T & D CIRCLE, JABALPUR TEST SCHEDULE IPLC-LIM Document No TD/SW-6321/IPLC-LIMS No of Pages. Issue No. 19 I Issued By: T&D Circle, Jabalpur Approved By: Date of Issue: CGM T&D Circle 04.10.2008 Amendment No (If Any) 01 No of Pages: 01(Page no.19) Issued by: INSPECTION CIRCLE, JABALPUR Date of Issue: 02-07-2010 Restricted use by BSNL Employees only “FIX IT RIGHT THE FIRST TIME” TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR IPCL LIM TEST SCHEDULE INDEX PART A PRE SWITCH ON TEST PART B POST SWITCH ON TEST B-1 LAN SWITCH/FFU/XDM-DXC B-2 SERVER B-3 STORAGE SYSTEM B-4 ROUTER PART C NODE WISE TEST C-1 IPCL-LIS C-2 IIPCL-LMS C-3 OPERATION AND MANAGEMENT History sheet Sl.no 1 2. Name ot Test schedule Date of approval IPLC-LIM --- Issue I IPLC-LIM--- Issue II TD/SW-6321-IPLC-LIM 4-10-2008 02-07-2010 Page no made Section/ amendment sl.no.of added Original nil Page no.19 Part-C/C3 sl.no.19 Page 1 of19 test Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR IPCL LIM TEST SCHEDULE TEST SCHEDULE FOR IPLC-LIM PART A S. No. PRE SWITCH ON TEST Name of Test Reference Guidelines 1. Check of Earthing System and its Distribution As per T&D EI and Installation If earth is existing, then document earth measurement is to done, if not feasible, a certificate from planning along with last reading (within six months) to be taken 2. Check of Air Conditioning As per T&D Test Schedule If existing, required temp. and humidity conditions are to be ensured as per node requirement. 3. Check of Fire Alarm System - DO - If existing, it should be operational 4. Check of False Flooring / Antistatic - DO Flooring / False Ceiling In case of Core Router locations only. Optional for others. 5. Check of Engine Alternator - DO - If existing, sufficient capacity and redundancy is to be ensured. 6. Check of Power Plant / Battery including UPS with battery backup - DO - If existing Power plant / battery, sufficient capacity is to be ensured 7. Check of Lighting and Power Outlets - DO - Should be adequate 8. Check of Cable Laying and Termination Should be neatly laced and clean 9. Voltage Drop Test. It should be < 1 Volt 10. Approved Lay out, LAR, Approved IP allotment & General Inspection As per switching schedule 11. Hardware Conformity Test including racks, Lap Top Computers, spares As per P.O. and vetted B.O.M TD/SW-6321-IPLC-LIM As per Installation Document Page 2 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR IPCL LIM TEST SCHEDULE & Protocol/performance analyzer 12. Check of Ethernet Cabling Penta scanner report/Certificate for GE Cables should be obtained. 13. 14. QA Certificate for the indigenous Equipments Check of Documentation FTR for imported items. (Factory Test Report) Documents in English on the following to be submitted: a. Interconnectivity diagram of all the equipments b. Hardware configuration for each Server. c. System description, System operation, training, repair related documents. 15 a. Application software version details, operating software & various modules b. Verification of software license of various applications / system software in the name of BSNL TD/SW-6321-IPLC-LIM A certificate is to be furnished by the vendor that software of the system being supplied is the latest Page 3 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR PART B B-1 POST SWITCH ON TEST LAN SWITCH/FFU/PROBE/XDM-DXC S.No. 1. IPCL LIM TEST SCHEDULE Test Item Check of LAN Switch Reference Guidelines 1. Hardware check 2. Check for redundancy a. Power Supply b. Hard disk c. Processor 3. Software conformity a. Record boot procedure b. Check for additional software and updation of patches. 4. Check for proper working of all peripheral. 5. Check for connected networks and redundancy, if any. 6. Check for backup and restore 7. Extension of alarms 8. Network Management in terms of viewing the health of all Managed devices. 2. Check of FFU (Fast Filtering Unit) 3. Check of XDM/DXC 4. Telephony Probe TD/SW-6321-IPLC-LIM Check for proper functioning equipment Check for proper functioning equipment ------------------do----------------- Page 4 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR B- 2 SERVER S.No. NAME OF Test 1. H/W & S/W Check (as per BOM) 2. Boot up & Shutdown process Cluster fail over to be checked for all the servers with the application is running System health diagnostics and performance monitoring 3. 4. IPCL LIM TEST SCHEDULE Procedure Remark Check for all Hardware & Software available, up and running Redundancy 1. Processors 2. Ports/Networks 3. Power Supply 4. Fan assembly 5. Hot Swapping 1. Processor 2. Hard disk 3. PCI Cards 6. Configuration/Partitioning (O/S) 7. Backup/Restoration of O/S - Application and Database 8. Alarms in Network Management 9. User authority/ Administration Management 10. Log / Audit Note : Servers to be deployed at IPLC-LMS for applications like Analysis Server, Storage server, SERVERS etc. shall have following peripherals/ interfaces/ HDD in addition to CPU, RAM and clustering requirements as indicated in schedule of requirements: 1. Servers shall use 64 bit CPUs of latest processor in the family and 1.2 GHz or higher clock speed, available from the bidder at the time of submission of bid. 2. Servers other than blade servers shall have Symmetrical Multi-Processing (SMP) architecture 3. One CD /DVD combo Drive (Read and Write) 4. 20/40 GB or higher DAT Drive (Only for SSSC, PMS and Subscriber Management application Servers) 5. Two RJ45 GigE Ports (10/100/1000) on different cards (both electrical) TD/SW-6321-IPLC-LIM Page 5 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR IPCL LIM TEST SCHEDULE 6. A minimum of 4 MB of L2/L3 Cache per CPU 7. A minimum of 2 GB of ECC RAM per CPU 8. One console port on servers; one parallel port, one serial port and one console port on management consoles. 9. 2 USB ports (High speed USB 2.0 or above) on management consoles 10. 2 x 73 GB mirrored, hot swappable FCAL/SCSI Hard Disk, 15,000 RPM or higher 6 PCI Expansion Slots 11. Redundant load sharing and hot swappable power supplies. 12. Redundant power supplies shall have multiple feeds. 13. High availability cluster: For Back end Servers, bidder shall quote cluster software license along with application HA agents 14. Journal File System and volume manager to mirror OS disks. 15. The database clustering shall be based on an architecture that shall eliminate the application or its part going down in case of failure of any of the node in cluster. 16. All servers shall be rack mounted in server vendor’s 19” (42 U) racks (OEM). The number of racks shall be minimised for optimised floor space utilization. TD/SW-6321-IPLC-LIM Page 6 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR B-3 IPCL LIM TEST SCHEDULE STORAGE SYSTEM S. No. Name of Test Procedure 1. BOM Verification (Hardware & Software) 2. Connectivity diagram between Servers and Storage units : Physical checks & records. 3. Redundancy for all units individually: a. Power supply. b. Fan assembly. 4. Configuration: a. Hard disks b. Spare Disks. 5. Error log 6. User Management TD/SW-6321-IPLC-LIM Remark Raid configurations for storage is to be checked as per the design Page 7 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR IPCL LIM TEST SCHEDULE B-4 ROUTER Check of Routers i. Hardware Conformity ii. Router connectivity iii. Verify Hostname iv.View IOS version v.Verify modules vi.View connections vii.IP address viewing. viii. Link status ix. Configuration x. Route information xi. Remote IP reachability xii. View Neighbors xiii. MPLS functionality enable xiv. Redundancy Check xv. Interface check. xvi. MPLS QoS Levels Check xvii. Alarms TD/SW-6321-IPLC-LIM Page 8 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR PART C IPCL LIM TEST SCHEDULE Node wise TEST C-1 IPLC-LIS S. No. 1. Test Item Procedure Hardware and Software Verification 2. Verify that capability of intercepting the IPLC traffic of following interfaces: A E1 interface as per ITU-T recommendation G.703. The probe shall be capable of being configured to intercept traffic being carried in any combination of timeslots. B E3 interface as per ITU-T recommendation G.703. The Probe shall be capable of being configured to intercept traffic being carried in any of the E1s and also any combination of timeslots in that E1. C STM-1 interface as per ITU-T recommendation G.703 and/or G.783. The probe shall be capable of configuration to intercept any of the E1 being carried in the SDH Container. It shall also be capable of being configured to intercept the traffic being carried in any group of the timeslots of any E1 channel in SDH container. The probe in this case shall be remotely manageable from the Central Site. D 45 Mbps as per ITU-T recommendation G.703 (E32) E IPLC-LIM Optical interface monomode Long haul F 10/ 100/ 1000 Mbps Auto sensing Ethernet as per IEEE standards TD/SW-6321-IPLC-LIM Remarks As per BOM . Network Elements as per approved connectivity diagram with full details of input and output paths with formats Page 9 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR 3 (i)Check that the Probe can stealthily intercept the IPLC traffic without revealing its identity (ii) Check that neither the targeted IPLC / user(s) nor any other unauthorized person gets any indication whatsoever that intercept function has been invoked. 4 Check that the probe can the intelligence to detect that the traffic being carried in the intercepted IPLC target is voice or data and accordingly route/switch the traffic to different interfaces. 5 Check that IPLC-LIS has access to the entire content transmitted or caused to be transmitted to and from the targeted IPLC in real time and shall be capable of intercepting the following IPLC traffic along with the relevant IRI A Data traffic including the Internet traffic (HTTP, email, ftp etc) Voice or Data including SMS, GPRS, CDMA or MMS traffic that may appear over the Channelised links, including analysis of the following out-of-band and in-band signaling: a) SS7 including MAP b) R2 c) ISDN PRI B C Voice-over-IP (ITU-T H.323, H.248, G.711, G.722.2, G.723.1, G.726, G.728, G.729AB), SIP D Fax including Fax over IP (ITU-T T.37, T.38) E Video including Video over IP (ITU-T H.261, H.263, H.264) F 6 Any combination of the above forms The system shall be capable of intercepting the target(s), whose definition shall be done from the IPLCLMS through the local terminals and/ or remote terminals located at Mumbai TD/SW-6321-IPLC-LIM IPCL LIM TEST SCHEDULE The operation and services of the targeted IPLC(s)/ user(s) shall not be affected in any manner Page 10 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR I II III IV V VI VII VIII IX X XI XII XIII XIV XV XVI XVII XVIII XIX XX 7 IPCL LIM TEST SCHEDULE and other IPLC sites respectively by the Operators on receipt of request from the competent authority and whose traffic is to be monitored, by any combinations of the following parameters: MAC address of the actual physical device Source and Destination IP address (IP version 4 and IP version 6) TCP and UDP Port number E-mail address in SMTP (Simple Message Transfer Protocol), POP3 (Post Office Protocol version 3), IMAP4 (Internet Message Access Protocol version4) [To, From, Copy to] POP3, IMAP4 Username RADIUS (Remote Authentication DialIn User Service), AAA and DHCP Username [Login-id] RADIUS CLI (Caller Line Identification) URL (Universal Resource Locator) address Threshold for a type in a connection i.e. a PPP session or a leased line with percentage TCP, UDP, SCTP, etc. traffic more than a specified value Traffic Content dependent targets (e.g. a particular keyword in http, email etc or chat traffic and scanning the relevant text after protocol decoding) User groups (e.g. Yahoo user groups) Web mail (To, From, Copy to) IM ID (Instant Messaging Identity) Phone Number /VOIP Phone Number Subnet address Leased Line (Circuit/ Channel number) X.25 address ATM/Frame Relay address Mobile - GSM/CDMA Number (Called and Calling Party) for SMS, GPRS and MMS Any combination of above including Boolean conditions (AND, OR, NOT etc.) for above Check that target grouping rules is possible for the purpose of interception of IPCL traffic: TD/SW-6321-IPLC-LIM Page 11 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR IPCL LIM TEST SCHEDULE I Packets originating from or destined to an IP - Sub-network II Packets between two specific IP – Subnetwork III Packets destined to a specific IP address (client or server) and port-range IV Packets originating from a specific IP address (client or server) and portrange Check that IPLC TC and IRI are made available at the MC in real time. The system shall be able to support 7000 defined targets, based on interception criteria, for LEAs. For each LEA minimum 1000 targets assignment, based on interception criteria, shall be possible at each site. It shall be possible to simultaneously intercept a single target, based on interception criteria, by at least seven LEAs. In such cases, each access shall be kept separate and distinct to ensure the privacy to each security agency. It shall be possible for the LEAs to log into the IPLC-LMS as remote operator and do the keyword indexing on all the targets of all the different LEAs for intercepted traffic stored in the IPLCLMS i.e. each LEA shall be capable of querying on any given keyword from all the targets in the Data base. IPLC-LIS shall support at least 210 concurrent keyword targets and atleast 3000 targets using any combination of targets as defined in clause 3.1.10 The interception-by-keywords shall support email and/or SMS filtering wherein keywords can be case insensitive and intercepted email and/or SMS is fully captured Check of availability of the Probes at the interception points/sites.: 8 9 10 11 12 13 14. 15 As per BOM Check that Traffic Aggregator(TA) is able to buffer intercepted traffic in case of failure of link to IPLC-LMS. It shall have the storage for at least 280 GB of TD/SW-6321-IPLC-LIM Page 12 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR 16 17 data. Check that Interface between IPLCLMS and TA supports file transfer standards like FTP (File Transfer Protocol) Check that TA generates an alarm message in case of disconnection of link with the Probe. 18. Check that only the authorized LEA receives the intercepted data. 19 23 24 The system shall be capable to deliver the captured information to multiple LEAs i.e. upto 7 while keeping anonymity between the LEAs The system shall transform and transmit the TC and IRI to the proper LEA in the appropriate format. The system shall enable listening to voice calls in near real time as well as off-line. The near real time voice functionality should be IP based so that LEA station can be easily mobilised. LEA workstation client must be web based. Operations and Management Calender Management 25 Password Management 20 21 22 IPCL LIM TEST SCHEDULE TD/SW-6321-IPLC-LIM Alarm for such incidence shall be raised on maintenance terminal/ alarm panel of TA. TA shall ensure during delivery that the intercepted data is delivered only to the proper LEAs while providing no visibility to additional LEAs that maybe targeting the same IPLC/ user It shall be possible to execute any command at any time by attaching a time tag to command and it shall be executed when the real time matches the time tag). Access to system operations shall be controlled by at least two levels. The manmachine language shall have facility for restricting the use of certain commands of procedures certain staff/ terminals Page 13 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR 26 27 28 29 30 31 C2 1 I II III IV V VI VII IPCL LIM TEST SCHEDULE Suitable safeguards shall be provided in the man-machine communication programs to bar unauthorized persons from making any changes in the stored data contents. Commands and responses shall be stored in a read-only log file in the system disk, which can be retrieved whenever required using manmachine commands. Alarm must appear in case of disk capacity utilisation beyond pre-defined limit. System Backup The system backup feature shall be provided on offline storages like CD/ DVD ROM, tape, etc. The system shall provide for printouts and visual/ audible alarms to assist in efficient administration Any malfunction in the system shall initiate a fault message and/or a visible maintenance procedure for location of the faulty unit or for detailed procedures on further action to be taken for rectification of the fault conditions. The classification of alarms in the system may be indicated. IPLC- LMS Check that IPLC-LMS supports the following : Define and manage system users and targets/ group of targets Start and stop of monitoring of target either automatically or manually Assign targets to operators/ group of operators, depending on privileges, for monitoring at the terminal for optimal division of workload Generate reports about system definitions and user activities, and maintain various system parameters Define the archiving framework for targets or grouping of targets Manage all archiving devices within the system to ensure all required media are available and operational Create, modify and delete targets or group of targets TD/SW-6321-IPLC-LIM Page 14 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR VIII IX X 2 3 a) b) c) d) e) f) g) h) i) j) k) IPCL LIM TEST SCHEDULE Create and manage target’s monitoring start and end date/time Generate target related reports For VOIP traffic detection and analysis the following list of reports shall be possible: a) Call Direction by Number b) Call Direction by Volume c) Destination Country by Duration d) Destination Country by Number e) Calls by International or Domestic f) Destination Country by Number g) Origination Country by Number h) Volume Breakdown by Protocol The Monitoring/ Analysis Servers each shall have file Logger, which shall store the intercepted traffic for short-term use. The storage shall be capable of storing at least 1000 GB of data or 3 months of intercepted data whichever is greater The Analysis server(s) shall be able to decode, analyse and reconstruct the following protocols: HDLC PPP including encryption and compression Frame Relay AAL5 - ATM X.25 SNA IP (IP address) TCP (frames with minimum errors, sorted sequentially according to connection or port number UDP (frames sorted sequentially according to connection or port number) Email (POP3 [incoming messages], SMTP [outgoing messages], IMAP4 [incoming messages, mail and folder lists]) MIME [formats and encoding] TD/SW-6321-IPLC-LIM Page 15 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR l) m) n) o) p) q) r) s) t) u) v) w) x) y) 4 5 6. I II IPCL LIM TEST SCHEDULE Radius Chat and Instant Messaging (IRC [Chat and file transfer over IRC], Microsoft Messenger [Messenger via Server, Text and nick names], Yahoo Messenger [Messenger via Server, Text and nick names], AOL Messenger [Messenger Peer-To-Peer and via Server, File transfers, Text and nick names], ICQ [Messenger via Server, Text and nick names]) AOL Access 5.0, 6.0, 7.0 (ISP access and TCP/IP protocols such as HTTP and FTP excluding AOL proprietary protocols such as email) AOL mail 5.0 (Incoming/Outgoing emails and attachments) HTTP Version 1.0, 1.1 (XML, HTML) [Web pages, downloads, uploads, compression] FTP/TFTP (full session transcript, details, summary and transferred files) Telnet (Transferred communication) NNTP (Messages and folder list) SIP Voice-over-IP (ITU-T H.323, H.248, G.711, G.722.2, G.723.1, G.726, G.728, G.729AB, SIP) RTP/RTCP Lotus Notes WAP (Wireless Application Protocol) for SMS, GPRS and MMP Video over IP (H.263) Check that it is possible to examine the contents of e-mail attachments. It shall be possible to do free text search on the intercepted data. The Analysis server(s) shall be capable of near real-time analysis of the incoming traffic. Storage Storage at MC: Storage with minimum 5 TB capacity with Open Source Platform as per requirement of applications or 3 months of intercepted data storage for analysis purpose, whichever is greater . The calculations/ dimensioning rule shall be submitted by the VENDOR so that storage quoted shall meet the IPLC-LIMS requirements. Storage at Interception Site(s ):This TD/SW-6321-IPLC-LIM Page 16 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR III IV 7 8 C3 9 10 11 IPCL LIM TEST SCHEDULE shall contain the raw/ processed data intercepted by the probes. This Online temporary storage shall have minimum capacity of 280 GB or 24 hours of intercepted data storage whichever is greater The storage system shall be connected to the LAN Switch at IPLC-LMS over at least 1 + 1 Gigabit Ethernet interface. LAN Switch: LAN Switch having at least 16 ports or 1.5 times the number of servers/ Network elements, whichever is greater, shall be deployed for implementing No Single Point of Failure (NSPOF) storage Architecture. Each Server/ Network Element shall be connected to Main and redundant card/ Module Port. information that originates from different targets will be stored on different media. It shall be possible to retrieve and present the IPLC intercepted traffic target-wise to an operator at a monitoring position Operations and Management Minimum 8 number of monitoring positions with associated hardware and software shall be supported Suitable safeguards in the form of multi level password (atleast four) shall be provided in the man-machine communication programs to bar unauthorized persons from making any changes in the stored data contents. The intercepted data stored at the IPLC-LMS shall not be modifiable by any operator including the Administrator Password Policies: TD/SW-6321-IPLC-LIM forcing the users to modify the password on first login, defining expiration-period for passwords defining required password complexity (combination of letters and numbers and minimum length) blocking access after a number of unsuccessful Page 17 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR 12 The system should provide audit trail for all user actions The system should provide query tools for searching for specific audit events. 13 Access to system operations shall be controlled by at least four levels. 14 Log Generation: I It shall be possible to store a log of commands given on admin/ user workstations and their responses in a read-only file in the system disk, which can be retrieved whenever required by using man-machine commands. Alarm must appear in case of disk capacity utilization beyond pre defined limit. When viewing web pages that were captured the view shall show the page as the target saw it, including handling of Java scripts, ActiveX elements, etc. The system backup feature shall be provided on offline storages like CD/ DVD ROM, tape, etc Monitoring Requirements The monitoring equipment shall support recording and storing of the call content of at least 210 targets/keyword targets/cases simultaneously. The monitoring shall be possible for the entire duration of the call. The monitoring equipment shall only receive originating and terminating telecommunications of the target subscriber. The call content is transmitted to the monitoring equipment in its original form without any encryption and encoding, If the target subscriber modifies the call content, the monitoring agency shall be II 15. 16. 17 I II III IV V TD/SW-6321-IPLC-LIM IPCL LIM TEST SCHEDULE attempts e.g. defining a target, modifying a target, deleting a target, defining a user, modifying intercepted object’s transcription The man-machine language shall have facility for restricting the use of certain commands of procedures to certain staff/ terminals. Page 18 of19 Issue –II Dated 02.07.2010 TECHNICAL AND DEVELOPMENT CIRCLE JABALPUR VI VII VIII IX X XI 18. 19. IPCL LIM TEST SCHEDULE capable of extracting the intelligence from the call. The monitoring equipment shall be capable of recognizing the transmission and reception of FAX and data communication of the target subscriber. The monitoring equipment shall store the FAX and data communication target wise, which should be retrievable and presented in its original form, whenever required. The monitoring equipment shall recognize the indication of “start of the call” (ring) and “end of the call” sent by the transmission/end equipment. The monitoring equipment shall be capable of receiving and storing the call-related data in the system disk for all the calls routed to it. No indication whatsoever should be given to the target subscriber that interception has been invoked on the target. The monitoring shall not affect the basic and supplementary services of the target subscriber. Traffic reports shall be generated by the monitoring equipment, for each target or user wise (LEAs) O&M Support It shall be possible to all FCAP management functions from the centralized NOC As per the tender condition section-IV Integration of new equipment with existing LI System. TD/SW-6321-IPLC-LIM Page 19 of19 Issue –II Dated 02.07.2010