Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
Redundant Firewalls
131
213455-L, October 2005
7.
Enable the failover type for the cluster.
or
N
OTE
–
If you are configuring active-active failover, then modify the second virtual IP address
(
/cfg/net/if #/vrrp/ip2
) in Step 5 from 0.0.0.0 to a specific value.
8.
Set the adint, garp, gbcast, and phcintvl values.
9.
(optional) Set the Sync Interface.
The optional Sync interface requires a dedicated port on both units and a local connection. Its
configuration differs from the other virtual router interfaces in that both
/cfg/net/if
#/vrrp/ip1
and
/cfg/net/if #/vrrp/ip2
are both set to 0.0.0.0. For additional
information about the Sync interface, see
Synchronizing Nortel Switched Firewalls on page
186
.
Configure the real addresses for the router interface and enable the interface for the sync
network.
Configure the vrid for the sync network.
Enable synchronization and apply the changes.
>> Main#
/cfg/net/vrrp/ha y
(Enable active-standby failover)
>> Main#
/cfg/net/vrrp/aa y
(Enable active-active failover)
>> Main#
/cfg/net/vrrp/adint 10
>> Main#
/cfg/net/vrrp/garp 1
default value
>> Main#
/cfg/net/vrrp/gbcast 2
default value
>> Main#
/cfg/net/if 1/addr1 10.10.1.1
>> Main#
/cfg/net/if 1/addr2 10.10.1.2
>> Main#
/cfg/net/if 1/mask 255.255.255.0
>> Main#
/cfg/net/if 1/vlanid 0
>> Main#
/cfg/net/if 1/port 2
>> Main#
/cfg/net/if 1/ena y
>> Main#
/cfg/net/if 1/vrrp/vrid 192
>> Main#
/cfg/fw/sync/ena
Enable synchronization
>> Main#
apply