Vrrp interface tracking configuration example, Network requirements, Configuration procedure – H3C Technologies H3C S10500 Series Switches User Manual
Page 152
143
VRRP interface tracking configuration example
Network requirements
•
Host A wants to access Host B on the Internet, using 202.38.160.111/24 as its default gateway.
•
Switch A and Switch B belong to VRRP group 1 with the virtual IP address of 202.38.160.111/24.
•
If Switch A operates normally, packets sent from Host A to Host B are forwarded by Switch A. If
VLAN-interface 3 through which Switch A connects to the Internet is not available, packets sent from
Host A to Host B are forwarded by Switch B.
•
To prevent attacks to the VRRP group from illegal users by using spoofed packets, configure the
authentication mode as plain text to authenticate the VRRP packets in VRRP group 1, and specify the
authentication key as hello.
Figure 38 Network diagram for VRRP interface tracking
Host A
Switch A
Switch B
Virtual IP address:
202.38.160.111/24
Vlan-int2
202.38.160.1/24
Vlan-int2
202.38.160.2/24
Host B
202.38.160.3/24
203.2.3.1/24
Vlan-int3
Internet
Configuration procedure
1.
Configure Switch A
# Configure VLAN 2.
[SwitchA] vlan 2
[SwitchA-vlan2] port gigabitethernet 1/0/5
[SwitchA-vlan2] quit
[SwitchA] interface vlan-interface 2
[SwitchA-Vlan-interface2] ip address 202.38.160.1 255.255.255.0
# Create a VRRP group 1 and set its virtual IP address to 202.38.160.111.
[SwitchA-Vlan-interface2] vrrp vrid 1 virtual-ip 202.38.160.111
# Configure the priority of Switch A in the VRRP group to 110, which is higher than that of Switch B (100),
so that Switch A can become the master.
[SwitchA-Vlan-interface2] vrrp vrid 1 priority 110
# Configure the authentication mode of the VRRP group as simple and authentication key as hello.
[SwitchA-Vlan-interface2] vrrp vrid 1 authentication-mode simple hello
# Set the interval for Master to send VRRP advertisement to four seconds.
[SwitchA-Vlan-interface2] vrrp vrid 1 timer advertise 4
- H3C S5800 Series Switches H3C S5820X Series Switches H3C WX3000E Series Wireless Switches H3C SecPath F1000-E H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS