31.07.2015 Views

Cisco - Gateway to Gatekeeper (H.235) and ... - VOIP Information

Cisco - Gateway to Gatekeeper (H.235) and ... - VOIP Information

Cisco - Gateway to Gatekeeper (H.235) and ... - VOIP Information

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Cisco</strong> - <strong>Gateway</strong> <strong>to</strong> <strong>Gatekeeper</strong> (<strong>H.235</strong>) <strong>and</strong> <strong>Gatekeeper</strong> <strong>to</strong> <strong>Gatekeeper</strong> (IZCT) Security Troubleshooting Guideaaa authorization exec h323 localaaa accounting connection h323 start-s<strong>to</strong>p group radius!username gwa-1 password 0 2222username gwa-2 password 0 2222!gatekeeperzone local gka-1 cisco.com 172.16.13.35security <strong>to</strong>ken required-for all!--- The gatekeeper is configured for the "All level security"no shutdown!!line con 0exec-timeout 0 0line aux 0line vty 0 4password wwline vty 5 15!no scheduler max-task-timeno scheduler allocatentp master!--- This gatekeeper is set as an NTP master!endIn the example below, the following debugs were turned on:●●●●●debug rasdebug h225 asn1debug radiusdebug aaa authenticationdebug aaa authorizationThe first thing that occurs is the gateway sends a GRQ <strong>to</strong> the gatekeeper <strong>and</strong> the gatekeeper sends a <strong>Gatekeeper</strong> Confirm (GCF) <strong>to</strong> thegateway. The gateway then sends an RRQ <strong>and</strong> waits for either an RCF or RRJ.In the above configuration, the gateway is not set for any level of security so that its GRQ would carry no authenticationCapability thatwould be needed for the <strong>to</strong>kens. But still, the gatekeeper would send back a GCF as shown below.*Mar 2 13:32:45.413: RAS INCOMING ENCODE BUFFER::= 00 A00000060008914A 000200AC 100D0FD2 C6088001 3C050401 00204002 00006700 6B0061002D003102 400E0067 00770061 002D0031 00400063 00690073 0063006F 002E0063006F006D 0080CC*Mar 2 13:32:45.421:*Mar 2 13:32:45.425: RAS INCOMING PDU ::=value RasMessage ::= gatekeeperRequest :{requestSeqNum 1pro<strong>to</strong>colIdentifier { 0 0 8 2250 0 2 }rasAddress ipAddress :{ip 'AC100D0F'Hhttp://kbase:8000/paws/servlet/ViewFile/18729/gw_security.xml?convertPaths=1 (9 of 49) [12/2/2003 5:34:20 PM]

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!