Oracle SBC Security Guide
04 00000000 00000000 00000001
Enhanced Traffic Controller (ETC) NIU support
Hardware and software support requirements to support ETC NIU
The NN4500 CPU1 or CPU2 should have the Nov, 2010 or later bootloader in order to support the
Enhanced Traffic Controller (ETC) NIU.
The ETC NIU requires a software version of nnSCX630f1.xz or later.
Configuration deviations from HiFn
The ETC NIU supports only the SDES protocol for SRTP.
The configuration element “security-policy” is no longer required for SRTP using the ETC NIU.
The AES_CM_128 encryption and HMAC_SHA1_80 or HMAC_SHA1_32 authentication suites are
supported on the ETC NIU. ARIA Cipher suite will be supported in nnSCX630f2.
The ETC NIU contains one Cavium hardware chip that provides encryption/decryption. In order to
support 10,000 concurrent sessions and overcome the 1 GB bandwidth limitation per port, a major design
goal is to split the traffic between any 2 ports on ingress and remaining 2 ports on egress. Upon reaching
10,000 concurrent sessions limit, subsequent calls will be rejected.
Debugging Info
Following is the list of commands to be used in order to get SRTP and ETC specific information.
show nat flow-info srtp statistics
This command will show the global statistics for all SRTP flows.
SBASNQ06# show nat flow-info srtp statistics
PPM_ID_SRTP_E:
PPX Global Statistics
---------------------
alloc_count : 50
dealloc_count : 16
input-packets : 0
output-packets : 0
sessions-count : 2
init-requests : 4
init-success : 4
init-fail : 0
modify-requests : 0
modify-success : 0
modify-fail : 0
delete-requests : 2
delete-success : 2
delete-fail : 0
query-requests : 0
query-success : 0
query-fail : 0
resources-error : 0
protect-fail : 0
unprotect-fail : 0
status-err : 0
Kommentare zu diesen Handbüchern