F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices High Availability Configuration Guide-6PW100
60
111BConfiguring a failover interface and a backup VLAN
Failover interfaces send and receive stateful failover packets for data backup. Stateful failover packets
are identified by the backup VLAN. Each stateful failover device adds the backup VLAN tag to the
stateful failover packets, and sends the packets through the failover interface. Only the packets that are
received from failover interfaces and carry the backup VLAN tag are treated as stateful failover packets.
Do not configure other services for the backup VLAN. Otherwise, the operation of stateful failover might
be affected.
To configure a failover interface and a backup VLAN:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Configure a failover interface
and a backup VLAN.
dhbk interface interface-list vlan
vlan-id
By default, no failover interface or
backup VLAN is specified.
112BDisplaying and maintaining stateful failover
Task Command
Remarks
Display the running status and
related information of stateful
failover.
display dhbk status [ | { begin |
exclude | include }
regular-expression ]
Available in any view.
113BStateful failover configuration example
282BNetwork requirements
In 502HFigure 34, Device A and Device B serve as the internal gateways of an enterprise network. Firewall A
and Firewall B, respectively attached to Device A and Device B, provide portal access authentication for
internal users. Configure stateful failover between Firewall A and Firewall B. When one device fails, the
other device takes over the services to ensure service continuity.