firepower# show chassis-management-url
https://KSEC-FPR9K-1.cisco.com:443//
附註:在6.3後FTD中,使用命令show chassis detail。
Firepower-module1# show chassis detail Chassis URL : https://FP4100-5:443// Chassis IP : 10.62.148.187 Chassis IPv6 : :: Chassis Serial Number : JAD19500BAB Security Module : 1
如果兩個機箱具有相同的名稱,請使用以下命令在一個機箱中更改名稱:
KSEC-FPR9K-1-A# scope system
KSEC-FPR9K-1-A /system # set name FPR9K-1new
Warning: System name modification changes FC zone name and redeploys them non-disruptively
KSEC-FPR9K-1-A /system* # commit-buffer
FPR9K-1-A /system # exitFPR9K-1new-A#
> show high-availability config Failover On Failover unit Primary Failover LAN Interface: FOVER Port-channel3 (up) Reconnect timeout 0:00:00 Unit Poll frequency 1 seconds, holdtime 15 seconds Interface Poll frequency 5 seconds, holdtime 25 seconds Interface Policy 1 Monitored Interfaces 2 of 1291 maximum MAC Address Move Notification Interval not set failover replication http Version: Ours 9.18(4)210, Mate 9.18(4)210 Serial Number: Ours FLM1949C5RR, Mate FLM2108V9YG Last Failover at: 08:46:30 UTC Jul 18 2024 This host: Primary - Active Active time: 1999 (sec) slot 0: UCSB-B200-M3-U hw/sw rev (0.0/9.18(4)210) status (Up Sys) Interface diagnostic (0.0.0.0): Normal (Waiting) Interface Inside (192.168.75.10): Link Down (Shutdown) Interface Outside (192.168.76.10): Normal (Not-Monitored) slot 1: snort rev (1.0) status (up) slot 2: diskstatus rev (1.0) status (up) Other host: Secondary - Standby Ready Active time: 1466 (sec) slot 0: UCSB-B200-M3-U hw/sw rev (0.0/9.18(4)210) status (Up Sys) Interface diagnostic (0.0.0.0): Normal (Waiting) Interface Inside (192.168.75.11): Link Down (Shutdown) Interface Outside (192.168.76.11): Normal (Not-Monitored) slot 1: snort rev (1.0) status (up) slot 2: diskstatus rev (1.0) status (up)
firepower# show failover state
State Last Failure Reason Date/Time
This host - Primary
Active None
Other host - Secondary
Standby Ready Comm Failure 18:32:56 EEST Jul 21 2016
====Configuration State===
Sync Done
====Communication State===
Mac set
firepower#
步驟5.從主裝置(LINA CLI)驗證配置設定:
> show running-config failover failover failover lan unit primary failover lan interface FOVER Port-channel3 failover replication http failover mac address Ethernet1/4 aaaa.bbbb.1111 aaaa.bbbb.2222 failover mac address Port-channel2.202 aaaa.bbbb.3333 aaaa.bbbb.4444 failover link FOVER Port-channel3 failover interface ip FOVER 172.16.51.1 255.255.255.0 standby 172.16.51.2
> show running-config interface ! interface Port-channel2 no nameif no security-level no ip address ! interface Port-channel2.202 vlan 202 nameif Outside cts manual propagate sgt preserve-untag policy static sgt disabled trusted security-level 0 ip address 192.168.76.10 255.255.255.0 standby 192.168.76.11 ! interface Port-channel3 description LAN/STATE Failover Interface ! interface Ethernet1/1 management-only nameif diagnostic security-level 0 no ip address ! interface Ethernet1/4 shutdown nameif Inside security-level 0 ip address 192.168.75.10 255.255.255.0 standby 192.168.75.11 >
工作 4: 切換容錯移轉角色
工作需求:
在FMC中,將故障切換角色從主/主用、輔助/備用切換到主/備用、輔助/主用。
解決方案:
步驟1.選擇圖示。
步驟2.確認操作。
您可以使用show failover history命令輸出:
在新活動專案上
在新待機模式中
> show failover history ========================================================================== 從州到州的原因 ==========================================================================
世界協調時2024年7月18日09時27分11秒 Active Drain Active Applying Config其他裝置需要啟用 (通過config命令設定)
世界協調時2024年7月18日09時27分11秒 Active Applying Config Active Config Applied Other unit wes me Active (通過config命令設定)
世界協調時2024年7月18日09時27分11秒 Active Config Applied Active Other unit wes me Active (通過config命令設定)
> show failover history ========================================================================== 從州到州的原因 ==========================================================================
! interface Port-channel2 關機 no nameif 無安全級別 no ip address ! interface Port-channel3 關機 no nameif 無安全級別 no ip address ! interface Ethernet1/1 僅管理 關機 no nameif 無安全級別 no ip address ! interface Ethernet1/4 關機 no nameif 無安全級別 no ip address ! ftp mode passive ngips conn-match vlan-id object-group-search訪問控制 access-group CSM_FW_ACL_ global access-list CSM_FW_ACL_ remark rule-id 9998:預過濾器策略:預設通道和優先順序原則 access-list CSM_FW_ACL_ remark rule-id 9998:RULE:預設隧道操作規則 access-list CSM_FW_ACL_ advanced permit ipinip any any rule-id 9998 access-list CSM_FW_ACL_ advanced permit udp any eq 3544 any range 1025 65535 rule-id 9998 access-list CSM_FW_ACL_ advanced permit udp any range 1025 65535 any eq 3544 rule-id 9998 access-list CSM_FW_ACL_ advanced permit 41 any any rule-id 9998 access-list CSM_FW_ACL_ advanced permit gre any any rule-id 9998 access-list CSM_FW_ACL_ remark rule-id 268439552:ACCESS POLICY:acp_simple — 必填 access-list CSM_FW_ACL_ remark rule-id 268439552:L7 RULE:rule1 access-list CSM_FW_ACL_ advanced permit ip any any rule-id 268439552 ! tcp-map UM_STATIC_TCP_MAP tcp-options range 6 7 allow tcp選項範圍9 18 allow tcp-options range 20 255 allow urgent-flag allow ! 無尋呼機 no logging message 106015 no logging message 313001 no logging message 313008 no logging message 106023 no logging message 710003 no logging message 106100 no logging message 302015 no logging message 302014 no logging message 302013 no logging message 302018 no logging message 302017 no logging message 302016 no logging message 302021 no logging message 302020 無故障切換 <省略部分輸出>
> configure high-availability disable ? Optional parameter to clear interfaces (clear-interfaces) optional parameter to clear interfaces (clear-interfaces) (clear-interfaces) <cr>
> configure high-availability disable
High-availability will be disabled. Do you really want to continue?
Please enter 'YES' or 'NO': yes
Successfully disabled high-availability.
結果是:
主裝置(非待機)
輔助裝置(非活動)
> INFO: This unit is currently in standby state. By disabling failover, this unit will remain in standby state.
> show failover Failover Off (pseudo-Standby) Failover unit Primary Failover LAN Interface: FOVER Port-channel3 (up) Reconnect timeout 0:00:00 Unit Poll frequency 1 seconds, holdtime 15 seconds Interface Poll frequency 5 seconds, holdtime 25 seconds Interface Policy 1 Monitored Interfaces 0 of 1291 maximum MAC Address Move Notification Interval not set failover replication http
> show ip System IP Addresses: Interface Name IP address Subnet mask Method Port-channel3 FOVER 172.16.51.1 255.255.255.0 unset Current IP Addresses: Interface Name IP address Subnet mask Method Port-channel3 FOVER 172.16.51.1 255.255.255.0 unset
> show failover Failover Off Failover unit Secondary Failover LAN Interface: not Configured Reconnect timeout 0:00:00 Unit Poll frequency 1 seconds, holdtime 15 seconds Interface Poll frequency 5 seconds, holdtime 25 seconds Interface Policy 1 Monitored Interfaces 4 of 1291 maximum MAC Address Move Notification Interval not set
> show ip System IP Addresses: Interface Name IP address Subnet mask Method Port-channel2.202 NET202 172.16.202.1 255.255.255.0 CONFIG Port-channel2.203 NET203 172.16.203.1 255.255.255.0 CONFIG Ethernet1/4 NET204 172.16.204.1 255.255.255.0 CONFIG Current IP Addresses: Interface Name IP address Subnet mask Method Port-channel2.202 NET202 172.16.202.1 255.255.255.0 CONFIG Port-channel2.203 NET203 172.16.203.1 255.255.255.0 CONFIG Ethernet1/4 NET204 172.16.204.1 255.255.255.0 CONFIG
主要(非待機)
輔助(非活動)
> show running-config :已儲存
: :序列號:FLM1949C5RR :硬體:FPR4K-SM-24,73853 MB RAM,CPU Xeon E5系列2200 MHz,2個CPU(48個核心) : NGFW版本7.2.8 ! hostname Firepower-module1 enable password ***** encrypted strong-cryption-disable no asp inspect-dp ack-passthrough service-module 0 keepalive-timeout 4 service-module 0 keepalive-counter 6 姓名 no mac-address auto
! interface Port-channel2 關機 no nameif 無安全級別 no ip address < — 已刪除IP ! interface Port-channel3 說明LAN/STATE故障切換介面 ! interface Ethernet1/1 僅管理 關機 no nameif 無安全級別 no ip address ! interface Ethernet1/4 關機 no nameif 無安全級別 no ip address ! ftp mode passive ngips conn-match vlan-id no object-group-search access-control access-group CSM_FW_ACL_ global access-list CSM_FW_ACL_ remark rule-id 9998:預過濾器策略:預設通道和優先順序原則 access-list CSM_FW_ACL_ remark rule-id 9998:RULE:預設隧道操作規則 access-list CSM_FW_ACL_ advanced permit ipinip any any rule-id 9998 access-list CSM_FW_ACL_ advanced permit udp any eq 3544 any range 1025 65535 rule-id 9998 access-list CSM_FW_ACL_ advanced permit udp any range 1025 65535 any eq 3544 rule-id 9998 access-list CSM_FW_ACL_ advanced permit 41 any any rule-id 9998 access-list CSM_FW_ACL_ advanced permit gre any any rule-id 9998 access-list CSM_FW_ACL_ remark rule-id 268434433:ACCESS POLICY:acp_simple — 預設 access-list CSM_FW_ACL_ remark rule-id 268434433:L4 RULE:預設操作規則 access-list CSM_FW_ACL_ advanced permit ip any any rule-id 268434433 ! tcp-map UM_STATIC_TCP_MAP tcp-options range 6 7 allow tcp選項範圍9 18 allow tcp-options range 20 255 allow tcp選項md5 clear urgent-flag allow ! 無尋呼機 no logging message 106015 no logging message 313001 no logging message 313008 no logging message 106023 no logging message 710003 no logging message 106100 no logging message 302015 no logging message 302014 no logging message 302013 no logging message 302018 no logging message 302017 no logging message 302016 no logging message 302021 no logging message 302020 無故障切換 failover lan unit primary failover lan interface FOVER Port-channel3 故障切換複製http 故障切換鏈路FOVER Port-channel3 故障切換介面ip從172.16.51.1 255.255.255.0備用172.16.51.2 no monitor-interface service-module
<省略部分輸出>
> show running-config :已儲存
: :序列號:FLM2108V9YG :硬體:FPR4K-SM-24,73853 MB RAM,CPU Xeon E5系列2200 MHz,2個CPU(48個核心) : NGFW版本7.2.8 ! hostname Firepower-module1 enable password ***** encrypted strong-cryption-disable no asp inspect-dp ack-passthrough service-module 0 keepalive-timeout 4 service-module 0 keepalive-counter 6 姓名 no mac-address auto
! interface Port-channel2 no nameif 無安全級別 no ip address ! interface Port-channel2.202 vlan 202 nameif NET202 cts manual(cts手冊) propagate sgt preserve-untag 策略靜態sgt disabled trusted 安全級別0 ip address 172.16.202.1 255.255.255.0 standby 172.16.202.2 ! interface Port-channel2.203 vlan 203 nameif NET203 cts manual(cts手冊) propagate sgt preserve-untag 策略靜態sgt disabled trusted 安全級別0 ip address 172.16.203.1 255.255.255.0 standby 172.16.203.2 ! interface Port-channel3 no nameif 無安全級別 no ip address ! interface Ethernet1/1 僅管理 nameif diagnostic cts manual(cts手冊) propagate sgt preserve-untag 策略靜態sgt disabled trusted 安全級別0 no ip address ! interface Ethernet1/4 nameif NET204 cts manual(cts手冊) propagate sgt preserve-untag 策略靜態sgt disabled trusted 安全級別0 ip address 172.16.204.1 255.255.255.0 standby 172.16.204.2 ! ftp mode passive ngips conn-match vlan-id no object-group-search access-control access-group CSM_FW_ACL_ global access-list CSM_FW_ACL_ remark rule-id 9998:預過濾器策略:預設通道和優先順序原則 access-list CSM_FW_ACL_ remark rule-id 9998:RULE:預設隧道操作規則 access-list CSM_FW_ACL_ advanced permit ipinip any any rule-id 9998 access-list CSM_FW_ACL_ advanced permit udp any eq 3544 any range 1025 65535 rule-id 9998 access-list CSM_FW_ACL_ advanced permit udp any range 1025 65535 any eq 3544 rule-id 9998 access-list CSM_FW_ACL_ advanced permit 41 any any rule-id 9998 access-list CSM_FW_ACL_ advanced permit gre any any rule-id 9998 access-list CSM_FW_ACL_ remark rule-id 268434433:ACCESS POLICY:acp_simple — 預設 access-list CSM_FW_ACL_ remark rule-id 268434433:L4 RULE:預設操作規則 access-list CSM_FW_ACL_ advanced permit ip any any rule-id 268434433 ! tcp-map UM_STATIC_TCP_MAP tcp-options range 6 7 allow tcp選項範圍9 18 allow tcp-options range 20 255 allow tcp選項md5 clear urgent-flag allow ! 無尋呼機 no logging message 106015 no logging message 313001 no logging message 313008 no logging message 106023 no logging message 710003 no logging message 106100 no logging message 302015 no logging message 302014 no logging message 302013 no logging message 302018 no logging message 302017 no logging message 302016 no logging message 302021 no logging message 302020 mtu NET202 1500 mtu NET203 1500 mtu diagnostic 1500 mtu NET204 1500 無故障切換 monitor-interface NET202 monitor-interface NET203 no monitor-interface service-module
> configure high-availability disable High-availability will be disabled. Do you really want to continue? Please enter 'YES' or 'NO': YES Successfully disabled high-availability.
> configure high-availability disable clear-interfaces High-availability will be disabled. Do you really want to continue? Please enter 'YES' or 'NO': yes Successfully disabled high-availability.
> configure high-availability disable clear-interfaces High-availability will be disabled. Do you really want to continue? Please enter 'YES' or 'NO': YES Successfully disabled high-availability.
> configure high-availability suspend
Please ensure that no deployment operation is in progress before suspending high-availability.
Please enter 'YES' to continue if there is no deployment operation in progress and 'NO' if you wish to abort: YES
Successfully suspended high-availability.
步驟2.檢驗主裝置上的更改:
> show high-availability configFailover Off
Failover unit Primary
Failover LAN Interface: fover_link Ethernet1/4 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 1 of 1041 maximum
MAC Address Move Notification Interval not set
failover replication http
步驟3.輔助裝置上的結果:
> show high-availability config
Failover Off (pseudo-Standby)
Failover unit Secondary
Failover LAN Interface: fover_link Ethernet1/4 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 1 of 1041 maximum
MAC Address Move Notification Interval not set
failover replication http
步驟4.在主裝置上恢復HA:
> configure high-availability resume
Successfully resumed high-availablity.
> .
No Active mate detected
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Beginning configuration replication: Sending to mate.
End Configuration Replication to mate
>
> show high-availability configFailover On
Failover unit Primary
Failover LAN Interface: fover_link Ethernet1/4 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 1 of 1041 maximum
MAC Address Move Notification Interval not set
failover replication http
步驟5.恢復HA後輔助裝置上的結果:
> ..
Detected an Active mate
Beginning configuration replication from mate.
WARNING: Failover is enabled but standby IP address is not configured for this interface.
WARNING: Failover is enabled but standby IP address is not configured for this interface.
End configuration replication from mate.
>
> show high-availability configFailover On
Failover unit Secondary
Failover LAN Interface: fover_link Ethernet1/4 (up)
Reconnect timeout 0:00:00
Unit Poll frequency 1 seconds, holdtime 15 seconds
Interface Poll frequency 5 seconds, holdtime 25 seconds
Interface Policy 1
Monitored Interfaces 1 of 1041 maximum
MAC Address Move Notification Interval not set
failover replication http
>
> configure high-availability suspend
Please ensure that no deployment operation is in progress before suspending high-availability.
Please enter 'YES' to continue if there is no deployment operation in progress and 'NO' if you wish to abort: YES
Successfully suspended high-availability.
firepower# show failover | include Failover
Failover Off (pseudo-Standby)
Failover unit Secondary
Failover LAN Interface: FOVER Ethernet1/1 (up)
startup-config仍然啟用故障轉移:
firepower# show startup | include failoverfailover
failover lan unit secondary
failover lan interface FOVER Ethernet1/1
failover replication http
failover link FOVER Ethernet1/1
failover interface ip FOVER 192.0.2.1 255.255.255.0 standby 192.0.2.2
failover ipsec pre-shared-key *****
透過 CLISH 重新啟動裝置(reboot 命令):
> reboot
This command will reboot the system. Continue?
Please enter 'YES' or 'NO': YES
Broadcast message from root@
Threat Defense System: CMD=-stop, CSP-ID=cisco-ftd.6.2.2.81__ftd_001_JMX2119L05CYRIBVX1, FLAG=''
Cisco FTD stopping ...
裝置啟動後,容錯移轉便會啟用,因此裝置會進入容錯移轉交涉階段並嘗試偵測遠端對等:
User enable_1 logged in to firepower
Logins over the last 1 days: 1.
Failed logins since the last login: 0.
Type help or '?' for a list of available commands.
firepower> .
Detected an Active mate
firepower# reload
System config has been modified. Save? [Y]es/[N]o: Y <-- Be careful. This disables the failover in the startup-config
Cryptochecksum: 31857237 8658f618 3234be7c 854d583a
8781 bytes copied in 0.940 secs
Proceed with reload? [confirm]
firepower# show startup | include failoverno failover
failover lan unit secondary
failover lan interface FOVER Ethernet1/1
failover replication http
failover link FOVER Ethernet1/1
failover interface ip FOVER 192.0.2.1 255.255.255.0 standby 192.0.2.2
failover ipsec pre-shared-key *****
裝置啟動後,容錯移轉便會停用:
firepower# show failover | include FailFailover Off
Failover unit Secondary
Failover LAN Interface: FOVER Ethernet1/1 (up)