cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
481
Views
0
Helpful
2
Replies

GET VPN question:Key Server and latency consideration

news2010a
Level 3
Level 3

Hi, imagine that for redundancy reasons, I want to setup a Key Server in California and another Key Server in Hong Kong.


Is there any latency issue to be aware when deploying Key Servers far away from each other?

http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6635/ps7180/deployment_guide_c07_554713.html

1 Accepted Solution

Accepted Solutions

Collin Clark
VIP Alumni
VIP Alumni

I don't think so. The 2 key servers have a secure tunnel between each other so if there is a problem you should see it with that tunnel. The key servers don't provide any latency sensitive information that I have seen.

View solution in original post

2 Replies 2

Collin Clark
VIP Alumni
VIP Alumni

I don't think so. The 2 key servers have a secure tunnel between each other so if there is a problem you should see it with that tunnel. The key servers don't provide any latency sensitive information that I have seen.

Hi,

Minor correction here, with GETVPN the pseudo-time passed between the Key Servers is time sensitive, since it doesn't use a wall clock (eg., ntp) as a time reference. The pseudo-time will be exchanged during the KS election, and will later be used for both data and control plane time-based anti-replay. For the most part, the inaccuracy in pseudo-time due to latency is negligible (1 sec is a loooong time in networking ), so you shouldn't have to worry about it with any reasonable anti-replay threshold configured.

Thanks,

Wen