
11-32 Internetwork Design Guide
Security
Security
ISDN includes several features that you can use to increase the security of ISDN connections:
• Callback
• Screening
• Called Party Number Verification
• Calling Number Identification
Callback
Callback allows a router (typically a remote router) to initiate a circuit-switched WAN link to
another device and request that device to call back. The device, such as a central site router, responds
to the callback request by calling the device that made the initial call. Callback uses the
Point-to-Point Protocol (PPP) and the facilities specified in RFC 1570. Figure 11-10 shows a typical
negotiation.
Figure 11-10 ISDN Callback
In Figure 11-10, callback is completed in the following sequence of steps:
Step 1 Router A brings up a circuit-switched connection to Router B.
Step 2 Routers A and B negotiate PPP Link Control Protocol (LCP). Router A can request a
callback, or Router B can initiate a callback.
Step 3 Router A authenticates itself to Router B using PPP PAP or CHAP. Router B can
optionally authenticate itself to Router A.
Step 4 Both routers drop the circuit-switched connection.
Step 5 Router B brings up a circuit-switched connection to Router A.
Callback provides centralized billing for synchronous dial-up services. It also allows you to take
advantage of tariff disparities on both a national and international basis. However, because callback
requires a circuit-switched connection to be established before the callback request can be passed, a
small charge (dependent on local tariffing) is always incurred by the router initiating the call that
requests a callback. See “Using ISDN Effectively in Multiprotocol Networks” in the
Internetworking Case Studies publication for a callback configuration example.
Screening
Some central office switches support caller ID, which allows the router to verify that an incoming
call comes from an expected source. If you configure caller ID screening but your central office
switch does not support it, the router will reject all calls.
Callback request in LCP
Drop call and callback
Authentication
S4447
Router A
Router B
ISDN
Kommentare zu diesen Handbüchern