Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
124
Redundant Firewalls
213455-L, October 2005
Real Router IP addresses.
The IP addresses you enter for
addr1
and
addr2
(
cfg/net/if
)
at the Interface Menu becomes the real router IP addresses. Other real
interface parameters including the port must be filled in as well.
Virtual Router IP addresses.
The
vrid
and virtual router addresses (
ip1
and
ip2
) are
defined at the VRRP Interface Menu (
cfg/net/if_#/vrrp/ip1
or
ip2
) on the same
interface as the virtual router interface. For more information about the VRRP Interface Menu,
see
page 330
.
The virtual router IP address and the sub-addresses must be unique, but all three
IP addresses must belong to the same subnet.
Advanced failover check
If Advanced Failover Check (AFC),
cfg/net/vrrp/afc
is enabled, the system ARPs
before initiating a failover caused by missed VRRP advertisements.
Preferred Master
The Preferred Master command,
cfg/net/vrrp/prefmaster
allows you to specify
which Switched Firewall in the cluster to be the VRRP Master. The preferred master always
remains active when it has equal or better priority. It goes into backup mode only when its
links are down and regains its position once the links are up.
The preferred master command is applicable only for active-standby failover, because in
active-active failover both Switched Firewalls handle the load.