当前位置:网站首页>H3C firewall rbm+vrrp networking configuration
H3C firewall rbm+vrrp networking configuration
2022-07-06 05:51:00 【Creator of high-quality network system】
The basic networking is as above , This experiment adopts HCL Simulator complete .fw1 And fw2 establish RBM, The uplink and downlink use vrrp docking .sw3、sw4 by 2 Layer switch , Be a firewall RBM When the connection is accidentally disconnected , It can be transmitted through the switch vrrp message , by vrrp Its own negotiation mechanism realizes active and standby . stay fw1、fw2 Both use vrrp 2 Virtual address of ipsec To configure , Under normal circumstances, the flow goes fw1, Only fw1 and fw6 establish ipsec sa, because RBM Not yet ipsec Synchronization of , So normally fw2 Don't fw6 build ipsec, When the active and standby switches, the traffic goes up fw2, The flow of interest is automatically triggered fw2 and fw6 establish ipsec Tunnel , At the same time as fw6 And the only vrrp Virtual address establishment connection , Can't feel fw1 and fw2 Switch between main and backup , So you need to configure dpd Keep alive detection , When the active and standby switch, the new one can be negotiated in time ike sa and ipsec sa.
Configuration steps
One 、fw1 Basic configuration :
Configure interface ip Address and vrrp Virtual address ,g1/0/10 To act as RBM Interface
interface GigabitEthernet1/0/1
port link-mode route
ip address 1.1.1.1 255.255.255.0
vrrp vrid 1 virtual-ip 1.1.1.3 active
interface GigabitEthernet1/0/2
port link-mode route
ip address 2.2.2.1 255.255.255.0
vrrp vrid 2 virtual-ip 2.2.2.3 active
interface GigabitEthernet1/0/10
port link-mode route
ip address 10.0.0.1 255.255.255.0
Interface plus security domain ,RBM The interface does not need to add a security domain , The device is released by default
security-zone name Trust
import interface GigabitEthernet1/0/1
security-zone name Untrust
import interface GigabitEthernet1/0/2
Configure static routing
ip route-static 10.10.10.0 24 1.1.1.100
ip route-static 172.16.10.0 24 2.2.2.10
To configure RBM, The device acts as the master management device , Main standby mode
remote-backup group
data-channel interface GigabitEthernet1/0/10
configuration sync-check interval 12
local-ip 10.0.0.1
remote-ip 10.0.0.2
device-role primary
Configure detailed security policies , Let go local and trust、untrust Between domains vrrp message
security-policy ip
rule 1 name 1
action pass
source-zone local
destination-zone trust
service vrrp
rule 2 name 2
action pass
source-zone trust
destination-zone local
service vrrp
rule 3 name 3
action pass
source-zone local
destination-zone untrust
service vrrp
rule 4 name 4
action pass
source-zone untrust
destination-zone local
service vrrp
边栏推荐
- Quantitative description of ANC noise reduction
- As3013 fire endurance test of cable distribution system
- 26file filter anonymous inner class and lambda optimization
- B站刘二大人-反向传播
- Deep learning -yolov5 introduction to actual combat click data set training
- Construction of yolox based on paste framework
- 27io stream, byte output stream, OutputStream writes data to file
- Database: ODBC remote access SQL Server2008 in oracel
- P2802 go home
- 嵌入式面试题(四、常见算法)
猜你喜欢
网络协议模型
清除浮动的方式
[experience] install Visio on win11
01. Project introduction of blog development project
Migrate Infones to stm32
B站刘二大人-Softmx分类器及MNIST实现-Lecture 9
移植InfoNES到STM32
Station B, Master Liu Er - dataset and data loading
The ECU of 21 Audi q5l 45tfsi brushes is upgraded to master special adjustment, and the horsepower is safely and stably increased to 305 horsepower
[force buckle]43 String multiplication
随机推荐
养了只小猫咪
应用安全系列之三十七:日志注入
Novice entry SCM must understand those things
Easy to understand IIC protocol explanation
[Tang Laoshi] C -- encapsulation: classes and objects
清除浮动的方式
Clear floating mode
B站刘二大人-Softmx分类器及MNIST实现-Lecture 9
What is independent IP and how about independent IP host?
PDK process library installation -csmc
Promise summary
How to use PHP string query function
Problems encountered in installing mysql8 on MAC
移植InfoNES到STM32
华为BFD的配置规范
[machine learning notes] univariate linear regression principle, formula and code implementation
Li Chuang EDA learning notes 12: common PCB board layout constraint principles
05. Security of blog project
B站刘二大人-反向传播
OSPF configuration command of Huawei equipment