Note
To use the IP address transfer over ISDN function, you must obtain a free-of-charge
extra licence.
You can obtain the licence data for extra licences via the online licensing pages in the
support section at
. Please follow the online licensing instruc-
tions.
Before System Software Release 7.1.4, IPSec ISDN callback only supported tunnel setup if
the current IP address of the initiator could be determined by indirect means (e.g. via
DynDNS). However, DynDNS has serious disadvantages, such as the latency until the IP
address is actually updated in the database. This can mean that the IP address propagated
via DynDNS is not correct. This problem is avoided by transferring the IP address over
ISDN. This type of transfer of dynamic IP addresses also enables the more secure ID Pro-
tect mode (main mode) to be used for tunnel setup.
Method of operation: Various modes are available for transferring your own IP address to
the peer: The address can be transferred free in the D channel or in the B channel, but
here the call must be accepted by the remote station and therefore incurs costs. If a peer
whose IP address has been assigned dynamically wants to arrange for another peer to set
up an IPSec tunnel, it can transfer its own IP address as per the settings described in
Fields in the IPSec Callback menu
on page 323. Not all transfer modes are supported by all
telephone companies. If you are not sure, automatic selection by the device can be used to
ensure that all the available possibilities can be used.
Note
The callback configuration on the two devices should be the same so your device of
the called peer can identify the IP address information.
The following roles are possible:
• One side takes on the active role, the other the passive role.
• Both sides can take on both roles (both).
The IP address transfer and the start of IKE phase 1 negotiation take place in the following
steps:
(1)
Peer A (the callback initiator) sets up a connection to the Internet in order to be as-
signed a dynamic IP address and be reachable for peer B over the Internet.
(2)
Your device creates a token with a limited validity and saves it together with the cur-
18 VPN
Funkwerk Enterprise Communications GmbH
322
bintec Rxxx2/RTxxx2