Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
Leader
Leader

VRRP with R80.10 - Interfaces in backup mode

Hi Folks,

I am facing a weird issue with R80.10 Cluster in VRRP.

I have currently have only one firewall configured in VRRP cluster and management server is away one hop; that is on L3 switch. 

So my topology is INTERNET-----Firewall--> L3-->Mgmt server.

I then upgraded the firewall to R80.30 however after upgradation obviously it came up with Initial Policy since it could not fetch the policy from Mgmt server however when I decided to install policy it couldnt connect to Mgmt server. When I investigated I found that all the interfaces [though its single appliance in cluster] were in backup mode. And since no policy was installed HA module wasnt started.

I guess since being a single appliance it by default should come up as Primary, correct?

Any clue or any other alternative by which appliance can load last installed policy?

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
5 Replies
Maarten_Sjouw
Champion
Champion

If you look with cphaprob stat you will probably see it is in Raeady state, this means that when you have the flag MonitorFirewall set to ON it will not come up as master, so just change it to Monitor Firewall off.
set vrrp monitor-firewall off
Regards, Maarten
0 Kudos
Blason_R
Leader
Leader

I see does that mean since it does not have any policy it went in backup mode? And shutting down the monitor-firewall will make in Primary even if the policy is set as Initial?

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
Maarten_Sjouw
Champion
Champion

It checks the state of cphaprob, when it is still set to ready it will not go into Master mode.
As you only have one member ithis setting does not make sense to check. you always need to be in master mode with this member.
Regards, Maarten
0 Kudos
Blason_R
Leader
Leader

Oh ok - So, setting up firewall mode off makes sense, right?

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
Maarten_Sjouw
Champion
Champion

Yes, set vrrp monitor-firewall off makes sense.
Regards, Maarten
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events