This document provides an overview of IPSec router based encryption and discusses considerations for network design. It covers IPSec protocols including IKE, AH, and ESP. Platform throughput numbers are listed for Cisco routers. The document also discusses high availability and resiliency, noting that IPSec SAs can prevent underlying failover mechanisms from functioning if connectivity is lost. IKE keepalives are described as a way to detect lost connectivity but are not sufficient on their own for resilient network designs.