Configuring VRRP when the firewall has only one public address

14

Set the interface IP address to any private address. The active and standby interface IP addresses must be on the same network segment. Set the VRRP group address to a public address.

Other related questions:
Can the mapping between IP addresses be configured when there is only one public IP address
The mapping between IP addresses can be configured only when there are multiple public IP addresses.

The AR router has only one public IP address, how to configure full port mapping?
When the AR router has only one public IP, it can not configure full port mapping, only when it has multiple public IP addresses, it can configure full mapping.

Whether the firewall supports configuring only VRRP
No. VRRP applies only to hot standby.

How to configure an AR to allow only one public IP address to access intranet servers
To configure an AR to allow only one public IP address to access intranet servers, configure an ACL when you configure a NAT server.
For example, you can perform the following configurations to allow only public address 1.1.1.1 to access the intranet server (public address 2.1.1.1 and private address 10.1.1.22):
Configure an ACL to permit the source IP address 1.1.1.1.
acl number 2005
 rule 5 permit source 1.1.1.1 0 
Configure a NAT server and bind the ACL.
interface GigabitEthernet0/0/3
 nat server protocol tcp global 2.1.1.1 ftp inside 10.1.1.22 ftp acl 2005                                                            

If you have more questions, you can seek help from following ways:
To iKnow To Live Chat
Scroll to top