Groups the procedures that disable SNMP-based lawful intercept, configure inband management-plane protection, and enable the LI SNMP server configuration.
Use this topic to understand the SNMPv3 procedures that support lawful intercept.
System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
Groups the procedures that disable SNMP-based lawful intercept, configure inband management-plane protection, and enable the LI SNMP server configuration.
Use this topic to understand the SNMPv3 procedures that support lawful intercept.
Lawful Intercept is enabled by default on the router after installing and activating the LI RPM package.
The lawful-intercept disable command is available only after the LI RPM package is installed and activated.
Router# configure
Router(config)# lawful-intercept disable
Router(config)# commit
SNMP-based lawful intercept is disabled and all SNMP-based taps are dropped. Use the no form of the command to re-enable lawful intercept.
Configure the Management Plane Protection (MPP) feature for SNMP communication with the mediation device.
MPP is disabled by default. If MPP is not already configured for another protocol, configure it for SNMP communication with the mediation device. Configure an inband interface, such as a loopback interface, to allow SNMP commands to reach the router.
The inband management-plane configuration allows SNMP on loopback0. The verification output identifies the interface and confirms that SNMP is configured.
Configure the SNMP engine, host, user, views, and group required for lawful intercept.
Perform this task even if you recently upgraded to Cisco IOS XR Software from Cisco IOS and had MPP configured for a protocol.
If you use a loopback interface for SNMP messages, include that interface in the inband management configuration.
The SNMP server is configured to support lawful intercept communication with the mediation device.