当前位置:网站首页>H3C防火墙RBM+VRRP 组网配置
H3C防火墙RBM+VRRP 组网配置
2022-07-06 05:43:00 【优质网络系统领域创作者】
基本组网如上,本实验采用HCL模拟器完成。fw1与fw2建立RBM,上下行采用vrrp对接。sw3、sw4为2层交换机,当防火墙RBM连接意外断开时,可以通过交换机透传vrrp报文,靠vrrp自身的协商机制实现主备。在fw1、fw2均使用vrrp 2的虚地址进行ipsec配置,正常情况下流量走fw1,只有fw1和fw6建立ipsec sa,由于RBM还不支持ipsec的同步,因此正常情况下fw2不和fw6建ipsec,当主备切换时流量上到fw2,感兴趣流自动触发fw2和fw6建立ipsec隧道,同时由于fw6只和vrrp虚地址建立连接,无法感知到fw1和fw2的主备切换,因此需要配置dpd保活探测,当主备切换时能及时协商新的ike sa和ipsec sa。
配置步骤
一、fw1基本配置:
配置接口ip地址和vrrp虚地址,g1/0/10口作为RBM接口
interface GigabitEthernet1/0/1
port link-mode route
ip address 1.1.1.1 255.255.255.0
vrrp vrid 1 virtual-ip 1.1.1.3 active
interface GigabitEthernet1/0/2
port link-mode route
ip address 2.2.2.1 255.255.255.0
vrrp vrid 2 virtual-ip 2.2.2.3 active
interface GigabitEthernet1/0/10
port link-mode route
ip address 10.0.0.1 255.255.255.0
接口加安全域,RBM接口不需加安全域,设备默认放通
security-zone name Trust
import interface GigabitEthernet1/0/1
security-zone name Untrust
import interface GigabitEthernet1/0/2
配置静态路由
ip route-static 10.10.10.0 24 1.1.1.100
ip route-static 172.16.10.0 24 2.2.2.10
配置RBM,设备作为主管理设备,主备模式
remote-backup group
data-channel interface GigabitEthernet1/0/10
configuration sync-check interval 12
local-ip 10.0.0.1
remote-ip 10.0.0.2
device-role primary
配置明细的安全策略,放通local和trust、untrust域之间的vrrp报文
security-policy ip
rule 1 name 1
action pass
source-zone local
destination-zone trust
service vrrp
rule 2 name 2
action pass
source-zone trust
destination-zone local
service vrrp
rule 3 name 3
action pass
source-zone local
destination-zone untrust
service vrrp
rule 4 name 4
action pass
source-zone untrust
destination-zone local
service vrrp
边栏推荐
- 初识CDN
- 网站进行服务器迁移前应做好哪些准备?
- 【经验】win11上安装visio
- 毕业设计游戏商城
- RustDesk 搭建一个自己的远程桌面中继服务器
- 改善Jpopup以实现动态控制disable
- PDK process library installation -csmc
- [SQL Server fast track] - authentication and establishment and management of user accounts
- What is independent IP and how about independent IP host?
- Zoom and pan image in Photoshop 2022
猜你喜欢
What impact will frequent job hopping have on your career?
28io stream, byte output stream writes multiple bytes
Vulhub vulnerability recurrence 69_ Tiki Wiki
Application Security Series 37: log injection
大型网站如何选择比较好的云主机服务商?
无代码六月大事件|2022无代码探索者大会即将召开;AI增强型无代码工具推出...
剑指 Offer II 039. 直方图最大矩形面积
[Jiudu OJ 07] folding basket
YYGH-11-定时统计
27io stream, byte output stream, OutputStream writes data to file
随机推荐
Station B, Master Liu Er - dataset and data loading
Promotion hung up! The leader said it wasn't my poor skills
[imgui] unity MenuItem shortcut key
05. 博客项目之安全
Station B Liu Erden softmx classifier and MNIST implementation -structure 9
01. Project introduction of blog development project
ArcGIS应用基础4 专题图的制作
Embedded interview questions (I: process and thread)
[email protected]树莓派
Promotion hung up! The leader said it wasn't my poor skills
网站进行服务器迁移前应做好哪些准备?
[detailed explanation of Huawei machine test] statistics of shooting competition results
巨杉数据库再次亮相金交会,共建数字经济新时代
Vulhub vulnerability recurrence 68_ ThinkPHP
改善Jpopup以实现动态控制disable
无代码六月大事件|2022无代码探索者大会即将召开;AI增强型无代码工具推出...
What is independent IP and how about independent IP host?
【华为机试真题详解】统计射击比赛成绩
Notes, continuation, escape and other symbols
数字经济破浪而来 ,LTD是权益独立的Web3.0网站?