Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
118
Redundant Firewalls
213455-L, October 2005
VRRP on the Switched Firewall
This section describes Virtual Router Redundancy Protocol (VRRP) concepts and how VRRP
is implemented on the Switched Firewall with respect to the VRRP parameters that you must
configure.
VRRP overview on page 118
Switched Firewall cluster on page 118
Active master determination on page 119
VRRP router parameters on page 122
VRRP overview
The Virtual Router Redundancy Protocol (VRRP) defined by RFC 2338 eliminates single
point of failure by dynamically assigning responsibility for a
virtual router
to one of the
physical (VRRP) routers on a LAN. The advantage VRRP provides is a higher availability
default path without requiring configuration of dynamic routing or router discovery protocols
on every end-host.
N
OTE
–
VRRP on the Nortel Switched Firewall is a custom implementation that deviates from
RFC 2338 in some details.
The VRRP router controlling the IP addresses associated with the virtual router is called the
active master, and it forwards packets intended for these IP addresses. If the active master
becomes unavailable, VRRP provides dynamic failover in the forwarding responsibility to a
redundant VRRP router. This lets the end-hosts use the virtual router IP addresses as the
default first hop router, regardless of which VRRP router is active.
Two firewalls in a VRRP configuration communicate using VRRP packets. The purpose of the
VRRP packet is to communicate the state of the active firewall. VRRP packets are
encapsulated in IP packets that are sent to the multicast group address (224.0.0.18) assigned to
VRRP.
NSF 2.3.3 high-availability solution is supported in an OSPF network.
Switched Firewall cluster
Only two Switched Firewalls can be in a cluster. A cluster is created when a second Switched
Firewall is added to the first using the
join
command. The
join
command is accessed from
the Setup Menu, which appears when you first turn on the firewall that has not been configured