HP VPN Firewall Appliances High Availability Configuration Guide

41
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 1 virtual-ip 1::10
# Configure the priority of Firewall A in VRRP group 1 as 110, which is higher than that of Firewall
B (100), so that Firewall A can become the master.
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 1 priority 110
# Configure Firewall A to operate in preemptive mode so that it can become the master whenever
it works correctly; configure the preemption delay as five seconds to avoid frequent status
switchover.
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 1 preempt-mode timer delay 5
# Enable Firewall A to send RA messages, so that Host A can learn the default gateway address.
[FirewallA-GigabitEthernet0/1] undo ipv6 nd ra halt
2. Configure Firewall B:
<FirewallB> system-view
[FirewallB] ipv6
[FirewallB] interface gigabitethernet0/1
[FirewallB-GigabitEthernet0/1] ipv6 address fe80::2 link-local
[FirewallB-GigabitEthernet0/1] ipv6 address 1::2 64
# Create a VRRP group 1 and set its virtual IPv6 addresses to FE80::10 and 1::10.
[FirewallB-GigabitEthernet0/1] vrrp ipv6 vrid 1 virtual-ip fe80::10 link-local
[FirewallB-GigabitEthernet0/1] vrrp ipv6 vrid 1 virtual-ip 1::10
# Configure Firewall B to operate in preemptive mode, with the preemption delay set to five
seconds.
[FirewallB-GigabitEthernet0/1] vrrp ipv6 vrid 1 preempt-mode timer delay 5
# Enable Firewall B to send RA messages, so that Host A can learns the default gateway address.
[FirewallB-GigabitEthernet0/1] undo ipv6 nd ra halt
3. Verify the configuration:
After the configuration, Host B can be pinged successfully on Host A. To verify your configuration,
use the display vrrp ipv6 verbose command.
# Display the detailed information about VRRP group 1 on Firewall A.
[FirewallA-GigabitEthernet0/1] display vrrp ipv6 verbose
IPv6 Standby Information:
Run Mode : Standard
Run Method : Virtual MAC
Total number of virtual routers : 1
Interface Ethernet1/1
VRID : 1 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 110 Running Pri : 110
Preempt Mode : Yes Delay Time : 5
Auth Type : None
Virtual IP : FE80::10
1::10
Virtual MAC : 0000-5e00-0201
Master IP : FE80::1
# Display the detailed information about VRRP group 1 on Firewall B.
[FirewallB-GigabitEthernet0/1] display vrrp ipv6 verbose
IPv6 Standby Information: