Trying to figure out how to easily and securely deploy a few hundred VPN routers for your home office or small office users? Cisco’s ECT solution might be for you. Cisco Enterprise Class Teleworker (ECT) VPN solution is ideal for businesses that rely, or would like to rely, on having a large work from home staff. ECT is for those that have outgrown the capabilities a client based VPN solution offers and require a dedicated home VPN router, like a Cisco 871w. This solution provides home users with almost all of the network services they would receive if they were at the office. It allows for having an IP phone at home, corporate managed secure wireless access at your home, QoS on your home LAN, and advanced security features like FW and IPS. The ECT solution is popular with businesses that have call centers and want the flexibility of having their agents work from home anywhere in the world. Traditionally the way a large roll-out of client VPN routers is done is having the IT staff pre-configure each individual client VPN router first and then ship it out to the end user for installation. This process is very manpower intensive. Cisco’s ECT solution changes the game. One of the beauties of this solution is once the ECT framework is in place at the central site an off the shelf, factory default, remote client router will be automatically provisioned/configured on the fly by the ECT system. Cisco calls it a zero-touch deployment method, meaning the client VPN router is shipped directly to the end-user with a factory default configuration and never touched by an IT guy at HQ. The end-user plugs in the router to their internet connection, opens a web browser, enters a couple urls, authenticates, and poof the ECT system configures their router auto-magically. No changes are necessary on the head-end VPN router. Sweet! The ECT solution is usually deployed using Dynamic Multipoint VPN (DMVPN) technology. DMVPN greatly simplifies site-to-site VPN configuration and is ideal for dynamically addressed client routers and for IP telephony. From a provisioning stand-point, ECT makes things quick and easy. When a new user requests to work from home the IT folks will do the following:
- create a user account in AAA for the new user
- create a user account in AAA for the new VPN device
- Clone the client VPN template to create the new devices config. This is a one click operation
- Change two config object variables on the clones device. One defines what the inside ip address should be on the new client vpn router should be. The other defines what the inside IP subnet is on the client vpn router
- Save your changes and your done!
The new configuration file is tied to the user’s username so itwaits at HQ for the new router to request it. This happens when the user enters a url in their browser at home from a PC behind their shiny new, factory default Cisco router. They are then prompted to authenticate and BAM! the configuration for their specific router is sucked down from HQ. Here is a diagram of the solution: [img=450×350]http://www.jheary.com/ect1.gif[/img]
For more information on Cisco’s ECT solution see here: http://www.cisco.com/en/US/partner/products/ps6660/products_ios_protocol_group_home.html For detailed whitepapers on the solution see here: http://www.cisco.com/en/US/products/ps6660/prod_white_papers_list.html For info on the various layered security mechanisms ECT provides see here: http://www.cisco.com/en/US/products/ps6660/products_white_paper0900aecd8046cbc4.shtml So what do you think of ECT? If you have any questions about the solution feel free to ask. The opinions and information presented here are my personal views not those of my employeer.




