R3166-R3206-HP High-End Firewalls High Availability Configuration Guide-6PW101
12
• Firewall A and Firewall B belong to VRRP group 1 with the virtual IP address of 202.38.160.111/24.
• If Firewall A operates normally, packets sent from Host A to Host B are forwarded by Firewall A; if
GigabitEthernet 0/2 connecting Firewall A with the Internet becomes unavailable, packets sent
from Host A to Host B are forwarded by Firewall B.
Figure 10 Network diagram for single VRRP group configuration
Configuration procedure
Configure Firewall A
# Configure the IP address of GigabitEthernet 0/1.
• Select Device Management > Interface from the navigation tree, and click the icon
corresponding to GigabitEthernet 0/1.
• Select the Static Address option.
• Type 202.38.160.1 in the IP Address box.
• Select 24 (255.255.255.0) from the Mask box.
• Click Apply.
# Create VRRP group 1.
• Select High Reliability > VRRP from the navigation tree to enter the VRRP interfaces page. Click the
icon corresponding to GigabitEthernet 0/1 to enter the VRRP Configuration on Interface page
(as shown in Figure 7)
, and click Add.
• Type 1 in the VRID box.
• Type 202.38.160.111 in the Virtual IP box.
• Click Add to add the virtual IP address to the Virtual IP Members box.
• Click Apply.
# Configure VRRP group attributes.
• Click the icon corresponding to VRRP group 1 on the VRRP group page of GigabitEthernet 0/1.
• Type 11 0 in the Priority box.
• Select Preemptive from the Preempt Mode box.
• Type 5 in the Delay box.
• Select Simple from the Authentication box.
• Type hello in the Key box.