HP VPN Firewall Appliances High Availability Configuration Guide

49
Master IP : FE80::1
Interface GigabitEthernet0/1
VRID : 2 Adver Timer : 100
Admin Status : Up State : Master
Config Pri : 110 Running Pri : 110
Preempt Mode : Yes Delay Time : 0
Auth Type : None
Virtual IP : FE80::20
1::20
Virtual MAC : 0000-5e00-0202
Master IP : FE80::2
The output shows that in VRRP group 1, Firewall A is the master, Firewall B is the backup, and the
host with the default gateway of 1::10/64 access the Internet through Firewall A. In VRRP group
2, Firewall A is the backup, Firewall B is the master, and the host with the default gateway of
1::20/64 access the Internet through Firewall B.
NOTE:
To implement load balancing between the VRRP groups, be sure to confi
g
ure the default
g
ateway as
1::10 or 1::20 on the hosts on network segment 1::/64.
Troubleshooting VRRP
The screen frequently displays error prompts
Symptom
The screen frequently displays error prompts.
Analysis
This error is probably caused by:
Inconsistent configuration of the firewalls in the VRRP group.
A device is attempting to send illegitimate VRRP packets.
Solution
In the first case, modify the configuration.
In the latter case, resort to non-technical measures.
Multiple masters appear in a VRRP group
Symptom
Multiple masters are present in the same VRRP group.
Analysis
Multiple masters coexist for a short period. This is normal and requires no manual intervention.