
160
•
When Switch A operates normally, packets sent from Host A to Host B are forwarded by Switch A.
If VLAN-interface 3 through which Switch A connects to the Internet is not available, packets sent
from Host A to Host B are forwarded by Switch B.
•
To prevent attacks to the VRRP group by illegal users who use spoofed packets, configure the
authentication mode as plain text to authenticate the VRRP packets in VRRP group 1, and specify the
authentication key as
hello
.
Figure 44
Network diagram for VRRP interface tracking
Host A
Switch A
Switch B
Virtual IPv6 address:
FE80::10
1::10/64
Vlan-int2
FE80::1
1::1/64
Vlan-int2
FE80::2
1::2/64
Host B
Gateway:
1::10/64
Vlan-int3
Internet
Configuration procedure
1.
Configure Switch A
# Configure VLAN 2.
<SwitchA> system-view
[SwitchA] ipv6
[SwitchA] vlan 2
[SwitchA-vlan2] port gigabitethernet 1/0/5
[SwitchA-vlan2] quit
[SwitchA] interface vlan-interface 2
[SwitchA-Vlan-interface2] ipv6 address fe80::1 link-local
[SwitchA-Vlan-interface2] ipv6 address 1::1 64
# Create a VRRP group 1 and set its virtual IPv6 addresses to FE80::10 and 1::10.
[SwitchA-Vlan-interface2] vrrp ipv6 vrid 1 virtual-ip fe80::10 link-local
[SwitchA-Vlan-interface2] vrrp ipv6 vrid 1 virtual-ip 1::10
# Set the priority of Switch A in VRRP group 1 to 110, which is higher than that of Switch B, so that Switch
A can become the master.
[SwitchA-Vlan-interface2] vrrp ipv6 vrid 1 priority 110
# Set the authentication mode for VRRP group 1 to
simple
and authentication key to
hello
.
[SwitchA-Vlan-interface2] vrrp ipv6 vrid 1 authentication-mode simple hello
# Set the VRRP advertisement interval to 400 centiseconds.
[SwitchA-Vlan-interface2] vrrp ipv6 vrid 1 timer advertise 400
# Configure Switch A to work in preemptive mode, so that it can become the master whenever it works
normally; configure the preemption delay as five seconds to avoid frequent status switchover.