HP VPN Firewall Appliances High Availability Configuration Guide

47
Figure 26 Network diagram
Configuration procedure
1. Configure Firewall A:
<FirewallA> system-view
[FirewallA] ipv6
[FirewallA] interface gigabitethernet0/1
[FirewallA-GigabitEthernet0/1] ipv6 address fe80::1 link-local
[FirewallA-GigabitEthernet0/1] ipv6 address 1::1 64
# Create VRRP group 1 and set its virtual IPv6 addresses to FE80::10 and 1::10.
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 1 virtual-ip fe80::10 link-local
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 1 virtual-ip 1::10
# Set the priority of Firewall A in VRRP group 1 to 110, which is higher than that of Firewall B (100),
so that Firewall A can become the master in VRRP group 1.
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 1 priority 110
# Create VRRP group 2 set its virtual IPv6 addresses to FE80::20 and 1::20.
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 2 virtual-ip fe80::20 link-local
[FirewallA-GigabitEthernet0/1] vrrp ipv6 vrid 2 virtual-ip 1::20
2. Configure Firewall B:
<FirewallB> system-view
[FirewallB] ipv6
[FirewallB] interface gigabitethernet0/1
[FirewallB-GigabitEthernet0/1] ipv6 address fe80::2 link-local
[FirewallB-GigabitEthernet0/1] ipv6 address 1::2 64
# Create VRRP group 1 and set its virtual IPv6 addresses to FE80::10 and 1::10.
[FirewallB-GigabitEthernet0/1] vrrp ipv6 vrid 1 virtual-ip fe80::10 link-local
[FirewallB-GigabitEthernet0/1] vrrp ipv6 vrid 1 virtual-ip 1::10
# Create VRRP group 2 set its virtual IPv6 addresses to FE80::20 and 1::20.
[FirewallB-GigabitEthernet0/1] vrrp ipv6 vrid 2 virtual-ip fe80::20 link-local
[FirewallB-GigabitEthernet0/1] vrrp ipv6 vrid 2 virtual-ip 1::20
Host A
Host B
Host C
Firewall A
Firewall B
Virtual IP address 1:
FE80::10
1::10/64
Virtual IPv6 address 2:
FE80::20
1::20/64
GE0/1
FE80::1
1::1/64
GE0/1
FE80::2
1::2/64
Gateway:
1::10/64
Gateway:
1::20/64
Gateway:
1::20/64
Internet