F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices High Availability Configuration Guide-6PW100

49
Master IP : FE80::1
Interface GigabitEthernet0/1
VRID : 2 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 110 Running Pri : 110
Preempt Mode : Yes Delay Time : 0
Auth Type : None
Virtual IP : FE80::20
1::20
Virtual MAC : 0000-5e00-0202
Master IP : FE80::2
The output shows that in VRRP group 1, Firewall A is the master, Firewall B is the backup, and the
host with the default gateway of 1::10/64 access the Internet through Firewall A. In VRRP group
2, Firewall A is the backup, Firewall B is the master, and the host with the default gateway of
1::20/64 access the Internet through Firewall B.
NOTE:
To implement load balancing between the VRRP groups, be sure to configure the default gateway as 1::10
or 1::20 on the hosts on network segment 1::/64.
24B
Troubleshooting VRRP
99BThe screen frequently displays error prompts
270BSymptom
The screen frequently displays error prompts.
271BAnalysis
This error is probably caused by:
Inconsistent configuration of the firewalls in the VRRP group.
A device is attempting to send illegitimate VRRP packets.
272BSolution
In the first case, modify the configuration.
In the latter case, resort to non-technical measures.
100BMultiple masters appear in a VRRP group
273BSymptom
Multiple masters are present in the same VRRP group.
274BAnalysis
Multiple masters coexist for a short period. This is normal and requires no manual intervention.
Multiple masters coexist for a long period. This is because firewalls in the VRRP group cannot
receive VRRP packets, or the received VRRP packets are illegal.