CCNP ISCW Notes1 Apr 2008
Chapter 15: IPsec High Availability OptionsCommon Sources of Failure
IPsec Stateless FailoverIn a stateless failover configuration, routers do not directly track the status of tunnels. Dead Peer Detection (DPD)DPD can operate in either periodic mode or on-demand mode. Periodic mode:
On-demand mode (default):
DPD configuration:
IGP Within a GRE over IPsec TunnelAn IGP such as EIGRP or OSPF is run between peers, treating the tunnels like normal layer 3 links. HSRPHSRP is used on a pair of routers facing a peer, so that either will answer for the VPN peer address. The HSRP group on an interface must be designated as providing IPsec redundancy with the
IPsec Stateful FailoverStateful failover uses identical active and backup devices running HSRP and Stateful Switchover (SSO). Inside and outside interfaces on the devices must be LAN interfaces. Both modes of DPD (periodic and on-demand) are supported. The HSRP configuration of an interface is similar to the stateless configuration, but with the addition of SSO is enabled by specifying the HSRP group as follows: Inter-device Communication Protocol (IPC) facilitates inter-device communication: Stream Control Transmission Protocol (SCTP) is used as the transport protocol. Local and remote port numbers must match. |
Navigation
Armory
Online Toolbox
|
One of the best summary I have seen. It make life easier and time well spent. Good job. Gerard
nice work