Configuring HSB on Firewalls
Context
Firewalls on the campus network use hot standby (HSB) technology to improve device-level reliability. If the master firewall fails, traffic is switched to the backup firewall, improving network reliability. Uplink and downlink interfaces of a firewall are typically connected to switches. It is recommended that you deploy firewalls in HSB mode using Virtual Router Redundancy Protocol (VRRP) groups. Figure 5-6 shows the deployment of firewalls in HSB mode.
Plan Example
Device |
Operating Mode |
Role |
Heartbeat Interface |
Remote Interface IP Address |
Automatic Static Route Backup |
VRRP Monitoring |
Other Parameters |
||
---|---|---|---|---|---|---|---|---|---|
FW-a |
Master/Backup mode |
Master |
GE1/0/3 |
192.168.150.2 |
Enabled |
VRID: 1 Interface: GE1/0/4 Virtual interface IP/mask: 192.0.2.4/24 |
VRID: 2 Interface: GE1/0/5 Virtual interface IP/mask: 198.51.100.4/24 |
VRID: 3 Interface: Eth-Trunk 1 Virtual interface IP/mask: 192.168.10.1/24 |
Default |
FW-b |
Master/Backup mode |
Backup |
GE1/0/3 |
192.168.150.1 |
Enabled |
VRID: 1 Interface: GE1/0/4 Virtual interface IP/mask: 192.0.2.4/24 |
VRID: 2 Interface: GE1/0/5 Virtual interface IP/mask: 198.51.100.4/24 |
VRID: 3 Interface: Eth-Trunk 1 Virtual interface IP/mask: 192.168.10.1/24 |
Default |
Procedure
- Choose System > High Availability > Dual-System Hot Standby. Click Edit to configure the HSB function of the firewall.