Tunnel Endpoint Discovery
Tunnel Endpoint Discovery (TED) is a Cisco feature that improves the scalability and availability of IPsec VPNs by extending the capabilities of dynamic crypto maps. As mentioned in the preceding section, "Configuring Dynamic Crypto Maps," dynamic crypto maps greatly reduce your work by eliminating the configuration of specific IPsec peers. However, dynamic crypto maps (by default) are only receivers of IKE negotiation requests. That is, unlike regular crypto maps, they cannot initiate outbound SAs to remote peers—dynamic crypto maps rely on other peers to first contact them.
The listen-only behavior of dynamic crypto maps is acceptable in most access VPN environments where a central router accepts IKE requests from lots of dial-in users. However, in an intranet VPN environment, the listen-only approach isn't very useful because you want to give each peer the ability to initiate IKE with any other peer. This means you have to use regular, static crypto maps.
When you have a large intranet VPN—say over 20 or 30 routers—configuring static crypto maps to connect to all possible peers becomes laborious and difficult to manage. When it's time to add a new peer, you have to revisit all other peers and modify each configuration to accommodate the addition—that's a lot of work.
TED Improves IPsec Scalability
So here comes TEB: With TED, a dynamic crypto map can probe for and discover remote peers dynamicallyVWith TED, this means that a dynamic crypto map can be used to initiate SAs to multiple peers automatically, on demand, and with minimal configuration (the remote peers must also have TED enabled). Thus, many-to-many (mesh topology) peering is possible without a need to configure huge static crypto maps.
TED works by sending a probe packet and listening for a response to determine the other end of an IKE SA. When an outbound packet requires IPsec protection, TED dispatches a probe packet. The probe gets routed over the untrusted network toward the ultimate destination of the data until it reaches the remote, TED-cnabled peer. When the remote peer responds to the originator of the probe, the remote peer is "discovered" and the two devices establish an IKE SA. The rest of the IPsec process then continues as usual.
TIP TED is handy when you're deploying backup peers for high-availability VPNs. If the remote peer goes down, TED will dynamically discover a new remote peer (assuming you deployed one as a backup). When you add a backup peer, you do not have to reconfigure the other routers in the network—the new backup is automatically discovered by TED.
Configuring TED
To enable TED, you simply configure dynamic crypto maps as described in the preceding section, "Configuring Dynamic Crypto Maps," and add the keyword discover to the crypto map ipsec-isakmp dynamic command. The following is an example:
crypto dynamic-map DYN-TED-MAP 20 match address 101
set transform-set TRANS-ESP TRANS AH-ESP
crypto map MYMAP 500 ipsec-isakmp dynamic DYN-TED-MAP discover
interface Serial1 ip address 192.168.1.1 255.255.255.0 crypto map MYMAP
The preceding TED-enabled configuration is syntactically the same as the configuration for dynamic crypto maps except the keyword discover is appended to the crypto map entTy.
NOTE EPsec in IOS releases before 12.0(5)T and 12.0(5)XE do not support TED.

Post a comment