Languages German and English
Communication
Connection management Communication only via secured VPN tunnel or with simultaneous unsecured Internet access. Manual or automatic
connection establishment, adjustable hold-times with automatic connection establishment
Connection types VPN connection over existing IP connection
Protocols All IP-based protocols, NetBIOS/IP (Windows Networking), PPP, PPPoE and PPTP
VPN/IPSec
Standards Standard-conform IPSec with ESP (Encapsulation Security Payload) and/or AH (Authentication Header)
Encryption 3-DES (168 bit), AES (128, 192 or 256 bit), Blowfish (128 bit), RSA (1024 or 2048 bit)
Hashes MD-5, SHA-1, SHA-256, SHA-384 and SHA-512
IKE operating modes IKE with pre/shared keys or certificates, IKE Main or Aggressive Mode, DH groups 1, 2, 5 and 14. Re-keying after adjustable
transfer volumes or time. In combination with LANCOM VPN remote sites, an IKE extension enables separate pre-shared
keys to be used for each user in Aggressive Mode as well.
Additional functions
IPsec Path Finder SSL encapsulation for IPsec in TCP (Port 443 as HTTPS) to overcome VPN filter (e.g. port 500 blocking for IKE)
X.auth For authentication by username/password
IKE config mode For assignment of IP parameters (local IP address, DNS and WINS server) to the client
IPCOMP IPCOMP data compression (LZS) for optimal bandwidth exploitation
dead-peer detection (DPD) Dead-peer detection (DPD) for connection monitoring
NAT-Traversal NAT-Traversal (NAT-T) to overcome routers not capable of IPSec masking, or when using AH
RAS user template Configuration of all VPN client connections in IKE ConfigMode via a single entry in the LANCOM VPN gateway
EAP-MD5 For extended authentication of layer-2 devices such as switches or WLAN access points
PKI
Certificates Public Key Infrastructure according to X.509v3, PKCS#11, PKCS#12 Support
Certificate extension Control of, and notice about, a certificate’s validity period
Certificate revocation lists (CRL) Control of the CRL and ARL (Certificate and/or Authority Revocation List)
One-Time Password Convenient entry through separated PIN and password
Firewall
Stateful inspection, direction-dependant packet filter with IP- and port ranges per protocol, LAN-adapter protection
to protect PCs with active VPN connections from attacks from other LAN users, IP broadcast and NetBIOS/IP filter
Installation
Wizards Tailor-made Setup Wizards are available for all types of connection
Administration
Password protection Password protection for configuration and profile management, configuration rights can be defined for each function area,
display/hide parameter fields
Activation
Online/offline activation After installation, the software will function for a period of 30 days*.
Activation must take place within these 30 days. This can be conducted either directly online (requiring Internet access from
the corresponding Mac) or offline (requiring Internet access from any other Mac). Activation is anonymous. No user-specific
data of any kind is transmitted.