19
2024
10
23:52:32

华为防火墙二层透明模式下双机热备负载分担配置(两端为路由器)

a511f16d59753ede988cebb97031368d_e61b3a936a784a53007af14f5038dc97.png

这种模式只做负载分担,不能是主备备份,因为主备备份模式下,备设备会把vlan down掉,如果是主备备份模式,那在主挂后,备的状态在切换过程中先起vlan,再建立ospf邻接,那业务会断线较久,不推荐这样做。

FW1

hrp enable

hrp interface GigabitEthernet1/0/2 remote 172.16.0.2

hrp mirror sessio enable //在负载分担模式下一般要开启快速会话备份功能


vlan 2

port g1/0/0

prot g1/0/1

hrp track action

hrp track standby


interface GigabitEthernet1/0/2

undo shutdown

ip address 172.16.0.1 255.255.255.0


firewall zone trust

set priority 85

add interface GigabitEthernet0/0/0

add interface GigabitEthernet1/0/1


firewall zone untrust

set priority 5

add interface GigabitEthernet1/0/0


firewall zone dmz

set priority 50

add interface GigabitEthernet1/0/2


security-policy //暂时全允许

default action permit


FW2:


hrp enable

hrp interface GigabitEthernet1/0/2 remote 172.16.0.1

hrp mirror sessio enable //在负载分担模式下一般要开启快速会话备份功能


vlan 2

port g1/0/0

prot g1/0/1

hrp track standby

hrp track action


interface GigabitEthernet1/0/2

undo shutdown

ip address 172.16.0.2 255.255.255.0


firewall zone trust

set priority 85

add interface GigabitEthernet0/0/0

add interface GigabitEthernet1/0/1


firewall zone untrust

set priority 5

add interface GigabitEthernet1/0/0


firewall zone dmz

set priority 50

add interface GigabitEthernet1/0/2


security-policy

default action permit


查看

dis hrp state ver





推荐本站淘宝优惠价购买喜欢的宝贝:

image.png

本文链接:https://hqyman.cn/post/8196.html 非本站原创文章欢迎转载,原创文章需保留本站地址!

分享到:
打赏





休息一下~~


« 上一篇 下一篇 »

发表评论:

◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。

请先 登录 再评论,若不是会员请先 注册

您的IP地址是: