When you ping the virtual IP address of an interface, what is the source MAC address when firewall reply the ping packet?
For example, there is a interface configured as below:
ip address 192.168.2.2 255.255.255.0
vrrp vrid 3 virtual-ip 211.x1.y1.85 255.255.255.224 active ----the virtual mac is 0000-5e00-0103
vrrp vrid 7 virtual-ip 223.x2.y2.68 255.255.255.0 active ---the virtual mac is 0000-5e00-0107
vrrp virtual-mac enable
If customer enable the virtual mac function, firewall will use the MAC address corresponding to the first VRRP backup group on the interface forwarding the packet. If customer don't enable the virtual mac function, firewall will use the physical mac address of interface.