• No results found

Obtain the digital certificate required for the security GW Ensure that Huawei root CA certificate and Huawei CRL file are configured on the security GW.

Preparations for Remote eNodeB Commissioning on the M2000 With the Security GW

Step 2 Obtain the digital certificate required for the security GW Ensure that Huawei root CA certificate and Huawei CRL file are configured on the security GW.

----End

4.2.5 Configuring the Security Equipment

When the security gateway (GW) is deployed in the network, you need to configure data for the security GW. In the case that the digital certificate or pre-shared key is adopted for authentication,

the customized parameters, such as the IP address of the security GW and the IP address of the M2000 server, should be set on the public DHCP server. In this way, a security channel between the eNodeB and the security GW can be set up, and the eNodeB can be connected to the M2000. In the case that the IEEE 802.1x authentication is adopted, the authentication access equipment and the authentication server should be configured. Generally, an authentication server is the Authentication, Authorization and Accounting (AAA) server.

Prerequisite

l The Quidway S6500 Series Ethernet Switches Operation Manual is ready, and can be

downloaded from http://support.huawei.com/.

l The infoX AAA Commissioning Guide is ready, and can be downloaded from http://

support.huawei.com/.

l If the IEEE 802.1x authentication is adopted, the operator should use the authentication

access equipment that supports 802.1x authentication and the corresponding AAA server that supports Extensible Authentication Protocol (EAP).

Context

l Table 4-5 describes the configuration items that you need to pay special attention to when

the security GW is used.

Table 4-5 Security GW configuration

Item Description

IP address Both the public security GW and the serving security GW should be configured with the IP address of the interface for the untrusted domain on the eNodeB side and IP address of the interface for the trusted domain on the EPC side.

Route l Public security GW: The routes to the M2000, eNodeB, and

temporary OM IP address should be configured.

l Serving security GW: The routes to the M2000, S-GW, MME, IP

address of the interface to the eNodeB, S1 signaling, S1 services, and OM IP address should be configured.

ike local name

The public security GW and serving security GW should be configured. ike proposal l The authentication method item should be digital certificate mode or

pre-shared key mode according to the actual network.

l The authentication algorithm item must be SHA1. l The encryption algorithm item must be AES. l The DH group item must be DH group2.

Item Description

ike peer l Public security GW: The key or certificate domain should be

configured according to the authentication mode specified in the ike proposal. The local id type item must be name, the remote name item must be p-segw, the ike proposal item should be configured according to previous configurations, and the ike version item can be V1 or V2. The ip pool item should be configured to allocate the temporary OM IP for the eNodeB.

l Serving security GW: The key or certificate domain should be

configured according to the authentication mode specified in the ike proposal. The local id type item must be name, the remote name item must be s-segw, the ike proposal item should be configured according to previous configurations, and the ike version item can be V1 or V2. ipsec

proposal

The encapsulation mode item must be tunnel, the transform item must be esp, the esp authentication item must be shal, and the esp encryption item must be aes.

ipsec policy- template

The public security GW and serving security should be set to the template mode. The Acl should be configured according to previous configurations. If the public security GW and serving security GW are the same, different acl values must be configured. The psf group must be DH group2. The public security GW and serving security GW must correspond to different ike peer values. The ipsec proposal item should be configured according to previous configurations.

ipsec policy This item must be configured according to the template in the ipsec policy-template.

ipsec binding to port

The policy can be bound to the planned port according to the configuration in the ipsec policy.

l The purposes of configuring the public DHCP server are as follows:

– After obtaining the customized information through the message from the eNodeB to

the public DHCP server, the public DHCP server can identify Huawei eNodeB.

– Then, the public DHCP server returns the customized information to the eNodeB.

The public DHCP server needs to configure the information for identifying Huawei eNodeB and the customized information related to Huawei equipment. The customized information provides necessary configuration information for setup of the DHCP server with the security GW deployed, as described in Table 4-5.

Table 4-6 Descriptions of customized information Fiel

d ID Field FieldLengt

h (Unit: Byte) Description Configurati on Scenario 18 IP address of the public security GW

4 This is the IP address of the public security GW used to establish the IPSec channel.

Pre-shared key or digital certificate 19 Domain name of

the public security GW

1-64 This is the domain name of the public security GW used to establish the IPSec channel.

Pre-shared key or digital certificate 22 IP address of the

CR/CRL server

4 This is the IP address of the server used to download the CRL and cross certificate.

Digital certificate 23 CR/CRL server

access user name

1-32 This is the user name used to access the CR/CRL server.

Digital certificate 24 CR/CRL server

access password

1-16 This is the password used to access the CR/CRL server.

Digital certificate 25 Path of the cross

certificate on the CR/CRL server

1-64 This is the path for saving the cross certificate on the CR/ CRL server.

Digital certificate 26 Path of the CRL file

on the CR/CRL server

1-64 This is the save path of the operator's CRL file on the CR/ CRL server. Digital certificate 28 DHCP server IP address provided by the M2000

4 This is the IP address of the DHCP server that is provided by the M2000. Pre-shared key or digital certificate 29 DHCP server domain name provided by the M2000

1-64 This is the DHCP server domain name provided by the M2000.

Pre-shared key or digital certificate 31 Local name of the

public security GW

1-32 This is the local ID of the public security GW.

Pre-shared key or digital certificate

l When the authentication access equipment is used, the authentication mode of Radius

(remote authentication dial-in user service) and the authentication method of EAP should be configured, because certificate authentication is adopted at present.

l When the AAA server is used, the CA certificates of terminal users should be uploaded,

and the file names of the user certificate and private key should be configured for the AAA server.

Procedure