CLI方式:HA联动路由三层主备直路组网典型配置

使用版本

本举例是在M9000-AI-E8R9071版本上进行配置和验证的。

组网需求

如下图所示,某公司以Device作为网络边界安全防护设备,连接公司内部网络和InternetDevice的上、下行业务接口均为三层接口,上下行连接路由器,Device与路由器之间运行OSPF协议。为提高业务稳定性,使用两台Device进行HA组网,Device A作为主设备,Device B作为备设备。当Device A或其链路发生故障时,由Device B接替Device A继续工作,保证业务不中断。

图-1 HA联动路由三层主备直路组网图

 

注意事项

仅支持两台设备进行HA组网。

因为一台设备故障时另一台设备需要承担两台设备的流量,所以建议在正常情况下每台设备只负载各自实际能力50%的流量。

硬件环境一致

部署HA前,请先保证主/备设备硬件环境的一致性,具体要求如下:

软件环境一致

部署HA前,请先保证主/备设备软件环境的一致性,具体要求如下:

配置步骤

配置Router A

  1. 配置接口IPv4地址

# 根据组网图中规划的信息,配置各接口的IPv4地址,具体配置步骤如下。

<RouterA> system-view

[RouterA] interface gigabitethernet 1/0/7

[RouterA-GigabitEthernet1/0/7] ip address 2.1.1.2 255.255.255.0

[RouterA-GigabitEthernet1/0/7] quit

请参考以上步骤配置其他接口的IP地址,具体配置步骤略。

  1. 配置静态路由,保证外网路由可达

本举例仅以静态路由方式配置路由信息。实际组网中,请根据具体情况选择相应的路由配置方式。

# 请根据组网图中规划的信息,配置静态路由使设备与外网路由可达。本举例假设去往Internet流量的下一跳IPv4地址为3.1.1.15,实际环境中请以具体组网情况为准,具体配置步骤如下。

[RouterA] ip route-static 0.0.0.0 0.0.0.0 3.1.1.15

  1. 配置OSPF,保证内网路由可达

# 配置设备上的OSPF功能,OSPF协议自身的链路开销值建议保持默认配置即可。

[RouterA] router id 2.1.1.2

[RouterA] ospf

[RouterA-ospf-1] area 0

[RouterA-ospf-1-area-0.0.0.0] network 2.1.1.0 0.0.0.255

[RouterA-ospf-1-area-0.0.0.0] network 2.1.10.0 0.0.0.255

[RouterA-ospf-1-area-0.0.0.0] quit

[RouterA-ospf-1] quit

配置Router B

  1. 配置接口IPv4地址

# 根据组网图中规划的信息,配置各接口的IPv4地址,具体配置步骤如下。

<RouterB> system-view

[RouterB] interface gigabitethernet 1/0/7

[RouterB-GigabitEthernet1/0/7] ip address 10.1.1.2 255.255.255.0

[RouterB-GigabitEthernet1/0/7] quit

请参考以上步骤配置其他接口的IP地址,具体配置步骤略。

  1. 配置OSPF,保证路由可达

# 配置设备上的OSPF功能,OSPF协议自身的链路开销值建议保持默认配置即可。

[RouterB] router id 10.1.1.2

[RouterB] ospf

[RouterB-ospf-1] area 0

[RouterB-ospf-1-area-0.0.0.0] network 10.1.1.0 0.0.0.255

[RouterB-ospf-1-area-0.0.0.0] network 10.1.10.0 0.0.0.255

[RouterB-ospf-1-area-0.0.0.0] network 20.1.1.0 0.0.0.255

[RouterB-ospf-1-area-0.0.0.0] quit

[RouterB-ospf-1] quit

配置Device A

  1. 配置接口IPv4地址

# 根据组网图中规划的信息,配置各接口的IPv4地址,具体配置步骤如下。

<DeviceA> system-view

[DeviceA] interface gigabitethernet 1/0/1

[DeviceA-GigabitEthernet1/0/1] ip address 2.1.1.1 255.255.255.0

[DeviceA-GigabitEthernet1/0/1] quit

请参考以上步骤配置其他接口的IP地址,具体配置步骤略。

  1. 配置接口加入安全域。

# 请根据组网图中规划的信息,将接口加入对应的安全域,具体配置步骤如下。

[DeviceA] security-zone name untrust

[DeviceA-security-zone-Untrust] import interface gigabitethernet 1/0/1

[DeviceA-security-zone-Untrust] quit

[DeviceA] security-zone name trust

[DeviceA-security-zone-Trust] import interface gigabitethernet 1/0/2

[DeviceA-security-zone-Trust] quit

  1. 配置OSPF,保证路由可达

# 配置设备上的OSPF功能,OSPF协议自身的链路开销值建议保持默认配置即可。

[DeviceA] router id 2.1.1.1

[DeviceA] ospf

[DeviceA-ospf-1] area 0

[DeviceA-ospf-1-area-0.0.0.0] network 2.1.1.0 0.0.0.255

[DeviceA-ospf-1-area-0.0.0.0] network 10.1.1.0 0.0.0.255

[DeviceA-ospf-1-area-0.0.0.0] quit

[DeviceA-ospf-1] quit

  1. 配置安全策略,允许所需的业务报文通过

此部分安全策略只需在主管理设备配置,HA组网完成后,从管理设备会自动同步这些安全策略配置信息。

# 配置名称为trust-untrust的安全策略规则,使20.1.1.0/24网段的内网用户可以主动访问Internet,但是Internet上的用户不能访问内网,具体配置步骤如下。

[DeviceA] security-policy ip

[DeviceA-security-policy-ip] rule name trust-untrust

[DeviceA-security-policy-ip-0-trust-untrust] source-zone trust

[DeviceA-security-policy-ip-0-trust-untrust] destination-zone untrust

[DeviceA-security-policy-ip-0-trust-untrust] source-ip-subnet 20.1.1.0 24

[DeviceA-security-policy-ip-0-trust-untrust] action pass

[DeviceA-security-policy-ip-0-trust-untrust] quit

# 配置安全策略规则,允许OSPF协议报文通过,保证OSPF邻居的建立和路由的学习。

[DeviceA-security-policy-ip] rule name ospf1

[DeviceA-security-policy-ip-1-ospf1] source-zone trust

[DeviceA-security-policy-ip-1-ospf1] destination-zone local

[DeviceA-security-policy-ip-1-ospf1] service ospf

[DeviceA-security-policy-ip-1-ospf1] action pass

[DeviceA-security-policy-ip-1-ospf1] quit

[DeviceA-security-policy-ip] rule name ospf2

[DeviceA-security-policy-ip-2-ospf2] source-zone local

[DeviceA-security-policy-ip-2-ospf2] destination-zone trust

[DeviceA-security-policy-ip-2-ospf2] service ospf

[DeviceA-security-policy-ip-2-ospf2] action pass

[DeviceA-security-policy-ip-2-ospf2] quit

[DeviceA-security-policy-ip] rule name ospf3

[DeviceA-security-policy-ip-3-ospf3] source-zone untrust

[DeviceA-security-policy-ip-3-ospf3] destination-zone local

[DeviceA-security-policy-ip-3-ospf3] service ospf

[DeviceA-security-policy-ip-3-ospf3] action pass

[DeviceA-security-policy-ip-3-ospf3] quit

[DeviceA-security-policy-ip] rule name ospf4

[DeviceA-security-policy-ip-4-ospf4] source-zone local

[DeviceA-security-policy-ip-4-ospf4] destination-zone untrust

[DeviceA-security-policy-ip-4-ospf4] service ospf

[DeviceA-security-policy-ip-4-ospf4] action pass

[DeviceA-security-policy-ip-4-ospf4] quit

[DeviceA-security-policy-ip] quit

  1. 配置高可靠性

# 配置Track项监控接口状态。

[DeviceA] track 1 interface gigabitethernet 1/0/1

[DeviceA-track-1] quit

[DeviceA] track 2 interface gigabitethernet 1/0/2

[DeviceA-track-2] quit

# 使用两台Device进行HA组网,Device A作为主设备,Device B作为备设备。当Device A或其链路发生故障时,由Device B接替Device A继续工作,保证业务不中断。

[DeviceA] remote-backup group

[DeviceA-remote-backup-group] remote-ip 10.2.1.2

[DeviceA-remote-backup-group] local-ip 10.2.1.1

[DeviceA-remote-backup-group] data-channel interface gigabitethernet 1/0/3

[DeviceA-remote-backup-group] device-role primary

RBM_P[DeviceA-remote-backup-group] undo backup-mode

RBM_P[DeviceA-remote-backup-group] hot-backup enable

RBM_P[DeviceA-remote-backup-group] configuration auto-sync enable

RBM_P[DeviceA-remote-backup-group] configuration sync-check interval 12

# 开启HA调整备设备上动态路由协议OSPF的开销值功能,并以绝对方式对外通告开销值,绝对值为6000

RBM_P[DeviceA-remote-backup-group] adjust-cost ospf enable absolute 6000

# 配置HA与序号为12Track项联动。

RBM_P[DeviceA-remote-backup-group] track 1

RBM_P[DeviceA-remote-backup-group] track 2

RBM_P[DeviceA-remote-backup-group] quit

  1. 配置安全业务

# 以上有关HA的配置部署完成后,可以配置各种安全业务。对于HA支持配置信息备份的功能模块仅需要在此主管理设备上(Device A)进行配置即可。

配置Device B

  1. 配置接口IPv4地址

# 根据组网图中规划的信息,配置各接口的IPv4地址,具体配置步骤如下。

<DeviceB> system-view

[DeviceB] interface gigabitethernet 1/0/1

[DeviceB-GigabitEthernet1/0/1] ip address 2.1.10.1 255.255.255.0

[DeviceB-GigabitEthernet1/0/1] quit

请参考以上步骤配置其他接口的IP地址,具体配置步骤略。

  1. 配置接口加入安全域。

# 请根据组网图中规划的信息,将接口加入对应的安全域,具体配置步骤如下。

[DeviceB] security-zone name untrust

[DeviceB-security-zone-Untrust] import interface gigabitethernet 1/0/1

[DeviceB-security-zone-Untrust] quit

[DeviceB] security-zone name trust

[DeviceB-security-zone-Trust] import interface gigabitethernet 1/0/2

[DeviceB-security-zone-Trust] quit

  1. 配置OSPF,保证路由可达

# 配置设备上的OSPF功能,OSPF协议自身的链路开销值建议保持默认配置即可。

[DeviceB] router id 2.1.10.1

[DeviceB] ospf

[DeviceB-ospf-1] area 0

[DeviceB-ospf-1-area-0.0.0.0] network 2.1.10.0 0.0.0.255

[DeviceB-ospf-1-area-0.0.0.0] network 10.1.10.0 0.0.0.255

[DeviceB-ospf-1-area-0.0.0.0] quit

[DeviceB-ospf-1] quit

  1. 配置高可靠性

# 配置Track项监控接口状态。

[DeviceB] track 1 interface gigabitethernet 1/0/1

[DeviceB-track-1] quit

[DeviceB] track 2 interface gigabitethernet 1/0/2

[DeviceB-track-2] quit

# 使用两台Device进行HA组网,Device A作为主设备,Device B作为备设备。当Device A或其链路发生故障时,由Device B接替Device A继续工作,保证业务不中断。

[DeviceB] remote-backup group

[DeviceB-remote-backup-group] remote-ip 10.2.1.1

[DeviceB-remote-backup-group] local-ip 10.2.1.2

[DeviceB-remote-backup-group] data-channel interface gigabitethernet 1/0/3

[DeviceB-remote-backup-group] device-role secondary

RBM_S[DeviceB-remote-backup-group] undo backup-mode

RBM_S[DeviceB-remote-backup-group] hot-backup enable

RBM_S[DeviceB-remote-backup-group] configuration auto-sync enable

RBM_S[DeviceB-remote-backup-group] configuration sync-check interval 12

# 开启HA调整备设备上动态路由协议OSPF的开销值功能,并以绝对方式对外通告开销值,绝对值为6000

RBM_S[DeviceB-remote-backup-group] adjust-cost ospf enable absolute 6000

# 配置HA与序号为12Track项联动。

RBM_S[DeviceB-remote-backup-group] track 1

RBM_S[DeviceB-remote-backup-group] track 2

RBM_S[DeviceB-remote-backup-group] quit

配置Host

# 配置Host的默认网关为20.1.1.1

验证配置

Device A

# 以上配置完成后,通过执行以下显示命令可查看HA配置已生效,HA通道已建立。

RBM_P[DeviceA] display remote-backup-group status

Remote backup group information:

  Backup mode: Active/standby

  Device management role: Primary

  Device running status: Active

  Data channel interface: GigabitEthernet1/0/3

  Local IP: 10.2.1.1

  Remote IP: 10.2.1.2    Destination port: 60064

  Control channel status: Connected

  Keepalive interval 1s

  Keepalive count: 10

  Configuration consistency check interval: 12 hour

  Configuration consistency check result: Not Performed

  Configuration backup status: Auto sync enabled

  Session backup status: Hot backup enabled

  Delay-time: 0 min

  Uptime since last switchover: 0 days, 3 hours, 11 minutes

  Switchover records:

    Time                     Status change        Cause

    2021-06-22 13:33:33      Initial to Active    Local device rebooted

# 以上配置完成后,通过查看Device AOSPF路由信息,可看到Device ACost值小于Device B,上下行流量经过Device A转发。

RBM_P[DeviceA] display ospf interface

         OSPF Process 1 with Router ID 2.1.1.1

                 Interfaces

 Area: 0.0.0.0

 IP Address      Type      State    Cost  Pri   DR              BDR

 2.1.1.1         Broadcast BDR      1     1     2.1.1.2         2.1.1.1

 10.1.1.1        Broadcast DR       1     1     10.1.1.1        10.1.1.2

Device B

# 以上配置完成后,通过执行以下显示命令可查看HA配置已生效,HA通道已建立。

RBM_S[DeviceB] display remote-backup-group status

Remote backup group information:

  Backup mode: Active/standby

  Device management role: Secondary

  Device running status: Standby

  Data channel interface: GigabitEthernet1/0/3

  Local IP: 10.2.1.2

  Remote IP: 10.2.1.1    Destination port: 60064

  Control channel status: Connected

  Keepalive interval 1s

  Keepalive count: 10

  Configuration consistency check interval: 12 hour

  Configuration consistency check result: Not Performed

  Configuration backup status: Auto sync enabled

  Session backup status: Hot backup enabled

  Delay-time: 0 min

  Uptime since last switchover: 0 days, 3 hours, 11 minutes

  Switchover records:

    Time                     Status change        Cause

    2021-06-22 13:33:33      Initial to Standby   Local device rebooted

# 以上配置完成后,通过查看Device BOSPF路由信息,可看到Device ACost值小于Device B,上下行流量不经过Device B转发。

RBM_S[DeviceB] display ospf interface

         OSPF Process 1 with Router ID 2.1.10.1

                 Interfaces

 Area: 0.0.0.0

 IP Address      Type      State    Cost  Pri   DR              BDR

 2.1.10.1        Broadcast BDR      6000  1     2.1.10.2        2.1.10.1

 10.1.10.1       Broadcast BDR      6000  1     10.1.10.2       10.1.10.1

配置文件

#

 router id 2.1.1.2

#

ospf 1

 area 0.0.0.0

  network 2.1.1.0 0.0.0.255

  network 2.1.10.0 0.0.0.255

#

interface GigabitEthernet1/0/7

 port link-mode route

 ip address 2.1.1.2 255.255.255.0

#

interface GigabitEthernet1/0/8

 port link-mode route

 ip address 2.1.10.2 255.255.255.0

#

interface GigabitEthernet1/0/9

 port link-mode route

 ip address 3.1.1.14 255.255.255.0

#

 ip route-static 0.0.0.0 0 3.1.1.15

#

 router id 10.1.1.2

#

ospf 1

 area 0.0.0.0

  network 10.1.1.0 0.0.0.255

  network 10.1.10.0 0.0.0.255

  network 20.1.1.0 0.0.0.255

#

interface GigabitEthernet1/0/7

 port link-mode route

 ip address 10.1.1.2 255.255.255.0

#

interface GigabitEthernet1/0/8

 port link-mode route

 ip address 10.1.10.2 255.255.255.0

#

interface GigabitEthernet1/0/9

 port link-mode route

 ip address 20.1.1.1 255.255.255.0

#

 router id 2.1.1.1

#

track 1 interface GigabitEthernet1/0/1

#

track 2 interface GigabitEthernet1/0/2

#

ospf 1

 area 0.0.0.0

  network 2.1.1.0 0.0.0.255

  network 10.1.1.0 0.0.0.255

#

interface GigabitEthernet1/0/1

 port link-mode route

 ip address 2.1.1.1 255.255.255.0

#

interface GigabitEthernet1/0/2

 port link-mode route

 ip address 10.1.1.1 255.255.255.0

#

interface GigabitEthernet1/0/3

 port link-mode route

 ip address 10.2.1.1 255.255.255.0

#

security-zone name Trust

 import interface GigabitEthernet1/0/2

#

security-zone name Untrust

 import interface GigabitEthernet1/0/1

#

security-policy ip

 rule 0 name trust-untrust

  action pass

  source-zone trust

  destination-zone untrust

  source-ip-subnet 20.1.1.0 255.255.255.0

 rule 1 name ospf1

  action pass

  source-zone trust

  destination-zone local

  service ospf

 rule 2 name ospf2

  action pass

  source-zone local

  destination-zone trust

  service ospf

 rule 3 name ospf3

  action pass

  source-zone untrust

  destination-zone local

  service ospf

 rule 4 name ospf4

  action pass

  source-zone local

  destination-zone untrust

  service ospf

#

remote-backup group

 data-channel interface GigabitEthernet1/0/3

 configuration sync-check interval 12

 adjust-cost ospf enable absolute 6000

 track 1

 track 2

 local-ip 10.2.1.1

 remote-ip 10.2.1.2

 device-role primary

#

 router id 2.1.10.1

#

track 1 interface GigabitEthernet1/0/1

#

track 2 interface GigabitEthernet1/0/2

#

ospf 1

 area 0.0.0.0

  network 2.1.10.0 0.0.0.255

  network 10.1.10.0 0.0.0.255

#

interface GigabitEthernet1/0/1

 port link-mode route

 ip address 2.1.10.1 255.255.255.0

#

interface GigabitEthernet1/0/2

 port link-mode route

 ip address 10.1.10.1 255.255.255.0

#

interface GigabitEthernet1/0/3

 port link-mode route

 ip address 10.2.1.2 255.255.255.0

#

security-zone name Trust

 import interface GigabitEthernet1/0/2

#

security-zone name Untrust

 import interface GigabitEthernet1/0/1

#

remote-backup group

 data-channel interface GigabitEthernet1/0/3

 configuration sync-check interval 12

 adjust-cost ospf enable absolute 6000

 track 1

 track 2

 local-ip 10.2.1.2

 remote-ip 10.2.1.1

 device-role secondary