Professional Documents
Culture Documents
SUMMARY:
This article provides information on how to setup a HA pair with a simple Active/Active configuration.
PROBLEM OR GOAL:
This article addresses the following:
A.
Active/Active Overview
B.
C.
CAUSE:
SOLUTION:
A. Active/Active Overview
ScreenOS allows you to configure your Juniper firewall HA cluster as Active/Active. Although Active/Passive is the most common
implementation, the Active/Active implementation has the following pro's and con's:
Pro's
:
Load sharing
:
Routing flexibility
:
Con's
:
Complex to design
:
Creating an NSRP cluster, which automatically includes the creation of VSD group 0. To avoid confusion we ' unset vsd-
group 0'.
set
set
set
set
set
set
int
int
int
int
int
int
ethernet1/2 zone
ethernet1/2:1 ip
ethernet1/2:2 ip
ethernet2/1 zone
ethernet2/1:1 ip
ethernet2/1:2 ip
untrust
210.1.1.1/24
210.1.1.2/24
trust
10.1.1.1/24
10.1.1.2/24
Zone
MAC
VLAN State
MGT
HA
HA
Untrust
Untrust
Untrust
Untrust
Trust
ESC-DMZ
MEW-DMZ
STFC-DMZ
Untrust
Untrust
email-DMZ
HPCx-INT
0010.db42.6380
0010.db42.6385
0010.db42.6386
0010.db42.6387
0010.db42.6387
0010.db42.6387
0010.db42.6387
0010.db42.6388
0010.db42.6388
0010.db42.6388
0010.db42.6388
0010.db42.6388
0010.db42.6388
0010.db42.6388
0010.db42.6388
1000
1001
1002
16
66
83
26
79
2000
500
U
D
D
D
D
D
D
D
D
D
D
D
D
D
D
Note:By default, all the interfaces are a part of VSD-group 0. The VSI notification of being part of particular VSD-group is :
When an interface does not have an associated VSD_Group number, it is considered as a part of VSD-group 0 or not part of any VSDgroup, if VSD-group 0 is unset.
So, you need to create a VSI to bind the interface to a VSD group
3. Set the routes:
PURPOSE:
Troubleshooting