Chapter 8 Integrated Session Border Controller Security
Firewall (Media Pinhole Control)
Firewall (Media Pinhole Control)
The SBE Call Admission Control (CAC) function inspects the signaling message and instructs the firewall in the DBE to open and close pinholes as needed for the media streams and signaling.
H.248 Address Reporting Package
The data border element (DBE) supports the H.248 Address Reporting (adr) package, defined in “Draft New H.248.37 Amendment 1”,
The rsac event is generated by the media gateway (MG) when the remote source address for the termination changes (that is, when a stream latches), and is used to report the newly detected remote source address and port to which the stream has been latched.
The event is generated in both the LATCH and RELATCH scenarios. The DBE reports the event subscription with the audit response when the media gateway controller (MGC) audits the packages.
For further information on support for the H.248 IP NAPT Traversal package, see the “IP NAPT Traversal Package and Latch and Relatch Support” section on page
DBE Restrictions
The following are restrictions for adr package support:
•The MGC must explicitly subscribe for the rsac event.
•The adr package can be used only in conjunction with the IP NAPT Traversal package.
H.248 Session Failure Reaction Package
The data border element (DBE) supports the H.248 Session Failure Reaction (SFR) package. From a security point of view, the media gateway controller (MGC) can put a termination out of service when the H.248 connection between the MGC and media gateway (MG) is lost.
For more information on the SFR package, see the “H.248 Session Failure Reaction Package” section on page
H.248 Termination State Control Package
The data border element (DBE) supports the Termination State Control (TSC) package to monitor signaling pinholes.
The
For more information on the TSC package, see the “H.248 Termination State Control Package” section on page
Cisco IOS XE Integrated Session Border Controller Configuration Guide for the Cisco ASR 1000 Series Aggregation Services Routers
| ||
|