![]()  | 
    |||||||||||||||
Lawful Intercept Architecture 
    ![]()  | 
  |||||||||||||||
Contents 
 Lawful Intercept ArchitectureLast Updated: January 26, 2012 
The Lawful Intercept (LI) feature supports service providers in meeting the requirements of law enforcement agencies to provide the ability to intercept Voice-over-Internet protocol (VoIP) or data traffic going through the edge routers (or other network locations). This document explains LI architecture, including Cisco Service Independent Intercept architecture and PacketCable Lawful Intercept architecture. It also describes the components of the LI feature and provides instructions on how to configure the LI feature in your system. Finding Feature InformationYour software release may not support all the features documented in this module. For the latest feature information and caveats, see the release notes for your platform and software release. To find information about the features documented in this module, and to see a list of the releases in which each feature is supported, see the Feature Information Table at the end of this document. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required. Prerequisites for Lawful InterceptAccess to the Cisco LI MIB view should be restricted to the mediation device and to system administrators who need to be aware of lawful intercepts on the router. To access the MIB, users must have level-15 access rights on the router. Communication with Mediation DeviceFor the router to communicate with the mediation device to execute a lawful intercept, the following configuration requirements must be met: 
 Use the snmp-server user command, specifying the mediation device username and password, to add the mediation device to an SNMP user group, then use the snmp-server group command to associate the group with a view that includes the CISCO-TAP2-MIB and one or more optional MIBS, such as CISCO-IP-TAP-MIB. When you add the mediation device as a CISCO-TAP2-MIB user, you can include the mediation device authorization password if you want. The password must be at least eight characters in length. 
 To synchronize the time settings, ensure that Network Time Protocol (NTP) is running on both the router and mediation device. 
 If encryption of SMNP messages is required (optional), set the security level to "priv". Restrictions for Lawful InterceptGeneral Restrictions
 Information About Lawful Intercept
 Introduction to Lawful InterceptLI is the process by which law enforcement agencies (LEAs) conduct electronic surveillance as authorized by judicial or administrative order. Increasingly, legislation is being adopted and regulations are being enforced that require service providers (SPs) and ISPs to implement their networks to explicitly support authorized electronic surveillance. The types of SPs or ISPs that are subject to LI mandates vary greatly from country to country. LI compliance in the United States is specified by the Communications Assistance for Law Enforcement Act (CALEA), and accredited by the Commission on Accreditation for Law Enforcement Agencies. Cisco supports two architectures for LI: PacketCable and Service Independent Intercept. The LI components by themselves do not ensure customer compliance with applicable regulations but rather provide tools that can be used by SPs and ISPs to construct an LI-compliant network. Cisco Service Independent Intercept ArchitectureThe Cisco Service Independent Intercept Architecture Version 3.0 document describes implementation of LI for VoIP networks using the Cisco Broadband Telephony Softswitch (BTS) 10200 Softswitch call agent, version 5.0, in a non-PacketCable network. Packet Cable Event Message specification version 1.5-I01 is used to deliver the call identifying information along with version 2.0 of the Cisco Tap MIB for call content. The Cisco Service Independent Intercept Architecture Version 2.0 document describes implementation of LI for VoIP networks using the Cisco BTS 10200 Softswitch call agent, versions 4.4 and 4.5, in a non-PacketCable network. Although not a PacketCable network, PacketCable Event Messages Specification version I08 is still used to deliver call identifying information, along with version 1.0 or version 2.0 of the Cisco Tap MIB for call content. The Cisco Service Independent Intercept Architecture Version 2.0 document adds additional functionality for doing data intercepts by both IP address and session ID, which are both supported in version 2.0 of the Cisco Tap MIB (CISCO-TAP2-MIB). The Cisco Service Independent Intercept Architecture Version 1.0 document describes implementation of LI for VoIP networks that are using the Cisco BTS 10200 Softswitch call agent, versions 3.5 and 4.1, in a non-PacketCable network. Although not a PacketCable network, PacketCable Event Message Specification version I03 is still used to deliver call identifying information, along with version 1.0 of the Cisco Tap MIB (CISCO-TAP-MIB) for call content. Simple data intercepts by IP address are also discussed. PacketCable Lawful Intercept ArchitectureThe PacketCable Lawful Intercept Architecture for BTS Version 5.0 document describes the implementation of LI for VoIP using Cisco BTS 10200 Softswitch call agent, version 5.0, in a PacketCable network that conforms to PacketCable Event Messages Specification version 1.5-I01. The PacketCable Lawful Intercept Architecture for BTS Versions 4.4 and 4.5 document describes the implementation of LI for VoIP using Cisco BTS 10200 Softswitch call agent, versions 4.4 and 4.5, in a PacketCable network that conforms to PacketCable Event Messages Specification version I08. The PacketCable Lawful Intercept Architecture for BTS Versions 3.5 and 4.1 document describes the implementation of LI for VoIP using Cisco BTS 10200 Softswitch call agent, versions 3.5 and 4.1, in a PacketCable network that conforms to PacketCable Event Message Specification version I03. The PacketCable Control Point Discovery Interface Specification document defines an IP-based protocol that can be used to discover a control point for a given IP address. The control point is the place where Quality of Service (QoS) operations, LI content tapping operations, or other operations may be performed. CISCO ASR 1000 Series RoutersThe Cisco ASR 1000 series routers support two types of LI: regular and broadband (per-subscriber). Broadband wiretaps are executed on access subinterfaces. Regular wiretaps are executed on access subinterfaces and physical interfaces. Wiretaps are not required, and are not executed, on internal interfaces. The router determines which type of wiretap to execute based on the interface that the target's traffic is using. LI on the Cisco ASR 1000 series routers can intercept traffic based on a combination of one or more of the following fields: 
 The LI implementation on the Cisco ASR 1000 series routers is provisioned using SNMP3 and supports the following functionality: 
 VRF Aware LIVRF Aware LI is the ability to provision a LI wiretap on IPv4 data in a particular Virtual Private Network (VPN). This feature allows a LEA to lawfully intercept targeted data within that VPN. Only IPv4 data within that VPN is subject to the VRF-based LI tap. VRF Aware LI is available for the following types of traffic: 
 To provision a VPN-based IPv4 tap, the LI administrative function (running on the mediation device) uses the CISCO-IP-TAP-MIB to identify the name of the VRF table that the targeted VPN uses. The VRF name is used to select the VPN interfaces on which to enable LI in order to execute the tap. The router determines which traffic to intercept and which mediation device to send the intercepted packets based on the VRF name (along with the source and destination address, source and destination port, and protocol). 
 LI of IP Packets on ATM InterfacesThe Lawful Intercept feature enables you to configure the system so that IP packets that are sent and received on ATM interfaces are intercepted based on the PVC information, such as the Virtual Path Identifier (VPI) or Virtual Channel Identifier (VCI). If you specify an interface when configuring the system, then all IP traffic on the given interface corresponding to the VPI or VCI on the ATM PVC is intercepted. If you do not specify an interface when configuring the system, then IP traffic corresponding to the ATM PVC on all interfaces is intercepted. LI of IP traffic on ATM interfaces is available for the following interfaces and encapsulation types: 
 To provision an IP traffic tap on an ATM interface, the LI administrative function (running on the mediation device) uses the CISCO-IP-TAP-MIB to specify the VPI and VCI information for ATM PVCs. This information is used to select the interfaces on which to enable LI in order to execute the tap. The router determines which traffic to intercept and to which mediation device to send the intercepted packets based on the VPI and VCI information. When an ATM interface tap is provisioned, the system creates an IP_STREAM entry type, that stores all tap information (such as the PVC information and interface). The LI feature intercepts packets at the IP layer. If the interface is an ATM interface, LI extracts the PVC information from the packet and matches it against the provisioned streams. If an interface is specified when configuring the system, LI also matches the packet information against the interface. For each matching stream, the LI module sends a copy of the packet to the corresponding mediation device. IPv6 Based Lawful InterceptsTo configure IPv6 based lawful intercepts, the system identifies either the source or destination address as the target address and then determines if a less specific route to the target address exists. If a less specific route to the target address exists, the system identifies the list of interfaces that can used to reach the target address and applies the intercepts to those interfaces only. The system automatically detects route changes and reapplies intercepts on any changed routes. The system uses the IPv6 stream details specified by the snmp set command to identify the target address, using the following criteria: 
 Lawful Intercept MIBsDue to its sensitive nature, the Cisco LI MIBs are only available in software images that support the LI feature. These MIBs are not accessible through the Network Management Software MIBs Support page ( http://www.cisco.com/public/sw-center/netmgmt/cmtk/mibs.shtml ). Restricting Access to the Lawful Intercept MIBsOnly the mediation device and users who need to know about lawful intercepts should be allowed to access the LI MIBs. To restrict access to these MIBs, you must: 
 For more information, see the Creating a Restricted SNMP View of Lawful Intercept MIBs module. How to Configure Lawful InterceptAlthough there are no direct user commands to provision lawful intercept on the router, you do need to perform some configuration tasks, such as providing access to LI MIBs, setting up SNMP notifications, and enabling the LI RADIUS session feature. This section describes how to perform the following tasks: 
 Creating a Restricted SNMP View of Lawful Intercept MIBsTo create and assign users to an SNMP view that includes the Cisco lawful intercept MIBs, perform the steps in this section. Before You Begin
       
SUMMARY STEPS
      
      
      
      
      
      
      
      
      
      
    
 DETAILED STEPS Where to Go NextThe mediation device can now access the lawful intercept MIBs and issue SNMP set and get requests to configure and run lawful intercepts on the router. To configure the router to send SNMP notification to the mediation device, see the Enabling SNMP Notifications for Lawful Intercept. Enabling SNMP Notifications for Lawful InterceptSNMP automatically generates notifications for lawful intercept events. To configure the router to send lawful intercept notifications to the mediation device, perform the steps in this section. Before You Begin
       
SUMMARY STEPS
      
      
      
      
      
    
 DETAILED STEPS Disabling SNMP NotificationsTo disable SNMP notifications on the router, perform the steps in this section. DETAILED STEPS Enabling RADIUS Session InterceptsThere are no user CLI commands available to provision the mediation device or taps. However, to enable the intercepts through the CISCO-TAP-MIB you must configure the system to make the account-session-id value available to the mediation device. To enable RADIUS session intercepts on the router, perform the steps in this section. DETAILED STEPS Configuration Examples for Lawful Intercept
 Example Enabling Mediation Device Access Lawful Intercept MIBsThe following example shows how to enable the mediation device to access the lawful intercept MIBs. It creates an SNMP view (tapV) that includes three LI MIBs (CISCO-TAP2-MIB, CISCO-IP-TAP-MIB, CISCO-802-TAP-MIB). It also creates a user group that has read, write, and notify access to MIBs in the tapV view. snmp-server view tapV ciscoTap2MIB included snmp-server view tapV ciscoIpTapMIB included snmp-server view tapV cisco802TapMIB included snmp-server group tapGrp v3 auth read tapV write tapV notify tapV snmp-server user MDuser tapGrp v3 auth md5 MDpasswd snmp-server engineID local 1234 Example Enabling RADIUS Session Lawful InterceptThe following example shows the configuration of a RADIUS-Based Lawful Intercept solution on a router acting as a network access server (NAS) device employing a PPPoEoA link: aaa new-model ! aaa intercept ! aaa group server radius SG server 10.0.56.17 auth-port 1645 acct-port 1646 ! aaa authentication login LOGIN group SG aaa authentication ppp default group SG aaa authorization network default group SG aaa accounting send stop-record authentication failure aaa accounting network default start-stop group SG ! aaa server radius dynamic-author client 10.0.56.17 server-key cisco ! vpdn enable ! bba-group pppoe PPPoEoA-TERMINATE virtual-template 1 ! interface Loopback0 ip address 10.1.1.2 255.255.255.0 ! interface GigabitEthernet4/1/0 description To RADIUS server ip address 10.0.56.20 255.255.255.0 duplex auto ! interface GigabitEthernet4/1/2 description To network ip address 10.1.1.1 255.255.255.0 duplex auto ! interface GigabitEthernet5/0/0 description To subscriber no ip address ! interface GigabitEthernet5/0/0.10 encapsulation dot1q 10 protocol pppoe group PPPoEoA-TERMINATE ! interface Virtual-Template1 ip unnumbered Loopback0 ppp authentication chap ! radius-server attribute 44 include-in-access-req radius-server attribute nas-port format d radius-server host 10.0.56.17 auth-port 1645 acct-port 1646 radius-server key cisco Additional ReferencesRelated DocumentsMIBsTechnical Assistance
 Feature Information for Lawful InterceptThe following table provides release information about the feature or features described in this module. This table lists only the software release that introduced support for a given feature in a given software release train. Unless noted otherwise, subsequent releases of that software release train also support that feature. Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, go to www.cisco.com/go/cfn. An account on Cisco.com is not required. 
 
 Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R) Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. © 2012 Cisco Systems, Inc. All rights reserved. 
 | 
  |||||||||||||||
| 
        
        
		 |