实验目标:pc1pint 通pc2,FW1(主墙)上的接口出现故障之后,可以切换到FW2(备墙)上。
配置步骤:
1.配置各接口IP(略)
2.防火墙接口区域规划
FW1:
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
add interface GigabitEthernet1/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet1/0/0
FW2:
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
add interface GigabitEthernet1/0/1
#
firewall zone untrust
set priority 5
add interface GigabitEthernet1/0/0
3.接口配置vrrp
FW1:
interface GigabitEthernet0/0/0
undo shutdown
undo ip binding vpn-instance default
ip address 192.168.0.1 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.0.254 active
#
interface GigabitEthernet1/0/0
undo shutdown
ip address 172.16.0.1 255.255.255.0
vrrp vrid 2 virtual-ip 172.16.0.254 active
FW2:
interface GigabitEthernet0/0/0
undo shutdown
undo ip binding vpn-instance default
ip address 192.168.0.2 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.0.254 stanby
#
interface GigabitEthernet1/0/0
undo shutdown
ip address 172.16.0.2 255.255.255.0
vrrp vrid 2 virtual-ip 172.16.0.254 stanby
4.配置HRP
FW1:
hrp enable
hrp interface GigabitEthernet1/0/1 remote 12.1.1.2
FW2:
hrp enable
hrp interface GigabitEthernet1/0/1 remote 12.1.1.1
配置完成之后主墙显示:HRP_M[FW1] ;备墙显示:HRP_S[FW2]
5.配置策略(只需要在HRP_M上配置,且同步到备墙)
HRP_M[FW1]:
security-policy
rule name 1
source-zone trust
destination-zone untrust
action permit
6.查看vrrp状态
7.手动切换主备
hrp switch active/hrp seitch standby
8.检验pc1ping pc2;关闭FW1 g0/0/0口(略)