2 thoughts on “How does the H3C MSR3600-28 router configure the dual-machine thermal preparation and how to enter?”
Aubrey
The command is input through the following methods: . Use the console port to connect . Click to start -program -accessory -communication -super terminal โ select COM mouth silent recognition value to enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter it (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter Take XP as an example). . Enter the super -terminal window and enter the configuration H3C interface.
Coustically configure dual -machine thermal preparation: . Create RDO before configured dual -machine thermal preparation, you must create RDO on each device. Enter the system view: System-View Create RDO, and enter the RDO view: RDORDO-Id Note: The RDOID number between the two devices of the mutual preparation must be consistent. . Configuration of the HA interface of this end Themine and the end firewall need to use the main status of the HA interface to negotiate and simultaneously configure the command and status information. This configuration: ha-interfaceInterfaceInterface-name [peer-macmac-address] n can specify the MAC address of the end HA interface through the peer-mac parameter. If the MAC address of the opposite HA interface, use the broadcast MAC address FFFF-FFFFF-FFFF. Note: Double -machine thermal negotiation packets and business synchronization data are transmitted using the HA interface. These packets are different from ordinary messages. Therefore The message does not work. . Configure VIF The virtual interface includes the virtual IP address, interface authority and virtual MAC address of the configuration interface. Is when the firewall works under the routing mode, the business interface that is backup on the main reserve must be configured with the same virtual interface ID, virtual IP address, and virtual MAC address. The virtual IP address must be in the same network segment as the real IP address of the interface, but it cannot be the same as the real IP address of the interface. The virtual Mac cannot be the same as the real Mac of the interface. Is when the firewall is working under the bridge mode, the virtual IP address and the virtual MAC address cannot be configured. The interface right value is used to dynamically update the priority. When the interface is down/up, the system adjusts the real -time priority of the RDO according to the weight. 1, configure VIF: VIFVIF-IDINTERFACEIFACERFACE-NAMEVIRTUAL-IPIP-ADDRESS [VIRTUAL-MACH-H] [Receval-Reced] n, the value of Value-Reced is 10. 2, configured VIF VIFVIF-IDINTERFACEIFACERFACE-NAME [Receval-Reced] n under default, the value-reced value is 10. Note: 1) The virtual interface cannot be repeatedly configured. The original configuration must be canceled with the UNDO command to re -configure it. 2) The address of VIF cannot be the same as the address of the binding interface. 3) The virtual interface cannot be canceled with the UNDO command during the batch backup process. 4) In order to ensure that the real-time priority of the RDO is positive, the total value of each binding interface under a RDO cannot be greater than or equal to the static priority corresponding to the RDO. 5) When the dual -machine thermal preparation function is used, please do not configure and use VRRP, otherwise it will cause abnormal dual -machine thermal preparation function. . The adjustment and optimization of dual -machine thermal preparation (1) Configure RSO static connection RDO static priority refers to the priority of the RDO when the interface of the device is the UP state. The actual states and power values โโof static priority and interfaces can be calculated to calculate the real -time priority of RDO. The real -time priority of RDO can determine the main relationship between devices. The high -priority value is a master. The configuration of RDO static priority: PriorityValue Wef offssed, static priority is 100. Note: If the real -time priority of this end and the opposite end is equal, the main relationship relationship is determined according to the MAC address of the HA interface between the two parties. (2) Configuration authentication method The authentication method refers to the authentication method used when the device sends and receive data messages and control messages through the HA interface. The authentication method has a simple certification mode and MD5 certification mode. Configuration authentication method: -modekekeyword -modemd5password {plain | cipher} keyword
Note: The same authentication mode and authentication password should be used between the device -based equipment. The is recommended to configure the authentication mode and certification password before configuration to the end IP and the virtual interface. Once the main negotiation is completed, the configuration authentication method will cause some messages to lose, which may affect the state of the equipment. (3) Configuration notice isolation The main device in a RDO will regularly send suppression packets, notify the backup device to be in a normal working state, and notify your priority. The backup equipment determines the timeout of the inhibitory packet according to the notice time interval. If the inhibitory packet is not received for three consecutive times, it is considered that the main device has failed and the state switch is performed. The same announcement interval is recommended at this end and end settings. Configuration notice interval: Ad-IntervalTime-Value The notice interval is 3 seconds. Note: Due to the differences in the hardware performance of different types of products and the business volume of the equipment in the actual application, the preparation of the dual -machine thermal preparation may not be able to handle the host sending in time during the batch backup and recovery process. The announcement of the announcement, which causes the main equipment to reach a stable synchronization state. The abnormal phenomenon of frequent switching of the main reserve can be avoided by configuring a larger notice time interval. It is recommended that the notice time interval of the user configuration is greater than or equal to 3 seconds to prevent the above problems from occurring.
The command is input through the following methods:
. Use the console port to connect
. Click to start -program -accessory -communication -super terminal โ select COM mouth silent recognition value to enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter it (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter (you can enter Take XP as an example).
. Enter the super -terminal window and enter the configuration H3C interface.
Coustically configure dual -machine thermal preparation:
. Create RDO
before configured dual -machine thermal preparation, you must create RDO on each device.
Enter the system view: System-View
Create RDO, and enter the RDO view: RDORDO-Id
Note: The RDOID number between the two devices of the mutual preparation must be consistent.
. Configuration of the HA interface of this end
Themine and the end firewall need to use the main status of the HA interface to negotiate and simultaneously configure the command and status information.
This configuration:
ha-interfaceInterfaceInterface-name [peer-macmac-address] n can specify the MAC address of the end HA interface through the peer-mac parameter.
If the MAC address of the opposite HA interface, use the broadcast MAC address FFFF-FFFFF-FFFF.
Note: Double -machine thermal negotiation packets and business synchronization data are transmitted using the HA interface. These packets are different from ordinary messages. Therefore The message does not work.
. Configure VIF
The virtual interface includes the virtual IP address, interface authority and virtual MAC address of the configuration interface.
Is when the firewall works under the routing mode, the business interface that is backup on the main reserve must be configured with the same virtual interface ID, virtual IP address, and virtual MAC address.
The virtual IP address must be in the same network segment as the real IP address of the interface, but it cannot be the same as the real IP address of the interface. The virtual Mac cannot be the same as the real Mac of the interface.
Is when the firewall is working under the bridge mode, the virtual IP address and the virtual MAC address cannot be configured.
The interface right value is used to dynamically update the priority. When the interface is down/up, the system adjusts the real -time priority of the RDO according to the weight.
1, configure VIF:
VIFVIF-IDINTERFACEIFACERFACE-NAMEVIRTUAL-IPIP-ADDRESS [VIRTUAL-MACH-H] [Receval-Reced] n, the value of Value-Reced is 10.
2, configured VIF
VIFVIF-IDINTERFACEIFACERFACE-NAME [Receval-Reced] n under default, the value-reced value is 10.
Note:
1) The virtual interface cannot be repeatedly configured. The original configuration must be canceled with the UNDO command to re -configure it.
2) The address of VIF cannot be the same as the address of the binding interface.
3) The virtual interface cannot be canceled with the UNDO command during the batch backup process.
4) In order to ensure that the real-time priority of the RDO is positive, the total value of each binding interface under a RDO cannot be greater than or equal to the static priority corresponding to the RDO.
5) When the dual -machine thermal preparation function is used, please do not configure and use VRRP, otherwise it will cause abnormal dual -machine thermal preparation function.
. The adjustment and optimization of dual -machine thermal preparation
(1) Configure RSO static connection
RDO static priority refers to the priority of the RDO when the interface of the device is the UP state.
The actual states and power values โโof static priority and interfaces can be calculated to calculate the real -time priority of RDO.
The real -time priority of RDO can determine the main relationship between devices. The high -priority value is a master.
The configuration of RDO static priority: PriorityValue
Wef offssed, static priority is 100.
Note: If the real -time priority of this end and the opposite end is equal, the main relationship relationship is determined according to the MAC address of the HA interface between the two parties.
(2) Configuration authentication method
The authentication method refers to the authentication method used when the device sends and receive data messages and control messages through the HA interface.
The authentication method has a simple certification mode and MD5 certification mode.
Configuration authentication method:
-modekekeyword
-modemd5password {plain | cipher} keyword
Note: The same authentication mode and authentication password should be used between the device -based equipment.
The is recommended to configure the authentication mode and certification password before configuration to the end IP and the virtual interface.
Once the main negotiation is completed, the configuration authentication method will cause some messages to lose, which may affect the state of the equipment.
(3) Configuration notice isolation
The main device in a RDO will regularly send suppression packets, notify the backup device to be in a normal working state, and notify your priority.
The backup equipment determines the timeout of the inhibitory packet according to the notice time interval. If the inhibitory packet is not received for three consecutive times, it is considered that the main device has failed and the state switch is performed. The same announcement interval is recommended at this end and end settings.
Configuration notice interval: Ad-IntervalTime-Value
The notice interval is 3 seconds.
Note: Due to the differences in the hardware performance of different types of products and the business volume of the equipment in the actual application, the preparation of the dual -machine thermal preparation may not be able to handle the host sending in time during the batch backup and recovery process. The announcement of the announcement, which causes the main equipment to reach a stable synchronization state. The abnormal phenomenon of frequent switching of the main reserve can be avoided by configuring a larger notice time interval. It is recommended that the notice time interval of the user configuration is greater than or equal to 3 seconds to prevent the above problems from occurring.
The firewall can be used for double -machine heat. The router can only do redundant backups such as VRRP.