HP VPN Firewall Appliances High Availability Configuration Guide
167
# Create Layer 2 aggregate interface Bridge-Aggregation 2, and configure the load sharing
criterion for the link aggregation group as the destination IP addresses of packets.
[FirewallA] interface bridge-aggregation 2
[FirewallA-Bridge-Aggregation2] link-aggregation load-sharing mode
destination-ip
[FirewallA-Bridge-Aggregation2] quit
# Assign ports GigabitEthernet 0/3 and GigabitEthernet 0/4 to link aggregation group 2.
[FirewallA] interface gigabitethernet 0/3
[FirewallA-GigabitEthernet0/3] port link-aggregation group 2
[FirewallA-GigabitEthernet0/3] quit
[FirewallA] interface gigabitethernet 0/4
[FirewallA-GigabitEthernet0/4] port link-aggregation group 2
[FirewallA-GigabitEthernet0/4] quit
# Configure Layer 2 aggregate interface Bridge-Aggregation 2 as a trunk port and assign it to
VLAN 20.
[FirewallA] interface bridge-aggregation 2
[FirewallA-Bridge-Aggregation2] port link-type trunk
[FirewallA-Bridge-Aggregation2] port trunk permit vlan 20
Please wait... Done.
Configuring GigabitEthernet0/3... Done.
Configuring GigabitEthernet0/4... Done.
[FirewallA-Bridge-Aggregation2] quit
b. Configure Firewall B in the same way Firewall A is configured. (Details not shown.)
3. Verify the configuration
# Display summary information about all aggregation groups on Firewall A.
[FirewallA] display link-aggregation summary
Aggregation Interface Type:
BAGG -- Bridge-Aggregation, RAGG -- Route-Aggregation
Aggregation Mode: S -- Static, D -- Dynamic
Loadsharing Type: Shar -- Loadsharing, NonS -- Non-Loadsharing
Actor System ID: 0x8000, 000f-e2ff-0001
AGG AGG Partner ID Select Unselect Share
Interface Mode Ports Ports Type
-------------------------------------------------------------------------------
BAGG1 S none 2 0 Shar
BAGG2 S none 2 0 Shar
The output shows that link aggregation groups 1 and 2 are both load-sharing-capable Layer 2
static aggregation groups and each contains two Selected ports.
# Display all the group-specific load sharing criteria on Firewall A.
[FirewallA] display link-aggregation load-sharing mode interface