Funkwerk Bintec R41000 Reference page 313

Bintec r1xxx/r3xxx/r4xxx gateways reference manual
Table of Contents

Advertisement

Funkwerk Enterprise Communications GmbH
R1xxx/R3xxx/R4xxx
Transfer of IP Address over ISDN
Transferring the IP address of a device over ISDN (in the D channel and/or B channel)
opens up new possibilities for the configuration of IPSec VPNs. This enables restrictions
that occur in IPSec configuration with dynamic IP addresses to be avoided.
Note
To use the IP address transfer over ISDN function, you must obtain a free-of-charge
extra licence.
You can obtain the licence data for extra licences via the online licensing pages in the
support section at
www.funkwerk-ec.com
tions.
Before System Software Release 7.1.4, IPSec ISDN callback only supported tunnel setup if
the current IP address of the initiator could be determined by indirect means (e.g. via
DynDNS). However, DynDNS has serious disadvantages, such as the latency until the IP
address is actually updated in the database. This can mean that the IP address propagated
via DynDNS is not correct. This problem is avoided by transferring the IP address over
ISDN. This type of transfer of dynamic IP addresses also enables the more secure ID Pro-
tect mode (main mode) to be used for tunnel setup.
Method of operation: Various modes are available for transferring your own IP address to
the peer: The address can be transferred free in the D channel or in the B channel, but
here the call must be accepted by the remote station and therefore incurs costs. If a peer
whose IP address has been assigned dynamically wants to arrange for another peer to set
up an IPSec tunnel, it can transfer its own IP address as per the settings described in
Fields in the Advanced SettingsIPSec Callback menu
are supported by all telephone companies. If you are not sure, automatic selection by the
device can be used to ensure that all the available possibilities can be used.
Note
The callback configuration on the two devices should be the same so your device of
the called peer can identify the IP address information.
The following roles are possible:
• One side takes on the active role, the other the passive role.
• Both sides can take on both roles (both).
. Please follow the online licensing instruc-
on page 288. Not all transfer modes
18 VPN
287

Advertisement

Table of Contents
loading

Table of Contents