Configuration Command and State Information Backup

mhkabir1952
mhkabir1952  Diamond  (1)
7 years 10 months ago  View: 1120  Reply: 3
1F

Currently, the dual-system hot backup function on the Eudemon supports:

  • Configuration commands backup
  • Connection state information backup

Three ways are available for backing up the preceding information:

  • Automatic backup
  • Manual backup
  • Fast backup

Backed up Information

The backed up information includes:

  • State information

    The following state information is backed up:

    • Session entries created by the Eudemon
    • Source IP address monitoring table
    • Interface board dynamic Address Resolution Protocol (ARP) entries
    • Servermap entries include the Servermap entries produced when using QQ, MSN, Simple Traversal of UDP Through Network Address Translators (STUN) protocol, NAT Server, NO-PAT address allocation entry, and the ASPF in the process of fast backup
    • Address mapping entries of Application Specific Packet Filter (ASPF)
  • IPSec SA
  • Configuration commands

    The following configuration commands are backed up:

    • Access Control List (ACL) filtering commands
    • Attack defense commands
    • Blacklist commands, including commands for enabling blacklists and manually adding blacklist entries
    • Log commands
    • NAT commands, including commands for the NAT address pool and NAT Server, and commands applied in the interzones
    • Zone commands, including commands for creating security zones, setting security zone priority, adding interfaces to a security zone, and configuring interzones
    • ASPF commands
    • AAA commands
    • IPSec commands
    • Commands for clearing session entries
    • Commands for clearing configurations

Direction for Backing Up Information

State information is backed up from the master to the backup. If the two Eudemon firewalls used in load balancing and dual-system hot backup are the masters of two management groups, the connection state information is backed up on the two firewalls. The system determines which connection state information is backed up.

Configuration commands can be backed up in one direction. In other words, configuration commands can be backed from the primary configuration device to the secondary configuration device only.

Armetta
Armetta  Diamond 
7 years 10 months ago
2F
documentation very useful for my job

foisal
foisal  Gold 
7 years 10 months ago
3F

this doc is very useful

user_2837311
user_2837311  Diamond 
4 years 6 days ago
4F
Useful document, thanks