H3c-technologies H3C SecPath F5020 Manual de usuario

Busca en linea o descarga Manual de usuario para La Seguridad H3c-technologies H3C SecPath F5020. H3C Technologies H3C SecPath F5020 User Manual Manual de usuario

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 82
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 0
H3C Firewall Devices
Virtual Technologies
Configuration Guide (Comware V7)
Hangzhou H3C Technologies Co., Ltd.
http://www.h3c.com
Software version:
F5020/F5040 firewalls ESS9304
M9006/M9010/M9014 security
g
ateways
ESS9114
VFW1000 virtual firewalls ESS9204
Document version: 5W100-20150116
Vista de pagina 0
1 2 3 4 5 6 ... 81 82

Indice de contenidos

Pagina 1 - H3C Firewall Devices

H3C Firewall DevicesVirtual TechnologiesConfiguration Guide (Comware V7) Hangzhou H3C Technologies Co., Ltd. http://www.h3c.com So

Pagina 2

1 IRF overview H3C Intelligent Resilient Framework (IRF) technology combines multiple physical devices into one virtual system to provide data center

Pagina 3 - Preface

2 IRF functionality Network topology A security device IRF fabric can only use the daisy-chain topology. The device does not support the full mesh or

Pagina 4 - Conventions

3 Figure 2 Two-chassis IRF fabric implementation schematic diagram Single point of management An IRF fabric is accessible at a single IP address on

Pagina 5 - Port numbering in examples

4 Multichassis link aggregation You can use the Ethernet link aggregation feature to aggregate the physical links between an upstream or downstream d

Pagina 6 - Documentation feedback

5 • After you assign a distributed device with a member ID of 2 to an IRF fabric, the name of the interface GigabitEthernet 3/0/1 changes to Gigabit

Pagina 7 - Contents

6 For more information about physical interfaces that can be used for IRF links, see "IRF physical interface requirements." For more inform

Pagina 8

7 IRF split IRF split occurs when an IRF fabric breaks up into multiple IRF fabrics because of IRF link failures, as shown in Figure 4. The split IRF

Pagina 9

8 1. Current master, even if a new member has higher priority. When an IRF fabric is being formed, all members consider themselves as the master. T

Pagina 10 - IRF overview

9 Figure 6 BFD MAD scenario To use BFD MAD: • Set up dedicated BFD MAD link between each pair of IRF members or between each IRF member and the in

Pagina 11 - IRF functionality

10 Collision handling MAD mechanisms remove multi-active collisions by setting one IRF fabric to the Detect state and other IRF fabrics to the Recove

Pagina 12 - Link redundancy

Copyright © 2015, Hangzhou H3C Technologies Co., Ltd. and its licensors All rights reserved No part of this manual may be reproduced or transmitted

Pagina 13 - Basic concepts

11 MAD mechanism Advantages Disadvantages Application scenario ARP MAD • No intermediate device is required. • Intermediate device, if used, can c

Pagina 14 - IRF port

12 Figure 7 BFD MAD scenario BFD MAD (distributed devices) BFD MAD can work with or without intermediate devices. Figure 8 shows a typical BFD MAD

Pagina 15 - IRF domain ID

13 Figure 8 BFD MAD scenario ARP MAD ARP MAD is available only for distributed devices. ARP MAD detects multi-active collisions by using extended A

Pagina 16 - Master election

14 Figure 9 ARP MAD scenario Each IRF member compares the domain ID and the active ID in incoming extended ARP packets with its domain ID and activ

Pagina 17 - Detection

15 Figure 10 ND MAD scenario Each IRF member device compares the domain ID and the active ID in incoming NS packets with its domain ID and active I

Pagina 18

16 Setting up an IRF fabric (centralized IRF devices) This chapter guides you through the IRF fabric setup procedure for centralized IRF devices. Har

Pagina 19 - MAD mechanisms

17 Feature compatibility and configuration restrictions To form an IRF fabric, all member devices in the IRF fabric must use the same ACL hardware mo

Pagina 20

18 Tasks at a glance Remarks 11. (Optional.) Setting the IRF link down report delay N/A 12. (Optional.) Configuring BFD MAD N/A 13. (Optional.) Ex

Pagina 21

19 Step Command Remarks 3. (Optional.) Save the configuration. save If you have bound physical interfaces to IRF ports or assigned member priority,

Pagina 22 - ARP MAD

20 Binding physical interfaces to IRF ports When you bind physical interfaces to IRF ports, follow these guidelines: • Follow the restrictions in &q

Pagina 23 - Internet

Preface The H3C firewall devices configuration guides (Comware V7) describe the software features and configuration procedures for the Comware V7-base

Pagina 24

21 Step Command Remarks 8. Enter interface view or interface range view. • Enter interface range view: { Method 1: interface range { interface-typ

Pagina 25 - Hardware compatibility

22 Configuring a member device description Step Command Remarks 1. Enter system view. system-view N/A 2. Configure a description for a member devi

Pagina 26 - Configuration backup

23 Step Command Remarks 3. Configure a port-specific load sharing mode. irf-port load-sharing mode { destination-ip | destination-mac | source-ip |

Pagina 27

24 Enabling software auto-update for software image synchronization IMPORTANT: To ensure a successful software auto-update in a multi-user environme

Pagina 28

25 Setting the IRF link down report delay To prevent frequent IRF splits and merges when IRF links flap, configure the IRF ports to delay reporting l

Pagina 29 - { Method 2:

26 Configuration procedure To configure BFD MAD: Step Command Remarks 1. Enter system view. system-view N/A 2. (Optional.) Assign a domain ID to

Pagina 30 - Accessing the IRF fabric

27 Excluding a port from the shutdown action upon detection of multi-active collision By default, all ports except the console and IRF physical inter

Pagina 31

28 Figure 12 Recovering the IRF fabric If the active IRF fabric fails before the IRF link is recovered (see Figure 13), use the mad restore command

Pagina 32

29 Displaying and maintaining an IRF fabric Execute display commands in any view. Task Command Display information about all IRF members. display ir

Pagina 33 - Configuration procedure

30 Configuration procedure 1. Configure Device A: # Bind Ten-GigabitEthernet 1/0/24 to IRF port 1/2, and save the configuration. <Sysname> sys

Pagina 34 - Configuring BFD MAD

Conventions This section describes the conventions used in this document. Command conventions Convention Description Boldface Bold text represents co

Pagina 35

31 [Sysname] interface route-aggregation 3 [Sysname-Route-Aggregation3] quit # Add GigabitEthernet 1/0/1 and GigabitEthernet 2/0/1 to aggregation gro

Pagina 36 - Recovering an IRF fabric

32 Setting up an IRF fabric (distributed devices) This chapter guides you through the IRF fabric setup procedure for M9000 security gateways. Hardwa

Pagina 37 - 1. Enter system view

33 • You must use all or none of the four 10-GE breakout interfaces for IRF links. The four breakout interfaces can be bound to different IRF ports.

Pagina 38 - Network requirements

34 Tasks at a glance Remarks 7. (Optional.) Configuring IRF member devices in IRF mode: { Changing the member ID of a device { Changing the priori

Pagina 39

35 Step Command Remarks 1. (Optional.) Verify the member ID assignment status. display irf configuration Check the MemberID field. If the device doe

Pagina 40

36 Step Command Remarks 3. Bind a physical interface to the IRF port. port group interface interface-type interface-number [ mode { enhanced | norma

Pagina 41

37 Setting the operating mode to IRF mode By default, the device operates in standalone mode. To assign the device to an IRF fabric, you must change

Pagina 42 - Connecting IRF ports

38 Changing the member ID of a device CAUTION: In IRF mode, an IRF member ID change can invalidate member ID-related settings and cause data loss. B

Pagina 43

39 To configure IRF ports: Step Command Remarks 1. Enter system view. system-view N/A 2. Enter Ethernet interface view or interface range view. •

Pagina 44

40 Step Command Remarks 8. Enter interface view or interface range view. • Enter interface range view: { Method 1: interface range { interface-typ

Pagina 45

Network topology icons Represents a generic network device, such as a router, switch, or firewall. Represents a routing-capable device, such as a ro

Pagina 46

41 Step Command Remarks 2. Enable IRF auto-merge. irf auto-merge enable By default, this feature is enabled. Configuring a member device descriptio

Pagina 47

42 To configure a port-specific load sharing mode for an IRF port: Step Command Remarks 1. Enter system view. system-view N/A 2. Enter IRF port v

Pagina 48

43 Step Command Remarks 2. Configure IRF bridge MAC persistence. • Retain the bridge MAC address permanently even if the address owner has left the

Pagina 49

44 If sufficient storage space is not available, the MPU automatically deletes the current software images. If the reclaimed space is still insuffici

Pagina 50

45 { In a context environment, if you change the IRF domain ID on one context, the IRF domain IDs on all other contexts change automatically. The ir

Pagina 51

46 Step Command Remarks 5. Enter interface view or interface range view. • Enter interface range view: { Method 1: interface range { interface-typ

Pagina 52 - Network

47 { Enable the IRF fabric to change its bridge MAC address as soon as the address owner leaves. { Create an ARP MAD VLAN and assign the ports on t

Pagina 53 - Configuring MAD

48 Step Command Remarks 11. Enable ARP MAD. mad arp enable By default, ARP MAD is disabled. Configuring ND MAD When you use ND MAD, follow these gu

Pagina 54

49 Step Command Remarks 7. Assign the port or the range of ports to the ND MAD VLAN. • Assign the port to the VLAN as an access port: port access

Pagina 55

50 Figure 16 Recovering the IRF fabric If the active IRF fabric fails before the IRF link is recovered (see Figure 17), use the mad restore command

Pagina 56

Obtaining documentation Access the most up-to-date H3C product documentation on the World Wide Web at http://www.h3c.com. Click the following links to

Pagina 57

51 Displaying and maintaining an IRF fabric Execute display commands in any view. Task Command Display information about all IRF members. display ir

Pagina 58

52 Figure 18 Network diagram Configuration procedure 1. Configure Device A: # Assign member ID 1 to Device A, and bind Ten-GigabitEthernet 3/0/1 t

Pagina 59

53 Device A becomes a one-chassis IRF fabric. 2. Configure Device B: # Assign member ID 2 to Device B, and bind Ten-GigabitEthernet 3/0/1 to IRF-por

Pagina 60

54 [Sysname] interface gigabitethernet 2/4/0/1 [Sysname-gigabitethernet2/4/0/1] undo stp enable ARP MAD-enabled IRF configuration example Network req

Pagina 61

55 Do you want to convert the content of the next startup configuration file flash:/startup.cfg to make it available in IRF mode? [Y/N]:y Please wa

Pagina 62

56 [Sysname] undo irf mac-address persistent # Set the domain ID of the IRF fabric to 1. [Sysname] irf domain 1 # Create VLAN 3, and add GigabitEther

Pagina 63

57 Figure 20 Network diagram Configuration procedure 1. Configure Device A: # Assign member ID 1 to Device A, and bind Ten-GigabitEthernet 3/0/1 t

Pagina 64

58 [Sysname] irf member 2 Info: Member ID change will take effect after the member reboots and operates in IRF mode. [Sysname] irf-port 1 [Sysname-

Pagina 65

59 [Sysname-Vlan-interface3] mad nd enable You need to assign a domain ID (range: 0-4294967295) [Current domain is: 1]: The assigned domain ID is

Pagina 66

60 Configuration procedure 1. Identify the master. <IRF> display irf MemberID Slot Role Priority CPU-Mac Description *+1

Pagina 67

i Contents IRF overview ·····························································································································

Pagina 68

61 Now rebooting, please wait... Device A automatically reboots to complete the operating mode change. 6. Log in to Device B and change its operati

Pagina 69

62 Configuring contexts Overview A physical firewall or an IRF fabric can be virtualized into multiple logical firewalls called contexts. Each contex

Pagina 70

63 • Manage the entire physical firewall. • Create and delete non-default contexts (for example, Context 1, Context 2, and Context 3 in Figure 22).

Pagina 71 - Configuring contexts

64 • All contexts without the VLAN-unshared attribute share the same VLAN resources (VLAN 1 through VLAN 4094). You create VLANs on the default cont

Pagina 72 - Creating contexts

65 Assigning a context to a security engine group A context assigned to a security engine group resides on all security engines in the group. You can

Pagina 73

66 • Use the display context resource command to view the amount of disk space that has been used by the context before assigning disk space to the

Pagina 74

67 Assigning interfaces to a context By default, all interfaces belong to the default context. A non-default context cannot use any interfaces. To en

Pagina 75

68 Hardware Resource limits compatibility F5020/F5040 No M9006/M9010/M9014 Yes VFW1000 No Setting a throughput threshold This feature limits the thr

Pagina 76 - Assigning VLANs to a context

69 Setting the upper limit of session establishment rate This feature limits the number of sessions that can be established per second for a context.

Pagina 77

70 Task Command Display contexts. display context [ name context-name ] Display interfaces assigned to contexts. display context [ name context-name

Pagina 78 - Accessing a context

ii Configuring a member device description ··········································································································

Pagina 79

71 Configuration procedure 1. Configure security engine group test: # Create security engine group test. <Sysname> system-view [Sysname] blade

Pagina 80

72 [Sysname-context-3-cnt2] allocate interface gigabitethernet 1/0/2 gigabitethernet 1/0/12 [Sysname-context-3-cnt2] quit 4. Configure context cnt3:

Pagina 81 - Verifying the configuration

73 Index A B C D E F G H I M O P R S A Accessing a context,69 Accessing the IRF fabric,21 Accessing the IRF fabric,37 Assigning a member ID to each

Pagina 82 - A B C D E F G H I M O P R S

iii ND MAD-enabled IRF configuration example ···································································································· 56

Modelos relacionados H3C SecPath F5040 | H3C VMSG VFW1000 |

Comentarios a estos manuales

Sin comentarios