assigned to the session. In the Radius-based
LI mechanism, tapping is possible as soon as a session is established.
A RADIUS-based Lawful Intercept solution enables intercept requests to be sent (through Access-Accept
packets or Change of Authorization (CoA)-Request packets) to the network access server (NAS) or to the
Layer 2 Tunnel Protocol access concentrator (LAC) from the RADIUS server. All traffic data going to or
from a PPP or L2TP session is passed to a mediation device. Another advantage of RADIUS-based Lawful
Intercept solution is to set the tap with Access-Accept packets that allows all target traffic to be intercepted
simultaneously.
The RADIUS-based Lawful Intercept feature provides tap initiation support for these modes:
• Access-Accept based Lawful Intercept for the new session
• CoA based Lawful Intercept for existing session
By default, the Radius-based Lawful Intercept functionality is not enabled. For more information about
Note
enabling Radius-based Lawful Intercept, see

Enabling RADIUS-based Lawful Intercept

Perform this task to enable the Radius-based Lawful Intercept feature.
SUMMARY STEPS
1. configure
2. aaa intercept
3. aaa server radius dynamic-author
4. port port_number
5. server-key [0|7] word
6. client hostname{ vrf vrf_name | server-key [0|7] word }
7. Use the commit or end command.
DETAILED STEPS
Command or Action
Step 1
configure
Example:
RP/0/RSP0/CPU0:router# configure
Cisco ASR 9000 Series Aggregation Services Router Broadband Network Gateway Configuration Guide,
Release 4.3.x
226
Enabling RADIUS-based Lawful Intercept, on page
Purpose
Enters global configuration mode.
Configuring Subscriber Features
226.
OL-28375-03

Advertisement

Table of Contents
loading

Table of Contents