拓扑图:

防火墙6000配置
FW1(不含接口IP地址配置):
安全区域配置
firewall zone trust
add interface GigabitEthernet1/0/1
#
firewall zone untrust
add interface GigabitEthernet1/0/2
#
firewall zone dmz
add interface GigabitEthernet1/0/6
安全策略
security-policy
rule name Trust_Untrust_all_permit
source-zone trust untrust
destination-zone untrust trust
service icmp
action permit
rule name heart_line_permit
source-zone local dmz
destination-zone dmz local
action permit
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.1.1.254 active
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.1.1.254 active
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6 remote 100.1.1.2
hrp auto-sync(启用命令与状态信息的自动备份)
hrp mirror session enable(快速会话备份开启)
hrp preempt (抢位功能开启)
FW2(关键配置)
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.1.1.254 standby
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.1.1.254 standby
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6 remote 100.1.1.1
防火墙5000配置
拓扑图:

FW3(不含接口IP地址配置):
安全区域配置
firewall zone trust
add interface GigabitEthernet0/0/1
#
firewall zone untrust
add interface GigabitEthernet0/0/2
#
firewall zone dmz
add interface GigabitEthernet0/0/6
安全策略
#
policy interzone trust untrust inbound
firewall default packet-filter is permit
#
policy interzone trust untrust outbound
firewall default packet-filter is permit
#
policy interzone local trust inbound
firewall default packet-filter is permit
#
policy interzone local trust outbound
firewall default packet-filter is permit
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.2.1.254 master
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.2.1.254 master
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6
hrp auto-sync(启用命令与状态信息的自动备份)
hrp mirror session enable(快速会话备份开启)
hrp preempt (抢位功能开启)
FW4(关键配置)
VRRP/VGMP配置
interface GigabitEthernet1/0/1
vrrp vrid 1 virtual-ip 10.2.1.254 slave
vrrp virtual-mac enable
#
interface GigabitEthernet1/0/2
vrrp vrid 2 virtual-ip 20.21.254 slave
vrrp virtual-mac enable
HRP配置
hrp enable
hrp interface GigabitEthernet1/0/6 remote 100.2.1.1

