Chapter Six: Security

Callback 88

 

 

Callback

Callback is another effective method to control access to the DIVA LAN ISDN Modem. When callback is enabled, the DIVA LAN ISDN Modem functions as a callback client, and the remote site being called functions as a callback server.

The client calls the server, the connection is dropped or disconnected, then waits for the server to call back to re-establish the connection. While waiting for the server to call back, the DIVA LAN ISDN Modem may accept incoming calls that are not from the server. To ensure that only calls from the server are accepted you can use call authentication (set the always authenticate remote option as shown on page 87) to validate the incoming call.

The DIVA LAN ISDN Modem can only function as a callback client.

Note When you enable callback using the web configuration interface, the DIVA LAN ISDN Modem automatically enables support for incoming data calls (page 83).

Callback modes

Two callback modes are available. Each provides different features. For callback to work, both client and server must use the same mode.

Callback control protocol

This is a Microsoft-developed solution. It is used by NT4, and devices from Cisco, Ascend, and other vendors.

NCP enables you to specify a time delay before the server calls back, and supports both the user specified and administrator specified options.

ISDN callback

Unlike the callback control protocol, the server does not answer the initial call from the DIVA LAN ISDN Modem when using ISDN callback mode. Therefore, there is no charge for the call. This can be advantageous if you are making a lot of calls without a flat-rate package, or are making long distance calls.

ISDN modem only works with Cisco IOS. It uses caller ID information to return the call. Therefore, caller ID must be enable on your line to use this mode.

Callback options

Two callback options are available: user specified and administrator specified.

User specified

This option requires that the DIVA LAN ISDN Modem supply the server with the callback number to use. If the server is on a PBX, or must dial long distance, you may need to include appropriate dialing prefixes. Contact the system administrator of the server to determine the exact requirements.

The main advantage of this option is that if you change the DIVA LAN ISDN Modem’s ISDN phone numbers, you do not have to inform the server, since you supply the phone number with each call.

Administrator specified

With this option, the DIVA LAN ISDN Modem does not supply the server with a number to dial. Instead, the remote identifies the DIVA LAN ISDN Modem by its caller ID or information supplied during call authentication. The server then consults a pre-configured table to determine the number to dial.

The main advantage of this option is centralized security. The server maintains a list of all valid clients, with their physical phone numbers and security information.

Note It may not always be possible to support an MLPPP connection with the administrator specified option. The reason for this is that the server will only have one number configured for callback. When it tries to establish the second channel, it gets a busy signal. The solution is to use user specified, and send the server the two numbers that are required.

Page 88
Image 88
Eicon Networks DIVA LAN ISDN manual Callback modes, Callback options