Got it

High availability solution using IP-link on S12700 NGFW module [Case Sharing]

Latest reply: Oct 15, 2019 09:08:13 374 1 3 2

Hello everyone,

Today I will share with you High availability solution using IP-link on the S12700 NGFW module.

Project Background 

The customer wants to have an auto-failover solution on their WAN network to achieve an active-standby link going to two different ISPs for high availability. Currently, the S12700 has no fail-over solution and when the indirect link goes down, it needs to be switched to the backup link manually.

Project Solution 

There are two sites, the HQ and Branch between two different countries. There are two paths, L3 MPLS using static route and Internet using OSPF route. Configure IP-Link solution for detecting the status of the active link from HQ to Branch.    

Test Topology

mpls topy

Configuration

1. Configure IP-link for detecting the status of the active link from HQ to Branch.

[S12700-NGFW] ip-link check enable

[S12700-NGFW] ip-link 1 destination 10.117.167.229 interface Eth-Trunk 1 mode icmp next-hop 172.16.13.4

[S12700-NGFW] quit 

2. Configure two routes to Branch and bind the active route to IP-Link. When the active link becomes faulty, the backup route takes over service traffic.

[S12700-NGFW] ip route-static 10.117.167.228 30 172.16.13.4 description HQ_to_Branch

[S12700-NGFW] ip route-static 192.168.14.0 24 172.16.13.4 description Branch_LAN track ip-link 1

Test and Verification 

After the configuration, the HQ can detect the active link to the CN site. In case of link failure, the traffic will switch to the backup link.ping

That is all I want to share with you! Thank you!

  • x
  • convention:

rob9711
Created Oct 15, 2019 09:08:13 Helpful(0) Helpful(0)

Thanks for sharing
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."

My Followers

Login and enjoy all the member benefits

Login

Huawei Enterprise Support Community
Huawei Enterprise Support Community
Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.