组网图形
组网需求
通过配置根据链路优先级主备备份,FW可以在主接口链路故障时,使用备份接口链路转发流量,提高传输的可靠性。
配置思路
由于企业希望优先使用ISP1链路,所以全局智能选路方式可以设置为根据链路优先级主备备份,指定2条ISP1链路的优先级均为2,ISP2链路的优先级为1。而税务申报业务需要优先使用ISP2链路,所以要针对税务申报应用配置策略路由智能选路,选路方式也是根据链路优先级主备备份,并指定ISP2链路的优先级为2,2条ISP1链路的优先级均为1。为了保证主接口链路故障时,FW可以使用备份接口链路转发流量,还需要配置健康检查功能。
说明:
本例着重介绍智能选路相关的配置,其余配置如NAT请根据实际组网进行配置。
操作步骤
<FW> system-view [FW] healthcheck enable [FW] healthcheck name isp1_health_01 [FW-healthcheck-isp1_health_01] destination 3.3.10.10 interface GigabitEthernet 1/0/1 protocol tcp-simple destination-port 10001 [FW-healthcheck-isp1_health_01] destination 3.3.10.11 interface GigabitEthernet 1/0/1 protocol tcp-simple destination-port 10002 [FW-healthcheck-isp1_health_01] quit [FW] healthcheck name isp1_health_02 [FW-healthcheck-isp1_health_02] destination 3.3.10.12 interface GigabitEthernet 1/0/2 protocol tcp-simple destination-port 10001 [FW-healthcheck-isp1_health_02] destination 3.3.10.13 interface GigabitEthernet 1/0/2 protocol tcp-simple destination-port 10002 [FW-healthcheck-isp1_health_02] quit [FW] healthcheck name isp2_health [FW-healthcheck-isp2_health] destination 9.9.20.20 interface GigabitEthernet 1/0/7 protocol tcp-simple destination-port 10003 [FW-healthcheck-isp2_health] destination 9.9.20.21 interface GigabitEthernet 1/0/7 protocol tcp-simple destination-port 10004 [FW-healthcheck-isp2_health] quit
[FW] interface GigabitEthernet 1/0/1 [FW-GigabitEthernet1/0/1] ip address 1.1.1.1 255.255.255.0 [FW-GigabitEthernet1/0/1] gateway 1.1.1.254 [FW-GigabitEthernet1/0/1] bandwidth ingress 50000 [FW-GigabitEthernet1/0/1] bandwidth egress 50000 [FW-GigabitEthernet1/0/1] healthcheck isp1_health_01 [FW-GigabitEthernet1/0/1] quit [FW] interface GigabitEthernet 1/0/2 [FW-GigabitEthernet1/0/2] ip address 1.1.2.2 255.255.255.0 [FW-GigabitEthernet1/0/2] gateway 1.1.2.254 [FW-GigabitEthernet1/0/2] bandwidth ingress 50000 [FW-GigabitEthernet1/0/2] bandwidth egress 50000 [FW-GigabitEthernet1/0/2] healthcheck isp1_health_02 [FW-GigabitEthernet1/0/2] quit [FW] interface GigabitEthernet 1/0/3 [FW-GigabitEthernet1/0/3] ip address 10.3.0.1 255.255.255.0 [FW-GigabitEthernet1/0/3] quit [FW] interface GigabitEthernet 1/0/7 [FW-GigabitEthernet1/0/7] ip address 2.2.2.2 255.255.255.0 [FW-GigabitEthernet1/0/7] gateway 2.2.2.254 [FW-GigabitEthernet1/0/7] bandwidth ingress 10000 [FW-GigabitEthernet1/0/7] bandwidth egress 10000 [FW-GigabitEthernet1/0/7] healthcheck isp2_health [FW-GigabitEthernet1/0/7] quit
[FW] interface-group 1 name ifgrp1 [FW-interface-group-1] add interface GigabitEthernet 1/0/1 [FW-interface-group-1] add interface GigabitEthernet 1/0/2 [FW-interface-group-1] quit
[FW] multi-interface [FW-multi-inter] mode priority-of-userdefine [FW-multi-inter] add interface-group ifgrp1 priority 2 [FW-multi-inter] add interface GigabitEthernet1/0/7 [FW-multi-inter] quit
[FW] sa [FW-sa] user-defined-application name UD_tax_system [FW-sa-user-defined-app-UD_tax_system] rule name 1 [FW-sa-user-defined-app-UD_tax_system-rule-1] ip-address 8.8.8.8 32 [FW-sa-user-defined-app-UD_tax_system-rule-1] port 20001 [FW-sa-user-defined-app-UD_tax_system-rule-1] quit [FW-sa-user-defined-app-UD_tax_system] quit [FW-sa] quit
[FW] policy-based-route [FW-policy-pbr] rule name tax_system [FW-policy-pbr-rule-tax_system] source-zone trust [FW-policy-pbr-rule-tax_system] application app UD_tax_system [FW-policy-pbr-rule-tax_system] action pbr egress-interface multi-interface [FW-policy-pbr-rule-tax_system-multi-inter] mode priority-of-userdefine [FW-policy-pbr-rule-tax_system-multi-inter] add interface-group ifgrp1 [FW-policy-pbr-rule-tax_system-multi-inter] add interface GigabitEthernet1/0/7 priority 2 [FW-policy-pbr-rule-tax_system-multi-inter] quit [FW-policy-pbr] quit
[FW] firewall zone trust [FW-zone-trust] add interface GigabitEthernet 1/0/3 [FW-zone-trust] quit [FW] firewall zone untrust [FW-zone-untrust] add interface GigabitEthernet 1/0/1 [FW-zone-untrust] add interface GigabitEthernet 1/0/2 [FW-zone-untrust] add interface GigabitEthernet 1/0/7 [FW-zone-untrust] quit
[FW] security-policy [FW-policy-security] rule name policy_sec_local_untrust [FW-policy-security-rule-policy_sec_local_untrust] source-zone local [FW-policy-security-rule-policy_sec_local_untrust] destination-zone untrust [FW-policy-security-rule-policy_sec_local_untrust] destination-address 3.3.10.10 32 [FW-policy-security-rule-policy_sec_local_untrust] destination-address 3.3.10.11 32 [FW-policy-security-rule-policy_sec_local_untrust] destination-address 3.3.10.12 32 [FW-policy-security-rule-policy_sec_local_untrust] destination-address 3.3.10.13 32 [FW-policy-security-rule-policy_sec_local_untrust] destination-address 9.9.20.20 32 [FW-policy-security-rule-policy_sec_local_untrust] destination-address 9.9.20.21 32 [FW-policy-security-rule-policy_sec_local_untrust] service tcp [FW-policy-security-rule-policy_sec_local_untrust] action permit [FW-policy-security-rule-policy_sec_local_untrust] quit
[FW-policy-security] rule name policy_sec_trust_untrust [FW-policy-security-rule-policy_sec_trust_untrust] source-zone trust [FW-policy-security-rule-policy_sec_trust_untrust] destination-zone untrust [FW-policy-security-rule-policy_sec_trust_untrust] source-address 10.3.0.0 24 [FW-policy-security-rule-policy_sec_trust_untrust] action permit [FW-policy-security-rule-policy_sec_trust_untrust] quit [FW-policy-security] quit