To ensure the high availability of network applications, two firewall devices of the same model can be deployed at the edge of the network to be protected during the deployment of Juniper firewall to implement HA configuration. Juniper firewall provides three high-availability application configuration modes: master-slave mode, master-master mode, and dual-master redundancy mode. Here, we only describe the configuration of the master-slave mode.
Firewall HA network topology (active/standby mode ):
1. Web browser configuration
WebUI (device-)
① Interface
Network> Interfaces> Edit (for ethernet7): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet8): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet1): Enter the following content and click OK:
Zone Name: Untrust
Static IP: (select this option when it appears)
IP Address/Netmask: 210.1.1.1/24
Network> Interfaces> Edit (for ethernet3): Enter the following content, and then click
Apply:
Zone Name: Trust
Static IP: (select this option when it appears)
IP Address/Netmask: 10.1.1.1/24
Manage IP: 10.1.1.20
Enter the following information and click OK:
Interface Mode: NAT
② NSP
Network> NSP> Monitor> Interface> caf ID: Device Edit Interface: Enter
And then click Apply:
Ethernet1: (optional); Weight: 255
Ethernet3: (optional); Weight: 255
Network> NSP> Synchronization: Select "nsp rto Synchronization" and
Click Apply.
Network> NSP> Cluster: In the Cluster ID field, type 1 and click Apply.
WebUI (device-B)
① Interface
Network> Interfaces> Edit (for ethernet7): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet8): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet1): Enter the following content and click OK:
Zone Name: Untrust
Static IP: (select this option when it appears)
IP Address/Netmask: 210.1.1.1/24
Network> Interfaces> Edit (for ethernet3): Enter the following content, and then click
Apply:
Zone Name: Trust
Static IP: (select this option when it appears)
IP Address/Netmask: 10.1.1.1/24
Manage IP: 10.1.1.21
Enter the following information and click OK:
Interface Mode: NAT
② NSP
Network> NSP> Monitor> Interface> caf ID: Device Edit Interface: Enter
And then click Apply:
Ethernet1: (optional); Weight: 255
Ethernet3: (optional); Weight: 255
Network> NSP> Synchronization: Select "nsp rto Synchronization" and
Click Apply.
Network> NSP> Cluster: In the Cluster ID field, type 1 and click Apply.