7
Configuration Example of the Dual-System
Hot Backup in Routing Mode
As a security device, the EGW2100 is deployed between a protected network and other networks.
In order to maintain the stability of devices, two EGW2100s are used in master/backup mode.
Prerequisite
The operating mode of two EGW2100s have been configured in routing mode.
Networking Requirements
The network is planned as follows:
l
The network to be protected is deployed in the Trust security zone with the network segment
of 10.100.10.0/24.
l
Interfaces Ethernet 0/0/0 on both EGW2100s are configured to connect to a heartbeat line.
The network segment is 10.100.20.0/24. The DMZ zone connects to the interfaces Ethernet
0/0/0.
l
The external networks are classified into the Untrust zone, and the Untrust zone connects
to the interfaces Ethernet 1/0/1 (Vlanif 6) of the EGW2100s.
l
Two EGW2100s are connected to each zone through a LAN switch.
The mappings between the virtual IP addresses of the backup groups and the security zones are
as follows:
l
Trust: 10.100.10.1
l
DMZ: 10.100.20.1
l
Untrust: 202.38.10.1
HUAWEI EGW2100
Web Configuration Guide
7 Configuration Example of the Dual-System Hot Backup in
Routing Mode
Issue 01 (2010-02-20)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
7-1