Table Of Contents
End-to-End Cisco Unified Border Element
(SP Edition) Configuration Example
End-to-End Cisco Unified Border Element
(SP Edition) Configuration Example
This section contains a complete Cisco Unified Border Element (SP Edition) configuration on the Cisco ASR 1000 Series Routers.
Building configuration...
Current configuration : 17580 bytes
! Last configuration change at 11:12:56 SGT Sun Nov 21 2010
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
no platform punt-keepalive disable-kernel-core
boot system
bootflash:asr1000rp1-adventerprisek9.BLD_V151_1_S_XE32_THROTTLE_LATEST_20101109_090050.bin
boot system bootflash:asr1000rp1-adventerprisek9.BLD_MCP_DEV_LATEST_20101109_222533.bin
vrf definition h323-vrf-a
vrf definition h323-vrf-b
description VRF a-side for late-to-early
description VFR b-side for late-to-early
vrf definition sigpinhole_customer_a
description SigPinhole-VRF-Customer-A
vrf definition sigpinhole_customer_b
description SigPinhole-VRF-Customer-B
logging buffered 10000000
enable secret 5 $1$wVYL$r.SbA2ka.6l9g7baSdHJx/
no process cpu extended history
no process cpu autoprofile hog
ip host t-mobile.com 10.0.48.236
ip host ibcf.t-mobile.com 10.0.48.236
ip host scscf.t-mobile.com 10.0.48.236
ip name-server 20.21.28.125
ip name-server vrf vrf_a 20.21.28.125
ip name-server vrf vrf_b 20.21.28.125
ipv6 host opensips.cisco.com 2001:20:21:28:20:21:28:93
multilink bundle-name authenticated
priority 255 failover threshold 100
control GigabitEthernet0/0/1.726 protocol 1
data GigabitEthernet0/0/2
authentication md5 key-string cisco
class-map type inspect match-any sip-traffic-class
policy-map type inspect private-public-policy
class type inspect sip-traffic-class
zone-pair security private-public source private destination public
service-policy type inspect private-public-policy
ip address 10.160.90.4 255.255.255.0 secondary
ip address 10.160.90.11 255.255.255.0 secondary
ip address 10.160.90.12 255.255.255.0 secondary
ip address 10.160.90.13 255.255.255.0 secondary
ip address 10.160.90.14 255.255.255.0 secondary
ip address 10.160.90.15 255.255.255.0 secondary
ip address 10.160.90.16 255.255.255.0 secondary
ip address 10.160.90.17 255.255.255.0 secondary
ip address 10.160.90.18 255.255.255.0 secondary
ip address 10.160.90.19 255.255.255.0 secondary
ip address 10.160.90.3 255.255.255.0 secondary
ip address 20.24.34.1 255.255.255.0
ipv6 address 2001:A401::10:160:90:1/64
ipv6 address 2001:A401::10:160:90:2/64
ipv6 address 2001:A405::20:24:34:1/64
ip address 10.190.6.2 255.255.255.224 secondary
ip address 10.190.6.1 255.255.255.224
ip address 10.190.6.34 255.255.255.224 secondary
ip address 10.190.6.33 255.255.255.224
ip address 10.190.7.66 255.255.255.224 secondary
ip address 10.190.7.65 255.255.255.224
ip address 10.190.7.98 255.255.255.224 secondary
ip address 10.190.7.97 255.255.255.224
ip address 9.1.1.1 255.255.255.0
ip address 20.24.31.1 255.255.255.0
ipv6 address 2001:20:24:31:20:24:31:1/64
ip address 20.24.49.1 255.255.255.0
interface GigabitEthernet0/0/0
ip address 1.1.1.2 255.255.255.0
zone-member security private
interface GigabitEthernet0/0/1
interface GigabitEthernet0/0/1.726
ip address 20.21.26.120 255.255.255.0
interface GigabitEthernet0/0/2
ip address 1.1.2.2 255.255.255.0
zone-member security public
interface GigabitEthernet0/0/3
interface FastEthernet0/1/0
ip address 20.21.47.16 255.255.255.0 secondary
ip address 20.21.47.13 255.255.255.0
interface FastEthernet0/1/1
interface FastEthernet0/1/2
interface FastEthernet0/1/3
interface GigabitEthernet0
ip address 10.74.48.165 255.255.255.224
ip route 10.74.48.151 255.255.255.255 20.21.26.1
ip route vrf Mgmt-intf 0.0.0.0 0.0.0.0 10.74.48.161
ip route vrf Mgmt-intf 0.0.0.0 0.0.0.0 10.74.28.65
ip route vrf vrf_a 0.0.0.0 0.0.0.0 20.21.27.1
ip route vrf vrf_b 0.0.0.0 0.0.0.0 20.21.26.1
ipv6 route ::/0 2001:20:21:28:20:21:28:1
ipv6 route vrf vrf_b ::/0 2001:20:21:26:20:21:26:1
ipv6 route vrf vrf_a ::/0 2001:20:21:27:20:21:27:1
control address aaa ipv4 20.24.34.1
radius accounting Codenomicon
sip parameter-profile test
sip parameter-profile testb
sip parameter-profile proxy-param
sip parameter-profile access-param
action add-or-replace value public-ip-address
header-prio 1 header-name P-Called-Party-ID
header-prio 2 header-name P-Preferred-Identity
header P-Asserted-Identity entry 1
action replace-value value "ddd"
header P-KT-UE-IP entry 1
header P-KT-UE-IP entry 2
action add-header value "${msg.rmt_ip_addr}"
parameter-profile proxy-param
sip header-profile access
parameter-profile access-param
sip header-profile default
sip header-profile IMS_Access
header P-Called-Party-ID entry 1
sip header-profile P-Charging-Fucntion-Address
header P-Charging-Function-Addresses entry 1
action add-first-header value "1.1.1.1"
sip method-profile default
sip option-profile default
sip error-profile default
cause rtg-no-route-found sub-cause rtg-src-adjacency status-code 604 reason "Q.850
;cause=16 ;text=\"SBC: No route found based on src adjacency\""
adjacency h323 H323CCM134-GK
signaling-address ipv4 20.24.34.1
remote-address ipv4 10.0.50.134 255.255.255.255
signaling-peer gk 10.0.48.93
adjacency h323 H323CCM134-vrfa
signaling-address ipv4 10.190.7.65
remote-address ipv4 10.0.50.134 255.255.255.255
signaling-peer 10.0.50.134
signaling-address ipv4 20.24.34.1
statistics method summary
remote-address ipv4 10.0.244.81 255.255.255.255
signaling-peer 10.0.244.81
signaling-address ipv4 20.24.34.1
statistics method summary
remote-address ipv4 10.0.244.82 255.255.255.255
signaling-peer 10.0.244.82
inherit profile preset-access
signaling-address ipv4 192.168.2.1
statistics method summary
remote-address ipv4 10.0.120.19 255.255.255.255
signaling-peer 10.0.120.19
inherit profile preset-access
visited network identifier ims.net
signaling-address ipv4 192.168.2.1
statistics method summary
remote-address ipv4 192.168.1.1 255.255.255.255
signaling-peer 192.168.1.1
inherit profile preset-access
visited network identifier ims.net
signaling-address ipv4 192.168.130.1
statistics method summary
remote-address ipv4 192.168.129.1 255.255.255.255
signaling-peer 192.168.129.1
signaling-address ipv4 20.24.34.1
statistics method summary
remote-address ipv4 10.0.50.132 255.255.255.255
signaling-peer 10.0.50.132
ping-suppression ood-request
warrant match-order destination source diverted-by
vrf sigpinhole_customer_a
signaling-address ipv4 10.190.6.33
statistics method summary
remote-address ipv4 10.0.50.133 255.255.255.255
signaling-peer 10.0.50.133
signaling-address ipv4 20.24.34.1
statistics method summary
remote-address ipv4 10.0.50.135 255.255.255.255
signaling-peer 10.0.50.135
inherit profile preset-core
signaling-address ipv6 2001:A401::10:160:90:1
statistics method summary
remote-address ipv6 2001::216:ECFF:FE3B:40DD/128
signaling-peer 2001:A401::33:33:36:1
registration target address 2001:A401::33:33:36:2
header-name From passthrough
adjacency sip OpenIMSCore
inherit profile preset-core
signaling-address ipv4 20.24.34.1
statistics method summary
remote-address ipv4 10.0.48.236 255.255.255.255
signaling-peer 10.0.48.236
registration target address open-ims.test
header-name From passthrough
adjacency sip SoftphoneV6
inherit profile preset-access
signaling-address ipv6 2001:A401::10:160:90:1
statistics method summary
remote-address ipv6 2001::/64
signaling-peer 2001::10:0:120:19
registration rewrite-register
first-cac-scope src-adjacency
table-type limit src-adjacency
caller inband-dtmf-mode always
codec-preference-list pref-list1
callee-privacy privacy-service always
caller-privacy privacy-service never
payload-type asymmetric allowed
callee local-call-transfer allowed
action next-table msmbtb1
media bypass type hairpin full
first-inbound-na-table natable1
first-call-routing-table da1
first-reg-routing-table REG-ROUTE-ON-SRC-ADJ
rtg-dst-address-table da1
match-address kate string
dst-adjacency OpenIMSCore
rtg-src-adjacency-table REG-ROUTE-ON-SRC-ADJ
dst-adjacency OpenIMSCore
match-adjacency SoftphoneV6
match-adjacency OpenIMSCore
na-dst-address-table natable1
action next-table privacytb1
edit-src add-prefix 12345
match-address ^201[a-d]ef regex
na-src-name-anonymous-table privacytb1
first-call-routing-table ROUTE-ON-DEST-NUM
rtg-dst-address-table ROUTE-ON-DEST-NUM
match-address 1320X digits
first-call-routing-table table1
rtg-src-adjacency-table table1
call-policy-set default 1
description This is a description for DOMAIN1
call-policy-set inbound-na 3
! using call-policy-set outbound-na default
description This is a description for DOMAIN2
call-policy-set inbound-na 2
call-policy-set outbound-na 2
codec variant codec G7231L
local-address ipv4 20.24.34.1
packetcable-em 0 transport radius Codenomicon
local-address ipv4 20.24.34.1
reason cac-policy-rejection
blacklist vpn sigpinhole_customer_a
reason authentication-failure
reason endpoint-registration
reason cac-policy-rejection
blacklist global ipv6 2001::10:0:233:113
reason authentication-failure
reason endpoint-registration
reason cac-policy-rejection
media-address ipv4 10.160.90.3
port-range 10000 11000 voice tag CCM-132
port-range 11001 12000 video tag CCM-135
media-address ipv6 2001:A401::10:160:90:1
port-range 16384 32767 signaling
exception data-corruption buffer truncate
monitor session 22 type erspan-source
description SOURCE_SESSION_FOR_Gi0/0/0
origin ip address 20.21.28.72