The Key Server device is responsible for creating the GET VPN control plane and define the encryption policy as well. It serves a very critical function. You should look to get at least one or possibly redundant Key Servers on your network. I followed this document during my deployment and it was very useful