
这种模式只能是主备备份模式,不能是负载分担,因为会有环路。
 故障切换是,如果主故障,主设备所有接口全都会down状态,然后再up一次,用于改变mac转发表。
FW1
hrp enable
 hrp interface GigabitEthernet1/0/2 remote 172.16.0.2
vlan 2
 port g1/0/0
 prot g1/0/1
 hrp track action
interface GigabitEthernet1/0/2
 undo shutdown
 ip address 172.16.0.1 255.255.255.0
firewall zone trust
 set priority 85
 add interface GigabitEthernet0/0/0
 add interface GigabitEthernet1/0/1
firewall zone untrust
 set priority 5
 add interface GigabitEthernet1/0/0
firewall zone dmz
 set priority 50
 add interface GigabitEthernet1/0/2
security-policy //暂时全允许
 default action permit
FW2:
hrp enable
 hrp interface GigabitEthernet1/0/2 remote 172.16.0.1
vlan 2
 port g1/0/0
 prot g1/0/1
 hrp track standby
interface GigabitEthernet1/0/2
 undo shutdown
 ip address 172.16.0.2 255.255.255.0
firewall zone trust
 set priority 85
 add interface GigabitEthernet0/0/0
 add interface GigabitEthernet1/0/1
firewall zone untrust
 set priority 5
 add interface GigabitEthernet1/0/0
firewall zone dmz
 set priority 50
 add interface GigabitEthernet1/0/2
security-policy
 default action permit
查看
 dis hrp state ver