双机热备基本组网
配置主备备份的双机热备,FW1为主用,FW2为备用
VRRP1的虚拟IP为10.1.1.253,VRRP2的虚拟IP为202.100.1.253
心跳接口需要配置remote参数
FW底层配置
sysname FW1
#
interface GigabitEthernet1/0/1
ip address 10.1.1.10 255.255.255.0
service-manage ping permit
#
interface GigabitEthernet1/0/0
ip address 202.100.1.10 255.255.255.0
service-manage ping permit
#
sysname FW2
#
interface GigabitEthernet1/0/1
ip address 10.1.1.11 255.255.255.0
service-manage ping permit
#
interface GigabitEthernet1/0/0
ip address 202.100.1.11 255.255.255.0
service-manage ping permit
配置心跳接口
FW1的心跳接口,安全区域可自定义
#
interface GigabitEthernet1/0/3
ip address 172.16.1.1 255.255.255.252
#
firewall zone dmz
add interface GigabitEthernet1/0/3
FW2的心跳接口,安全区域可自定义
#
interface GigabitEthernet1/0/3
ip address 172.16.1.2 255.255.255.252
#
firewall zone dmz
add interface GigabitEthernet1/0/3
FW1双机热备配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.1.1.253 active
#
interface GigabitEthernet1/0/0
vrrp vrid 1 virtual-ip 202.100.1.253 active
#
hrp interface GigabitEthernet1/0/3 remode 172.16.1.1
hrp enable
FW2双机热备配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.1.1.253 standby
#
interface GigabitEthernet1/0/0
vrrp vrid 1 virtual-ip 202.100.1.253 standby
#
hrp standby-device
hrp interface GigabitEthernet1/0/3 remode 172.16.1.1
hrp enable
FW1查看VRRP状态
HRP_M[FW1]dis vrrp
GigabitEthernet1/0/1 | Virtual Router 1
State : Master
Virtual IP : 10.1.1.253
Master IP : 10.1.1.10
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2021-03-29 02:46:48
Last change time : 2021-03-29 03:02:36
GigabitEthernet1/0/0 | Virtual Router 2
State : Master
Virtual IP : 202.100.1.253
Master IP : 202.100.1.10
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0102
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2021-03-29 02:47:13
Last change time : 2021-03-29 02:48:02
FW2查看VRRP状态
HRP_M[FW2]dis vrrp
GigabitEthernet1/0/1 | Virtual Router 1
State : Master
Virtual IP : 10.1.1.253
Master IP : 10.1.1.10
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2021-03-29 02:48:23
Last change time : 2021-03-29 02:49:45
GigabitEthernet1/0/0 | Virtual Router 2
State : Master
Virtual IP : 202.100.1.253
Master IP : 202.100.1.10
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0102
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2021-03-29 02:48:49
Last change time : 2021-03-29 02:49:45