data:image/s3,"s3://crabby-images/27e8e/27e8ec9d5360c6a0c856f90a8faf63aa84ef1f82" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 456"
22-40
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 22 Applying Application Layer Protocol Inspection
GTP Inspection
GGSN Load Balancing
GGSN load balancing (GSN pooling) allows any GSN the belongs to a GSN pool to respond to an SGSN
request to achieve load balancing on the GGSN. To enable support for GNS pooling, use the
permit
response
command.
If the security appliance performs GTP inspection, by default the security appliance drops GTP
responses from GSNs that were not specified in the GTP request. This situation occurs when you use
load balancing among a pool of GSNs to provide efficiency and scalability of GPRS.
You can enable support for GSN pooling by using the
permit response
command. This command
configures the security appliance to allow responses from any of a designated set of GSNs, regardless of
the GSN to which a GTP request was sent. You identify the pool of load-balancing GSNs as a network
object. Likewise, you identify the SGSN as a network object. If the GSN responding belongs to the same
object group as the GSN that the GTP request was sent to, and if the SGSN is in an object group that the
responding GSN is permitted to send a GTP response to, the security appliance permits the response.
To create an object to represent the pool of load-balancing GSNs, perform the following steps:
Step 1
Define a new network object group representing the pool of load-balancing GSNs. To do so, use the
object-group
command.
hostname(config)#
object-group network
GSN-pool-name
hostname(config)#
where
GSN-pool-name
is the object group name for GGSNs.
Step 2
Specify the load-balancing GSNs using the
network-objec
t command. You can configure one
network-object
command per GSN using the
host
keyword. You can also specify a network containing
GSNs that perform load balancing.
hostname(config)#
network-object host
IP-address
hostname(config)#
where
IP-address
is the IP address of the host.
Step 3
Create an object to represent the SGSN that the load-balancing GSNs are permitted to respond to. To do
so, use the
object-group
command.
a.
Define an SGSN network object group that sends GTP requests to the GSN pool. To do so, use the
object-group
command.
hostname(config)#
object-group network
SGSN-name
hostname(config)#
where
SGSN-name
is the SGSN network object group name.
b.
Identify the SGSN. To do so, use the
network-object
command:
hostname(config)#
network-object host
IP-address
hostname(config)#
where
IP-address
is the SGSN.
Step 4
Allow GTP responses, from any GSN in the network object representing the GSN pool, to the network
object representing the SGSN. To do so, use the
gtp-map
and
permit responses
commands.
hostname(config)#
gtp-map
map_name
hostname(config-gtp-map)#
permit response to-object-group
SGSN-name
from-object-group
GSN-pool-name
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......