9.10.15  

Gatekeeper 
 


Settings | Network |Gatekeeper
 
The Gatekeeper menu item is used to specify parameters for the gatekeeper.
A gatekeeper must be configured for each node in a network system. In addition, an SNTP server must be specified to synchronize the time of the individual nodes and all IP clients. For standalone systems, the SNTP server data is configured here. For a network system, by contrast, the SNTP server data is only displayed here. The configuration of the SNTP server data occurs via Settings | Netwide Data.

Security as of HiPath 3000/5000 V5.0  
In order to prevent the operation of unauthorized IP clients and gatekeepers, a security mechanism was implemented starting with HiPath 3000/5000 V5.0. Every H.225 message from IP clients or gatekeepers can be optionally checked for validity via a realtime stamp (= crypto token). These crypto tokens are generated by the IP client and entered in the sent packets. The gatekeeper on the other side checks these crypto tokens for validity and discards the message if the token is invalid. The security functionality is defined by the parameters set under Gatekeeper and Security.

9.10.15.1  

Area: Gatekeeper 

HG 1500 Board  
Shows in which slot the HG 1500 board that is assigned as a gatekeeper is inserted (see also Gatekeeper (V5.0 and Later).

Identity  
This parameter is used for authentication purposes when the gatekeepers communicate with one another. The gatekeeper Identity is an alphanumeric value that identifies the gatekeeper and is sent along with H.225 communications.
In the communication system, if the security is set to Reduced Security or Full Security, the identities of all gatekeepers and all IP clients of a HiPath domain must be set identically in order to enable communications between the gatekeepers.

Password  
The password is used for authentication purposes when the gatekeepers communicate with one another. It is also used to compute the crypto tokens for the H.225 send and receive packets.
In the communication system, if the security is set to Reduced Security or Full Security, the passwords of all gatekeepers of a HiPath domain must be set via HiPath 3000 Manager to be identical in order to enable communications between the gatekeepers.

9.10.15.2  

Area: SNTP Server 

IP address  
IP address of the network-wide Time server. In order to use the H.235 security protocol, a central SNTP Time server and a time reference must be available for all IP clients and the gatekeeper, respectively.

Polling Time  
Multiple of 10 minutes.
The Polling Time defines how often the IP clients and the gatekeeper access the SNTP Time server to read the current time reference. The polling time depends on the accuracy of the internal clocks of the IP devices. Practical experience has shown that a value of 72 is appropriate (72x10=720 minutes = 12 hours = twice a day).

Timezone  
The time zone in which the gatekeeper is located is set here (local time zone of the communication system).
After setting the IP address and the polling time, these values are configured in all loaded CDBs via the All KDS equal button. The time zone is not affected by this, since a node-specific date is involved here.  
If an external SNTP server exists, then these settings will be OK in all nodes. If an internal HG1500 board is to be used as the SNTP server, then either an external SNTP server must be specified in the node in which this HG1500 board is installed or - as in the case of Germany - no IP address should be specified so that the ISDN time is used. In both cases, the time is then made available to the SNTP server on the HG1500 board via downloads.  

9.10.15.3  

Area: Security 

No Security, Reduced Security, Full Security  
Activation of the H.235 security protocol is configured here:
   -   No Security: The security protocol is not used, i.e., no crypto tokens are sent by the IP clients.
   -   Reduced security: The IP clients send crypto tokens, and the HG 1500 verifies these tokens. However, the HG 1500 itself does not send any crypto tokens.
   -   Full security: Both sides send and verify crypto tokens.

Identity  
The global gatekeeper identity is specified here.

Password (only for trunking) / Confirm password  
Enter the password here and confirm it by repeating the entry.

Security time  
This setting configures monitoring for the lifetime of IP packets. This means that a check is then performed in the communication system to ensure that the incoming IP packets are not older than the current time plus the time specified in the Security time field. This prevents IP packets from being potentially traced by a sniffer, for example, and then being resent to the original addressee after manipulation. The size of the Security time depends on the dynamic runtimes in the customer LAN. If the selected time is too small, and long runtimes occur, disruptions may occur in the VoIP traffic. A value of 90 seconds should work without problems in most cases.
In order to ensure that H.235 operates correctly, whenever any changes are made to the corresponding parameters (Gatekeeper and Security), the individual components must be restarted.  

See also:  
   -   Section 9.10 "Settings | Network"
   -   Section 9.10.16 "Ext. H.323-GK"
   -   Section 9.10.17 "Ext. SIP"
   -   Section 9.2.10 "Gatekeeper (V5.0 and Later)"