DPtech FW1000 Series Firewall Products User Configuration Guide
12-254
Figure12-2
VRRP configuration
Table12-1 describes the configuration items of VRRP.
Table12-1
VRRP configuration items
Item
Description
VRID
Virtual router identification. A virtual router consists of a group of routers with same
VRID.
Virtual IP
Virtual IP address: virtual router IP address. A virtual router has one or
several IP addresses.
Interface
Configure VRRP backup group interface, example
:
eth0_7.
Authentication mode
Allows you to select an authentication method, including
None, simple text and MD5
.
None authentication: No authentication is performed for any VRRP packet, without
security guarantee.
Simple text authentication: You can adopt the simple text authentication mode in a
network facing possible security problems. A router sending a VRRP packet fills an
authentication key into the packet, and the router receiving the packet compares its
local authentication key with that of the received packet. If the two authentication
keys are the same, the received VRRP packet is considered valid; otherwise, the
received packet is considered an invalid one.
MD5 authentication: You can adopt MD5 authentication in a network facing severe
security problems. The router encrypts a VRRP packet to be sent using the
authentication key and MD5 algorithm and saves the encrypted packet in the
authentication header. The router receiving the packet uses the authentication key
to decrypt the packet and checks whether the validity of the packet.
Advanced configuration
1.Configure elect parameter:
Priority: VRRP determines the role (master or backup) of each router in a virtual
router by priority.
Hello interval: Configure Hello packet time interval.
Non-preemptive mode: the backup working in non-preemptive mode remains as a
backup as long as the master does not fail. The backup will not become the master
even if the former is configured with a higher priority.
Preemptive mode: the backup working in preemptive mode compares the priority
in the packet with that of its own when a backup receives a VRRP advertisement. If
its priority is higher than that of the master if preempts as the master; otherwise, it
remains a backup.