双机热备NAT配置 - 防火墙6000
拓扑图:

FW1(不含接口IP地址配置):
安全区域配置
firewall zone trust
add interface GigabitEthernet1/0/1
#
firewall zone untrust
add interface GigabitEthernet1/0/2
#
firewall zone dmz
add interface GigabitEthernet1/0/6
安全策略
security-policy
rule name Trust_Untrust_all_permit
source-zone trust untrust
destination-zone untrust trust
service icmp
action permit
rule name heart_line_permit
source-zone local dmz
destination-zone dmz local
action permit
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.1.1.254 active
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.1.1.254 active
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6 remote 100.1.1.2
hrp mirror session enable
hrp preempt
创建NAT 地址池
nat address-group outip 0
mode no-pat global
vrrp 2 //vrrp vrid 2(该地址池分配给VRRP虚拟路由器标识2使用)
section 0 20.1.1.10 20.1.1.20
NAT策略
nat-policy
rule name vrrp2
source-zone trust
destination-zone untrust
action nat address-group outip
FW2(关键配置)
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.1.1.254 standby
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.1.1.254 standby
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6 remote 100.1.1.1
hrp mirror session enable
hrp preempt
业务信息查询
FW1:
display vrrp brief
Total:2 Master:2 Backup:0 Non-active:0
VRID State Interface Type Virtual IP
----------------------------------------------------------------
1 Master GE1/0/1 Vgmp 10.1.1.254
2 Master GE1/0/2 Vgmp 20.1.1.254
display vrrp
GigabitEthernet1/0/1 | Virtual Router 1
State : Master
Virtual IP : 10.1.1.254
Master IP : 10.1.1.101
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2020-07-04 07:26:11
Last change time : 2020-07-04 07:55:30
GigabitEthernet1/0/2 | Virtual Router 2
State : Master
Virtual IP : 20.1.1.254
Master IP : 20.1.1.101
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0102
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2020-07-04 07:26:11
Last change time : 2020-07-04 07:55:31
FW2:
display vrrp brief
Total:2 Master:0 Backup:2 Non-active:0
VRID State Interface Type Virtual IP
----------------------------------------------------------------
1 Backup GE1/0/1 Vgmp 10.1.1.254
2 Backup GE1/0/2 Vgmp 20.1.1.254
display vrrp
GigabitEthernet1/0/1 | Virtual Router 1
State : Backup
Virtual IP : 10.1.1.254
Master IP : 10.1.1.101
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0101
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2020-07-04 07:26:51
Last change time : 2020-07-04 07:55:31
GigabitEthernet1/0/2 | Virtual Router 2
State : Backup
Virtual IP : 20.1.1.254
Master IP : 20.1.1.101
PriorityRun : 120
PriorityConfig : 100
MasterPriority : 120
Preempt : YES Delay Time : 0 s
TimerRun : 60 s
TimerConfig : 60 s
Auth type : NONE
Virtual MAC : 0000-5e00-0102
Check TTL : YES
Config type : vgmp-vrrp
Backup-forward : disabled
Create time : 2020-07-04 07:26:52
Last change time : 2020-07-04 07:55:31
双机热备功能测试:
FW1上接口GigabitEthernet1/0/1主备切换测试

FW1由master切换至slave

FW1由slave切换至master

PC1 ping -t 测试


Wireshark抓包:
网络故障后,主备切换和NAT转换地址业务正常

双机热备NAT配置 - 防火墙5500
拓扑图:

FW3(不含接口IP地址配置):
安全区域配置
firewall zone trust
add interface GigabitEthernet0/0/1
#
firewall zone untrust
add interface GigabitEthernet0/0/2
#
firewall zone dmz
add interface GigabitEthernet0/0/6
安全策略
#
policy interzone trust untrust inbound
firewall default packet-filter is permit
#
policy interzone trust untrust outbound
firewall default packet-filter is permit
#
policy interzone local trust inbound
firewall default packet-filter is permit
#
policy interzone local trust outbound
firewall default packet-filter is permit
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.2.1.254 master
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.2.1.254 master
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6
hrp mirror session enable
hrp preempt
创建NAT 地址池
防火墙5500不能指定VRRP VRID
nat address-group 1 20.2.1.10 20.2.1.20 vrrp master
NAT 策略
nat-policy interzone trust untrust outbound
policy 0
action source-nat
address-group 1 no-pat
FW4(关键配置)
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.2.1.254 slave
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.21.254 slave
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6 remote 100.2.1.1
hrp mirror session enable
hrp preempt

