Configuring CALEA Server Support on IAPs
LILawful Interception. LI refers to the procedure of obtaining communications network data by the Law Enforcement Agencies for the purpose of analysis or evidence. allows the Law Enforcement Agencies to perform an authorized electronic surveillance. Depending on the country of operation, the ISPs are required to support LI in their respective networks.
In the United States, Service Providers are required to ensure LI compliance based on CALEACommunications Assistance for Law Enforcement Act. To comply with the CALEA specifications and to allow lawful interception of Internet traffic by the law enforcement and intelligence agencies, the telecommunications carriers and manufacturers of telecommunications equipment are required to modify and design their equipment, facilities, and services to ensure that they have built-in surveillance capabilities. specifications.
Aruba Central supports CALEA integration with an Instant Access Point (IAP) in a hierarchical and flat topology, mesh IAP network, the wired and wireless networks.
Enable this feature only if lawful interception is authorized by a law enforcement agency.
For more information on the communication and traffic flow from an IAP to CALEA server, see Aruba Instant User Guide.
To enable an IAP to communicate with the CALEA server, complete the following steps:
Creating a CALEA Profile
To create a CALEA profile, complete the following steps:
- In the app, set the filter to a group that contains at least one AP. The dashboard context for the group is displayed.
- Under , click .
- Click the icon. The tabs to configure access points is displayed.
- Click , and click tab. The Services page is displayed.
- Click the accordion.
-
Specify the following parameters:
- — Specify the IP address of the CALEA server.
- Aruba Central supports GREGeneric Routing Encapsulation. GRE is an IP encapsulation protocol that is used to transport packets over a network. only. — Specify the encapsulation type. The current release of
- — Specify the GRE type.
- MTUMaximum Transmission Unit. MTU is the largest size packet or frame specified in octets (eight-bit bytes) that can be sent in networks such as the Internet. within the range of 68—1500. After GRE encapsulation, if packet length exceeds the configured MTU, IP fragmentation occurs. The default MTU size is 1500. fragmentation occurs. The default MTU size is 1500. — Specify a size for the
- Click Save Settings.
Creating ACLs for CALEA Server Support
To create an access rule for CALEA, complete the following steps:
- In the app, use the filter to select a group or a device.
-
If you select a group, perform the following steps:
- Under , click > .
- Click the icon. The tabs to configure the group is displayed.
- If you select a device, under , click .
- Click , and click tab. The Security page is displayed.
- Click the accordion.
- Under , click icon. The window is displayed.
- Set the to .
- Click .
- Create a role assignment rule if required.
- Click .