H3c-technologies H3C SecPath F5020 Manual do Utilizador

Consulte online ou descarregue Manual do Utilizador para Segurança H3c-technologies H3C SecPath F5020. H3C Technologies H3C SecPath F5020 User Manual Manual do Utilizador

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 82
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 0
H3C Firewall Devices
Virtual Technologies
Configuration Guide (Comware V7)
Hangzhou H3C Technologies Co., Ltd.
http://www.h3c.com
Software version:
F5020/F5040 firewalls ESS9304
M9006/M9010/M9014 security
g
ateways
ESS9114
VFW1000 virtual firewalls ESS9204
Document version: 5W100-20150116
Vista de página 0
1 2 3 4 5 6 ... 81 82

Resumo do Conteúdo

Página 1 - H3C Firewall Devices

H3C Firewall DevicesVirtual TechnologiesConfiguration Guide (Comware V7) Hangzhou H3C Technologies Co., Ltd. http://www.h3c.com So

Página 2

1 IRF overview H3C Intelligent Resilient Framework (IRF) technology combines multiple physical devices into one virtual system to provide data center

Página 3 - Preface

2 IRF functionality Network topology A security device IRF fabric can only use the daisy-chain topology. The device does not support the full mesh or

Página 4 - Conventions

3 Figure 2 Two-chassis IRF fabric implementation schematic diagram Single point of management An IRF fabric is accessible at a single IP address on

Página 5 - Port numbering in examples

4 Multichassis link aggregation You can use the Ethernet link aggregation feature to aggregate the physical links between an upstream or downstream d

Página 6 - Documentation feedback

5 • After you assign a distributed device with a member ID of 2 to an IRF fabric, the name of the interface GigabitEthernet 3/0/1 changes to Gigabit

Página 7 - Contents

6 For more information about physical interfaces that can be used for IRF links, see "IRF physical interface requirements." For more inform

Página 8

7 IRF split IRF split occurs when an IRF fabric breaks up into multiple IRF fabrics because of IRF link failures, as shown in Figure 4. The split IRF

Página 9

8 1. Current master, even if a new member has higher priority. When an IRF fabric is being formed, all members consider themselves as the master. T

Página 10 - IRF overview

9 Figure 6 BFD MAD scenario To use BFD MAD: • Set up dedicated BFD MAD link between each pair of IRF members or between each IRF member and the in

Página 11 - IRF functionality

10 Collision handling MAD mechanisms remove multi-active collisions by setting one IRF fabric to the Detect state and other IRF fabrics to the Recove

Página 12 - Link redundancy

Copyright © 2015, Hangzhou H3C Technologies Co., Ltd. and its licensors All rights reserved No part of this manual may be reproduced or transmitted

Página 13 - Basic concepts

11 MAD mechanism Advantages Disadvantages Application scenario ARP MAD • No intermediate device is required. • Intermediate device, if used, can c

Página 14 - IRF port

12 Figure 7 BFD MAD scenario BFD MAD (distributed devices) BFD MAD can work with or without intermediate devices. Figure 8 shows a typical BFD MAD

Página 15 - IRF domain ID

13 Figure 8 BFD MAD scenario ARP MAD ARP MAD is available only for distributed devices. ARP MAD detects multi-active collisions by using extended A

Página 16 - Master election

14 Figure 9 ARP MAD scenario Each IRF member compares the domain ID and the active ID in incoming extended ARP packets with its domain ID and activ

Página 17 - Detection

15 Figure 10 ND MAD scenario Each IRF member device compares the domain ID and the active ID in incoming NS packets with its domain ID and active I

Página 18

16 Setting up an IRF fabric (centralized IRF devices) This chapter guides you through the IRF fabric setup procedure for centralized IRF devices. Har

Página 19 - MAD mechanisms

17 Feature compatibility and configuration restrictions To form an IRF fabric, all member devices in the IRF fabric must use the same ACL hardware mo

Página 20

18 Tasks at a glance Remarks 11. (Optional.) Setting the IRF link down report delay N/A 12. (Optional.) Configuring BFD MAD N/A 13. (Optional.) Ex

Página 21

19 Step Command Remarks 3. (Optional.) Save the configuration. save If you have bound physical interfaces to IRF ports or assigned member priority,

Página 22 - ARP MAD

20 Binding physical interfaces to IRF ports When you bind physical interfaces to IRF ports, follow these guidelines: • Follow the restrictions in &q

Página 23 - Internet

Preface The H3C firewall devices configuration guides (Comware V7) describe the software features and configuration procedures for the Comware V7-base

Página 24

21 Step Command Remarks 8. Enter interface view or interface range view. • Enter interface range view: { Method 1: interface range { interface-typ

Página 25 - Hardware compatibility

22 Configuring a member device description Step Command Remarks 1. Enter system view. system-view N/A 2. Configure a description for a member devi

Página 26 - Configuration backup

23 Step Command Remarks 3. Configure a port-specific load sharing mode. irf-port load-sharing mode { destination-ip | destination-mac | source-ip |

Página 27

24 Enabling software auto-update for software image synchronization IMPORTANT: To ensure a successful software auto-update in a multi-user environme

Página 28

25 Setting the IRF link down report delay To prevent frequent IRF splits and merges when IRF links flap, configure the IRF ports to delay reporting l

Página 29 - { Method 2:

26 Configuration procedure To configure BFD MAD: Step Command Remarks 1. Enter system view. system-view N/A 2. (Optional.) Assign a domain ID to

Página 30 - Accessing the IRF fabric

27 Excluding a port from the shutdown action upon detection of multi-active collision By default, all ports except the console and IRF physical inter

Página 31

28 Figure 12 Recovering the IRF fabric If the active IRF fabric fails before the IRF link is recovered (see Figure 13), use the mad restore command

Página 32

29 Displaying and maintaining an IRF fabric Execute display commands in any view. Task Command Display information about all IRF members. display ir

Página 33 - Configuration procedure

30 Configuration procedure 1. Configure Device A: # Bind Ten-GigabitEthernet 1/0/24 to IRF port 1/2, and save the configuration. <Sysname> sys

Página 34 - Configuring BFD MAD

Conventions This section describes the conventions used in this document. Command conventions Convention Description Boldface Bold text represents co

Página 35

31 [Sysname] interface route-aggregation 3 [Sysname-Route-Aggregation3] quit # Add GigabitEthernet 1/0/1 and GigabitEthernet 2/0/1 to aggregation gro

Página 36 - Recovering an IRF fabric

32 Setting up an IRF fabric (distributed devices) This chapter guides you through the IRF fabric setup procedure for M9000 security gateways. Hardwa

Página 37 - 1. Enter system view

33 • You must use all or none of the four 10-GE breakout interfaces for IRF links. The four breakout interfaces can be bound to different IRF ports.

Página 38 - Network requirements

34 Tasks at a glance Remarks 7. (Optional.) Configuring IRF member devices in IRF mode: { Changing the member ID of a device { Changing the priori

Página 39

35 Step Command Remarks 1. (Optional.) Verify the member ID assignment status. display irf configuration Check the MemberID field. If the device doe

Página 40

36 Step Command Remarks 3. Bind a physical interface to the IRF port. port group interface interface-type interface-number [ mode { enhanced | norma

Página 41

37 Setting the operating mode to IRF mode By default, the device operates in standalone mode. To assign the device to an IRF fabric, you must change

Página 42 - Connecting IRF ports

38 Changing the member ID of a device CAUTION: In IRF mode, an IRF member ID change can invalidate member ID-related settings and cause data loss. B

Página 43

39 To configure IRF ports: Step Command Remarks 1. Enter system view. system-view N/A 2. Enter Ethernet interface view or interface range view. •

Página 44

40 Step Command Remarks 8. Enter interface view or interface range view. • Enter interface range view: { Method 1: interface range { interface-typ

Página 45

Network topology icons Represents a generic network device, such as a router, switch, or firewall. Represents a routing-capable device, such as a ro

Página 46

41 Step Command Remarks 2. Enable IRF auto-merge. irf auto-merge enable By default, this feature is enabled. Configuring a member device descriptio

Página 47

42 To configure a port-specific load sharing mode for an IRF port: Step Command Remarks 1. Enter system view. system-view N/A 2. Enter IRF port v

Página 48

43 Step Command Remarks 2. Configure IRF bridge MAC persistence. • Retain the bridge MAC address permanently even if the address owner has left the

Página 49

44 If sufficient storage space is not available, the MPU automatically deletes the current software images. If the reclaimed space is still insuffici

Página 50

45 { In a context environment, if you change the IRF domain ID on one context, the IRF domain IDs on all other contexts change automatically. The ir

Página 51

46 Step Command Remarks 5. Enter interface view or interface range view. • Enter interface range view: { Method 1: interface range { interface-typ

Página 52 - Network

47 { Enable the IRF fabric to change its bridge MAC address as soon as the address owner leaves. { Create an ARP MAD VLAN and assign the ports on t

Página 53 - Configuring MAD

48 Step Command Remarks 11. Enable ARP MAD. mad arp enable By default, ARP MAD is disabled. Configuring ND MAD When you use ND MAD, follow these gu

Página 54

49 Step Command Remarks 7. Assign the port or the range of ports to the ND MAD VLAN. • Assign the port to the VLAN as an access port: port access

Página 55

50 Figure 16 Recovering the IRF fabric If the active IRF fabric fails before the IRF link is recovered (see Figure 17), use the mad restore command

Página 56

Obtaining documentation Access the most up-to-date H3C product documentation on the World Wide Web at http://www.h3c.com. Click the following links to

Página 57

51 Displaying and maintaining an IRF fabric Execute display commands in any view. Task Command Display information about all IRF members. display ir

Página 58

52 Figure 18 Network diagram Configuration procedure 1. Configure Device A: # Assign member ID 1 to Device A, and bind Ten-GigabitEthernet 3/0/1 t

Página 59

53 Device A becomes a one-chassis IRF fabric. 2. Configure Device B: # Assign member ID 2 to Device B, and bind Ten-GigabitEthernet 3/0/1 to IRF-por

Página 60

54 [Sysname] interface gigabitethernet 2/4/0/1 [Sysname-gigabitethernet2/4/0/1] undo stp enable ARP MAD-enabled IRF configuration example Network req

Página 61

55 Do you want to convert the content of the next startup configuration file flash:/startup.cfg to make it available in IRF mode? [Y/N]:y Please wa

Página 62

56 [Sysname] undo irf mac-address persistent # Set the domain ID of the IRF fabric to 1. [Sysname] irf domain 1 # Create VLAN 3, and add GigabitEther

Página 63

57 Figure 20 Network diagram Configuration procedure 1. Configure Device A: # Assign member ID 1 to Device A, and bind Ten-GigabitEthernet 3/0/1 t

Página 64

58 [Sysname] irf member 2 Info: Member ID change will take effect after the member reboots and operates in IRF mode. [Sysname] irf-port 1 [Sysname-

Página 65

59 [Sysname-Vlan-interface3] mad nd enable You need to assign a domain ID (range: 0-4294967295) [Current domain is: 1]: The assigned domain ID is

Página 66

60 Configuration procedure 1. Identify the master. <IRF> display irf MemberID Slot Role Priority CPU-Mac Description *+1

Página 67

i Contents IRF overview ·····························································································································

Página 68

61 Now rebooting, please wait... Device A automatically reboots to complete the operating mode change. 6. Log in to Device B and change its operati

Página 69

62 Configuring contexts Overview A physical firewall or an IRF fabric can be virtualized into multiple logical firewalls called contexts. Each contex

Página 70

63 • Manage the entire physical firewall. • Create and delete non-default contexts (for example, Context 1, Context 2, and Context 3 in Figure 22).

Página 71 - Configuring contexts

64 • All contexts without the VLAN-unshared attribute share the same VLAN resources (VLAN 1 through VLAN 4094). You create VLANs on the default cont

Página 72 - Creating contexts

65 Assigning a context to a security engine group A context assigned to a security engine group resides on all security engines in the group. You can

Página 73

66 • Use the display context resource command to view the amount of disk space that has been used by the context before assigning disk space to the

Página 74

67 Assigning interfaces to a context By default, all interfaces belong to the default context. A non-default context cannot use any interfaces. To en

Página 75

68 Hardware Resource limits compatibility F5020/F5040 No M9006/M9010/M9014 Yes VFW1000 No Setting a throughput threshold This feature limits the thr

Página 76 - Assigning VLANs to a context

69 Setting the upper limit of session establishment rate This feature limits the number of sessions that can be established per second for a context.

Página 77

70 Task Command Display contexts. display context [ name context-name ] Display interfaces assigned to contexts. display context [ name context-name

Página 78 - Accessing a context

ii Configuring a member device description ··········································································································

Página 79

71 Configuration procedure 1. Configure security engine group test: # Create security engine group test. <Sysname> system-view [Sysname] blade

Página 80

72 [Sysname-context-3-cnt2] allocate interface gigabitethernet 1/0/2 gigabitethernet 1/0/12 [Sysname-context-3-cnt2] quit 4. Configure context cnt3:

Página 81 - Verifying the configuration

73 Index A B C D E F G H I M O P R S A Accessing a context,69 Accessing the IRF fabric,21 Accessing the IRF fabric,37 Assigning a member ID to each

Página 82 - A B C D E F G H I M O P R S

iii ND MAD-enabled IRF configuration example ···································································································· 56

Modelos relacionados H3C SecPath F5040 | H3C VMSG VFW1000 |

Comentários a estes Manuais

Sem comentários