当前位置:首页>微思动态>详情
全国免费电话 400-881-4699

在线留言

【每日必学】ASA Single-Mode Active. Standby Failover

发布作者:微思网络   发布时间:2017-05-16   浏览量:0


实验拓扑:


泉州CCNP培训教你ASA1 基本配置:

 

hostname ASA1 interface Ethernet0/0 nameif Outside security-level 0

 

ip address 11.1.1.254 255.255.255.0 standby 11.1.1.253 no shutdown

 

interface Ethernet0/1 nameif Inside security-level 100

 

ip address 22.1.1.254 255.255.255.0 standby 22.1.1.253 no shutdown

 

interface Ethernet0/3 no shutdown

 

ASA2 基本配置: interface Ethernet0/3 no shutdown

 

配置 Failover:

 

ASA1:

 

failover lan unit primary

failover lan interface FO Ethernet0/3

 

failover interface ip FO 10.1.1.1 255.255.255.0 standby 10.1.1.254 failover key cisco

failover

failover link FO Ethernet0/3

 

ASA2:

 

failover lan unit secondary

failover lan interface FO Ethernet0/3

 

failover interface ip FO 10.1.1.1 255.255.255.0 standby 10.1.1.254 failover key cisco

failover

failover link FO Ethernet0/3

 

R1 上验证:show failover

 

 

R2 上验证:show failover


测试:

 

R2  ping 或是 telnet  R1

 

telnet 11.1.1.1 后关闭交换机的接口(交换机连接到 Active 状态的 ASA Inside 或 Outside 的接口)

 

再查看 telnet 连接是否断开

 

手工改变设备的主用状态:

 

ASA1(config)# failover active

 

常用验证命令:

 

Show failover ,show conn , show run interface ,show run,show run failover


 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

ASA1 基本配置:

 

hostname ASA1 interface Ethernet0/0 nameif Outside security-level 0

 

ip address 11.1.1.254 255.255.255.0 standby 11.1.1.253 no shutdown

 

interface Ethernet0/1 nameif Inside security-level 100

 

ip address 22.1.1.254 255.255.255.0 standby 22.1.1.253 no shutdown

 

interface Ethernet0/3 no shutdown

 

ASA2 基本配置: interface Ethernet0/3 no shutdown


 

TEL:0592-2236681 - 1 - HTTP://WWW.XMWS.CN


微思网络,专注高端

 

配置 Failover:

 

ASA1:

 

failover lan unit primary

failover lan interface FO Ethernet0/3

 

failover interface ip FO 10.1.1.1 255.255.255.0 standby 10.1.1.254 failover key cisco

failover

failover link FO Ethernet0/3

 

ASA2:

 

failover lan unit secondary

failover lan interface FO Ethernet0/3

 

failover interface ip FO 10.1.1.1 255.255.255.0 standby 10.1.1.254 failover key cisco

failover

failover link FO Ethernet0/3

 

R1 上验证:show failover


 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

TEL:0592-2236681 - 2 - HTTP://WWW.XMWS.CN


微思网络,专注高端

 

R2 上验证:show failover

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

测试:

 

R2  ping 或是 telnet  R1

 

telnet 11.1.1.1 后关闭交换机的接口(交换机连接到 Active 状态的 ASA Inside 或 Outside 的接口)

 

再查看 telnet 连接是否断开

 

手工改变设备的主用状态:

 

ASA1(config)# failover active

 

常用验证命令:

 

Show failover ,show conn , show run interface ,show run,show run failover


 

返回顶部