实验拓扑图

需求分析
- 出口防火墙实现双机热备【难点】
- 无线AC实现双机热备【难点】
- 主校区和分校区配置IPSEC技术(主校区分校区防火墙双机热备模式下,配置IPSECVPPN技术)【难点】
- 内网流量负载分担(MSTP/VRRP)
- 整体实验主要考察高可靠性,主校区和分校区高可靠性技术,实验相对复杂,尤其在IPSEC技术以及无线AC双机热备技术,难度高,内存要求16G以上才可运行该实验
技术名词介绍
- 出口防火墙实现双机热备
- 无线AC实现双机热备
- 主校区和分校区配置IPSEC技术(主校区分校区防火墙双机热备模式下,配置IPSECVPPN技术)
- 内网流量负载分担(MSTP/VRRP)
- 整体实验主要考察高可靠性,主校区和分校区高可靠性技术,实验相对复杂,尤其在IPSEC技术以及无线AC双机热备技术,难度高,内存要求16G以上才可运行该实验
重难点技术配置
防火墙双机热备配置
[FW_A] hrp interface GigabitEthernet 1/0/7 remote 10.10.0.2
[FW_A] hrp enable
[FW_A] hrp mirror session enable
[FW_A] hrp standby config enable
[FW_B] hrp interface GigabitEthernet 1/0/7 remote 10.10.0.1
[FW_B] hrp enable
[FW_B] hrp mirror session enable
[FW_B] hrp standby-device
[FW_B] hrp standby config enable
无线AC双机热备配置
在AC1上配置VRRP方式的双机热备份
[AC1] vrrp recover-delay 60
[AC1] interface vlanif 100
[AC1-Vlanif100] vrrp vrid 1 virtual-ip 10.23.100.3
[AC1-Vlanif100] vrrp vrid 1 priority 120
[AC1-Vlanif100] vrrp vrid 1 preempt-mode timer delay 1800
[AC1-Vlanif100] admin-vrrp vrid 1
[AC1-Vlanif100] quit
[AC1] hsb-service 0
[AC1-hsb-service-0] service-ip-port local-ip 10.23.102.1 peer-ip 10.23.102.2 local-data-port 10241 peer-data-port 10241
[AC1-hsb-service-0] service-keep-alive detect retransmit 3 interval 6
[AC1-hsb-service-0] quit
[AC1] hsb-group 0
[AC1-hsb-group-0] bind-service 0
[AC1-hsb-group-0] track vrrp vrid 1 interface vlanif 100
[AC1-hsb-group-0] quit
[AC1] hsb-service-type access-user hsb-group 0
[AC1] hsb-service-type ap hsb-group 0
[AC1] hsb-service-type dhcp hsb-group 0
[AC1] hsb-group 0
[AC1-hsb-group-0] hsb enable
[AC1-hsb-group-0] quit
在AC2上配置VRRP方式的双机热备份
[AC2] vrrp recover-delay 60
[AC2] interface vlanif 100
[AC2-Vlanif100] vrrp vrid 1 virtual-ip 10.23.100.3
[AC2-Vlanif100] admin-vrrp vrid 1
[AC2-Vlanif100] quit
[AC2] hsb-service 0
[AC2-hsb-service-0] service-ip-port local-ip 10.23.102.2 peer-ip 10.23.102.1 local-data-port 10241 peer-data-port 10241
[AC2-hsb-service-0] service-keep-alive detect retransmit 3 interval 6
[AC2-hsb-service-0] quit
[AC2] hsb-group 0
[AC2-hsb-group-0] bind-service 0
[AC2-hsb-group-0] track vrrp vrid 1 interface vlanif 100
[AC2-hsb-group-0] quit
[AC2] hsb-service-type access-user hsb-group 0
[AC2] hsb-service-type ap hsb-group 0
[AC2] hsb-service-type dhcp hsb-group 0