Overview of Lawful Intercept Using Flow-Tap

This document explains flow-tap configuration, testing, and basic troubleshooting on Juniper Networks M Series Multiservice Edge Routers and Juniper Networks T Series Core Routers using Juniper Networks Junos® Platform configuration commands and third party scripts. Flow-tap is the Junos OS application used for performing lawful intercept of targeted packet flows.

Lawful intercept (LI) is a process for obtaining communications network data related to an individual (a target), as authorized by a judicial or administrative order. To facilitate the lawful intercept process, certain legislation and regulations require service providers (SPs) and Internet service providers (ISPs) to explicitly support authorized electronic surveillance on their networks to facilitate the interception of telecommunications by law enforcement agencies (LEAs), regulatory or administrative agencies, and intelligence services, in accordance with local law.

The Junos operating system uses the flow-tap application to dynamically capture network flows as required for lawful intercept. Dynamic Tasking Control Protocol (DTCP) is the basis of the dynamic flow capture (DFC) feature in the Junos OS. DFC uses DTCP requests to capture packet flows based on dynamic filtering criteria.

The flow-tap application extends the use of DTCP and DFC to intercept IPv4 packets in an active monitoring router, and sends a copy of packets that match filter criteria to one or more content destinations, including mediation devices and traffic analyzers.

Flow-tap is supported on Juniper Networks M Series and T Series routers, with the exception of the M160 routers and the TX Matrix routers.

Note: More information regarding DTCP can be found in Internet draft draft-cavuto-dtcp-00.txt, DTCP: Dynamic Tasking Control Protocol at http://www.ietf.org/internet-drafts.

Primary Requirements for Lawful Intercept

The primary requirements for a Juniper Networks (or any vendor’s) device to participate in lawful intercept include:

Flow-Tap Features

These are the major features of Junos OS flow-tap:

Related Topics