RBM主备模式中shutdown 主防火墙或者备防火墙联动组中的任意一个track口。都会导致两台防火墙的所有track口down掉。
比如FW1中1/0/1和1/0/2为联动组,FW2中1/0/1和1/0/2为联动组,shutdown FW1de 1/0/1后会导致FW1 1/0/2和FW2的1/0/1和1/0/2也down。
(0)
冗余口,冗余组嘛
(0)
冗余组是单台设备内部的啊大哥。
有具体配置嘛
(1)FW主 配置track口: track 1 interface GigabitEthernet1/0/22 track 2 interface Ten-GigabitEthernet1/0/12 配置联动组: collaboration-group 1 配置Loopback地址: interface LoopBack0 ip address 192.168.100.1 255.255.255.0 quit 配置ospf router id 192.168.100.1 ospf 1 default-route-advertise always import-route static area 0.0.0.0 network 192.168.100.1 0.0.0.0 network 10.94.12.161 0.0.0.3 quit # 端口地址配置 interface Route-Aggregation1 description RBM ip address 1.1.1.5 255.255.255.252 quit # interface GigabitEthernet1/0/22 description to9508 ip address 10.94.12.161 255.255.255.252 port collaboration-group 1 quit # interface GigabitEthernet1/0/4 port link-mode route port link-aggregation group 1 quit # interface GigabitEthernet1/0/5 port link-mode route port link-aggregation group 1 quit # interface Ten-GigabitEthernet1/0/12 port link-mode route description TO 1002A ip address 10.94.12.170 255.255.255.252 port collaboration-group 1 quit # BFD配置: interface GigabitEthernet1/0/22 ospf bfd enable bfd min-transmit-interval 100 bfd min-receive-interval 100 bfd detect-multiplier 3 quit 配置安全域: security-zone name Trust import interface ten-GigabitEthernet1/0/14 import interface GigabitEthernet1/0/22 # security-zone name Untrust import interface Ten-GigabitEthernet1/0/15 import interface GigabitEthernet1/0/12 # security-zone name RBM import interface Route-Aggregation1 # 配置安全策略 security-policy ip rule 0 name ANY action pass logging enable profile 0_IPv4 quit # security-policy ip rule name ospf1 source-zone trust destination-zone local service ospf action pass quit # security-policy ip rule name ospf2 source-zone local destination-zone trust service ospf action pass quit # security-policy ip rule name ospf3 source-zone untrust destination-zone local service ospf action pass quit # security-policy ip rule name ospf4 source-zone local destination-zone untrust service ospf action pass quit # security-policy ip rule name vrrp1 source-zone trust destination-zone local service vrrp action pass quit # security-policy ip rule name vrrp2 source-zone local destination-zone trust service vrrp action pass quit # security-policy ip rule name vrrp3 source-zone untrust destination-zone local service vrrp action pass quit # security-policy ip rule name vrrp4 source-zone local destination-zone untrust service vrrp action pass quit # quit # 配置用户服务: ssh server enable # local-user weihu class manage password hash ***.***@123 service-type ssh terminal https authorization-attribute user-role level-3 authorization-attribute user-role network-admin authorization-attribute user-role network-operator # ip https enable # 配置RBM: remote-backup group data-channel interface Route-Aggregation1 configuration sync-check interval 12 configuration auto-sync enable undo backup-mode hot-backup enable adjust-cost ospf enable absolute 6000 track 1 track 2 local-ip 1.1.1.5 remote-ip 1.1.1.6 device-role primary # (2)FW备 配置track口 track 1 interface GigabitEthernet1/0/22 track 2 interface GigabitEthernet1/0/12 配置OSPF router id 192.168.100.2 ospf 1 default-route-advertise always import-route static area 0.0.0.0 network 192.168.100.2 0.0.0.0 network 10.94.12.165 0.0.0.3 quit 配置联动组 collaboration-group 1 配置端口IP地址 interface Route-Aggregation1 description RBM ip address 1.1.1.6 255.255.255.252 quit # interface GigabitEthernet1/0/22 description to9508B ip address 10.94.12.165 255.255.255.252 port collaboration-group 1 quit # interface LoopBack0 ip address 192.168.100.2 255.255.255.252 quit # interface GigabitEthernet1/0/4 port link-mode route port link-aggregation group 1 quit # interface GigabitEthernet1/0/5 port link-mode route port link-aggregation group 1 quit # Interface GigabitEthernet1/0/12 port link-mode route description to1002B ip address 10.94.12.174 255.255.255.252 port collaboration-group 1 quit # BFD配置: interface GigabitEthernet1/0/22 ospf bfd enable bfd min-transmit-interval 100 bfd min-receive-interval 100 bfd detect-multiplier 3 quit 配置安全域: security-zone name Trust import interface GigabitEthernet1/0/2 import interface GigabitEthernet1/0/22 quit # security-zone name Untrust import interface GigabitEthernet1/0/1 import interface GigabitEthernet1/0/12 quit # security-zone name RBM import interface Route-Aggregation1 quit 配置用户服务: ssh server enable # local-user weihu class manage password hash ***.***@123 service-type ssh terminal https authorization-attribute user-role level-3 authorization-attribute user-role network-admin authorization-attribute user-role network-operator quit # ip https enable 配置安全策略: security-policy ip rule 0 name ANY action pass logging enable profile 0_IPv4 quit # security-policy ip rule name ospf1 source-zone trust destination-zone local service ospf action pass quit # security-policy ip rule name ospf2 source-zone local destination-zone trust service ospf action pass quit # security-policy ip rule name ospf3 source-zone untrust destination-zone local service ospf action pass quit # security-policy ip rule name ospf4 source-zone local destination-zone untrust service ospf action pass quit # security-policy ip rule name vrrp1 source-zone trust destination-zone local service vrrp action pass quit # security-policy ip rule name vrrp2 source-zone local destination-zone trust service vrrp action pass quit # security-policy ip rule name vrrp3 source-zone untrust destination-zone local service vrrp action pass quit # security-policy ip rule name vrrp4 source-zone local destination-zone untrust service vrrp action pass quit 配置RBM: remote-backup group data-channel interface Route-Aggregation1 configuration sync-check interval 12 configuration auto-sync enable undo backup-mode hot-backup enable adjust-cost ospf enable absolute 6000 track 1 track 2 local-ip 1.1.1.6 remote-ip 1.1.1.5 device-role secondary
这个配置看的眼花
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
这个配置看的眼花