Diameter
SpherAAA can act as a Diameter peer for HSS/carrier-network integrations, such as EAP-AKA/AKA' (mobile/SIM subscriber) authentication. Connections to Diameter peers are configured through the Diameter Peers and Diameter Certificates pages, which only appear in the navigation if Diameter is enabled on your account's license - if you don't see them, that's why.
Beyond authentication, SpherAAA's PolicyLogic scripting framework can combine Diameter, RADIUS, and HTTP calls within a single script, enabling routing and bridging logic between a Diameter peer, a RADIUS server, and an HTTP backend. This is a scripting capability built on the same request/response primitives described below, rather than a separate configurable mode.
Diameter Peers
Diameter Peers manages the Diameter connections SpherAAA accepts from, or dials out to.
Add or edit a peer with these fields:
- Peer Role: the main fork in the form - it changes which fields below apply.
- Server (an outbound peer): SpherAAA dials out to the peer (for example, your carrier's HSS).
- Client (an inbound peer): the peer (for example, an MME/DRA) connects in to SpherAAA, matched by its source address, similar to a NAS.
- Peer Host: for a Server peer, the address to dial (e.g.
hss.epc.mnc001.mcc001.3gppnetwork.org). For a Client peer, the IP or CIDR the inbound connection is expected from - optional here, since a Client peer can also be matched purely by its TLS certificate. - Origin Host / Origin Realm: SpherAAA's own Diameter identity, as presented to the peer (e.g.
aaa.epc.mnc001.mcc001.3gppnetwork.org/epc.mnc001.mcc001.3gppnetwork.org). - Enabled: turns the whole peer entry on or off.
- Environment (Server peers only): which PolicyLogic environment this peer's traffic is associated with.
- Peer Group (Server peers only, optional): give multiple peers the same group name to load-balance traffic across them; leave blank for a standalone peer.
- Peer Port (Server peers only): defaults to 3868, the standard Diameter port.
- Watchdog Interval (Server peers only): how often, in seconds (default 30), to send a keep-alive on the outbound connection.
- Use TLS (Server peers) / Also Accept Over TLS (Client peers): reveals a certificate section - pick Use existing certificate (from certificates already imported on the Diameter Certificates page) or Generate new certificate (one is generated and auto-downloaded after saving; install it on the actual peer device). Server peers also let you restrict which TLS versions (1.2/1.3) are allowed for the handshake.
!!! note Also Accept Over TLS is visible on a Client (inbound) peer, but inbound Diameter-over-TLS isn't implemented yet - it's a coming-soon option. Plain Client-peer matching by host/IP works normally; only the TLS option for inbound peers doesn't yet do anything.
Diameter Certificates
Diameter Peers → Diameter Certificates manages the TLS certificates used for outbound Diameter connections configured on the Diameter Peers page above - the private key, certificate, and CA chain SpherAAA presents when it dials out to a peer such as a carrier's HSS.
Import Certificate opens a form with three fields, each accepting a file upload or pasted PEM text:
- Private key
- Certificate
- CA Certificate - the CA the peer's TLS connection should trust the remote end (the HSS) against.
- Plus a free-text Comment to help identify the entry later.
The private key is stored encrypted.
The certificate table lists each entry's type (server certificate for an outbound peer, or client identity for an inbound peer), serial/ID, creation and expiration dates (flagged if expired or expiring within 30 days), subject, issuer, comment, and which peer(s) currently use it. From the row actions you can download a certificate (as PEM or P12, if it includes a private key) or delete it - deletion is disabled while a peer still references the certificate.
!!! note An inbound (Client-role) peer's certificate identity is registered from the Diameter Peers form itself (via Generate new certificate), not imported here - this page's import flow is for outbound Server-role peers.
Using Diameter peers in PolicyLogic
A configured, enabled Diameter peer (or peer group) is referenced by name from PolicyLogic scripts:
DiameterRequestsends an arbitrary Diameter request to a peer.EapAkaauthenticates an EAP-AKA/AKA' subscriber against a peer's HSS.
Testing an EAP-AKA/AKA' script could be done through the PolicyLogic Validate modal's EAP-AKA (SWx) authentication mode.
For routing or bridging traffic between a Diameter peer and a RADIUS server or HTTP backend, combine DiameterRequest/EapAka with RadiusProxy and HTTPClient in the same script.

