R3721-F3210-F3171-HP High-End Firewalls High Availability Configuration Guide-6PW101

44
# Set the authentication mode of VRRP group 1 as simple and authentication key to hello.
[FirewallA-GigabitEthernet0/2] vrrp ipv6 vrid 1 authentication-mode simple hello
# Set the interval on Firewall A for sending VRRP advertisements to 400 centiseconds.
[FirewallA-GigabitEthernet0/2] vrrp ipv6 vrid 1 timer advertise 400
# Configure Firewall A to operate in preemptive mode, so that it can become the master whenever it
operates properly; configure the preemption delay as five seconds to avoid frequent status switchover.
[FirewallA-GigabitEthernet0/2] vrrp ipv6 vrid 1 preempt-mode timer delay 5
# Set interface GigabitEthernet 0/1 on Firewall A to be tracked, and configure the amount by which the
priority value decreases to be more than 10 (30 in this example), so that when GigabitEthernet 0/1 fails,
the priority of Firewall A in VRRP group 1 decreases to a value lower than 100 and thus Firewall B can
become the master.
[FirewallA-GigabitEthernet0/2] vrrp ipv6 vrid 1 track interface GigabitEthernet 0/1
reduced 30
# Enable Firewall A to send RA messages, so that Host A can learn the default gateway address.
[FirewallA-GigabitEthernet0/2] undo ipv6 nd ra halt
Configuring Firewall B
<FirewallB> system-view
[FirewallB] ipv6
[FirewallB] interface gigabitethernet 0/2
[FirewallB-GigabitEthernet0/2] ipv6 address fe80::2 link-local
[FirewallB-GigabitEthernet0/2] ipv6 address 1::2 64
# Create a VRRP group 1 and set its virtual IPv6 addresses to FE80::10 and 1::10.
[FirewallB-GigabitEthernet0/2] vrrp ipv6 vrid 1 virtual-ip fe80::10 link-local
[FirewallB-GigabitEthernet0/2] vrrp ipv6 vrid 1 virtual-ip 1::10
# Set the authentication mode of VRRP group 1 as simple and authentication key as hello.
[FirewallB-GigabitEthernet0/2] vrrp ipv6 vrid 1 authentication-mode simple hello
# Set the interval between sending VRRP advertisements to 400 centiseconds.
[FirewallB-GigabitEthernet0/2] vrrp ipv6 vrid 1 timer advertise 400
# Configure Firewall B to operate in preemptive mode, so that Firewall B can become the master after the
priority of Firewall A decreases to a value lower than 100. Configure the preemption delay as five
seconds to avoid frequent status switchover.
[FirewallB-GigabitEthernet0/2] vrrp ipv6 vrid 1 preempt-mode timer delay 5
# Enable Firewall B to send RA messages, so that Host A can learn the default gateway address.
[FirewallB-GigabitEthernet0/2] undo ipv6 nd ra halt
Verifying the configuration
After the configuration, Host B can be pinged successfully on Host A. To verify your configuration, use the
display vrrp ipv6 verbose command.
# Display detailed information about VRRP group 1 on Firewall A.
[FirewallA-GigabitEthernet0/2] display vrrp ipv6 verbose
IPv6 Standby Information:
Run Mode : Standard
Run Method : Virtual MAC
Total number of virtual routers : 1
Interface GigabitEthernet0/2