System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Additional lawful intercept information

Want to summarize with AI?

Log in

Groups reference information about interception mode, data flow, scale, packet interception, filters, encapsulation, and high availability.


Use this topic to locate operational information about lawful intercept after the feature is installed and configured.


Interception mode

Lawful intercept operates in Global LI mode.

In Global LI mode, taps are installed on all line cards in the ingress direction. A global tap can intercept target traffic regardless of the ingress point. Only a tap with wildcards in the interface field is supported.


How lawful intercept data flows

The router and mediation device exchange lawful intercept information through SNMPv3.

Summary

The process includes these components:

  • The mediation device initiates communication content intercept requests.

  • The content IAP router intercepts and replicates the communication content.

  • The mediation device sends intercepted data to the law enforcement agency collection function.

Workflow

These stages describe how intercepted data flows:

  1. The mediation device uses SNMPv3 to initiate communication content intercept requests to the content IAP router.

  2. The content IAP router intercepts and replicates the communication content, then sends it to the mediation device in IPv4 or IPv6 UDP format.

  3. The mediation device sends intercepted data sessions to the law enforcement agency collection function using a supported lawful intercept delivery standard.

Result

The authorized communication content reaches the mediation device and the law enforcement agency collection function.


Mediation device responsibilities

The mediation device performs these tasks:

  • Activates the intercept at the authorized time.

  • Removes the intercept when the authorized time period expires.

  • Periodically audits network elements to ensure that only authorized intercepts are in place and that all authorized intercepts are in place.


Lawful intercept scale and performance values

The router supports these lawful intercept scalability values:

  • A maximum of 1024 IPv4 intercepts.

  • A maximum of 512 IPv6 intercepts.


Intercept IPv4 and IPv6 packets

Use this topic to understand how lawful intercept handles IPv4 and IPv6 packets.

Lawful intercept supports the interception of IPv4 and IPv6 packets. The tap filters classify packets, and the router replicates and encapsulates matching packets before forwarding them to the mediation device.

Use these filters to classify a tap:

  • IP address type

  • Destination IP address

  • Destination mask

  • Source IP address

  • Source mask

  • Type of Service (ToS) and ToS mask

  • Layer 4 protocol

  • Layer 4 destination port with range

  • Layer 4 source port with range

VPN Routing and Forwarding (VRF), flow-id, and interface filters are not supported.


Encapsulation types supported for intercepted packets

Use this topic to identify the encapsulation types supported for intercepted packets.

The router replicates and encapsulates intercepted packets before forwarding them to the mediation device.

  • IPv4 packets use IPv4 UDP encapsulation.

  • IPv6 packets use IPv6 UDP encapsulation.

  • The replicated packet receives a new UDP header and a new IPv4 or IPv6 header, depending on the packet type.

  • The IP header information is derived from the mediation device configuration.

  • A 4-byte channel identifier (CCCID) is inserted after the UDP header.

  • The router does not support forwarding the same replicated packet to multiple mediation devices.

RTP and RTP-NOR encapsulation types are not supported.


How high availability preserves lawful intercept flows

High availability preserves operational continuity for tap flows and provisioned mediation device tables during route processor failover (RPFO).

Summary

The high-availability process depends on these actions:

  • The mediation device detects loss of taps through the SNMP configuration process.

  • The mediation device re-provisions the stream, mediation device, and IP tap table entries.

  • The replay timer provides time for re-provisioning while existing tap flows continue.

Workflow

These stages describe lawful intercept behavior during route processor failover:

  1. When RPFO is detected, the replay timer starts on the active route processor.

  2. The mediation device detects the loss of taps and re-provisions all rows relating to CISCO-TAP2-MIB and CISCO-IP-TAP-MIB to synchronize the database view across the route processor and mediation device.

  3. Existing taps continue to flow while the mediation device re-provisions the entries within the replay interval.

  4. Interception stops on taps that are not re-provisioned before the replay timer expires.

Result

The mediation device restores the lawful intercept tables and minimizes interruption to existing tap flows.


Preserve TAP and MD tables during route processor failover

After RPFO, the mediation device must re-provision the entries required to synchronize its database view with the route processor.

Summary

The mediation device re-provisions the stream tables, mediation device tables, and IP taps with the same values used before failover.

Workflow

These conditions apply after RPFO:

  1. Rows that are not re-provisioned return NO_SUCH_INSTANCE for an SNMP Get operation.

  2. Create an entire row in one configuration step with the same values used before RPFO and with rowStatus set to CreateAndGo .

  3. Set the cTap2MediationTimeOut object to a valid future time.

Result

Existing taps continue to flow when their entries are re-provisioned within the replay interval.


Replay timer

The replay timer is an internal timeout that

  • provides time for the mediation device to re-provision lawful intercept (LI) tap entries while existing tap flows continue

  • starts and resets on the active route processor when route processor failover (RPFO) occurs, and

  • has a value based on the number of LI entries on the router, with a minimum value of 10 minutes.

Replay timer behavior after failover

Interception stops on taps that are not re-provisioned before the replay timer expires.

If high availability is not required, the mediation device waits for entries to age out after failover. The mediation device cannot change an entry after the replay timer expires; it can reinstall taps as they are or wait for the entries to age out.