Field
Description
•
/3
: IP packets are only allowed through if the con-
nection has been initiated from "inside".
We recommend you use this setting if you want to use IPv6
outside of your LAN.
•
)3
(default value): All IP packets are allowed through
except for those which are explicitly prohibited.
We recommend you use this setting if you want to use IPv6
on your LAN.
You can configure exceptions for the selected setting in the
on page 277 menu.
Local IPv6 Network
Select a network. You can choose from the Link Prefixes avial-
bale under LAN->IP Configuration->Interfaces->New.
Enter the Local IPv6 address and the corresponding prefix
length. The default prefix length is /64.This prefix must end with
::.
Remote IPv6 Network
Add a new prefix. Enter the address of the other tunnel end-
point. The default prefix Length is
and the default Priority is
. The lower the value entered for Priority, the higher the prior-
ity of the route.
Additional data traffic filters
bintec elmeg Gateways support two different methods for establishing IPSec connections:
• a method based on policies and
• a method based on routing.
The policy-based method uses data traffic filters to negotiate the IPSec phase 2 SAs. This
enables the filtering of the IP packets to be very "fine grained" down to protocol and port
level.
The routing-based method offers various advantages over the policy-based method, e.g.,
NAT/PAT within a tunnel, IPSec in combination with routing protocols and the creation of
VPN backup scenarios. With the routing-based method, the configured or dynamically
learned routes are used to negotiate the IPSec phase 2 SAs. While it is true that this meth-
od simplifies many configurations, at the same time there can be problems due to compet-
ing routes or the "coarser" filtering of the data traffic.
The Additional IPv4 Traffic Filter parameter fixes this problem. You can filter more
14 VPN
bintec elmeg GmbH
242
be.IP 4isdn