l
The security GW is deployed on the network
File
Specified File Path in the USB Storage Device
Common configuration file
usb:\eNodeB\
Cross certificate granted by
Huawei
usb:\eNodeB\Certificates\CrossCACert\
Operator's root CA
certificate
usb:\eNodeB\Certificates\CACert\
Operator's CRL file
usb:\eNodeB\Certificates\CRL\
eNodeB software package
usb:\eNodeB\Software\
Data configuration file
usb:\eNodeB\
----End
6.2.4 Configuring the Security Equipment
When the security gateway (GW) is deployed in the network, you need to configure data for the
security GW. In the case that the IEEE 802.1x authentication is adopted, the authentication access
equipment and the authentication server should be configured. Generally, an authentication
server is the Authentication, Authorization and Accounting (AAA) server.
Prerequisite
l
The
Quidway S6500 Series Ethernet Switches Operation Manual
is ready, and can be
downloaded from http://support.huawei.com/.
l
The
infoX AAA Commissioning Guide
is ready, and can be downloaded from http://
support.huawei.com/.
l
If the IEEE 802.1x authentication is adopted, the operator should use the authentication
access equipment that supports 802.1x authentication and the corresponding AAA server
that supports Extensible Authentication Protocol (EAP).
Context
l
describes the configuration items that you need to pay special attention to when
the security GW is used.
Table 6-3
Security GW configuration
Item
Description
IP address
Both the public security GW and the serving security GW should be
configured with the IP address of the interface for the untrusted domain
on the eNodeB side and IP address of the interface for the trusted domain
on the EPC side.
6 Commissioning the MBTS by Using USB and M2000
3900 Series Multi-Mode Base Station
Commissioning Guide
6-10
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Issue 02 (2010-07-30)