If it has to be done and MT can’t! Man! what a market killer!
Over night the US could be dead for MT. ![]()
Yeah. No way are we going to do the right thing and ignore this. Jackbooted thugs can ruin your whole day…
Most people will only need this capability at their gateway. MT should be given a chance to repond before leaping all over them.
Worst case, run another product to connect to your upstream. A PITA, but at least you’re covered.
George
Yea, Mikrotik may not need to do anything but tell people to get a third party device.
either enable sniffer on the mikrotik box, and save all packet data to some file … or better - just get a switch that can mirror a port to another one. the second option is better, it won’t overload your router.
either enable sniffer on the mikrotik box, and save all packet data to some file … or better - just get a switch that can mirror a port to another one. the second option is better, it won’t overload your router.
That sounds like a workable solution except. Apparently the FCC and DOJ has dicatated how to do this. They want it in a standardized format with all providers. They have decided on T1.IAS and LAES.
Lets not forget about the 10k per day retroactive fine for non-compliance.
Matt
They want it in a standardized format with all providers. They have decided on T1.IAS and LAES.
Does this mean they publish the format they are asking for? Can you point us to them ?
Sam
according to:
http://www.askcalea.net/docs/calea.pdf
103.b.1.a,
This title does not authorize any law enforcement agency or officer–
(A) to require any specific design of equipment, facilities, services, features, or system configurations to be adopted by any provider of a wire or electronic communication service, any manufacturer of telecommunications equipment, or any provider of telecommunications support services;
They are not asking for a specific design of equipment, they just want you to provide the data in a specific format.
How you meet the requirement is entirely up to you. As is paying the $10k per day fine if you don’t meet the requirement and get a CALEA court order.
Ouch!!
George
The streaming packet sniffer (tszp) would be probably be perfect for this. Why should Mikrotik support CALEA when they aren’t even based in the US ? Our laws don’t apply to other countries. Well, I’d ask myself the same question. My answer would be; because lots of my customers are in the US. : ) And if its only included in 3.0 I could see a ton of upgrades coming in the next few months.
Sam
The US WISPS MUST comply with CALEA! Cowboy attitudes and stamping one’s feet about how “they will get the info over my dead body” are not going to cut it.
The other router vendors support it. Mikrotik has many, many customers in the USA who have chosen them as supplier for various reasons.
Because a requirement doesn’t exist in Latvia is not a valid justification for not supporting what customers in another country are requesting. If it is a lack of understanding, or a language barrier, I’m quite sure we could get them some help on that front.
Bottom line is customer support. Without the support they need, customers will cease to be that.
Come on, Mikrotik- Please don’t make your excellent product have a black eye among US customers because of something you can (but won’t) address right in software.
This might help some understand more.
http://www.educause.edu/content.asp?PAGE_ID=645&PARENT_ID=698&bhcp=1
my understanding here is, if you provide any public internet service fast enough for VoIP, whether you do VoIP or not, you must comply with CALEA
The timeline for implementing this is insane.
I am against the government spying on me or my customers, but.. if it is the law, i would provide them one of many methods (tcpdumps remotely or whatever), but making us conform to a standard that we can’t even find any information on.. is insane.
I understand if Mikrotik doesn’t get involved, but, I know there are alot of isp’s and wisp’s (mostly small) screaming for help now, and they only have until March to file the SSI (their plan) and then May to become compliant. and they are looking for someone with a cost effective way to meet these deadlines.
we need all the information you have on this, please send it to mikrotik. we need some information on implementing this, not the requirements of the wisp. we will see what we can do
I would hope that the packet sniffer could be extended to support this. The streaming (TZSP) protocol is not exactly what is required, but I would think that a comparable streaming wrapper of this sort would work.
My thoughts…
-
Use existing packet sniffer with modified streaming function that complies with their format specification (if you can figure that part out)
-
Allow ability to use address-list to specify IPs for which to capture in addition to the 2 filter fields currently present.
-
Obtain thousands of new customers in the USA overnight because everyone is scrambling to find affordable equipment that can handle this.
Sam
ChangeIP
Good Idea. We are doing just that. We are using the Mikrotik as Passive Probe to stream intercept to our mediation device. We also use the mikrotik OS as the VPN Server for the LEA. We are testing with LEAs as we speak.
Sam
Normis,
How about looking at T1.IAS for specifics?
Here’s some info:
CALEA requires broadband service providers to have proper tools in place by May 14, 2007 to isolate, intercept, export and selectively monitor in real-time, a legally identified criminal suspect on the BSP’s network, without compromising the constitutional right to privacy for the rest of the customers on the network.
When a Law Enforcement Agency issues a legal warrant to a BSP, the Caller Identifying Information (CII) or Call Content (CC), such as VoIP traffic, to and from a particular user is captured or redirected and sent to the Law Enforcement Agency for real-time forensic analysis. The warrant has to be very specific about the types of data traffic to be captured and distribution process to the Law Enforcement Agencies.
Besides VoIP, we also need to be able to capture info pertaining to e-mail or chats with the ability to separate session content and session header info (akin to CII and CC). The CALEA law itself is not clear enough. So, guys please provide all info that you know of (and hopefully valid information).
I contacted Parasun technologies today to look into implementing thier third party solution. We provide wireless broadband as well as cable modem services… here is their response from the initial engineer looking at how my network is setup:
Regarding the switched end:
Switches need to be managed. This is a requirement for any access switch that connects to a user device. If unmanaged switches are used then port spanning cannot be implemented, and port-port traffic cannot be forwarded to the probe. There are unmanaged switches in the diagram.
Regarding the wireless RF end:
There are wireless routers missing from the bottom left of the diagram (not CPE, but infrastructural routers). I’ll need detailed info on how they’re connected. Wireless is a different kind of problem - our probe doesn’t have a wirless interface. So the wireless router has to support LI, at the very least bridging. Bridging will require internal network renumbering, since the wireless network will spill over up to the primary Mikrotik router. A quick check of this companies LI/CALEA support position suggests these units may need replacement:
http://forum.mikrotik.com/t/t1-ias-laes-calea-support-mandatory-in-usa/11497/12It may be possible to re-engineer this network by introducing tagged traffic port mirroring on the units. This requires a lot more info than that in the diagram, starting with vendor and software release on each device, free ports on each unit, VLAN’s that have been configured on the switches, etc.
Many vendors don’t implement full port mirroring - like SMC which allows mirroring of sent or received port traffic but not both - this may require replacement of the unit in such cases.
The cheapest solution for this customer may end up being the purchase of a replacement provisioning system from us.
My apologies for the number of issues and questions raised.
Here are some companies i have com across offering Third party solutions for providers:
http://www.apogee.net
(thier solution starts at approx $800-$1000 and up based on subs, and currently requires Cisco routers although Juniper support is coming soon. they were unsure how to proceed with the mikrotik part of it.)
http://www.neustar.biz/pressroom/datasheets/index.cfm
(I am still waiting for a call back from this company but my initial conversation with them seemed positive)
http://www.verisign.com/products-services/communications-services/connectivity-and-interoperability-services/calea-compliance/index.html
(Have not contacted them yet, but they are next on the list, with the history of verisign though i assume thier pricing will be high)
http://www.parasun.com/
(The quote above is from one of thier engineers. Thier solution requires them to install a server into your network which costs approx $3500-$4000 then requires you to pay monthly either $300 (under 1000 subs) or $700 (up to ?? subs) but it sounds like they may not even be able to help me due to the mikrotik, and it also sounds like they want full access to every device on my network… don’t think i like this idea!)
http://www.verint.com/communications_interception/section2a.cfm?article_level2_category_id=7&article_level2a_id=200
(Supposedly have a cost effective product for rural broadband providers, I have requested more information)
Informational sites regarding CALEA:
http://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act
http://www.askcalea.net/
http://chat.part-15.org/index.php
http://www.calea.org/
http://www.fcc.gov/calea/
http://www.eff.org/Privacy/Surveillance/CALEA/?f=faq.html
http://www.opastco.org/tech/calea.htm MUST READ!!!
http://www.educause.edu/Browse/645?PARENT_ID=698 (has examples of the forms to file)
http://www.educause.edu/ (search for Keywords like CALEA LAES etc)
Link to DRAFT specs:
http://contributions.atis.org/UPLOAD/PTSC/LAES/PTSC-LAES-2006-014R2.doc
Hopefully this will help, I myself am still trying to get a grip on all of this so I do not know the technical requirements of the devices, however. maybe someone else can find somehting in this mound of reading.. ![]()
From my point of view this whole thing seems unrealistic for small providers, it would almsot seem like they want to put us all out of business. There has got to be either a way around it, or a way to do this economically for the small guys…
Enjoy! IF I figure anything else out, ill let you all know here.
I will update this list as i aquire more information.
To add to your list of URLs: