首先,現(xiàn)場的場景是上聯(lián)二層SW踩验,這個時候上聯(lián)SW上行口down掉之后涉茧,上聯(lián)SW的下行接口不會down赴恨,導(dǎo)致Fw感知不到光貓的接口有問題,所以要配置track+nqa伴栓,并且在RBM視圖下調(diào)用伦连,一定要記得,先保證track的狀態(tài)是postive的
然后再在RBM視圖下引用
nqa entry admin rbm
type icmp-echo
? destination ip x.x.x.x
? frequency 100
? out interface GigabitEthernet1/0/28
? reaction 1 checked-element probe-fail threshold-type consecutive 5 action-type trigger-only
#
nqa entry admin rbm1
type icmp-echo
? destination ip x.x.x.x
? frequency 100
? out interface GigabitEthernet1/0/29
? reaction 1 checked-element probe-fail threshold-type consecutive 5 action-type trigger-only
nqa schedule admin rbm start-time now lifetime forever
nqa schedule admin rbm1 start-time now lifetime forever
track 4 nqa entry admin rbm reaction 1
track 5 nqa entry admin rbm1 reaction 1
remote-backup group
backup-mode dual-active
data-channel interface Route-Aggregation1
configuration sync-check interval 1
delay-time 1
track 4? ? ?
track 5
local-ip 10.10.10.2
remote-ip 10.10.10.1
device-role primary
主設(shè)備上關(guān)于路由的配置要這樣配置:
ip route-static 0.0.0.0 0 x.x.x.x track 4
ip route-static 0.0.0.0 0 x.x.x.x track 5 preference 70
其次钳垮,在兩個出口下使用nat outbound 要使用地址池惑淳,并且要是對應(yīng)的vrrp的虛地址
否則RBM主備切換,公網(wǎng)的流量回不來饺窿,并且對應(yīng)地址池下要綁定VRRP的VID歧焦,否則會報地址沖突
nat address-group 1
address x.x.x.x x.x.x.x
vrrp vrid 1
#
nat address-group 2
address x.x.x.x x.x.x.x
vrrp vrid 2
interface GigabitEthernet1/0/28
port link-mode route
combo enable fiber
最后,要開啟nat 鏈路轉(zhuǎn)換重新創(chuàng)建會話短荐,否則持續(xù)命中之前的會話倚舀,會有問題
nat link-switch recreate-session
#
補充一下叹哭,備機的RBM中不用track4 與track5