Field
Description
The function is enabled by default.
Deactivate this function if you do not wish to send the peer the
certificates of all levels (from your level to the CA level).
Send CRLs
Select whether CRLs are to be sent during IKE (phase 1).
The function is enabled with
7+
.
The function is disabled by default.
Send Key Hash Pay-
loads
Select whether key hash payloads are to be sent during IKE
(phase 1).
In the default setting, the public key hash of the remote end is
sent together with the other authentication data. Only applies for
RSA encryption. Activate this function with
7+
to sup-
press this behaviour.
14.2 be.IP Secure Client
Here you can download the current Secure IPsec Client software for free.
14.3 LISP Light
The Locator/ID Separation Protocol (LISP) provides a new kind of addressing nodes for a
more efficient structuring of the internet.
A large number of reasons warrants the introduction of LIPS, the main one being the
quickly increasing number of mobile devices accessing the internet as well as local net-
works. Having to change the complete IP address for every change of location is inefficient
and lets routing tables grow out of proportion quickly and unnecessarily.
LISP employs the concept of separating the notion of identity and location of a device in-
side the network: A Routing Locator (RLOC) specifies the location of a device, and an End-
point Identifier (EID) specifies its identity. A mapping systems connects both parameters.
When using traditional IP-addressing, identity and location are linked to each other by the
IP address. If a device receives a new IP address via DHCP - as is the rule especially in
mobile computing -, the new IP address is completely unrelated to the previous one, i.e.,
not only the location has changed, but the complete combination of lidentity has
bintec elmeg GmbH
14 VPN
be.IP 4isdn
269