0% found this document useful (0 votes)
2 views36 pages

Getting Started

This document provides a step-by-step guide for setting up the ACG2000 using the NetExplorer (NX) GUI, including accessing the NX system, licensing the system, and configuring the ACG. Users are instructed to enter activation keys, configure various parameters, and ensure the ACG is properly added to the NX network. The document emphasizes the importance of saving changes and rebooting the ACG for the configurations to take effect.

Uploaded by

Taha Sakhi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
2 views36 pages

Getting Started

This document provides a step-by-step guide for setting up the ACG2000 using the NetExplorer (NX) GUI, including accessing the NX system, licensing the system, and configuring the ACG. Users are instructed to enter activation keys, configure various parameters, and ensure the ACG is properly added to the NX network. The document emphasizes the importance of saving changes and rebooting the ACG for the configurations to take effect.

Uploaded by

Taha Sakhi
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Getting Started

7 Getting Started
The steps in this chapter must be completed to finish setting up the ACG2000. The
procedures will be performed entirely through the NetExplorer (NX) GUI. More
information about the NX system can be found in the NetXplorer Operation Guide
and the NetXplorer Installation and Administration Guide.

7.1 Accessing your NetXplorer


Use the following procedure to access the NX system for the first time. The
application runs on Java and will prompt for an update if needed.
1. Access the ACG Main Dashboard by navigating to
<ip_address>:5000/main_dashboard.

Figure 7-1: The ACG Main Dashboard, with the NX Information pane highlighted
2. Copy the Instance Ip under the NX Information pane.

7-26 Application Control Gateway User Guide


Getting Started
3. Open a new tab in your browser and navigate to the copied IP address. To do
this, paste the IP address into the address bar and then hit <enter>. The
NetXplorer Launcher appears.

Figure 7-2: The NetXplorer Launcher

4. Click Install Java JRE first. When prompted, select your operating system. The
Java JRE Setup Wizard downloads.
5. Run the Java JRE Setup Wizard. When the Java installation has concluded, go
back to the NetXplorer Launcher.
6. Click Launch NetXplorer. The browser downloads a small file called
[Link]. When asked whether to keep or discard this file, select keep.

7-27 Application Control Gateway User Guide


Getting Started
7. Run [Link]. The file verifies its own integrity and then opens the Allot
NetXplorer Log On Screen.

Figure 7-3: The Allot NetXplorer Log On Screen


8. Enter your User Name and Password

7.2 Licensing your System


The ACG needs two license keys set before beginning normal operation. Make sure
you have your license keys ready before performing the following procedures.

Enabling NetXplorer Server


In order to manage the ACG using NetXplorer, NetXplorer Server must be enabled
by entering the appropriate key. This key may be entered at installation or at any
time following.

To enable NetXplorer Server:


Select Tools > NetXplorer Application Server Registration from the
NetXplorer Menu bar.

7-28 Application Control Gateway User Guide


Getting Started

The NetXplorer Application Server Registration dialog box appears.

Figure 7-4: NetXplorer Application Server Registration Dialog


Enter the Activation Key and Serial Number provided by Allot to enable
the NetXplorer Server functionality.
A Key Version, Marketing Version and Expiration Date will be generated
automatically after clicking Save.
The number of devices supported by the key is indicated.
If Enforcement Policy Provisioning is enabled by the key that has been
entered, it will be indicated (along with the maximum number of
accounts) after NPP. For more information, see the NPP User Guide.
If Classification of Hosts by Country is enabled by the key that has been
entered, it will be indicated after Country Classification Subscription.
If Accounting information is enabled by the key that has been entered, it
will be indicated after Net Accounting.
If Service Catalog updates via the web are enabled by the key that has
been entered, it will be indicated after APU.
If Subscriber Management is enabled by the key that has been entered, it
will be indicated by one of the following attributes being enabled – e.g:
Tiered Services or Quota Management. In addition, the number of
supported active subscribers, the current number of subscribers and the
highest number of subscribers over the last 7 days will be indicated if
relevant. This information is provided on the system level (i.e: for all SMP

7-29 Application Control Gateway User Guide


Getting Started
Groups). For more information, see the SMP Installation and
Administration Guide.
If Session Management is enabled by the key that has been entered, it will
be indicated by at least one of the following attributes being enabled –
e.g: Tiered Services Gx, Volume Reporting or Cell Awareness. In addition,
the licensed maximum number of active IP sessions, the current number of
active IP sessions and the highest number of IP sessions over the last 7
days will be indicated if relevant. This information is provided on the
system level (i.e: for all SMP Groups). For more information, see the SMP
Installation and Administration Guide.
NOTE If Mobile Analytics is enabled by the key that has been entered, it will be
indicated by the following attribute being enabled: Mobile Reports SMP. In
addition, the number of active IP sessions, the current number of IP sessions
and the highest number of IP sessions over the last 7 days will be indicated if
relevant. This information is provided on the system level (i.e: for all SMP
Groups). For more information, see the SMP Installation and Administration
Guide.
Click Save to enter the key and close the dialog box.

Licensing the ACG


The parameters available in the Service Gateway Configuration window are
grouped on the following tabs:
• General
• Identification & Key
• SNMP
• Security
• Interface
• Networking
• IP Properties
• Date/Time
• Service Activation
• Slots & Boards
Each tab includes parameters that can be configured as required. After modifying
configuration parameters, you must select Save in order for the changes to take
effect. The save process prompts a reset of the Service Gateway. Resetting is
sometimes required to ensure that some saved parameter values are committed
and activated on the Service Gateway. To license the ACG, you will need to access
the Identification and Key tab.

7-30 Application Control Gateway User Guide


Getting Started
Identification & Key
The Identification & Key tab includes parameters that provide system information
and activate optional Service Gateway modules.

Figure 7-5: Configuration - Identification & Key Parameters


The Identification & Key tab includes the following parameters:

PARAMETER DEFINITION

The activation key enables the Service Gateway.


Enter the activation key supplied to you at
Activation Key
purchase. The functionality enabled by the key is
summarized in the fields below the key.

Serial Number The Serial Number of the Service Gateway.

Key Version For Internal Use Only

Marketing
For Internal Use Only
Version

Device Type The Type of Service Gateway.

7-31 Application Control Gateway User Guide


Getting Started

PARAMETER DEFINITION

Expiration Date The expiration date of the entered Activation Key.

Quality of Service is enabled/disabled on the


QoS
Service Gateway.

Real Time Reporting is enabled/disabled on the


Real Time
Service Gateway. Real Time Reporting requires an
Reporting
appropriate key to be enabled.
Long Term Reporting is enabled/disabled on the
Long Term
Service Gateway. Long Term Reporting is enabled
Reporting
by default.
The maximum number of Lines that may be
defined on the Service Gateway. This field also
Number of Lines
indicates the current number of lines and the
highest number of lines during the last seven days.
The maximum number of Pipes that may be
defined on the Service Gateway. This field also
Number of Pipes
indicates the current number of pipes and the
highest number of pipes during the last seven days.
The maximum number of Virtual Channels that
may be defined on the Service Gateway. This field
Number of VCs
also indicates the current number of VCs and the
highest number of VCs during the last seven days.
Allot Protocol Update is enabled/disabled on the
APU
Service Gateway.

WebSafe is enabled/disabled on the Service


WebSafe
Gateway, listing the number of Core Controllers
Enforcement
covered by the license.
WebSafe is subscribed to the Internet Watch
WebSafe
Foundation blacklist service. This subscription is
Subscription
optional
Port or URL Redirection is enabled/disabled on the
Service Gateway. For further information see
Error! Reference source not found. on page Error!
Traffic Steering
Bookmark not defined.. If Enabled, the maximum
Bandwidth (Mbps), No of Active Elements and No
of Subscribers on the system level appears.

7-32 Application Control Gateway User Guide


Getting Started

PARAMETER DEFINITION

Listing the number of Core Controllers enabled for


Service Protector as covered by the license. If this
SP Mitigation field lists a value of 0, it indicates the service is not
enabled by the current license. A NetEnforcer will
list this value as 1 if the service is enabled.
Listing the number of Core Controllers enabled for
SP Embedded Sensors as covered by the license. If
SP Embedded
this field lists a value of 0, it indicates the service is
Sensors
not enabled by the current license. A NetEnforcer
will list this value as 1 if the service is enabled.
Listing the number of Core Controllers enabled for
Mobile Reporting as covered by the license. If this
Mobile Reports field lists a value of 0, it indicates the service is not
enabled by the current license. A NetEnforcer will
list this value as 1 if the service is enabled.
Listing the number of Core Controllers enabled for
Statistics Export as covered by the license. If this
Statistics Export field lists a value of 0, it indicates the service is not
enabled by the current license. A NetEnforcer will
list this value as 1 if the service is enabled.
Listing the number of Core Controllers enabled for
Tethering as covered by the license. If this field lists
Tethering a value of 0, it indicates the service is not enabled
by the current license. A NetEnforcer will list this
value as 1 if the service is enabled.
Listing the number of Core Controllers enabled for
HTTP CDRs as covered by the license. If this field
HTTP CDRs lists a value of 0, it indicates the service is not
enabled by the current license. A NetEnforcer will
list this value as 1 if the service is enabled.
MediaSwift – The Cache Out bandwidth of the MediaSwift
Cache Out Service, in Mbps.
Listing the number of Core Controllers enabled for
Autonomous
Autonomous System features as covered by the
System
license.
Http Header Listing the number of Core Controllers enabled for
Enrichment HTTP Header Enrichment as covered by the license.

7-33 Application Control Gateway User Guide


Getting Started

PARAMETER DEFINITION

Video Data Listing the number of Core Controllers enabled for


Records VDRs as covered by the license.

Platform Type The platform series of the Service Gateway

The software version running on the Service


Software Version
Gateway.

The Protocol Pack release and version loaded into


Protocol Pack
the Service Catalog of the Service Gateway.

Box Number The ID number of the Service Gateway.

Bandwidth The way bandwidth limitations are imposed on the


Capacity Service Gateway; Inbound & Outbound Defined
Limitations – Separately, Inbound & Outbound Defined the
Limitation Type Same or Half Duplex.
The incoming bandwidth limitation of the
Inbound
NetEnforcer, in Kbps. Select the Max Allowed
Bandwidth
checkbox to allow the maximum value to be
Limited to:
passed.
The outgoing bandwidth limitation of the
Outbound
NetEnforcer, in Kbps. Select the Max Allowed
Bandwidth
checkbox to allow the maximum value to be
Limited to:
passed.
Once you have accessed the tab, fill in all the information to ensure smooth
operations for your ACG unit.

7.3 Configuring your ACG in the NX


In order for NetXplorer to manage the ACG, it must be added to the NetXplorer's
network and properly configured. The IP address of the ACG is required for this
procedure.

7-34 Application Control Gateway User Guide


Getting Started
NOTE Initial configuration of the ACG should be performed on the ACG (via the CLI
interface) before it is added to the NetXplorer configuration. Refer to the
hardware manual for the specific ACG model for details.
NOTE In the NetXplorer GUI ACG units and Service Gateways are referred to as
NetEnforcers.

To add the ACG:


In the Navigation pane, right-click Network in the Network of the
Navigation tree and select New NetEnforcer from the popup menu.
OR
Select Network in the Network pane of the Navigation tree and then select
New NetEnforcer from the Actions menu.
The NetEnforcer Properties - New dialog is displayed.

Figure 7-6: NetEnforcer Properties – New Dialog


Enter the Name you want the ACG referred to by, as well as the SSH
Password of the ACG in the designated fields.
Enter the Network Address of the ACG in the designated field. This may be
an IPv4 address or an IPv6 address.
Choose a Monitoring Collector or Collector Group for the ACG from the
drop-down menus. The new ACG will transmit its monitoring data to that
Collector or Group only. The default option is <system defined> which
means that the Service Gateway will transmit its monitoring data to the
internal Short Term Collector which is built into the NetXplorer server. If
you do not have any Monitoring Collectors on the Network and you do not
want to use the NetXplorer’s internal monitoring collector, select No
Collector.

7-35 Application Control Gateway User Guide


Getting Started
Click OK. The ACG is added to the Navigation tree. The Add NetEnforcer
operation can take up to a few minutes to complete.

To Configure the ACG via the NetXplorer:


In the Navigation pane, select and right-click the ACG in the Navigation
tree and select Configuration from the popup menu.
OR
Select the ACG in the Navigation tree and then select Configuration from
the View menu.
OR
Select the ACG in the Navigation tree and then click the Configuration icon
on the toolbar.
The Configuration window for the selected ACG is displayed.

Sg
Figure 7-7: ACG Configuration
Configure the ACG parameters, as required.

Click or select Save from the File menu to save the changes to the ACG
configuration.
The Configuration parameters available in the ACG Configuration window are
grouped on the following tabs:
• General – indicates the ACG’s bypass status.
• Identification and Keys – includes parameters that provide system
information and activation keys

7-36 Application Control Gateway User Guide


Getting Started
• SNMP – enter the contact person, location, system name and description
for SNMP purposes
• Security – includes security and authorization parameters
• Interface – includes parameters to configure the system interfaces to
either automatically sense the direction and speed of traffic or use default
parameters as well as parameters to define ports
• Networking – includes parameters that enable you to configure network
topology
• IP Properties – enables you to modify the IP and host name configuration
of your network interfaces as well as the DNS and connection control
parameters
• Date/Time – includes the date, time and NTP server settings for the ACG
• Service Activation - includes IP and Port Redirection Parameters
• Slots and Boards - includes device layout to provide schematic device
components layout (when applicable) and status information. This tab
does not appear when not relevant to the ACG.
After modifying configuration parameters you must select Save in order for the
changes to take effect. The save process prompts a rebooting of the ACG.
Rebooting is required to ensure that some saved parameter values are committed
and activated on the ACG.
Once the ACG is configured to work with the NX, the entire setup can be controlled
through the command line. For mor information about managing the elements of
the ACG through the CLI, see the AOS Operation Guide.

7.4 Adding and Configuring your Data Mediator


To Add a Data Mediator
1. Open NetXplorer.
In the Navigation pane, right-click Servers in the Network pane in the
Navigation tree and select New Data Mediation… from the popup menu.
The Data Mediation Properties - New dialog is displayed.

7-37 Application Control Gateway User Guide


Getting Started

Figure 7-8: Data Mediation Properties


Enter the name of the Data Mediator.
Enter the Network Address of the Data Mediator in the designated field.
This may be an IPv4 address or an IPv6 Address.
Select the Enable SSL Between NetXplorer Server and Device checkbox if
you wish the connection between NetXplorer and the DM to be more
secure.
In the Source Units area, use the arrow keys to move the ACG and SMPs
from the Available to the Selected lists. Those selected will provide data to
the Data Mediator.
To collect WSP Buckets, enter the IP address (IPv4 or IPv6) of your
NetworkSecure in the NetworkSecure Details field and click the Right
Button to add it to the Selected sources.

7-38 Application Control Gateway User Guide


Getting Started
Note: SDR, CMDR, CMCS and CMBM collection is only possible if you have included
an SMP in the Selected Sources.

CMDR, CMCS and CMBM collection requires an SMP in SMF Mode. For more
information, see the SMP Installation and Administration Guide.

WSP Bucket collection is only possible if you have added the NetworkSecure IP
to the Selected Sources.
• Depending on the ClearSee license you purchased with your ACG, select
either the default Metrics, Analytics, or Realtime profile. For more
information on Profiles, see Data Mediator Installation and Administration
Guide.
Data Mediator Profiles
Click Save to add the Data Mediator to the network.
• NOTEFor more information concerning DMs, see the Data Mediator
Installation and Administration Guide.

Data Mediator Profiles


Allot Default Profile

7-39 Application Control Gateway User Guide


Getting Started
Figure 7-9: Default Data Mediation Profile
“Allot default profile” includes all the fields that appear in the DataDictionary file
for the following buckets with immediate trigger (no keys and no excluding rules):
• VC
• Conv
• Conv_RTS
• Conv_RTU
• UDR
• SDR
• HDR
• VDR
• CMDR
• CMCS
• CMBS
• WSP Buckets

7-40 Application Control Gateway User Guide


Getting Started
Note: This Profile may be edited.

Allot Default ClearSee Metrics Profile

Figure 7-10: Default ClearSee Metrics Profile

Allot Default ClearSee Light profile includes all the fields of all the records that
appear in the following AOS buckets with immediate trigger (no keys and no
excluding rules):
• HTTP
• Conv
• SDR
• CMDR
• WSP Buckets

7-41 Application Control Gateway User Guide


Getting Started
Note: This Profile may not be edited and is only available with a ClearSee license.

Allot Default ClearSee Analytics Profile

Figure 7-11: Default ClearSee Analytics Profile


Allot Default ClearSee Analytics Profile includes all the fields that appear in the
following AOS buckets with immediate trigger (no keys and no excluding rules):
• VC
• Conv
• UDR
• SDR
• HDR
• VDR
• CMDR
• MOU
• HTTP
• WSP Buckets
Note: This Profile may not be edited and is only available with a ClearSee license.

7-42 Application Control Gateway User Guide


Getting Started
Allot Default ClearSee Real Time Profile

Figure 7-12: Default ClearSee Real Time Profile

Allot Default ClearSee Real Time Profile includes all the fields that appear in the
following AOS buckets with immediate trigger (no keys and no excluding rules):
• Conv-RTS
• Conv-RTU
Note: This Profile may not be edited and is only available with a Real Time
Monitoring license.

7.5 Building your ClearSee System


This procedure describes how to build the Standalone ClearSee system, which you
must do after installation.
It involves defining the BI-DW instance and the DM, then configuring the system on
the network, and finally performing some optional configurations.
Complete information about your ClearSee system can be found in the ClearSee
Installation and Administration Guide and the ClearSee Operation Guide.

7-43 Application Control Gateway User Guide


Getting Started
To build the Standalone ClearSee system:
Define the BI-DW instance, as described in Defining a BI Instance in the
Navigation Pane.
NOTE When situated in a standalone system, the BI instance is actually referred to
as the BI-DW instance.
Define the DM, as described in Chapter 3 of the Data Mediator Install and
Admin Guide, and associate the ClearSee output profile with it.
In the NetXplorer Navigation pane, right-click the Network node, and then
select Configuration.
The Network Configuration area appears.
Select the ClearSee tab.

Figure 7-13: ClearSee Tab in NetXplorer


In the ClearSee Systems area, click Add.
The ClearSee System – New dialog box appears, on the General tab.

7-44 Application Control Gateway User Guide


Getting Started

Figure 7-14: ClearSee System – Dialog Box


Do the following:
⧫ In the System Name field, name your ClearSee system.
⧫ From the Selected BI dropdown list, select the BI instance for your
ClearSee system.
The BI Type and Deployment Type fields are populated accordingly.
NOTE When situated in a Standalone system, the BI instance is actually the BI-DW
instance, and thus it is referred.
⧫ From the NetworkSecure Deployment Mode dropdown list, select the
appropriate mode, which determines the NetworkSecure dashboards
and templates that appear for you in ClearSee.
⧫ If you do not intend to use ClearSee’s GUI, but rather just use the
ClearSee back end, then, to save resources, select Smart Data Export
Only Mode.
⧫ Define the ETL group, as described in DEFINING THE STANDALONE ETL
GROUP.

7-45 Application Control Gateway User Guide


Getting Started
⧫ From the SNMP tab, configure any additional SNMP traps destination.
⧫ From the Data Source Files tab, define any external data files.
⧫ From the Aggregations tab, configure data retention and aggregation
delay.
NOTES The actions performed on the Aggregations tab are required.
As Transfer Method, the FTP option is currently not in use.
⧫ From the Report Mode dropdown list, select the appropriate mode,
which determines the reports and dashboards that appear for you in
ClearSee. For a list of which reports, dashboards and templates
appear with which modes, see the ClearSee Operation Guide,
Chapter 4: Reports and Dashboards, Reports and Dashboards
Overview.
Click Prime Time Configuration for Prime Time settings.
Click OK.
On the ClearSee tab of the Network Configuration area, in the
ClearSee Systems area, the Standalone ClearSee system appears.

Figure 7-15: Completed ClearSee Systems Area (Standalone)


From the NetXplorer menu bar, click Save to permanently save the
ClearSee system.
In the Network Configuration area, under Data Mediation > Output Profiles, a
new associated output profile is automatically created, called after the
name of your ClearSee system, as follows:

7-46 Application Control Gateway User Guide


Getting Started
⧫ If you have a Metrics license, then the name of the profile is
comprised of ClearSee Light Profile and then your ClearSee system.
⧫ If you have an Analytics license, then the name of the profile is
comprised of ClearSee Professional Profile and then your ClearSee
system.
Return to Integrating ClearSee with NetXplorer.

Defining a BI Instance in the Navigation Pane


Define in the NetXplorer Navigation pane the BI instance that you created earlier.
If this is a Standalone deployment, then the instance is called BI-DW.
In the NetXplorer Navigation pane, in the Network tree, right-click the
Servers node , and then select New ClearSee BI.

To define the BI instance:


In the NetXplorer Navigation pane, in the Network tree, right-click the
Servers node , and then select New ClearSee BI.
The ClearSee BI Properties – New dialog box appears.

Figure 7-16: ClearSee BI Properties – New Dialog Box


Do the following:
a. In the Name field, name the BI instance as you want it to appear in the Navigation pane.
b. In the IP Address area, enter the IPv4 and/or IPv6 addresses of the BI instance.
c. Click Save.
The BI instance appears in the Navigation pane, under Servers.

7-47 Application Control Gateway User Guide


Getting Started
Click Save to permanently save the BI instance on the network.

Defining the Standalone ETL Group


This procedure describes how to define the ETL group in a Standalone deployment.
Involved is adding the ETL group including the DW, and selecting the DM.
To configure the Standalone ClearSee system on the network:
In the ETL Groups area, click Add.
The ETL Group – New dialog box appears.

Figure 7-17: ETL Group – New Dialog Box (Standalone)


In the ETL Group Name field, name the ETL group.
In the DWs area, use the arrow key to move the BI-DW instance from
Available DWs to Selected DWs.
NOTE As this is a Standalone deployment, there is only one available DW, that which
the BI-DW instance comprises.
In the DMs area, click Add.
The Add DM to ETL Group dialog box appears.

7-48 Application Control Gateway User Guide


Getting Started

Figure 7-18: Add DM to ETL Group Dialog Box


Do the following:
a. From the Selected DM dropdown list, select for your ETL group the DM with the
associated ClearSee output file.
In the IP field, the IP of the DM appears.
b. Ensure that Enable Data Collection is selected.
c. Click OK.
In the DMs area of the ETL Group – New dialog box, the DM appears in the
table.

7-49 Application Control Gateway User Guide


Getting Started

Figure 7-19: DMs Area of ETL Group – New


Click OK.
In the ETL Groups area of the ClearSee System – New dialog box, the ETL
group appears.

7-50 Application Control Gateway User Guide


Getting Started

Figure 7-20: ETL Groups Area of ClearSee Systems – New

7.6 Adding your SMP Server


To add an SMP to the ACG:
In the Navigation pane, right-click Servers and select New SMP from the
popup menu.
OR
Select Servers in the Network pane of the Navigation tree and then select
New SMP from the Actions menu.
The SMP Properties - New dialog is displayed.
Enter the Name and IP address (IPv4 or IPv6) of the SMP.
Select the Enable SSL Between NetXplorer Server and Device checkbox if
you wish the connection between NetXplorer and the SMP to be more
secure.

7-51 Application Control Gateway User Guide


Getting Started

Figure 7-21: SMP Properties – New Dialog


Note: The name defined for the new SMP cannot be left empty. It cannot be more
than 128 characters long. The following characters are valid:
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890_
-@#^()+=[]{}
Note: If you have configured an HA SMP Cluster, you should enter the “virtual” IP
address here (instead of the individual SMP Server IPs that make up the
cluster).
Click Save.
Complete information about using your SMP can be found in the SMP Installation
and Administration Guide.

Verifying an SMP Configuration


To verify that an SMP server has been configured correctly, you can do the
following:
In the Navigation pane, right-click the SMP server you have configured and
select Configuration from the popup menu.
OR
Select the SMP Server in the navigation pane, and choose Configuration
from the main View menu.
The Configuration tabs appear in the Applications pane.
To view the SMP server configuration, click on the IP Properties tab:

7-52 Application Control Gateway User Guide


Getting Started

Figure 7-21: IP Properties of the SMP Server

Enabling Active Directory Support


Enabling Active Directory Support (Optional)
Allot’s Active Directory Adapter (ADA) is a solution which enables Allot subscriber
management services to be deployed in enterprise networks which use Microsoft
Active Directory to manage their user authentication. Using Allot subscriber
management capabilities, enterprise network administrators can monitor users’
internet usage and enforce corporate policies concerning high-internet usage or
control the network utilization of specific applications.

7-53 Application Control Gateway User Guide


Getting Started
Note: The ADA mechanism from SMP15.1 was completely refactored and improved.
For further details of the changes consult with the 15.1 Software Release
Notes.
ADA associates user identification information with the IP address used and
enables the application of traffic management policies on a per user basis (service
plans). In order to operate, the Allot solution needs to be able to query security
logs in the Active Directory Domain Server.
Note: To this end, the Allot solution will need an AD user with wmic (Windows
Management Instrumentation Command-line) for remove access and Security
logs query privileges.
The data flow of the solution was described in Chapter 1 above. The configuration
of the solution consists of 6 steps, as described below:
Note: Before beginning these 6 steps, ensure that the SMP has been added to the
NetXplorer Navigation Tree as detailed here and that the SMP Group has been
created in the NetXplorer as detailed here.
Note: It is important that the SMP is able to communicate to the Active Directory via
FQDN. If needed edit the /etc/hosts file to make sure that the SMP is under
the same domain as the Active Directory Server.

• Step 1: Configure SMP to perform DHCP gleaning (Optional)


• Step 2: Configure AD Adapter file
• Step 3: Set policy source as Active Directory
• Step 4: Upload groups to NX UI
• Step 5: Create Service Plans and Add to Policy
• Step 6: Configure Active Directory Domain Server
These steps are described in detail below.

Step 1: Configure SMP to perform DHCP gleaning (Optional)


Configuring SMP to perform DHCP gleaning is an optional step. By default, if DHCP
gleaning is not configured, SMP will receive an Active Directory login event which
includes both user name and allocated IP. Any changes in IP due to lease expiration
will not be identified however. In order to ensure that changes to the allocated IP
are also recorded, you should setup the SMP to perform DHCP gleaning.
This is enabled by configuring [Link] and then configuring the
[Link] file (for out of band gleaning only) or configuring the Service
Gateway to mirror packets (for in-band gleaning only). All of these steps are
outlined earlier in the SMP Installation and Admin Guide in the section on DHCP
Gleaning.

7-54 Application Control Gateway User Guide


Getting Started
Step 2: Configure AD Adapter File
Follow the instructions below to enable the ADA and to enter the details of the
Active Directory Domain Servers to be queried by the SMP. The active directory file
is located in /opt/allot/conf/[Link]. It can be configured by
running the script below.
To enable the Active Directory Adapter, login to the SMP server and run
the following script: [Link] -f enable
Note: If you wish to later disable the functionality, run: [Link] –f
disable
To add the Active Directory Domain Controller attributes (Host IP, Domain
Name, User and Password) to the SMP, run the following script:

[Link] -a -dip <DC_IP> -dname <Domain_Name> -user


<AD_Admin_User> -pass <AD_Admin_Pass> -g <Default Domain Group
with Quotation marks>
For example, to add a Domain Controller with an IP of [Link], with
the domain name “[Link]”, a user name “aguero”, a password
“200goals” and a default domain group called “Domain Users”, you would
enter the following command:

[Link] -a -dip [Link] -dname [Link] -user aguero -


pass 200goals -g "Domain Users"

Restart the ADA process on the SMP by entering the following CLI
command:
[Link] –reload

Step 3: Set Policy Source as Active Directory


Follow the instructions below to configure the SMP to use the Active Directory as a
policy source (and to ensure that SMP is managing subscribers not sessions).
Open the [Link] file. The file located in
/opt/allot/conf/[Link].
In the AdminParameters section, make sure that “QoSType” is set to
“Subscriber” and that PolicySourceType is set to “ACTIVE_DIRECTORY” as
shown below

<?xml version="1.0" encoding="UTF-8"?>


<RouterFlowRules xmlns:xsd="[Link]
xmlns:xsi="[Link]
xsi:noNamespaceSchemaLocation="[Link]">
<ConfigurationVersion value="1"/>

7-55 Application Control Gateway User Guide


Getting Started
<FlowRulesConfig>
<FlowRuleList>
<!--FlowRuleEntry RuleName = "">
<ConditionList>
<ParamEntry ParamName = "DATA_ACCESS_ID" Value = "Fixed_Access"/>
</ConditionList>
<ActionList>
<ActionEntry Type ="AddParam" QosType = "Subscriber"/>
</ActionList>
</FlowRuleEntry> -->

</FlowRuleList>
<DefaultActionList>
<ActionEntry Type ="AddParam" QosType = "Subscriber"/>
<ActionEntry Type ="AddParam" PolicySourceType = "ACTIVE_DIRECTORY"/>
<!-- <ActionEntry Type ="AddParam" ParamName = "" Value = ""/> -->
</DefaultActionList>
</FlowRulesConfig>
</RouterFlowRules>
After configuring the [Link] file, restart the smp_router
process by entering the following command:
keeperMgr –R smprouter

Step 4: Upload Groups to NX UI


Follow the instructions below to map between Active Directory Organization Units
(groups) and Service Plans, and to set priority in case of conflict.
In the NetXplorer Navigation pane, right-click the Network and select
Configuration from the popup menu

OR

Select Network in the NetXplorer navigation pane, and then choose


Configuration from the Actions menu.

The network tabs will be displayed in the Applications pane.


Select the SMP tab. The “General” sub-tab will appear. Towards the
bottom of the sub-tab the “Active Directory Integration” pane is displayed.
It may be necessary to minimize the “Alarms Log” in order to view this
pane in full.

7-56 Application Control Gateway User Guide


Getting Started

Figure 7-22: Active Directory Integration


Create a file to map groups to service plans. The file should be saved on
the NX server in .csv format then uploaded to the NetXplorer by entering
the path and clicking on the “upload file” button. Each line in the file
should consist of group name, service plan name and priority, each
separated by a comma as in the example below:

Group_1, ServicePlan_1, 45
Group_2, ServicePlan_2, 63
cs-all, cs, 27
all, all, 30

Note: The service plan and group mapping is not case sensitive. Therefore if the
active directory group is called “All” and the file uploaded includes “all” SMP
will consider this to refer to the same group.

The higher the number the higher the priority. Therefore referring to the
example file uploaded above, if a user is a member of both “all” (priority 30)
and “cs-all” (priority 27), that user will be mapped to the service plan
associated with the “all” group.
If you wish to exclude certain IP ranges from being mapped to a service
plan (e.g: IT servers), create an additional .csv file which lists the relevant
IP range, as per the example below:

[Link]-[Link]
[Link]-[Link]
The file should be saved on the NetXplorer server in .csv format then
uploaded to the NetXplorer by entering the path and clicking on the
“upload file” button.

7-57 Application Control Gateway User Guide


Getting Started
If you wish to exclude certain users from being mapped to a service plan
(e.g: generic users), create an additional .csv file which lists the relevant
user names as per the example below:

canada\user1
canada\user2
canada\user3
The file should be saved on the NetXplorer server in .csv format then
uploaded to the NetXplorer by entering the path and clicking on the
“upload file” button.

Step 5: Create Service Plans and Add to Policy


Now you should create service plans corresponding to the service plan names
which you defined in the active directory group – service plan mapping file in step 4
above.
Full instructions for creating service plans and inserting them into the policy are
contained in the SMP Installation and Administration Guide

Step 6: Configure Active Directory Domain Server


Finally you should configure the customer’s Active Directory Domain Server in
order to enable the AD Adapter on the SMP Server to access logon events from the
security log.

AD configuration
Create a user account in the AD that will be used for the remote WMI queries. Join
it to the following groups: distributed COM users, event log readers.

7-58 Application Control Gateway User Guide


Getting Started

Figure 7-23: Active Directory Domain Server Configuration

Note: Optionally, you can create a dedicated security group and grant permissions
to that security group. Then you must add the user used by the SMP to that
group.

AD Domain Controller configuration


The SMP requires permissions to query all the Domain Controllers via LDAP and
WMI. By default, those permissions are granted to domain admins, however if
more strict permissions are desired, those permissions can be granted manually.
Please note that those steps need to be executed on each DC in the domain. This
includes any new DCs after they are promoted.
Login to the DC.
Run [Link]
Right click on wmi control – click security and mark root folder
Add the relevant user (or group) and mark allow checkbox for Enable
Account and Remote Enable.
Click on Advanced, select the user you just added, click edit and choose
apply to this namespace and subnamespaces. Click OK several times to
confirm the operation.

7-59 Application Control Gateway User Guide


Getting Started

Figure 7-24: WMI Configuration on Active Directory Domain Server

Logging Events
To enable creation of the required event logs via Group Policy, you need to
configure Advanced Audit Policy settings in a GPO that applies to all the DCs:
Computer configuration – polices – windows settings – security settings –
advanced audit policy configuration – audit policies – logon / logoff
Enable Success and Failure for the following subcategories:
• Audit logoff
• Audit logon
• Audit network policy server
• Audit special logon

7-60 Application Control Gateway User Guide


Getting Started
Note: The legacy audit policy and the Advanced Audit Policy are incompatible and
only one of them should be used at a given time. If the domain controllers are
currently using the legacy Audit Policy, do not enable Advanced Audit Policy as
it can break the auditing policy and cause unexpected results.

Figure 7-25: Group Policy Management Editor on Active Directory Domain Server

Firewall Configuration
The traffic between the SMP and the DCs is using DCE-RPC. This means that the
communication is starting from port TCP 135 and then redirected to a random high
port. If a firewall is deployed between the Allot server and the DC, it may be
desirable to fix the high port for this traffic.
To fix the high WMI port, perform the following procedure on each DC:
Login to the DC
Open elevated command prompt
Run:
winmgmt -standalonehost
Restart Windows Management Instrumentation service
This will fix the high port on TCP 24158. Note that TCP 135 is still required
to be opened

7-61 Application Control Gateway User Guide

You might also like