双机热备特指基于高可用系统中的两台服务器的热备(或高可用),因两机高可用在国内使用较多,故得名双机热备,双机高可用按工作中的切换方式分为:主-备方式(Active-Standby方式)和双主机方式(Active-Active方式),主-备方式即指的是一台服务器处于某种业务的激活状态(即Active状态),另一台服务器处于该业务的备用状态(即Standby状态)。而双主机方式即指两种不同业务分别在两台服务器上互为主备状态(即Active-Standby和Standby-Active状态)。
PC1
PC2
进入HRP
hrp enable
hrp interface GigabitEthernet1/0/1 remote 100.1.1.2
FW1(先配防火墙接口地址,vrrp备份)
interface GigabitEthernet1/0/0
undo shutdown
ip address 192.168.1.100 255.255.255.0
vrrp vrid 1 virtual-ip 192.168.1.254 active
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
#
interface GigabitEthernet1/0/1
undo shutdown
ip address 100.1.1.1 255.255.255.0
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
#
interface GigabitEthernet1/0/2
undo shutdown
ip address 172.16.1.100 255.255.255.0
vrrp vrid 2 virtual-ip 172.16.1.254 active
service-manage http permit
service-manage https permit
service-manage ping permit
service-manage ssh permit
service-manage snmp permit
service-manage telnet permit
FW1(接口加入各安全区域)
#
firewall zone trust
set priority 85
add interface GigabitEthernet0/0/0
add interface GigabitEthernet1/0/0
#
firewall zone untrust
set priority 5
add interface GigabitEthernet1/0/2
#
firewall zone dmz
set priority 50
add interface GigabitEthernet1/0/1
安全区域(FW2不用配,如果FW1宕掉,自动会传给FW2)
security-policy
rule name t-u
source-zone trust
destination-zone untrust
action permit
默认路由、
ip route-static 0.0.0.0 0.0.0.0 172.16.1.1
FW2配置与FW1类似,只是需要把active改成standby 。
查看两个防火墙的会话表
fw1
FW2
PC1长pingPC2
当宕掉FW1,会有短暂的丢包,立刻恢复正常