Oracle SBC Security Guide
VPN should be implemented for session replication, and thorough testing should be conducted to
understand impacts to session capacity.
Guidelines are presented in “520-0011-03 BCP - High Availability Configuration”.
Configuration is detailed in Section 14 “High Availability Nodes” of the ACLI Configuration Guide.
Link Detection and Gateway Polling
If the gateway-heartbeat is enabled, the SBC periodically sends ARP requests for each configured
network-interface gateway. If the configured number of retransmissions has been exceeded, the SBC will
mark that gateway as unreachable and decrement its health score. If the health score decrements far
enough, and the health score of the standby unit is higher, an HA failover will occur.
It is recommended that exactly one network-interface per physical interface have gateway-heartbeat
enabled.
The following configuration fragment depicts the recommended default settings for the gateway heartbeat
sub-element. It is also advisable to increment the health-score value by one with each new heartbeat
configuration for ease of failure identification based on score.
gw-heartbeat
state enabled
heartbeat 10
retry-count 3
retry-timeout 3
health-score 30
The feature is explained in detail in Section 14 “High Availability Nodes” of the “Net-Net 4000 <Current
Release> ACLI Configuration Guide”.
Physical Link Redundancy
Physical Link Redundancy can be configured between the two virtual slot pairs on a physical NIU.
Should the active interface fail, the standby will take over.
The active interfaces are slot 0 port 0 (M00) and slot 1 port 0 (M10). The standby interfaces are slot 0 port
1 (M01) and slot 1 port 1 (M11).
Although this feature can be used in conjunction with the max-signaling-bandwidth feature and static
ACLs, this feature is incompatible with the Net-SAFE Architecture. Hence this functionality is
considered optional and should only be deployed where DDoS protection is not a factor (e.g. Peering
deployments), and where QoS metrics are not required. This feature is not commonly deployed.
Configuration is detailed in Section 3 “System Configuration” of the ACLI Configuration Guide.
Kommentare zu diesen Handbüchern