HA (high availability) configuration of Juniper Firewall

Source: Internet
Author: User

To ensure the high availability of network applications, two firewall devices of the same model can be deployed at the edge of the network to be protected during the deployment of Juniper firewall to implement HA configuration. Juniper firewall provides three high-availability application configuration modes: master-slave mode, master-master mode, and dual-master redundancy mode. Here, we only describe the configuration of the master-slave mode.

Firewall HA network topology (active/standby mode ):

1. Web browser configuration

WebUI (device-)
① Interface
Network> Interfaces> Edit (for ethernet7): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet8): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet1): Enter the following content and click OK:
Zone Name: Untrust
Static IP: (select this option when it appears)
IP Address/Netmask: 210.1.1.1/24
Network> Interfaces> Edit (for ethernet3): Enter the following content, and then click
Apply:
Zone Name: Trust
Static IP: (select this option when it appears)
IP Address/Netmask: 10.1.1.1/24

Manage IP: 10.1.1.20
Enter the following information and click OK:
Interface Mode: NAT
② NSP
Network> NSP> Monitor> Interface> caf ID: Device Edit Interface: Enter
And then click Apply:
Ethernet1: (optional); Weight: 255
Ethernet3: (optional); Weight: 255
Network> NSP> Synchronization: Select "nsp rto Synchronization" and
Click Apply.

Network> NSP> Cluster: In the Cluster ID field, type 1 and click Apply.

 

WebUI (device-B)
① Interface
Network> Interfaces> Edit (for ethernet7): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet8): Enter the following content and click OK:
Zone Name: HA
Network> Interfaces> Edit (for ethernet1): Enter the following content and click OK:
Zone Name: Untrust
Static IP: (select this option when it appears)
IP Address/Netmask: 210.1.1.1/24
Network> Interfaces> Edit (for ethernet3): Enter the following content, and then click
Apply:
Zone Name: Trust
Static IP: (select this option when it appears)
IP Address/Netmask: 10.1.1.1/24
Manage IP: 10.1.1.21
Enter the following information and click OK:

Interface Mode: NAT
② NSP
Network> NSP> Monitor> Interface> caf ID: Device Edit Interface: Enter
And then click Apply:
Ethernet1: (optional); Weight: 255
Ethernet3: (optional); Weight: 255
Network> NSP> Synchronization: Select "nsp rto Synchronization" and
Click Apply.
Network> NSP> Cluster: In the Cluster ID field, type 1 and click Apply.

  • 1
  • 2
  • Next Page

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.