一、 组网需求:
两台SecPath500F防火墙部署在Internet出口,通过做双机热备实现冗余备份。
配置信息
1. SecPath500F_1的主要配置
firewall packet-filter enable
firewall packet-filter default permit
#
vrrp ping-enable //启用VRRP的ping功能
#
firewall statistic system enable
#
radius scheme system
#
domain system
#
acl number 3000
description NAT
rule 0 permit ip source 192.168.1.0 0.0.0.255
interface GigabitEthernet0/0
description WAN
ip address 202.38.1.253 255.255.255.0
vrrp vrid 2 virtual-ip 202.38.1.252 //配置VRRP组2的虚IP
vrrp vrid 2 priority 110 //配置VRRP组2的优先级
vrrp vrid 2 track GigabitEthernet0/1 reduced 20 //配置VRRP组2的track属性
nat outbound 3000
interface GigabitEthernet0/1
description LAN
ip address 172.16.1.253 255.255.255.0
vrrp vrid 1 virtual-ip 172.16.1.252 //配置VRRP组1的虚IP
vrrp vrid 1 priority 110 //配置VRRP组1的优先级
vrrp vrid 1 track GigabitEthernet0/0 reduced 20 //配置VRRP组1的track属性
interface Encrypt2/0
interface NULL0
firewall zone local
set priority 100
firewall zone trust
add interface GigabitEthernet0/1
set priority 85
firewall zone untrust
add interface GigabitEthernet0/0
set priority 5
ip route-static 0.0.0.0 0.0.0.0 202.38.1.1 preference 60
ip route-static 192.168.0.0 255.255.0.0 172.16.1.1 preference 60
#
user-interface con 0
user-interface aux 0
user-interface vty 0 4
#