Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
Objectives
2
NetScreen Redundancy Protocol
3
NSRP Active/Passive
X
Protected
Network HA Link
4
NSRP Active/Active
X
Protected
Network HA Link
5
NSRP Terminology
6
HA Link/Port/Zone
HA link
HA Zone
HA ports
7
NSRP Cluster
8
VSD/VSI/VSD Group
• Virtual Security
Device
– Logical representation
VSI E1 VSI E1
of a NetScreen
– VSD0 by default
VSD 0 VSD 0
• Virtual Security
Interface
– Logical representation VSI E2 VSI E2
of interfaces
VSD Group
• VSD Group
– 2 NetScreens sharing
VSD configuration
9
VSD States and Failover
– Preempt
VSD 0 VSD 0
• Backup
• Initial VSI E2 VSI E2
• Ineligible
• Inoperable
VSI E1 VSI E1
VSI E1 VSI E1
VSD VSD
Group id 0 Group id 0
Priority 50 VSD 0 VSD 0 Priority 100
Active Backup
VSI E2 VSI E2
11
NSRP VSD Group - Active/Active
VSD 10 VSD 11
Priority 50 Priority 50
Active VSI E1:10VSI E1:11 VSI E1:10 VSI E1:11 Active
VSD 11 VSD 10
Priority 100 Priority 100
Backup Backup
12
Run Time Objects (RTO)
13
Syncing Sessions
Master Backup
HA Link
Session established
E5 - HA
E8 E1
E1
E8
Zone 1 Internet
15
NSRP Configuration Steps – Active/Passive
On both devices
1. Assign interface to HA zone (if not using dedicated
HA ports)
2. Configure cluster settings
3. Configure interfaces to be monitored
4. Adjust VSD settings (if desired)
On one device
5. Change interfaces, policies, etc. as desired
• Changes will automatically be copied via HA link
16
1: Assign Interface to HA Zone
Network>Interfaces (Edit)
17
2: Configure Cluster Settings
Network>NSRP>Cluster
18
3: Set Interfaces for Monitoring
Network>NSRP>Monitor>TrackIP>Edit
Network>NSRP>Monitor>Interface>Edit
19
4: Adjust VSD settings
Network>NSRP>VSD Group>Configuration
20
Verifying NSRP Configuration
Network>NSRP>VSD Group
Network>NSRP>Monitor>Interface
21
Verifying NSRP Configuration
23
Factors that Affect Failover Time
• Heartbeat Messages
set nsrp vsd-group hb-threshold <number>
set nsrp vsd-group hb-interval <milliseconds>
• Switching technologies
– Spanning Tree Protocol
– Channeling, Bonding, PAgP
– Trunking protocols
24
Points to Consider
Good
Protected
Network
Better!
Protected
Network
25
What if HA Link Fails?
26
Network > NSRP > Link
NSRP-Lite
Untrust: Untrust:
1.1.1.1/24 2.2.2.2/24
Trust
10.1.1.1/24
27
Tuning Failover Behavior
• Monitored objects
– Interface
– Zone
– Target host
• Failover calculation
If FailedObjectWeight ≥ FailoverThreshold, fail over
• Defaults
– Failover threshold: 255
– Individual object weights: 255
– Therefore, by default, one failure will cause failover
28
Setting Device Failover Threshold
29
Adjusting Interface Weight
set nsrp monitor vsd id <group_num> monitor int <name> weight <1-255>
30
Adjusting Zone Weight
set nsrp monitor vsd id <group_num> monitor zone <name> weight <1-255>
31
IP Tracking
• Defaults
– IP Track Threshold: 255
– IP Track Weight: 255
– IP Address Weight: 1
• Reachability tested by ping (for remote hosts) or ARP
(for directly-connected hosts)
32
Configuring IP Tracking
1. Enable IP Tracking
– Set failure threshold for tracking
– Set weight for tracking
2. Configure tracked addresses
– Set tracking method and parameters
– Set weight per address
33
1: Enable IP Tracking
34
2: Configure Tracked Addresses – WebUI
36
Summary
• In this module we
– Discussed NSRP-related terms and concepts
– Configured NSRP Active/Passive setup
– Verifed NSRP operations
– Identified factors that affect failover time
– Configured NSRP Active/Active Setup
– Configured interface redundancy
– Tuned NSRP failover behavior
37
Review Questions
38
NSRP Active/Passive Demo
E5 - HA
E1
E7 E8 E2
E1
E2 E3 E4 E3
E4 E7 E8
39