例:デフォルトゲートウェイ導入でのマルチノード高可用性の設定
このトピックでは、デフォルトゲートウェイ(レイヤー2)導入向けにアクティブ/バックアップモードでマルチノード高可用性(MNHA)を設定する方法について説明します。企業は、クライアントの通信を中断することなく、アクティブなサービスとトラフィックステアリング機能をバックアップノードに自動的に転送することで、ビジネス継続性を維持できます。
|
可読性スコア |
フレッシュの読解のしやすさ: 45-50 (大学レベル) フレッシュ・キンケイドの学年レベル: 12-14 |
|
読書時間 |
15-20分(平均読み取り速度) |
|
設定時間 |
90-120分(テストベッドにいる経験豊富なエンジニア) |
前提条件の例
|
ハードウェア要件 |
SRXシリーズファイアウォールとEX9214イーサネットスイッチ |
|
ソフトウェア要件 |
|
|
追加要件 |
|
始める前に
|
利点 |
|
|
詳細はこちら |
|
|
ハンズオンエクスペリエンス |
|
|
詳細はこちら |
機能の概要
| マルチノードの高可用性 | SRX-01とSRX-02の両方のファイアウォールでスイッチングモードで設定されたアクティブ/パッシブMNHA導入。SRX-01は、アクティブ性優先度200とプリエンプションを有効にしたプライマリとして設定され、SRX-02はバックアップとして機能し、優先度1です。 |
| シャーシ間リンク(ICL)暗号化 | IPSEC_VPN_ICLという名前のIPsec暗号化プロファイルは、2つのノード間のHA制御リンク(ge-0/0/2)に適用されます。 |
| 仮想IPアドレス(VIP) | フェイルオーバー用に設定された2つの仮想IPアドレス:両方のファイアウォールのtrustゾーンインターフェイス(ge-0/0/3.0)では10.1.0.200/16、untrustゾーンインターフェイス(ge-0/0/4.0)では10.2.0.200/16により、IPアドレスを変更することなくシームレスなフェイルオーバーを実現します。 |
| インターフェイス監視 | インターフェイスge-0/0/3(信頼)とge-0/0/4(信頼できない)の両方のSRXシリーズファイアウォールで正常性監視を設定し、インターフェイス障害が検出されたときにフェイルオーバーイベントをトリガーします。 |
| 仮想MACアドレス | 仮想MACアドレスは、両方のSRXシリーズファイアウォール上のtrustおよびuntrustインターフェイスに自動的に割り当てられ、HAフェイルオーバーイベント中に一貫したMACアドレスを提供します。 |
| 主要な検証タスク | MNHAステータスとSRX-01とSRX-02間の同期を確認します。正しい優先度設定でアクティブ/バックアップロールを確認し、ICLでIPsec暗号化を検証します。 |
トポロジー図
図1 は、この例で使用されているトポロジーを示しています。
におけるマルチノード高可用性
このトポロジーでは、LAN内のクライアントがトラフィックをデフォルトゲートウェイ(VIP)に送信します。スイッチはこのトラフィックを両方のSRXシリーズファイアウォールノードに転送しますが、そのSRGのアクティブノード(図のSRX-01など)のみがVIPを所有し、パケットを処理します。アクティブノードは、セキュリティチェックを実行し、セッションを作成し、信頼できない側にトラフィックを転送します。同時に、ICLリンクを介してバックアップノードとセッション情報を同期し、ピアがいつでも引き継ぐ準備ができるようにします。
アクティブノードまたはそのパスに障害が発生した場合、バックアップノードがVIPとvMACを素早く引き継ぎます。その後、LAN側とuntrust側からのトラフィックは、ホストを変更することなく、新しいアクティブノードにリダイレクトされます。セッションはすでに同期されているため、ほとんどのフローは最小限の中断で継続され、ネットワーク内でシームレスなフェイルオーバーを実現します。
この例では、わかりやすくするために、SRXシリーズファイアウォールとスイッチ間の直接接続を使用しています。特に、HAリンクゾーンのICLは、デバイス間で直接ge-0/0/2.0インターフェイスを使用して確立されます。ただし、本番環境では、これらのリンクは中間のルーティングネットワークを通過することもできます。
トポロジーの概要
| デバイス | インターフェース | ゾーン | IPアドレス | 設定対象 |
|---|---|---|---|---|
| SRX-01 | ge-0/0/2.0 | ハリンク | 10.22.0.1/24 | シャーシ間リンク(ICL) |
| ge-0/0/3.0 | 信頼 | 10.1.0.1/24 | スイッチ-01に接続します | |
| ge-0/0/4.0 | 信頼できない | 10.2.0.1/24 | スイッチ-02に接続します。 | |
| SRX-02 | ge-0/0/2.0 | ハリンク | 10.22.0.2/24 | シャーシ間リンク(ICL) |
| ge-0/0/3.0 | 信頼 | 10.1.0.2/24 | スイッチ-01に接続します | |
| ge-0/0/4.0 | 信頼できない | 10.2.0.2/24 | スイッチ-02に接続します。 |
以下のタスクを実行して、MNHAセットアップを構築します。
- IDを割り当てて、ファイアウォールのペアをローカルノードおよびピアノードとして設定します。
- サービス冗長性グループ(SRG)を設定します。
- アクティブ性の判断と適用のために仮想IPアドレスを設定します。この例では、複数の
ipステートメントを使用して単一の仮想IPにIPv4とIPv6の両方のアドレスを設定し、デュアルスタックサポートを有効にしています。 - IKEv2を使用して、高可用性(ICL)トラフィック用のVPNプロファイルを構成します。
- 適切なセキュリティポリシーを設定して、ネットワーク内のトラフィックを管理します。
- ネットワーク要件に応じてインターフェイスとゾーンを設定します。リンク暗号化用の IKE や設定同期用の SSH などのサービスを、ICL に関連付けられたセキュリティーゾーン上のホストインバウンドシステムサービスとして許可する必要があります。
設定
- ステップ1:物理インターフェイスを設定する
- ステップ2:セキュリティゾーンを構成する
- ステップ3:HAリンク暗号化用のIKEプロポーザルを設定する(SRX-01およびSRX-02)
- ステップ4:IKEポリシーとゲートウェイを設定する(SRX-01およびSRX-02)
- ステップ5:IPsecプロポーザルとポリシーの設定(SRX-01およびSRX-02)
- ステップ6:HAリンク暗号化用のIPsec VPNの設定(SRX-01およびSRX-02)
- ステップ7:セキュリティポリシーを設定する(SRX-01およびSRX-02)
- ステップ8:シャーシの高可用性ローカルIDを設定する
- ステップ9:シャーシの高可用性ピアIDを設定する
- ステップ10:サービス冗長性グループを設定する
- ステップ11:コミット設定
ステップ1:物理インターフェイスを設定する
HAリンク、trustゾーンインターフェイス、untrustゾーンインターフェイスなど、高可用性セットアップに参加する物理インターフェイスを設定します。
-
SRX-01
[edit] user@host# set interfaces ge-0/0/2 description ha_link user@host# set interfaces ge-0/0/2 unit 0 family inet address 10.22.0.1/24 user@host# set interfaces ge-0/0/3 description trust user@host# set interfaces ge-0/0/3 unit 0 family inet address 10.1.0.1/24 user@host# set interfaces ge-0/0/4 description untrust user@host# set interfaces ge-0/0/4 unit 0 family inet address 10.2.0.1/24
- SRX-02
[edit] user@host# set interfaces ge-0/0/2 description ha_link user@host# set interfaces ge-0/0/2 unit 0 family inet address 10.22.0.2/24 user@host# set interfaces ge-0/0/3 description trust user@host# set interfaces ge-0/0/3 unit 0 family inet address 10.1.0.2/24 user@host# set interfaces ge-0/0/4 description untrust user@host# set interfaces ge-0/0/4 unit 0 family inet address 10.2.0.2/24
インターフェイス設定は、MNHA向けに3つの重要なネットワークセグメントを確立します。インターフェイスge-0/0/2は、専用のHAリンクとして機能します。インターフェイスge-0/0/3はトラストゾーンに接続し、内部ネットワークトラフィックを処理します。インターフェイスge-0/0/4はuntrustゾーンに接続し、外部ネットワークトラフィックを管理します。
ステップ2:セキュリティゾーンを構成する
セキュリティゾーンを定義し、必要なホストインバウンドトラフィックサービスとプロトコルを備えた適切なゾーンにインターフェイスを割り当てます。
- SRX-01
[edit] user@host# set security zones security-zone untrust host-inbound-traffic system-services ike user@host# set security zones security-zone untrust host-inbound-traffic system-services ping user@host# set security zones security-zone untrust host-inbound-traffic system-services ssh user@host# set security zones security-zone untrust host-inbound-traffic protocols bfd user@host# set security zones security-zone untrust host-inbound-traffic protocols bgp user@host# set security zones security-zone untrust interfaces ge-0/0/4.0 user@host# set security zones security-zone trust host-inbound-traffic system-services ike user@host# set security zones security-zone trust host-inbound-traffic system-services ping user@host# set security zones security-zone trust host-inbound-traffic system-services ssh user@host# set security zones security-zone trust host-inbound-traffic protocols bgp user@host# set security zones security-zone trust host-inbound-traffic protocols bfd user@host# set security zones security-zone trust interfaces ge-0/0/3.0 user@host# set security zones security-zone halink host-inbound-traffic system-services ike user@host# set security zones security-zone halink host-inbound-traffic system-services ping user@host# set security zones security-zone halink host-inbound-traffic system-services high-availability user@host# set security zones security-zone halink host-inbound-traffic system-services ssh user@host# set security zones security-zone halink host-inbound-traffic protocols bfd user@host# set security zones security-zone halink host-inbound-traffic protocols bgp user@host# set security zones security-zone halink interfaces ge-0/0/2.0
- SRX-02
[edit] user@host# set security zones security-zone untrust host-inbound-traffic system-services ike user@host# set security zones security-zone untrust host-inbound-traffic system-services ping user@host# set security zones security-zone untrust host-inbound-traffic system-services ssh user@host# set security zones security-zone untrust host-inbound-traffic protocols bfd user@host# set security zones security-zone untrust host-inbound-traffic protocols bgp user@host# set security zones security-zone untrust interfaces ge-0/0/4.0 user@host# set security zones security-zone trust host-inbound-traffic system-services ike user@host# set security zones security-zone trust host-inbound-traffic system-services ping user@host# set security zones security-zone trust host-inbound-traffic system-services ssh user@host# set security zones security-zone trust host-inbound-traffic protocols bgp user@host# set security zones security-zone trust host-inbound-traffic protocols bfd user@host# set security zones security-zone trust interfaces ge-0/0/3.0 user@host# set security zones security-zone halink host-inbound-traffic system-services ike user@host# set security zones security-zone halink host-inbound-traffic system-services ping user@host# set security zones security-zone halink host-inbound-traffic system-services high-availability user@host# set security zones security-zone halink host-inbound-traffic system-services ssh user@host# set security zones security-zone halink host-inbound-traffic protocols bfd user@host# set security zones security-zone halink host-inbound-traffic protocols bgp user@host# set security zones security-zone halink interfaces ge-0/0/2.0
セキュリティゾーンは、ネットワークトラフィックをセグメント化し、セキュリティポリシーを適用します。untrust ゾーンと trust ゾーンでは、接続、管理、ルーティングのための IKE、ping、SSH、BGP/BFD サービスを許可し、halink ゾーンは高可用性専用です。
MNHAの設定では、通常、この設定にはIKE、BGP、BFDの許可が含まれます。ネットワークとセキュリティの要件に合わせてセキュリティルールを常に調整します。
ステップ3:HAリンク暗号化用のIKEプロポーザルを設定する(SRX-01およびSRX-02)
暗号化されたHAリンクトンネルの暗号化パラメーターを定義するIKEフェーズ1プロポーザルを作成します。
[edit] user@host# set security ike proposal MNHA_IKE_PROP description mnha_link_encr_tunnel user@host# set security ike proposal MNHA_IKE_PROP authentication-method pre-shared-keys user@host# set security ike proposal MNHA_IKE_PROP dh-group group14 user@host# set security ike proposal MNHA_IKE_PROP authentication-algorithm sha-256 user@host# set security ike proposal MNHA_IKE_PROP encryption-algorithm aes-256-cbc user@host# set security ike proposal MNHA_IKE_PROP lifetime-seconds 3600
IKEプロポーザルでは、事前共有鍵、DHグループ14、SHA-256、AES-256-CBCを使用して、ライフタイムが1時間のセキュアなHAリンク通信を定義しています。IKEネゴシエーションを成功させるには、両方のMNHAノードで設定が一致している必要があります
ステップ4:IKEポリシーとゲートウェイを設定する(SRX-01およびSRX-02)
プロポーザルを参照する IKE ポリシーを定義し、IKE ゲートウェイを HA リンク暗号化用に構成します。
[edit security ike] user@host# set security ike policy MNHA_IKE_POL description mnha_link_encr_tunnel user@host# set security ike policy MNHA_IKE_POL proposals MNHA_IKE_PROP user@host# set security ike policy MNHA_IKE_POL pre-shared-key ascii-text "$ABC123" user@host# set security ike gateway MNHA_IKE_GW ike-policy MNHA_IKE_POL user@host# set security ike gateway MNHA_IKE_GW version v2-only
IKEポリシーは暗号化プロポーザルを認証資格情報とリンクさせますが、IKEゲートウェイはIKEv2のみを使用して安全で効率的なトンネル確立を行います。このゲートウェイは、MNHAメンバー間のHA同期トラフィックを保護するために、IPsec VPNによって後で参照されます。
ステップ5:IPsecプロポーザルとポリシーの設定(SRX-01およびSRX-02)
HAリンクトンネルのデータプレーン暗号化パラメーターを定義するIPsecフェーズ2のプロポーザルとポリシーを作成します。
[edit] user@host# set security ipsec proposal MNHA_IPSEC_PROP description mnha_link_encr_tunnel user@host# set security ipsec proposal MNHA_IPSEC_PROP protocol esp user@host# set security ipsec proposal MNHA_IPSEC_PROP encryption-algorithm aes-256-gcm user@host# set security ipsec proposal MNHA_IPSEC_PROP lifetime-seconds 3600 user@host# set security ipsec policy MNHA_IPSEC_POL description mnha_link_encr_tunnel user@host# set security ipsec policy MNHA_IPSEC_POL proposals MNHA_IPSEC_PROP
IPsecプロポーザルは、ESPとAES-256-GCMを使用してHAトラフィックを保護し、効率的な暗号化と整合性保護を実現します。IPsecポリシーはこれらの設定をカプセル化し、VPN設定によって参照されます。
ステップ6:HAリンク暗号化用のIPsec VPNの設定(SRX-01およびSRX-02)
高可用性リンク暗号化用に特別に指定されたIPsec VPNプロファイルを作成します。
[edit] user@host# set security ipsec vpn IPSEC_VPN_ICL ha-link-encryption user@host# set security ipsec vpn IPSEC_VPN_ICL ike gateway MNHA_IKE_GW user@host# set security ipsec vpn IPSEC_VPN_ICL ike ipsec-policy MNHA_IPSEC_POL
IPsec VPNは、IKEゲートウェイとIPsecポリシーを組み合わせて、暗号化されたHAトンネルを作成します。 ha-link-encryption オプションは、安全なHA通信用にVPNを指定します。
ステップ7:セキュリティポリシーを設定する(SRX-01およびSRX-02)
ファイアウォールを通過するトラフィック処理のデフォルトのセキュリティポリシーを確立します。
[edit security policies] user@host# set default-policy permit-all
デフォルトのpermit-allポリシーでは、明示的なセキュリティルールを必要とせずにゾーン間のトラフィックが許可されます。ラボや初期導入には便利ですが、実稼働環境では制限の厳しいポリシーに置き換える必要があります。
ステップ8:シャーシの高可用性ローカルIDを設定する
高可用性設定内でローカルデバイスのIDを定義します。
- SRX-01
[edit] user@host# set chassis high-availability local-id 1 user@host# set chassis high-availability local-id local-ip 10.22.0.1
- SRX-02
[edit] user@host# set chassis high-availability local-id 2 user@host# set chassis high-availability local-id local-ip 10.22.0.2
ローカルIDとローカルIPは、このMNHAメンバーを一意に識別します。ローカル ID(1)はピアと区別し、ローカル IP(10.22.0.2)はHA通信に使用されます。
ステップ9:シャーシの高可用性ピアIDを設定する
HA内でピアデバイスのIDと接続パラメーターを定義します。
- SRX-01
[edit] user@host# set chassis high-availability peer-id 2 peer-ip 10.22.0.2 user@host# set chassis high-availability peer-id 2 interface ge-0/0/2.0 user@host# set chassis high-availability peer-id 2 vpn-profile IPSEC_VPN_ICL user@host# set chassis high-availability peer-id 2 liveness-detection minimum-interval 200 user@host# set chassis high-availability peer-id 2 liveness-detection multiplier 3
- SRX-02
[edit] user@host# set chassis high-availability peer-id 1 peer-ip 10.22.0.1 user@host# set chassis high-availability peer-id 1 interface ge-0/0/2.0 user@host# set chassis high-availability peer-id 1 vpn-profile IPSEC_VPN_ICL user@host# set chassis high-availability peer-id 1 liveness-detection minimum-interval 200 user@host# set chassis high-availability peer-id 1 liveness-detection multiplier 3
ピア設定によりリモートHAメンバーが識別され、専用HAリンクを介した安全なHA通信が可能になります。IPsec VPNプロファイルIPSEC_VPN_ICLをピアノードにアタッチします。ノード間のセキュアなICLリンクを確立するには、この設定が必要です。ライブネス検出は、200ミリ秒ごとにハートビートを送信し、ハートビートを3回見逃すとピアダウンを宣言し、迅速なフェイルオーバー検出を可能にします。
ステップ10:サービス冗長性グループを設定する
仮想IPとフェイルオーバー動作を管理するサービス冗長性グループを作成および設定します。
- SRX-01
[edit] user@host# set chassis high-availability services-redundancy-group 1 deployment-type switching user@host# set chassis high-availability services-redundancy-group 1 peer-id 2 user@host# set chassis high-availability services-redundancy-group 1 preemption user@host# set chassis high-availability services-redundancy-group 1 activeness-priority 200 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 10.1.0.200/24 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 2001:db8:6700::3/64 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 interface ge-0/0/3.0 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 use-virtual-mac user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 10.2.0.200/24 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 2001:db8:6701::7/64 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 interface ge-0/0/4.0 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 use-virtual-mac user@host# set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/3 user@host# set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/4
- SRX-02
[edit] user@host# set chassis high-availability services-redundancy-group 1 deployment-type switching user@host# set chassis high-availability services-redundancy-group 1 peer-id 1 user@host# set chassis high-availability services-redundancy-group 1 activeness-priority 1 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 10.1.0.200/24 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 2001:db8:6700::3/64 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 interface ge-0/0/3.0 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 1 use-virtual-mac user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 10.2.0.200/24 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 2001:db8:6701::7/64 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 interface ge-0/0/4.0 user@host# set chassis high-availability services-redundancy-group 1 virtual-ip 2 use-virtual-mac user@host# set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/3 user@host# set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/4
注:use-virtual-macオプションの設定は、ほとんどのケースで推奨されます。ただし、周囲のインフラストラクチャがローカルMACアドレスに加えてポートでアクティブな仮想MACアドレスの移動をサポートしていない場合を除きます。 - サービス冗長性グループにより、高可用性設定でアクティブ/パッシブフェイルオーバーが可能になります。
- スイッチングモードは、レイヤー2に隣接するHAの導入に使用されます。
- 仮想IP(VIP)は、フェイルオーバー中にHAメンバー間を移動します。
- 仮想MAC(VMAC)はVIPとともに移動することで、ARPの問題を防ぎ、シームレスなフェイルオーバーを可能にします。
- インターフェイス監視は、重要なインターフェイスを追跡し、障害が発生した場合はフェイルオーバーをトリガーします。
- プリエンプションにより、優先度の高いデバイスが回復後にアクティブ状態を取り戻すことができます。
- アクティブ性優先度200を指定すると、MNHAの起動および回復時にこのデバイスがアクティブノードになります。
ステップ11:コミット設定
デバイスの設定が完了したら、設定モードから commit を入力します。
user@host# commit warning: High Availability Mode changed, please reboot the device to avoid undesirable behavior commit complete
検証
| コマンド | 検証タスク |
| show chassis high-availability information |
アクティブノードとバックアップノードの全体的な高可用性(HA)ステータス(HAが有効になっているかどうか、ノードの役割、コアHAの健全性インジケーターなど)を検証します。 |
| show chassis high-availability peer-info |
ピアノードに到達可能であることを確認します。 |
| show chassis high-availability services-冗長性グループ |
冗長性グループのステータス、優先度、プリエンプト動作、フェイルオーバーの準備状況を検証します。 |
| show interface terse |
仮想IPアドレスがインターフェイスにインストールされていることを確認します。 |
| show security ipsec security-associations ha-link-encryption detail |
HAリンク暗号化IPsec SAが確立されていることを確認します(IKE/IPsecがHAパスに対して稼働しています)。 |
- 高可用性フォーメーションとピア接続の検証
- HAピア通信の詳細とパケット交換の検証
- サービス冗長グループのステータスとロール割り当ての確認
- インターフェイスでのIPアドレスインストールの確認
- HAリンク暗号化のためのIPsecセキュリティアソシエーションの確認
高可用性フォーメーションとピア接続の検証
目的
両方のノードがオンラインでMNHAが正しく形成されていること、ピアディスカバリーが正常に機能していること、ノード間の暗号化された制御チャネルが動作していることを検証します。この検証により、状態の同期やフェイルオーバー機能など、すべてのHA運用の基盤が確認されます。
アクション
SRX-01
user@host> show chassis high-availability information
Node failure codes:
HW Hardware monitoring LB Loopback monitoring
MB Mbuf monitoring SP SPU monitoring
CS Cold Sync monitoring SU Software Upgrade
Node Status: ONLINE
Grid-id: 0
Local-id: 1
Local-IP: 10.22.0.1
HA Peer Information:
Peer Id: 2 IP address: 10.22.0.2 Interface: ge-0/0/2.0
Routing Instance: default
Encrypted: YES Conn State: UP
Configured BFD Detection Time: 3 * 200ms
Cold Sync Status: COMPLETE
SRG failure event codes:
BF BFD monitoring
IP IP monitoring
IF Interface monitoring
CP Control Plane monitoring
Services Redundancy Group: 1
Deployment Type: SWITCHING
Status: ACTIVE
Activeness Priority: 200
Preemption: ENABLED
Process Packet In Backup State: NO
Control Plane State: READY
System Integrity Check: N/A
Failure Events: NONE
Peer Information:
Peer Id: 2
Status : BACKUP
Health Status: HEALTHY
Failover Readiness: READY
SRX-02
user@host> show chassis high-availability information
Node failure codes:
HW Hardware monitoring LB Loopback monitoring
MB Mbuf monitoring SP SPU monitoring
CS Cold Sync monitoring SU Software Upgrade
Node Status: ONLINE
Grid-id: 0
Local-id: 2
Local-IP: 10.22.0.2
HA Peer Information:
Peer Id: 1 IP address: 10.22.0.1 Interface: ge-0/0/2.0
Routing Instance: default
Encrypted: YES Conn State: UP
Configured BFD Detection Time: 3 * 200ms
Cold Sync Status: COMPLETE
SRG failure event codes:
BF BFD monitoring
IP IP monitoring
IF Interface monitoring
CP Control Plane monitoring
Services Redundancy Group: 1
Deployment Type: SWITCHING
Status: BACKUP
Activeness Priority: 1
Preemption: DISABLED
Process Packet In Backup State: NO
Control Plane State: READY
System Integrity Check: COMPLETE
Failure Events: NONE
Peer Information:
Peer Id: 1
Status : ACTIVE
Health Status: HEALTHY
Failover Readiness: N/A
意味
Node Status: ONLINEローカル ノードが動作しており、HA セットアップに参加していることを確認します。Local-id: 1HAメンバーシップに必要な一意のノード識別Peer Id: 2検証します。-
Conn State UPピアへのHAリンク(ge-0/0/2.0上の10.22.0.1または10.22.0.2)が確立されていることを示します。 -
Encrypted: YESIPsec暗号化がインターフェイス上のHA制御トラフィックを保護していることを確認します。 -
Deployment Type: SWITCHINGは、デフォルトのゲートウェイ(スイッチング)モード設定を示します。つまり、ネットワークの両端でスイッチが接続されています(レイヤー2ネットワーク)。 -
Services Redundancy Group: 1SRGの現在のステータスを表示するStatus: ACTIVEまたはStatus: BACKUPを表示します。 Cold Sync Status: COMPLETESRGフェイルオーバー準備のための前提条件である初期設定の同期が正常に完了したことを確認します。
HAピア通信の詳細とパケット交換の検証
目的
内部セキュアトンネルパラメータを確認し、HAピア間の双方向パケット交換を検証します。この検証により、コントロールプレーン通信インフラストラクチャが健全であり、状態の同期とフェイルオーバーメッセージングをサポートできることが確認されます。
アクション
SRX-01
user@host> show chassis high-availability peer-info
HA Peer Information:
Peer-ID: 2 IP address: 10.22.0.2 Interface: ge-0/0/2.0
Routing Instance: default
Encrypted: YES Conn State: UP
Cold Sync Status: COMPLETE
Internal Interface: st0.16000
Internal Local-IP: 180.100.1.1
Internal Peer-IP: 180.100.1.2
Internal Routing-instance: __juniper_private1__
Packet Statistics:
Receive Error : 0 Send Error : 0
Packet-type Sent Received
SRG Status Msg 3 5
SRG Status Ack 4 2
Attribute Msg 3 2
Attribute Ack 2 2
Pkt Req 0 0
Pkt Req Ack 0 0
SRX-02
user@host> show chassis high-availability peer-info
HA Peer Information:
Peer-ID: 1 IP address: 10.22.0.1 Interface: ge-0/0/2.0
Routing Instance: default
Encrypted: YES Conn State: UP
Cold Sync Status: COMPLETE
Internal Interface: st0.16000
Internal Local-IP: 180.100.1.2
Internal Peer-IP: 180.100.1.1
Internal Routing-instance: __juniper_private1__
Packet Statistics:
Receive Error : 0 Send Error : 0
Packet-type Sent Received
SRG Status Msg 5 2
SRG Status Ack 2 4
Attribute Msg 3 2
Attribute Ack 2 2
Pkt Req 0 0
Pkt Req Ack 0 0
意味
Conn State UPHAピア接続が確立され、正常であることを確認します。注:コマンド出力に示されているIP範囲(180.100.1.x)は、ICL IPsecトラフィックセレクターとして機能します。このIP範囲はシステムによって動的に割り当てられるため、変更や修正を行わないことが不可欠です。さらに、BFD(双方向フォワーディング検出)が、より広い180.x.x.x IP範囲に対して自動的に有効になります。Internal Routing-instance: juniper_private1は、ユーザーデータプレーンからHA制御トラフィックを分離するシステム生成VRFです- ゼロの
Send ErrorとReceive Errorは報告されており、クリーンなHAコントロールプレーン通信を示しています。
サービス冗長グループのステータスとロール割り当ての確認
目的
両方のHAノードで、SRGの動作状態、アクティブ/バックアップロールの割り当て、フェイルオーバーの準備状況を検証します。この検証により、適切なリソース所有権が確認され、必要に応じてHAがフェイルオーバーを実行できることが保証されます。
アクション
SRX-01
user@host> show chassis high-availability services-redundancy-group 1
SRG failure event codes:
BF BFD monitoring
IP IP monitoring
IF Interface monitoring
CP Control Plane monitoring
Services Redundancy Group: 1
Deployment Type: SWITCHING
Status: ACTIVE
Activeness Priority: 200
Preemption: ENABLED
Process Packet In Backup State: NO
Control Plane State: READY
System Integrity Check: N/A
Failure Events: NONE
Peer Information:
Peer Id: 2
Status : BACKUP
Health Status: HEALTHY
Failover Readiness: READY
Virtual IP Info:
Index: 2
IP: 2001:db8:6701::7/64
IP2: 10.2.0.200/24
VMAC: 00:10:db:fe:01:02
Interface: ge-0/0/4.0
Status: INSTALLED
Index: 1
IP: 2001:db8:6700::3/64
IP2: 10.1.0.200/24
VMAC: 00:10:db:fe:01:01
Interface: ge-0/0/3.0
Status: INSTALLED
Split-brain Prevention Probe Info:
DST-IP: 2001:db8:6700::3
Routing Instance: default
Type: ICMP Probe
Status: NOT RUNNING
Result: N/A Reason: N/A
DST-IP: 10.1.0.200
Routing Instance: default
Type: ICMP Probe
Status: NOT RUNNING
Result: N/A Reason: N/A
Interface Monitoring:
Status: UP
IF Name: ge-0/0/4 State: Up
IF Name: ge-0/0/3 State: Up
IP SRGID Table:
SRGID IP Prefix Routing Table
1 10.2.0.200/32 default
1 2001:db8:6701::7/128 default
1 10.1.0.200/32 default
1 2001:db8:6700::3/128 default
SRX-02
user@host> show chassis high-availability services-redundancy-group 1
SRG failure event codes:
BF BFD monitoring
IP IP monitoring
IF Interface monitoring
CP Control Plane monitoring
Services Redundancy Group: 1
Deployment Type: SWITCHING
Status: BACKUP
Activeness Priority: 1
Preemption: DISABLED
Process Packet In Backup State: NO
Control Plane State: READY
System Integrity Check: COMPLETE
Failure Events: NONE
Peer Information:
Peer Id: 1
Status : ACTIVE
Health Status: HEALTHY
Failover Readiness: N/A
Virtual IP Info:
Index: 2
IP: 2001:db8:6701::7/64
IP2: 10.2.0.200/24
VMAC: N/A
Interface: ge-0/0/4.0
Status: NOT INSTALLED
Index: 1
IP: 2001:db8:6700::3/64
IP2: 10.1.0.200/24
VMAC: 00:10:db:fe:01:01
Interface: ge-0/0/3.0
Status: NOT INSTALLED
Split-brain Prevention Probe Info:
DST-IP: 2001:db8:6700::3
Routing Instance: default
Type: ICMP Probe
Status: NOT RUNNING
Result: N/A Reason: N/A
DST-IP: 10.1.0.200
Routing Instance: default
Type: ICMP Probe
Status: NOT RUNNING
Result: N/A Reason: N/A
Interface Monitoring:
Status: UP
IF Name: ge-0/0/4 State: Up
IF Name: ge-0/0/3 State: Up
IP SRGID Table:
SRGID IP Prefix Routing Table
1 10.2.0.200/32 default
1 2001:db8:6701::7/128 default
1 10.1.0.200/32 default
1 2001:db8:6700::3/128 default
意味
Status: ACTIVEノード1とノード2のStatus: BACKUPで、SRG 1の適切なロール割り当てを確認します。これは、ピアが正常でバックアップ準備完了状態であることを示し、フェイルオーバー機能があることを示しています。Virtual IP Info: INSTALLEDアクティブノードにVIPが表示されていることを示します。バックアップノードノードの場合、Virtual IP Info: NOT INSTALLEDが表示されます。VMAC: 00:10:db:fe:01:02VMAC: 00:10:db:fe:01:01は、アクティブノード上の仮想IPに関連付けられています。Virtual IP Info: IP: 2001:db8:6701::7/64また、IPv4とIPv6の両方のVIPが存在するデュアルスタックサポートを確認するIP2: 10.2.0.200/24です。Preemption: ENABLEDノード1では、障害から回復した後にアクティブなステータスが回復することを意味しますPreemption: DISABLEDノード2では、ノード1がオンラインに戻ったときに不要なフェイルオーバーが発生するのを防ぎますFailure Events: NONE両方のノードで監視障害がないことを確認します(BFD、IP、インターフェイス、コントロールプレーン)Health Status: HEALTHYFailover Readiness: READYは、必要に応じてバックアップノードがすぐにアクティブなロールを引き受けることができることを示します。System Integrity Check: COMPLETEバックアップ時に、設定と状態の同期が最新であることを確認します。Interface Monitoring Status: UP監視サブシステムがインターフェイスの健全性をアクティブに追跡していることを確認しますState: Up監視対象の両方のインターフェイスについて、SRGフェイルオーバーをトリガーするリンク障害は検出されません
インターフェイスでのIPアドレスインストールの確認
目的仮想IPアドレスがインターフェイスにインストールされていることを確認します。
アクション動作モードから、以下のコマンドを実行します。
SRX-01
user@host> show interfaces terse | no-more
Interface Admin Link Proto Local Remote
ge-0/0/0 up up
gr-0/0/0 up up
ip-0/0/0 up up
lsq-0/0/0 up up
lt-0/0/0 up up
mt-0/0/0 up up
sp-0/0/0 up up
sp-0/0/0.0 up up inet
inet6
sp-0/0/0.16383 up up inet
ge-0/0/1 up up
ge-0/0/2 up up
ge-0/0/2.0 up up inet 10.22.0.1/24
ge-0/0/3 up up
ge-0/0/3.0 up up inet 10.1.0.1/24
10.1.0.200/24
inet6 2001:db8:6700::3/64
fe80::5604:1aff:fe00:4882/64
ge-0/0/4 up up
ge-0/0/4.0 up up inet 10.2.0.1/24
10.2.0.200/24
inet6 2001:db8:6701::7/64
fe80::5604:1aff:fe00:7541/64
...
SRX-02
user@host> show interfaces terse | no-more
Interface Admin Link Proto Local Remote
ge-0/0/0 up up
gr-0/0/0 up up
ip-0/0/0 up up
lsq-0/0/0 up up
lt-0/0/0 up up
mt-0/0/0 up up
sp-0/0/0 up up
sp-0/0/0.0 up up inet
inet6
sp-0/0/0.16383 up up inet
ge-0/0/1 up up
ge-0/0/2 up up
ge-0/0/2.0 up up inet 10.22.0.2/24
ge-0/0/3 up up
ge-0/0/3.0 up up inet 10.1.0.2/24
ge-0/0/4 up up
ge-0/0/4.0 up up inet 10.2.0.2/24
dsc up up
...
簡潔にするために、showコマンドの出力は切り捨てられ、いくつかのサンプルのみが表示されます。
意味
コマンド出力は、以下の情報を提供します。
- アクティブノードでは、VIPインデックス1のインターフェイスge-0/0/3.0に、VIPインデックス2のインターフェイスge-0/0/4.0に
10.2.0.200/16と2001:db8:6701::7/64の両方がインストールされていることが22001:db8:6700::3/6410.1.0.200/16、インターフェイスに示されています。 - バックアップノードには、ローカルインターフェイスのIPアドレスのみが存在し、VIPはインストールされていません。
この出力により、アクティブなノードのみがトラフィックを処理するようになります。フェイルオーバー中、VIP はアクティブノードからバックアップノードに移動し、IPv4 と IPv6 の両方のトラフィックのサービス継続性を維持します
HAリンク暗号化のためのIPsecセキュリティアソシエーションの確認
目的
HA制御トラフィックを保護するIPsecトンネルが正しい暗号化パラメーターで確立され、トラフィックをアクティブに処理していることを確認します。この検証により、HAノード間の構成同期と状態更新の機密性と整合性が確保されます。
アクション
user@host> show security ipsec security-associations ha-link-encryption detail
ID: 495005 Virtual-system: root, VPN Name: IPSEC_VPN_ICL
Local Gateway: 10.22.0.1, Remote Gateway: 10.22.0.2
Traffic Selector Name: __IPSEC_VPN_ICL__ICL__2__0__multi_node__
Local Identity: ipv4(180.100.1.1-180.100.1.1)
Remote Identity: ipv4(180.100.1.2-180.100.1.2)
TS Type: traffic-selector
Version: IKEv2
Quantum Secured: No
Hardware Offloaded: No
PFS group: N/A, Packet Encapsulation: None, Dest port: 0
Passive mode tunneling: Disabled
DF-bit: clear, Copy-Outer-DSCP: Disabled, Bind-interface: st0.16000, Policy-name: MNHA_IPSEC_POL
Port: 500, Nego#: 0, Fail#: 0, Def-Del#: 0 Flag: 0
HA Link Encryption Mode: Inter-Chassis-Link
Location: FPC -, PIC -
Anchorship: Thread -
Distribution-Profile: default-profile
Direction: inbound, SPI: 0x0008a5a8, AUX-SPI: 0
, VPN Monitoring: UP Mode: Always-Send Interval: 10secs Threshold: 10
Hard lifetime: Expires in 3392 seconds
Lifesize Remaining: Unlimited
Soft lifetime: Expires in 2774 seconds
Mode: Tunnel(0 0), Type: dynamic, State: installed
Protocol: ESP, Authentication: aes256-gcm, Encryption: aes-gcm (256 bits)
Anti-replay service: counter-based enabled, Replay window size: 64
Extended-Sequence-Number: Disabled
tunnel-establishment: establish-tunnels-immediately
Location: FPC 0, PIC 0
Anchorship: Thread 0
IKE SA Index: 16776197
Direction: outbound, SPI: 0x00065b1f, AUX-SPI: 0
, VPN Monitoring: UP Mode: Always-Send Interval: 10secs Threshold: 10
Hard lifetime: Expires in 3392 seconds
Lifesize Remaining: Unlimited
Soft lifetime: Expires in 2774 seconds
Mode: Tunnel(0 0), Type: dynamic, State: installed
Protocol: ESP, Authentication: aes256-gcm, Encryption: aes-gcm (256 bits)
Anti-replay service: counter-based enabled, Replay window size: 64
Extended-Sequence-Number: Disabled
tunnel-establishment: establish-tunnels-immediately
Location: FPC 0, PIC 0
Anchorship: Thread 0
IKE SA Index: 16776197
意味
Local Gateway: 10.22.0.1Remote Gateway: 10.22.0.2トンネルエンドポイントがHAピアアドレスと一致していることを確認します。HA Link Encryption Mode: Inter-Chassis-Linkこれが専用のHA暗号化トンネルであることを確認します。IPSEC_VPN_ICL使用されたIPsec VPNプロファイルの名前を表示します。注意:コマンド出力に示されているIP範囲(180.100.1.x)は、ICL IPsecトラフィックセレクターとして機能します。このIP範囲はシステムによって動的に割り当てられるため、変更や修正を行わないことが不可欠です。さらに、BFD(双方向フォワーディング検出)が、より広い180.x.x.x IP範囲に対して自動的に有効になります。
付録1:すべてのデバイスでコマンドを設定する
この例をすばやく設定するには、次のコマンドをコピーしてテキスト ファイルに貼り付け、改行を削除し、ネットワーク構成に合わせて必要な詳細を変更します。次に、コマンドを [edit] 階層レベルのCLIにコピーアンドペーストし、設定モードから commit を入力します。
これらの設定はラボ環境から取得したものであり、参照用にのみ提供されています。実際の構成は、環境の要件によって異なる場合があります。
SRX-01の場合
set chassis high-availability local-id 1 set chassis high-availability local-id local-ip 10.22.0.1 set chassis high-availability peer-id 2 peer-ip 10.22.0.2 set chassis high-availability peer-id 2 interface ge-0/0/2.0 set chassis high-availability peer-id 2 vpn-profile IPSEC_VPN_ICL set chassis high-availability peer-id 2 liveness-detection minimum-interval 200 set chassis high-availability peer-id 2 liveness-detection multiplier 3 set chassis high-availability services-redundancy-group 1 deployment-type switching set chassis high-availability services-redundancy-group 1 peer-id 2 set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 10.1.0.200/24 set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 2001:db8:6700::3/64 set chassis high-availability services-redundancy-group 1 virtual-ip 1 interface ge-0/0/3.0 set chassis high-availability services-redundancy-group 1 virtual-ip 1 use-virtual-mac set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 10.2.0.200/24 set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 2001:db8:6701::7/64 set chassis high-availability services-redundancy-group 1 virtual-ip 2 interface ge-0/0/4.0 set chassis high-availability services-redundancy-group 1 virtual-ip 2 use-virtual-mac set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/3 set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/4 set chassis high-availability services-redundancy-group 1 preemption set chassis high-availability services-redundancy-group 1 activeness-priority 200 set security ike proposal MNHA_IKE_PROP description mnha_link_encr_tunnel set security ike proposal MNHA_IKE_PROP authentication-method pre-shared-keys set security ike proposal MNHA_IKE_PROP dh-group group14 set security ike proposal MNHA_IKE_PROP authentication-algorithm sha-256 set security ike proposal MNHA_IKE_PROP encryption-algorithm aes-256-cbc set security ike proposal MNHA_IKE_PROP lifetime-seconds 3600 set security ike policy MNHA_IKE_POL description mnha_link_encr_tunnel set security ike policy MNHA_IKE_POL proposals MNHA_IKE_PROP set security ike policy MNHA_IKE_POL pre-shared-key ascii-text "$ABC123" set security ike gateway MNHA_IKE_GW ike-policy MNHA_IKE_POL set security ike gateway MNHA_IKE_GW version v2-only set security ipsec proposal MNHA_IPSEC_PROP description mnha_link_encr_tunnel set security ipsec proposal MNHA_IPSEC_PROP protocol esp set security ipsec proposal MNHA_IPSEC_PROP encryption-algorithm aes-256-gcm set security ipsec proposal MNHA_IPSEC_PROP lifetime-seconds 3600 set security ipsec policy MNHA_IPSEC_POL description mnha_link_encr_tunnel set security ipsec policy MNHA_IPSEC_POL proposals MNHA_IPSEC_PROP set security ipsec vpn IPSEC_VPN_ICL ha-link-encryption set security ipsec vpn IPSEC_VPN_ICL ike gateway MNHA_IKE_GW set security ipsec vpn IPSEC_VPN_ICL ike ipsec-policy MNHA_IPSEC_POL set security zones security-zone untrust host-inbound-traffic system-services ike set security zones security-zone untrust host-inbound-traffic system-services ping set security zones security-zone untrust host-inbound-traffic system-services ssh set security zones security-zone untrust host-inbound-traffic protocols bfd set security zones security-zone untrust host-inbound-traffic protocols bgp set security zones security-zone untrust interfaces lo0.0 set security zones security-zone untrust interfaces ge-0/0/4.0 set security zones security-zone trust host-inbound-traffic system-services ike set security zones security-zone trust host-inbound-traffic system-services ping set security zones security-zone trust host-inbound-traffic system-services ssh set security zones security-zone trust host-inbound-traffic protocols bgp set security zones security-zone trust host-inbound-traffic protocols bfd set security zones security-zone trust interfaces ge-0/0/3.0 set security zones security-zone halink host-inbound-traffic system-services ike set security zones security-zone halink host-inbound-traffic system-services ping set security zones security-zone halink host-inbound-traffic system-services high-availability set security zones security-zone halink host-inbound-traffic system-services ssh set security zones security-zone halink host-inbound-traffic protocols bfd set security zones security-zone halink host-inbound-traffic protocols bgp set security zones security-zone halink interfaces ge-0/0/2.0 set security policies default-policy permit-all set interfaces ge-0/0/2 description ha_link set interfaces ge-0/0/2 unit 0 family inet address 10.22.0.1/24 set interfaces ge-0/0/3 description trust set interfaces ge-0/0/3 unit 0 family inet address 10.1.0.1/24 set interfaces ge-0/0/4 description untrust set interfaces ge-0/0/4 unit 0 family inet address 10.2.0.1/24
SRX-02では
set chassis high-availability local-id 2 set chassis high-availability local-id local-ip 10.22.0.2 set chassis high-availability peer-id 1 peer-ip 10.22.0.1 set chassis high-availability peer-id 1 interface ge-0/0/2.0 set chassis high-availability peer-id 1 vpn-profile IPSEC_VPN_ICL set chassis high-availability peer-id 1 liveness-detection minimum-interval 200 set chassis high-availability peer-id 1 liveness-detection multiplier 3 set chassis high-availability services-redundancy-group 1 deployment-type switching set chassis high-availability services-redundancy-group 1 peer-id 1 set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 10.1.0.200/24 set chassis high-availability services-redundancy-group 1 virtual-ip 1 ip 2001:db8:6700::3/64 set chassis high-availability services-redundancy-group 1 virtual-ip 1 interface ge-0/0/3.0 set chassis high-availability services-redundancy-group 1 virtual-ip 1 use-virtual-mac set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 10.2.0.200/24 set chassis high-availability services-redundancy-group 1 virtual-ip 2 ip 2001:db8:6701::7/64 set chassis high-availability services-redundancy-group 1 virtual-ip 2 interface ge-0/0/4.0 set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/3 set chassis high-availability services-redundancy-group 1 monitor interface ge-0/0/4 set chassis high-availability services-redundancy-group 1 activeness-priority 1 set security ike proposal MNHA_IKE_PROP description mnha_link_encr_tunnel set security ike proposal MNHA_IKE_PROP authentication-method pre-shared-keys set security ike proposal MNHA_IKE_PROP dh-group group14 set security ike proposal MNHA_IKE_PROP authentication-algorithm sha-256 set security ike proposal MNHA_IKE_PROP encryption-algorithm aes-256-cbc set security ike proposal MNHA_IKE_PROP lifetime-seconds 3600 set security ike policy MNHA_IKE_POL description mnha_link_encr_tunnel set security ike policy MNHA_IKE_POL proposals MNHA_IKE_PROP set security ike policy MNHA_IKE_POL pre-shared-key ascii-text "$ABC123" set security ike gateway MNHA_IKE_GW ike-policy MNHA_IKE_POL set security ike gateway MNHA_IKE_GW version v2-only set security ipsec proposal MNHA_IPSEC_PROP description mnha_link_encr_tunnel set security ipsec proposal MNHA_IPSEC_PROP protocol esp set security ipsec proposal MNHA_IPSEC_PROP encryption-algorithm aes-256-gcm set security ipsec proposal MNHA_IPSEC_PROP lifetime-seconds 3600 set security ipsec policy MNHA_IPSEC_POL description mnha_link_encr_tunnel set security ipsec policy MNHA_IPSEC_POL proposals MNHA_IPSEC_PROP set security ipsec vpn IPSEC_VPN_ICL ha-link-encryption set security ipsec vpn IPSEC_VPN_ICL ike gateway MNHA_IKE_GW set security ipsec vpn IPSEC_VPN_ICL ike ipsec-policy MNHA_IPSEC_POL set security zones security-zone untrust host-inbound-traffic system-services ike set security zones security-zone untrust host-inbound-traffic system-services ping set security zones security-zone untrust host-inbound-traffic system-services ssh set security zones security-zone untrust host-inbound-traffic protocols bfd set security zones security-zone untrust host-inbound-traffic protocols bgp set security zones security-zone untrust interfaces lo0.0 set security zones security-zone untrust interfaces ge-0/0/4.0 set security zones security-zone trust host-inbound-traffic system-services ike set security zones security-zone trust host-inbound-traffic system-services ping set security zones security-zone trust host-inbound-traffic system-services ssh set security zones security-zone trust host-inbound-traffic system-services all set security zones security-zone trust host-inbound-traffic protocols bgp set security zones security-zone trust host-inbound-traffic protocols bfd set security zones security-zone trust host-inbound-traffic protocols all set security zones security-zone trust interfaces ge-0/0/3.0 set security zones security-zone halink host-inbound-traffic system-services ike set security zones security-zone halink host-inbound-traffic system-services ping set security zones security-zone halink host-inbound-traffic system-services high-availability set security zones security-zone halink host-inbound-traffic system-services ssh set security zones security-zone halink host-inbound-traffic protocols bfd set security zones security-zone halink host-inbound-traffic protocols bgp set security zones security-zone halink interfaces ge-0/0/2.0 set security policies default-policy permit-all set interfaces ge-0/0/2 description ha_link set interfaces ge-0/0/2 unit 0 family inet address 10.22.0.2/24 set interfaces ge-0/0/3 description trust set interfaces ge-0/0/3 unit 0 family inet address 10.1.0.2/24 set interfaces ge-0/0/4 description untrust set interfaces ge-0/0/4 unit 0 family inet address 10.2.0.2/24
以下のセクションでは、ネットワーク内でMNHAの設定に必要なスイッチの設定スニペットを示します。
スイッチ -01
set interfaces ge-0/0/0 description to-vsrx-1 set interfaces ge-0/0/0 mtu 9192 set interfaces ge-0/0/0 unit 0 family ethernet-switching interface-mode access set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members lan set interfaces ge-0/0/1 description to-vsrx-2 set interfaces ge-0/0/1 mtu 9192 set interfaces ge-0/0/1 unit 0 family ethernet-switching interface-mode access set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members lan set interfaces ge-0/0/2 description lan set interfaces ge-0/0/2 mtu 9192 set interfaces ge-0/0/2 unit 0 family ethernet-switching interface-mode access set interfaces ge-0/0/2 unit 0 family ethernet-switching vlan members lan set vlans lan vlan-id 1001
スイッチ-02について
set interfaces ge-0/0/0 description to-vsrx-1 set interfaces ge-0/0/0 mtu 9192 set interfaces ge-0/0/0 unit 0 family ethernet-switching interface-mode access set interfaces ge-0/0/0 unit 0 family ethernet-switching vlan members lan set interfaces ge-0/0/1 description to-vsrx-2 set interfaces ge-0/0/1 mtu 9192 set interfaces ge-0/0/1 unit 0 family ethernet-switching interface-mode access set interfaces ge-0/0/1 unit 0 family ethernet-switching vlan members lan set vlans lan vlan-id 1001
付録2:show configuration output
結果 (SRX-01)
設定モードから、以下のコマンドを入力して設定を確認します。出力に意図した設定が表示されない場合は、この例の設定手順を繰り返して修正します。
[edit]
user@host# show chassis high-availability
local-id {
1;
local-ip 10.22.0.1;
}
peer-id 2 {
peer-ip 10.22.0.2;
interface ge-0/0/2.0;
vpn-profile IPSEC_VPN_ICL;
liveness-detection {
minimum-interval 200;
multiplier 3;
}
}
services-redundancy-group 1 {
deployment-type switching;
peer-id {
2;
}
virtual-ip 1 {
ip 2001:db8:6700::3/64;
ip 10.1.0.200/24;
interface ge-0/0/3.0;
use-virtual-mac;
}
virtual-ip 2 {
ip 2001:db8:6701::7/64;
ip 10.2.0.200/24;
interface ge-0/0/4.0;
use-virtual-mac;
}
monitor {
interface {
ge-0/0/3;
ge-0/0/4;
}
}
preemption;
activeness-priority 200;
}
[edit]
user@host# show security ike
proposal MNHA_IKE_PROP {
description "mnha_link_encr_tunnel";
authentication-method pre-shared-keys;
dh-group group14;
authentication-algorithm sha-256;
encryption-algorithm aes-256-cbc;
lifetime-seconds 3600;
}
policy MNHA_IKE_POL {
description "mnha_link_encr_tunnel";
proposals MNHA_IKE_PROP;
pre-shared-key {
ascii-text "$ABC123";
}
}
gateway MNHA_IKE_GW {
ike-policy MNHA_IKE_POL;
version v2-only;
}
}
[edit]
user@host# show security ipsec
proposal MNHA_IPSEC_PROP {
description "mnha_link_encr_tunnel";
protocol esp;
encryption-algorithm aes-256-gcm;
lifetime-seconds 3600;
}
policy MNHA_IPSEC_POL {
description "mnha_link_encr_tunnel";
proposals MNHA_IPSEC_PROP;
}
vpn IPSEC_VPN_ICL {
ha-link-encryption;
ike {
gateway MNHA_IKE_GW;
ipsec-policy MNHA_IPSEC_POL;
}
}
[edit]
user@host# show security zones
security-zone untrust {
host-inbound-traffic {
system-services {
ike;
ping;
ssh;
}
protocols {
bfd;
bgp;
}
}
interfaces {
ge-0/0/4.0;
}
}
security-zone trust {
host-inbound-traffic {
system-services {
ike;
ping;
ssh;
}
protocols {
bgp;
bfd;
}
}
interfaces {
ge-0/0/3.0;
}
}
security-zone halink {
host-inbound-traffic {
system-services {
ike;
ping;
high-availability;
ssh;
}
protocols {
bfd;
bgp;
}
}
interfaces {
ge-0/0/2.0;
}
}
[edit]
user@host# show interfaces
ge-0/0/2 {
description ha_link;
unit 0 {
family inet {
address 10.22.0.1/24;
}
}
}
ge-0/0/3 {
description trust;
unit 0 {
family inet {
address 10.1.0.1/24;
}
}
}
ge-0/0/4 {
description untrust;
unit 0 {
family inet {
address 10.2.0.1/24;
}
}
}
デバイスの設定が完了したら、設定モードから commit を入力します。
結果 (SRX-02)
設定モードから、以下のコマンドを入力して設定を確認します。出力に意図した設定が表示されない場合は、この例の設定手順を繰り返して修正します。
[edit]
user@host# show chassis high-availability
local-id {
2;
local-ip 10.22.0.1;
}
peer-id 1 {
peer-ip 10.22.0.2;
interface ge-0/0/2.0;
vpn-profile IPSEC_VPN_ICL;
liveness-detection {
minimum-interval 200;
multiplier 3;
}
}
services-redundancy-group 1 {
deployment-type switching;
peer-id {
1;
}
virtual-ip 1 {
ip 10.1.0.200/16;
ip 2001:db8:6700::3/64;
interface ge-0/0/3.0;
use-virtual-mac;
}
virtual-ip 2 {
ip 10.2.0.200/16;
ip 2001:db8:6701::7/64;
interface ge-0/0/4.0;
use-virtual-mac;
}
monitor {
interface {
ge-0/0/3;
ge-0/0/4;
}
}
activeness-priority 1;
}
[edit]
user@host# show security ike
proposal MNHA_IKE_PROP {
description "mnha_link_encr_tunnel";
authentication-method pre-shared-keys;
dh-group group14;
authentication-algorithm sha-256;
encryption-algorithm aes-256-cbc;
lifetime-seconds 3600;
}
policy MNHA_IKE_POL {
description "mnha_link_encr_tunnel";
proposals MNHA_IKE_PROP;
pre-shared-key {
ascii-text "$ABC123";
}
}
gateway MNHA_IKE_GW {
ike-policy MNHA_IKE_POL;
version v2-only;
}
[edit]
user@host# show security ipsec
proposal MNHA_IPSEC_PROP {
description "mnha_link_encr_tunnel";
protocol esp;
encryption-algorithm aes-256-gcm;
lifetime-seconds 3600;
}
policy MNHA_IPSEC_POL {
description "mnha_link_encr_tunnel";
proposals MNHA_IPSEC_PROP;
}
vpn IPSEC_VPN_ICL {
ha-link-encryption;
ike {
gateway MNHA_IKE_GW;
ipsec-policy MNHA_IPSEC_POL;
}
}
[edit]
user@host# show security zones
security-zone untrust {
host-inbound-traffic {
system-services {
ike;
ping;
ssh;
}
protocols {
bfd;
bgp;
}
}
interfaces {
ge-0/0/4.0;
}
}
security-zone trust {
host-inbound-traffic {
system-services {
ike;
ping;
ssh;
all;
}
protocols {
bgp;
bfd;
all;
}
}
interfaces {
ge-0/0/3.0;
}
}
security-zone halink {
host-inbound-traffic {
system-services {
ike;
ping;
high-availability;
ssh;
}
protocols {
bfd;
bgp;
}
}
interfaces {
ge-0/0/2.0;
}
}
[edit]
user@host# show interfaces
ge-0/0/2 {
description ha_link;
unit 0 {
family inet {
address 10.22.0.2/24;
}
}
}
ge-0/0/3 {
description trust;
unit 0 {
family inet {
address 10.1.0.2/24;
}
}
}
ge-0/0/4 {
description untrust;
unit 0 {
family inet {
address 10.2.0.2/24;
}
}
}