HP VPN Firewall Appliances High Availability Configuration Guide
19
Ste
p
Command
Remarks
4. Configure the firewall in the
VRRP group to operate in
preemptive mode and
configure preemption delay.
vrrp vrid virtual-router-id
preempt-mode [ timer delay
delay-value ]
Optional.
The firewall in the VRRP group
operates in preemptive mode and
the preemption delay is 0 seconds
by default.
5. Configure the interface to be
tracked.
vrrp vrid virtual-router-id track
interface interface-type
interface-number [ reduced
priority-reduced ]
Optional.
By default, no interface is being
tracked.
6. Configure VRRP to track a
specified track entry.
vrrp vrid virtual-router-id track
track-entry-number [ reduced
priority-reduced | switchover ]
Optional.
By default, VRRP is not configured
to track a specified track entry.
Configuring VRRP packet attributes
Configuration prerequisites
Before you configure the relevant attributes of VRRP packets, create a VRRP group and configure a virtual
IP address for it.
Configuration guidelines
• You might configure different authentication modes and authentication keys for the VRRP groups on
an interface. However, the members of the same VRRP group must use the same authentication
mode and authentication key.
• Excessive traffic might cause a backup to trigger a change of its status because the backup does not
receive any VRRP advertisements for a specified period of time. To solve this problem, increase the
time interval to send VRRP advertisements.
• Configuring different intervals for sending VRRP advertisements on the firewalls in a VRRP group
might cause a backup to trigger a change of its status. This is because the backup does not receive
any VRRP advertisements for a specified period of time. To solve this problem, configure the same
interval for sending VRRP advertisements on each firewall in the VRRP group.
• After you specify an interface as the source interface for sending VRRP packets, this interface,
instead of the interface where the VRRP group resides, sends and receives VRRP packets. If you
specify the interface where the VRRP group resides as the source interface for sending VRRP packets,
the configuration does not take effect.
Configuration procedure
To configure VRRP packet attributes:
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter the specified interface
view.
interface interface-type
interface-number
N/A