You are on page 1of 49

NGN and related Concepts

Session 2
• Firewall/SBC Concepts
• Different ACLs and How Commands are read on SBC
• How IPs are defined at Trusted and untrusted side of SBC
• NAT and PAT Concepts
• MAPGroups configurations in SBC for new clients
• Configruations for SIP Trunk in SS for Corporate clients and their call
flows from public to private networks
• SBC Basic Commands

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


TL1 NBI (North bound Interface) mode

- The TL1 NBI of the N2000 UMS is used for the interconnection between the element management system
(EMS) and the operation support system (OSS).
- Through the TL1 NBI, the OSS can provision and maintain integrated access devices (IADs), multimedia
terminals, voice users, basic rate access (BRA) users, multimedia users and manage the NGN resources
OSS: The OSS delivers TL1 commands for automatically provisioning services to the N2000 UMS.
TL1 service provision NBI: It provides an interface for the OSS to connect to the N2000 UMS,
so that the OSS can perform the operations such as the service provision and resource querying.

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


SBC

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


What is a Firewall?
A firewall :
◼ Acts as a security gateway between Internet
two networks
 Usually between trusted and
untrusted networks (such as between
a corporate network and the Corporate
Internet) Network Gateway

◼ Tracks and controls network


communications
 Decides whether to pass, reject,
encrypt, or log communications
(Access Control)
Corporate
Site

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Firewall Characteristics
◼ Design goals:
 All traffic from inside from/to outside must pass
through the firewall

 Only authorized traffic (defined by the local


security policy) will be allowed to pass

 The firewall itself should be immune to


penetration

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.
Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.
Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.
Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.
Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.
Step 1 ACL

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Advance ACL

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Step 2: Define Private Signaling IP for New Trunk

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Step 3: Define Private Media IP for New Trunk

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


WAN End Information

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Step 3: Allow well known Ports for Clients IPs

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Step 4: Allow well known Ports for Softx IPs

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Step 5: Define NAT/PAT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Step 5: Define Map-group/NAT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Step 5: Define Map-group/NAT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


NAT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved. Page21
NAT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved. Page22
Step 5: Define Map-group/NAT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Configurations in SS for Client via SBC:OFC

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Configurations in SS for Client via SBC:SRT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Configurations in SS for Client via SBC:RT

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Configurations in SS for Client via SBC:RTANA

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Configurations in SS for Client via SBC:CNACLD

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Configurations in SS for Client via SBC:CALL Source

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Configurations in SS for Client via SBC:CALL Source

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Mini-Quiz

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


ADD SIP TG

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


ADD SIP TG

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Perform NAT

SBC
NADRA
PIE 100
SS
TG

PIE
Check routing, route it MSAG
towards 100 number
trunk which is
Source IP of configured with SBC
SBC/Dest IP
of NADRA

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to display Version/Memory of SBC

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to display patch information of SBC

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to define user with cipher password

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to define user with cipher password

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to define/delete user with simple password

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


User with cipher/simple password

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Memory Usage

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to define timeout for user in case user is idle

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to Change the SBC Name

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Compare save and current configurations

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to find something in Configurations

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


How to find something in Configurations

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Current and configured Session count

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


AAA Schemes

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.


Display Current and on Waiting access Users

Copyright © 2008 Huawei Technologies Co., Ltd. All rights reserved.

You might also like