Dual-System Hsb Overview; Dual-System Hsb Features Supported By The Spu - Huawei S9700 Series Configuration Manual

Terabit routing switches spu
Hide thumbs Also See for S9700 Series:
Table of Contents

Advertisement

S9700 Core Routing Switch
Configuration Guide - SPU

7.1 Dual-System HSB Overview

This section describes the dual-system HSB concepts.
Firewalls are the nodes that traffic must pass through on a network. If firewalls are faulty, services
are interrupted on the network. The reliability of firewalls greatly affects HA of the network.
Using dual-system HSB, the session table can be synchronized between two firewalls in real
time. If a firewall is faulty, user sessions are not interrupted. The HA of user connections is thus
improved.
To ensure HA of a user network and prevent firewall faults from affecting communication
between security zones, enable the Virtual Router Redundancy Protocol (VRRP) is enabled
between firewalls and synchronize the firewall status between firewalls. As shown in
7-1, FWA and FWB constitute a VRRP backup group that function as a virtual FW.
l
l
l
Figure 7-1 Networking of dual-system HSB
Server

7.2 Dual-System HSB Features Supported by the SPU

This section describes the dual-system HSB features supported by the SPU.
Synchronization Channel and Heartbeat Detection
l
l
Issue 01 (2012-03-15)
NOTE
The S9700 firewall boards support dual-system HSB. In this document, firewall or FW refers to the dual-
system and S9700.
A host on the LAN only learns the IP address of the virtual FW, but does not learn IP
addresses of interfaces of FWA and FWB in the VRRP backup group.
A host on the LAN sets the default next hop address as the IP address of the virtual FW.
Then the host on the LAN communicates with other networks through the virtual FW.
In the VRRP backup group, one device is in active state, which is the master device such
as FWA shown in
Figure
device such as FWB shown in
PC
Internal network
VRRP Backup group
The firewalls synchronize data using a channel.
If the channel fails to be set up, an alarm is generated and recorded in to log.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
7-1. The other device is in backup state, which is the backup
Figure
7-1.
FWA: Master
FWB: Backup
7 Dual-System HSB Configuration
Network
VRRP Backup group
Figure
299

Advertisement

Table of Contents
loading

Table of Contents