Migrating from Cisco HSRP to industry standard VRRP

Similar documents
HP Load Balancing Module

HP VPN Firewall Appliances

S Series Switch. Cisco HSRP Replacement. Issue 01. Date HUAWEI TECHNOLOGIES CO., LTD.

WLAN high availability

Exam questions. 1. How many HSRP (Hot Standby Routing Protocol) groups will need to be configured for each VLAN?

H3C S5830V2 & S5820V2 Switch Series

Configuring VRRP. Finding Feature Information. The Virtual Router Redundancy Protocol (VRRP) is an election protocol that dynamically assigns

Operation Manual VRRP. Table of Contents

First Hop Redundancy Protocols Configuration Guide, Cisco IOS XE Release 3SE (Catalyst 3850 Switches)

M2M CDMA Router. VRRP Configuration Guide

Configuring VRRP. Finding Feature Information. Contents

Virtual Router Redundancy Protocol (VRRP) Technical Support Guide

HP Routing Switch Series

Configuring HSRP. Understanding HSRP CHAPTER

Chapter 32 VSRP Commands

H3C Firewall Devices. High Availability Configuration Guide (Comware V7) Hangzhou H3C Technologies Co., Ltd.

H3C SecPath Series Firewalls and UTM Devices

HOT STANDBY ROUTING PROTOCOL (HSRP) - A Deep Dive

Implementing High Availability. in a Campus Environment. Implementing High Availability. Single Forwarding Path vs. Single Forwarding Path.

VRRPv3 Protocol Support

Network Design First Hop

HP FlexFabric 5700 Switch Series

Cisco IOS First Hop Redundancy Protocols Command Reference

Hot Standby Router Protocol (HSRP): Frequently Asked Questions

Vodafone MachineLink. VRRP Configuration Guide

Syntax instance instance [interface interface-name [vrid virtual-router-id] instance interface interface-name vrid virtual-router-id ipv6

Corporate Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA USA

HP 3600 v2 Switch Series

HP 6125 Blade Switch Series

This module was first published on May 2, 2005, and last updated on May 2, 2005.

HP MSR Router Series. EVI Configuration Guide(V7) Part number: b Software version: CMW710-R0304 Document version: 6PW

Performance Evaluation of First HOP Redundancy Protocols (HSRP, VRRP & GLBP)

ROUTING CONSORTIUM. Virtual Router Redundancy Protocol Operations Test Suite. Technical Document. Revision 2.5

Static NAT Mapping with HSRP

HP MSR Router Series. IPX Configuration Guide(V5) Part number: Software version: CMW520-R2513 Document version: 6PW

Layer 3 Routing (UI 2.0) User s Manual

Chapter 6 Lab 6-1, First Hop Redundancy Protocols HSRP and VRRP INSTRUCTOR VERSION

Spatially aware sublayer support of VRRP. Marc Holness, Nortel Networks IEEE WG b SG San Antonio, Texas November, 2004

VRRP (Virtual Router Redundancy Protocol) Function Added

Configuring HSRP. Finding Feature Information. Restrictions for HSRP

HPE VSR1000 Virtual Services Router

Assignment Six: Configure Hot Standby Router Protocol. Brian Dwyer. Morrisville State College

SecBlade Firewall Cards Stateful Failover Configuration Examples

HP A-F1000-A-EI_A-F1000-S-EI VPN Firewalls

HP 6125 Blade Switch Series

standby arp gratuitous through track vrrp

HP 6125G & 6125G/XG Blade Switches

HPE FlexFabric 5940 Switch Series

AppDirector Redundancy Mechanism

Configuring Spanning Tree Protocol

Configuring IP Multicast Routing

HP 6125 Blade Switch Series

Configuring PIM. Information About PIM. Send document comments to CHAPTER

HP Accelerated iscsi for Multifunction Network Adapters User Guide

HP A-F1000-A-EI_A-F1000-S-EI VPN Firewalls

HP FlexFabric 5700 Switch Series

HP 5920 & 5900 Switch Series

HP 5120 SI Switch Series

Section 6.2, IP Routing. Section 6.4, IP/VPN Policy. Section 6.5, IP Quality of Service. Section 6.6, The BANDIT as Firewall

HP A5500 EI & A5500 SI Switch Series Network Management and Monitoring. Configuration Guide. Abstract

3. What could you use if you wanted to reduce unnecessary broadcast, multicast, and flooded unicast packets?

Internetwork Expert s CCNP Bootcamp. Gateway Redundancy Protocols & High Availability. What is High Availability?

Zone-Based Policy Firewall High Availability

HP 5920 & 5900 Switch Series

HP 5820X & 5800 Switch Series Network Management and Monitoring. Configuration Guide. Abstract

Configuring IP Multicast Routing

Network-Level High Availability

HP 5120 EI Switch Series

HP FlexFabric 5930 Switch Series

HP D6000 Disk Enclosure Direct Connect Cabling Guide

HP MSR Routers Troubleshooting Guide (Comware V7)

HP 830 Series PoE+ Unified Wired-WLAN Switch Switching Engine

Chapter 14 Configuring SRP

RealCiscoLAB.com. Configure inter-vlan routing with HSRP to provide redundant, fault-tolerant routing to the internal network.

ITDumpsKR. IT 인증시험한방에패스시키는최신버전시험대비덤프

Configuring IP Multicast Routing

HSRP MD5 Authentication

Exam Questions

Lab Configuring HSRP and GLBP Topology

HP 6125 Blade Switch Series

Cisco Interconnecting Cisco Networking Devices Part 2

HP VSR1000 Virtual Services Router

VRRP Aware PIM with PIM NonDR Join Feature Configuration Example

Configuring STP. Understanding Spanning-Tree Features CHAPTER

HP A5830 Switch Series Layer 3 - IP Services. Configuration Guide. Abstract

HPE Security ArcSight Connectors

HP 5920 & 5900 Switch Series

HPE FlexFabric 12900E & 12900

HP 5920 & 5900 Switch Series

Configuring InterVLAN Routing

Brocade Vyatta Network OS High Availability Configuration Guide, 5.2R1

HP 6125XLG Blade Switch

HP A5120 EI Switch Series IRF. Command Reference. Abstract

Home Agent Redundancy

HPE FlexNetwork HSR6800 Routers

HP 5920 & 5900 Switch Series

Configuring IP Multicast Routing

examcollection.premium.exam.68q. Exam code: Exam name: Troubleshooting and Maintaining Cisco IP Networks (TSHOOT) Version 15.

HP A3100 v2 Switch Series

HP FlexFabric 5700 Switch Series

Transcription:

Migrating from Cisco HSRP to industry standard VRRP Technical white paper Table of contents Router Redundancy Protocol overview... 2 Introduction to Cisco Hot Standby Router Protocol (HSRP)... 2 Introduction to RFC 3768 VRRP... 2 Router Redundancy Protocols supported by HP devices... 3 Comparison of HSRP and VRRP... 3 Router Redundancy application... 4 Network diagram... 4 Configuring HSRP... 4 Verifying the configuration... 5 Migrating from Cisco HSRP to VRRP... 5 Migration guidelines... 5 VRRP configuration and verification procedures... 6 Configuring VRRP... 6 Verifying the configuration... 7 Summary... 8

Router Redundancy Protocol overview Introduction to Cisco Hot Standby Router Protocol (HSRP) In a LAN, if all packets destined to other network segments are forwarded by the same router, when the gateway fails, all the hosts that use the router as the default next-hop fail to communicate with external networks. To address this problem, Cisco developed a proprietary protocol HSRP, which provides redundancy for gateways of hosts in a LAN, increasing the network reliability. HSRP is an error-tolerant protocol, which improves the network reliability and simplifies configurations on hosts. On a multicast and broadcast LAN such as Ethernet, HSRP provides highly reliable default links without configuration changes (such as dynamic routing protocols, route discovery protocols) when a router fails, and prevent network interruption due to a single link failure. HSRP adds a group of routers that can act as network gateways to an HSRP group, which forms a virtual router. Routers in the HSRP group elect a master through the HSRP election mechanism to act as a gateway. The virtual router has its virtual MAC address and IP address. Hosts on a LAN use the virtual IP address and virtual MAC address as the IP address and MAC address of their default gateway. An HSRP group comprises one active router, one standby router, and multiple listen routers. The active router forwards packets sent by hosts, and the standby router acts as the backup of the active router. When the active router fails, or it has a lower priority than the standby router, the standby router takes over as the active router. If the standby router fails or becomes the active router, then another router is elected as the standby router. Routers in an HSRP group have six states: initial, learn, listen, speak, standby, and active. HSRP has three types of packets, hello, resign, and coup packets. HSRP packets are encapsulated in UDP packets, with port number 1985, and destination IP a multicast address (224.0.0.2 for HSRPv1 and 224.0.0.102 for HSRPv2). Routers in speak, standby, and active states all send HSRP packets. Introduction to RFC 3768 VRRP VRRP is defined by Internet Engineering Task Force (IETF) to solve single-point failures. VRRP is an error-tolerant protocol, which improves the network reliability and simplifies configurations on hosts. On a multicast and broadcast LAN such as Ethernet, VRRP provides highly reliable default links without configuration changes (such as dynamic routing protocols, route discovery protocols) when a router fails, and prevents network interruption due to a single link failure. VRRP adds a group of routers that can act as network gateways to a VRRP group, which forms a virtual router. Routers in the VRRP group elect a master through the VRRP election mechanism to act as a gateway, and hosts on a LAN only need to configure the virtual router as their default network gateway. VRRP combines a group of routers (including a master and multiple backups) on a LAN into a virtual router called VRRP group. The virtual router has a virtual IP address. A host on the LAN only needs to know the IP address of the virtual router and uses the IP address as the next hop of the default route. Every host on the LAN communicates with external networks through the virtual router. Routers in the VRRP group elect a master that acts as the gateway according to their priorities. The other routers function as the backups. When the master fails, to ensure that the hosts in the network segment can uninterruptedly communicate with external networks, the backups in the VRRP group elect a new gateway to undertake the responsibility of the failed master. Status of routers in a VRRP group includes initialize, master, and backup. VRRP defines only one type of packet: VRRP advertisement. Only the master in a VRRP group periodically sends VRRP advertisements to notify status and parameters of the master and to elect the master, and the backups do not send VRRP advertisements. VRRP packets are encapsulated in IP packets, with the protocol number 112. VRRP works as follows: 1. Routers in a VRRP group determine their roles by priority and IP address. The router with the highest priority is the master, and the others are the backups. If the routers have the same priority, the one with the highest IP address becomes the master. The master periodically sends VRRP advertisements to notify the backups that it is working properly, and each of the backups starts a timer to wait for advertisements from the master. 2

2. In preemptive mode, when a backup receives a VRRP advertisement, it compares the priority in the packet with its own priority. If the priority of the backup is higher, the backup becomes the master; otherwise, it remains as a backup. With the preemptive mode, a VRRP group always has a router with the highest priority as the master for packet forwarding. 3. In non-preemptive mode, a router in the VRRP group remains as a master or backup as long as the master does not fail. A backup does not become the master even if it is configured with a higher priority. The non-preemptive mode helps avoid frequent switchover between the master and backups. 4. If the timer of a backup expires but the backup still does not receive any VRRP advertisement, it considers that the master fails. In this case, the backup considers itself as the master and sends VRRP advertisements to start a new master election. Router Redundancy Protocols supported by HP devices HP devices support RFC 3768 compliant VRRP and do not support Cisco-proprietary HSRP. Comparison of HSRP and VRRP Protocol type HSRP VRRP Standard Cisco-proprietary RFC 3768 Advertisement interval Ranges from 1 to 254 seconds, and defaults to 3 seconds Ranges from 1 to 255 seconds, and defaults to 1 second Switchover time Hold time, which ranges from (Hello time + 1) to 255 seconds, and defaults to 10 seconds Three advertisement intervals plus skew-time Interoperability Virtual IP address Supported by a few vendors such as Cisco Cannot be the same as the real IP address of an interface Supported by most vendors Can be the same as the real IP address of an interface Priority Ranges from 0 to 255 Ranges from 1 to 255, where 255 is reserved for the IP address owner. Authentication mode None, simple text, and MD5 authentication None, simple text, and MD5 authentication Group number 0 to 255 for HSRPv1 0 to 4095 for HSRPv2 1 to 255 VRRP can implement interoperability among different vendors as a standard protocol as opposed to HSRP. 3

Router Redundancy application Network diagram As shown in Figure 1, Router A and Router B back up each other to act as the gateway of the hosts in the LAN. Host A communicates with Host B on the Internet through the gateway. The default gateway of Host A is 202.38.160.111/24. Router A and Router B belong to standby group 1 with the virtual IP address of 202.38.160.111/24. When Router A operates normally, packets sent from Host A to Host B are forwarded by Router A; if Router A fails, packets sent from Host A to Host B are forwarded by Router B. Configure standby group 1 to monitor Track 1 on Router A. When the status of Track 1 becomes negative, the priority of Router A in group 1 decreases by 20 to trigger Router B to preempt as the master (active router). Figure 1: Network diagram Configuring HSRP 1. Configure Router A hostname RouterA! track 1 interface ethernet2/1 line-protocol! interface ethernet 1/1 ip address 202.38.160.1 255.255.255.0 standby 1 ip 202.38.160.111 standby 1 priority 110 standby 1 preempt standby 1 track 1 decrement 20 4

2. Configure Router B hostname RouterB! interface ethernet 1/1 ip address 202.38.160.2 255.255.255.0 standby 1 ip 202.38.160.111 standby 1 preempt Verifying the configuration # Display the status of Router A to verify that the configuration has taken effect, and the HSRP group is formed. RouterA#show standby Ethernet1/1 - Group 1 State is Active 15 state changes, last state change 00:44:06 Virtual IP address is 202.38.160.111 Active virtual MAC address is 0000.0c07.ac01 Local virtual MAC address is 0000.0c07.ac01 (v1 default) Hello time 3 sec, hold time 10 sec Next hello sent in 2.264 sec Preemption enabled Active router is local Standby router is 202.38.160.2, priority 100 (expires in 7.716 sec) Priority 110 (configured 110) Track object 1 state Up decrement 20 IP redundancy name is "hsrp-et1/1-1" (default) Migrating from Cisco HSRP to VRRP Migration guidelines VRRP implements all HSRP functions and its configuration is similar to HSRP. The key to migrating from an HSRP network to a VRRP network is to plan the virtual IP address, priorities of the master and backups, link monitoring, and switchover time when a fault occurs. In the network shown in Figure 1, configure VRRP on Router A to replace Cisco HSRP configurations: Item Cisco HSRP VRRP Interface IP address 202.38.160.1/24 202.38.160.1/24 VRRP group ID 1 1 Virtual IP address 202.38.160.111 202.38.160.111 VRRP group priority 110 110 Preemption mode Preempt Preempt Advertisement interval 3 seconds 3 seconds Fault switch time 10 seconds Unconfigurable. It takes the value of (3x3 + (256 110)/256)s= 9.57s Monitored object Track 1 Track 1 Authentication mode None authentication None authentication 5

Configure VRRP on Router B to replace Cisco HSRP configurations: Configuration items Cisco HSRP VRRP Interface IP address 202.38.160.2/24 202.38.160.2/24 VRRP group ID 1 1 Virtual IP address 202.38.160.111 202.38.160.111 VRRP group priority Default value 100 Default value 100 Preemption mode Preempt Preempt Advertisement interval 3 seconds 3 seconds Monitored object None None Authentication mode None authentication None authentication VRRP configuration and verification procedures Configuring VRRP 1. Configure Router A <RouterA> system-view [RouterA] interface ethernet 1/1 [RouterA-Ethernet1/1] ip address 202.38.160.1 255.255.255.0 # Create VRRP group 1 and configure its virtual IP address as 202.38.160.111. [RouterA-Ethernet1/1] vrrp vrid 1 virtual-ip 202.38.160.111 # Configure the priority of Router A in the VRRP group 1 as 110, which is higher than that of Router B (100), so that Router A can become the master. [RouterA-Ethernet1/1] vrrp vrid 1 priority 110 # Configure Router A to work in preemptive mode so that it can become the master whenever it works normally. [RouterA-Ethernet1/1] vrrp vrid 1 preempt-mode # Configure the preemption delay as three seconds to avoid frequent status switchover. [RouterA-Ethernet1/1] vrrp vrid 1 timer advertise 3 # Set interface Ethernet 2/1 to be tracked, and configure the amount by which the priority value decreases to be 20, so that when Ethernet 2/1 fails, the priority of Router A in VRRP group 1 decreases to a value lower than 100 and thus Router B can become the master. [RouterA-Ethernet1/1] vrrp vrid 1 track 1 reduced 20 [RouterA-Ethernet1/1] quit [RouterA] track 1 interface ethernet 2/1 2. Configure Router B <RouterB> system-view [RouterB] interface ethernet 1/1 [RouterB-Ethernet1/1] ip address 202.38.160.2 255.255.255.0 # Create VRRP group 1 and configure its virtual IP address as 202.38.160.111. [RouterB-Ethernet1/1] vrrp vrid 1 virtual-ip 202.38.160.111 # Configure Router B to work in preemptive mode. [RouterB-Ethernet1/1] vrrp vrid 1 preempt-mode 6

# Configure the preemption delay as three seconds to avoid frequent status switchover. [RouterB-Ethernet1/1] vrrp vrid 1 timer advertise 3 Verifying the configuration Check that you can ping Host B from Host A. To verify your configuration, use the display vrrp verbose command. # Display detailed information about VRRP group 1 on Router A. [RouterA-Ethernet1/1] display vrrp verbose IPv4 Standby Information: Run Mode : Standard Run Method : Virtual MAC Total number of virtual routers : 1 Interface Ethernet1/1 VRID : 1 Adver Timer : 3 Admin Status : Up State : Master Config Pri : 110 Running Pri : 110 Preempt Mode : Yes Delay Time : 0 Auth Type : None Virtual IP : 202.38.160.111 Virtual MAC : 0000-5e00-0101 Master IP : 202.38.160.1 VRRP Track Information: Track Object : 1 State : Positive Pri Reduced : 20 # Display detailed information about VRRP group 1 on Router B. [RouterB-Ethernet1/1] display vrrp verbose IPv4 Standby Information: Run Mode : Standard Run Method : Virtual MAC Total number of virtual routers : 1 Interface Ethernet1/1 VRID : 1 Adver Timer : 3 Admin Status : Up State : Backup Config Pri : 100 Running Pri : 100 Preempt Mode : Yes Delay Time : 0 Auth Type : None Virtual IP : 202.38.160.111 Master IP : 202.38.160.1 The output shows that in VRRP group 1 Router A is the master, Router B is the backup and packets sent from Host A to Host B are forwarded by Router A. 7

Summary As a standard IETF protocol, VRRP is supported by most vendors. Migrate from Cisco HSRP to VRRP throughout the network. VRRP supports all functions of Cisco HSRP. For more information visit www.hp.com Copyright 2012 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein. 4AA3-9291ENW, Created February 2012