Community discussions

MikroTik App
pixitha
newbie
Topic Author
Posts: 27
加入: Thu Jun 14, 2007 1:52 am

Calea?

Mon Jun 09, 2008 8:48 am

Just wondering if anyone has had a chance to setup and test the calea packages (hopefully not via a LEA request!)....

按计划工作好吗?

What type of device did you end up using as the Calea server?

Any other suggestions?

-thanks
Kyle
Top
用户头像
lastguru
Trainer
Trainer
Posts: 432
加入: Fri May 28, 2004 9:04 pm
Location:Certified Trainer/Consultant in Riga, Latvia
Contact:

Re: Calea?

Mon Jun 09, 2008 10:12 am

I have done that long time ago (about the time calea appeared in ROS) and it worked fine for the test setup. The target machine was a regular PC with some average specifications. Fortunately, never had the need to deploy this in a production environment:)
Top
pixitha
newbie
Topic Author
Posts: 27
加入: Thu Jun 14, 2007 1:52 am

Re: Calea?

Mon Jun 09, 2008 9:10 pm

Here is a problem im running into, in my head...

we have 2 upstream providers in 2 seperate physical locations geographically, for our network....how can I do that?

have a network tap at both head ends....and have 1 calea logging server?

-kyle
Top
csickles
Forum Guru
Forum Guru
Posts: 1255
加入: Fri May 28, 2004 8:46 pm
Location:Phoenix, AZ
Contact:

Re: Calea?

Mon Jun 09, 2008 11:42 pm

You will need two taps. One for each chain.
You will need atleast one mediation device (collection server) (If the link between the sites is fast enough)
I would NOT count on this.
You will probably want a mediation device on each "string".. YOU MUST NOT LOOSE PACKETS !!

There are some updates to the CALEA package in the works related to out of band data as well as using TCP ( I seem to remember) rather that UDP for sending the stream to the mediation device.

I dont think you need two tapps for each string, as you can create multiple rules for packets going to and from the target device, You can create the tapps so that ANY source to the target or any destination from the target can be captured... so even with two upstream connections per network "string / pathway", it shuld not matter... it is the path from the target to the tap that is important. The Tapp must be able to "see" the packets (they must pass thru the tap device) and the tapp must be able to identify the traffic as belonging to the target device..
Top
pixitha
newbie
Topic Author
Posts: 27
加入: Thu Jun 14, 2007 1:52 am

Re: Calea?

Mon Jun 09, 2008 11:52 pm

Yea, this site is connected with a oc3, with little traffic in all reality, so having 2 taps and 1 mitigation server would actually be feasible until the amount of data increases....

Ill have to try that option first

-kyle
Top

Who is online

Users browsing this forum:chua,memelchenkovand 9 guests