The value
63
is available for this purpose in the field Service. This entry ensures that
incoming calls for this number are routed to the IPSec service.
If callback is active, the peer is caused to initiate setting up an IPSec tunnel by an ISDN
call as soon as this tunnel is required. If callback is set to passive, setting up a tunnel to
the peer is always initiated if an ISDN call is received on the relevant number ( MSN in
menu Physical Interfaces->ISDN Ports->MSN Configuration->New for Service
63
). This ensures that both peers are reachable and that the connection can be set
up over the Internet. The only case in which callback is not executed is if SAs (Security
Associations) already exist, i.e. the tunnel to the peer already exists.
Note
If a tunnel is to be set up to a peer, the interface over which the tunnel is to
be implemented is activated first by the IPSec Daemon. If IPSec with
DynDNS is configured on the local device, the own IP address is propagated
first and then the ISDN call is sent to the remote device. This ensures that
the remote device can actually reach the local device if it initiates the tunnel
setup.
Transfer of IP Address over ISDN
Transferring the IP address of a device over ISDN (in the D channel and/or B channel)
opens up new possibilities for the configuration of IPSec VPNs. This enables restrictions
that occur in IPSec configuration with dynamic IP addresses to be avoided.
Note
To use the IP address transfer over ISDN function, you must obtain a free-
of-charge extra licence.
You can obtain the licence data for extra licences via the online licensing
pages in the support section at
. Please follow the
online licensing instructions.
Before System Software Release 7.1.4, IPSec ISDN callback only supported tunnel setup
if the current IP address of the initiator could be determined by indirect means (e.g. via
DynDNS). However, DynDNS has serious disadvantages, such as the latency until the IP
address is actually updated in the database. This can mean that the IP address propag-
ated via DynDNS is not correct. This problem is avoided by transferring the IP address
over ISDN. This type of transfer of dynamic IP addresses also enables the more secure
ID Protect mode (main mode) to be used for tunnel setup.
13 VPN
Gigaset Communications GmbH
262
hybird 120 Gigaset Edition