防火墙旁挂、和热备

旁挂

拓扑

防火墙配置

interface GigabitEthernet0/0/0
 undo shutdown
 ip binding vpn-instance default
 ip address 172.25.254.2 255.255.255.0
 alias GE0/METH
 service-manage http permit
 service-manage https permit
 service-manage ping permit
 service-manage ssh permit
 service-manage snmp permit
 service-manage telnet permit
#
interface GigabitEthernet1/0/0
 undo shutdown
 ip address 192.168.1.6 255.255.255.252
#
interface GigabitEthernet1/0/1
 undo shutdown
 ip address 192.168.2.6 255.255.255.252

ip route-static 0.0.0.0 0.0.0.0 GigabitEthernet1/0/0 192.168.1.5
ip route-static 192.168.3.1 255.255.255.255 GigabitEthernet1/0/1 192.168.2.5

策略

r1

interface GigabitEthernet0/0/0
 ip address 192.168.1.1 255.255.255.252 
#
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255 
#
ip route-static 192.168.3.1 255.255.255.255 192.168.1.2

r2


ip vpn-instance r1
 ipv4-family
  route-distinguisher 1:1
  vpn-target 1:1 export-extcommunity
  vpn-target 1:1 import-extcommunity
#
ip vpn-instance r3
 ipv4-family
  route-distinguisher 2:2
  vpn-target 2:2 export-extcommunity
  vpn-target 2:2 import-extcommunity
#
interface GigabitEthernet0/0/0
 ip binding vpn-instance r1
 ip address 192.168.1.5 255.255.255.252 
#
interface GigabitEthernet0/0/1
 ip binding vpn-instance r3
 ip address 192.168.2.5 255.255.255.252 
#
interface GigabitEthernet0/0/2
 ip binding vpn-instance r1
 ip address 192.168.1.2 255.255.255.252 
#
interface GigabitEthernet4/0/0
 ip binding vpn-instance r3
 ip address 192.168.2.2 255.255.255.252 
#
interface NULL0
#
ip route-static vpn-instance r1 1.1.1.1 255.255.255.255 192.168.1.1
ip route-static vpn-instance r1 192.168.3.1 255.255.255.255 192.168.1.6
ip route-static vpn-instance r1 192.168.3.1 255.255.255.255 vpn-instance r3 192.
168.2.1 preference 100
ip route-static vpn-instance r3 1.1.1.1 255.255.255.255 192.168.2.6
ip route-static vpn-instance r3 1.1.1.1 255.255.255.255 vpn-instance r1 192.168.
1.1 preference 100
ip route-static vpn-instance r3 192.168.3.1 255.255.255.255 192.168.2.1

r3

interface GigabitEthernet0/0/0
 ip address 192.168.2.1 255.255.255.252 
#
interface LoopBack0
 ip address 192.168.3.1 255.255.255.255 
#
ip route-static 0.0.0.0 0.0.0.0 192.168.2.2

结果

热备

拓扑

r1

interface GigabitEthernet0/0/0
 ip address 12.1.1.1 255.255.255.0 
#
interface LoopBack0
 ip address 1.1.1.1 255.255.255.255 
#
ip route-static 192.168.2.1 255.255.255.255 12.1.1.2
ip route-static 192.168.2.1 255.255.255.255 12.1.1.3
 

r2

interface GigabitEthernet0/0/0
 ip address 192.168.1.1 255.255.255.0 
#
interface LoopBack0
 ip address 192.168.2.1 255.255.255.255 
#
ip route-static 1.1.1.1 255.255.255.255 192.168.1.2
ip route-static 1.1.1.1 255.255.255.255 192.168.1.3

FW3

 interface GigabitEthernet0/0/0
  undo shutdown
  ip binding vpn-instance default
  ip address 172.25.254.2 255.255.255.0
  alias GE0/METH
  service-manage http permit
  service-manage https permit
  service-manage ping permit
  service-manage ssh permit
  service-manage snmp permit
  service-manage telnet permit
 #
 interface GigabitEthernet1/0/0
  undo shutdown
  ip address 12.1.1.3 255.255.255.0
  vrrp vrid 1 virtual-ip 12.1.1.4 active
  vrrp virtual-mac enable
 #
 interface GigabitEthernet1/0/1
  undo shutdown
  ip address 192.168.1.3 255.255.255.0
  vrrp vrid 2 virtual-ip 192.168.1.4 active
  vrrp virtual-mac enable
 #
 interface GigabitEthernet1/0/2
  undo shutdown
  ip address 192.168.3.2 255.255.255.0
 ip route-static 1.1.1.1 255.255.255.255 12.1.1.1
 ip route-static 192.168.2.1 255.255.255.255 192.168.1.1

 

FW4

interface GigabitEthernet0/0/0
  undo shutdown
  ip binding vpn-instance default
  ip address 169.254.225.250 255.255.255.0
  alias GE0/METH
  service-manage http permit
  service-manage https permit
  service-manage ping permit
  service-manage ssh permit
  service-manage snmp permit
  service-manage telnet permit
 #
 interface GigabitEthernet1/0/0
  undo shutdown
  ip address 12.1.1.2 255.255.255.0
  vrrp vrid 1 virtual-ip 12.1.1.4 standby
  vrrp virtual-mac enable
 #
 interface GigabitEthernet1/0/1
  undo shutdown
  ip address 192.168.1.2 255.255.255.0
  vrrp vrid 2 virtual-ip 192.168.1.4 standby
  vrrp virtual-mac enable
#
 interface GigabitEthernet1/0/2
  undo shutdown
  ip address 192.168.3.1 255.255.255.0
#
  ip route-static 1.1.1.1 255.255.255.255 12.1.1.1
 ip route-static 192.168.2.1 255.255.255.255 192.168.1.1

结果

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值