Sunteți pe pagina 1din 34

Huawei Symantec Technologies Co., Ltd.

VRRP Principle
page 2
Huawei Symantec Technologies Co., Ltd.
Foreword
This course introduces the Virtual Router Redundancy Protocol (VRRP).
VRRP specifies an election protocol that dynamically assigns
responsibility for a Virtual Router to one of the VRRP Routers on a LAN.
page 3
Huawei Symantec Technologies Co., Ltd.
References
RFC2338: Virtual Router Redundancy
Protocol
VRP Operation Manual
page 4
Huawei Symantec Technologies Co., Ltd.
Objectives
Master the principle of VRRP
page 5
Huawei Symantec Technologies Co., Ltd.
Chapter 1 VRRP Overview Chapter 1 VRRP Overview
Chapter 2 Protocol Packets and State Machine Chapter 2 Protocol Packets and State Machine
Chapter 3 Special Topics Chapter 3 Special Topics
page 6
Huawei Symantec Technologies Co., Ltd.
Why VRRP ?
10.1.1.1/24
10.1.1.254
Ethernet
RTA
Internet
10.1.1.2/24
10.1.1.254
10.1.1.3/24
10.1.1.254
10.1.1.4/24
10.1.1.254
10.1.1.254/24
Only one gateway,
no redundancy
PCA
PCB
PCC PCD
page 7
Huawei Symantec Technologies Co., Ltd.
What is VRRP
10.1.1.1/24
10.1.1.254
Ethernet
RTA
Internet
10.1.1.2/24
10.1.1.254
10.1.1.3/24
10.1.1.254
10.1.1.4/24
10.1.1.254
10.1.1.251/24
PCA
PCB
PCC PCD
RTB
10.1.1.252/24
Virtual
Router
10.1.1.254 E0/0 E0/0
page 8
Huawei Symantec Technologies Co., Ltd.
Virtual Router ID and Virtual IP Address
Virtual Router ID
configured on RTA is 1
Virtual Router ID
configured on RTB is also 1
IP Address of
Virtual Router 1
IP Address of Virtual Router
1 should be the same as
configured on RTA
page 9
Huawei Symantec Technologies Co., Ltd.
Electing the Master
10.1.1.1/24
10.1.1.254
Ethernet
RTA
Internet
10.1.1.2/24
10.1.1.254
10.1.1.3/24
10.1.1.254
10.1.1.4/24
10.1.1.254
10.1.1.251/24
Priority = 200
PCA
PCB
PCC PCD
RTB
10.1.1.252/24
Priority = 150
Virtual
Router
10.1.1.254 E0/0 E0/0
The Master The Backup
page 10
Huawei Symantec Technologies Co., Ltd.
Electing the Master
The Master has the
highest priority value
The Backup has lower
priority value
The Master
page 11
Huawei Symantec Technologies Co., Ltd.
Special values of Priority ---- 255
10.1.1.1/24
10.1.1.254
Ethernet
RTA
Internet
10.1.1.2/24
10.1.1.254
10.1.1.3/24
10.1.1.254
10.1.1.4/24
10.1.1.254
10.1.1.254/24
PCA
PCB
PCC PCD
RTB
10.1.1.252/24
Virtual
Router
10.1.1.254 E0/0 E0/0
IP Address Owner
page 12
Huawei Symantec Technologies Co., Ltd.
Special values of Priority ---- 255
The Running Priority is
255 since this router is
the IP Address Owner
RTB is the Backup although its
Configured Priority is higher
page 13
Huawei Symantec Technologies Co., Ltd.
Special values of Priority ---- 0
The Priority value 0 indicates that
the current Master has stopped
participating in VRRP
Deleting VRRP
configuration
page 14
Huawei Symantec Technologies Co., Ltd.
Preempt_Mode and Timers
The Advertisement_Interval
is 1 second
The Preempt_Mode is TRUE
Time to delay when a higher
priority Backup preempts a
lower priority Master
page 15
Huawei Symantec Technologies Co., Ltd.
Summary
What is VRRP?
Virtual Router; Virtual Router ID,
Virtual IP Address.
Electing the Master.
Special values of Priority.
Preemption mode and Timers.
page 16
Huawei Symantec Technologies Co., Ltd.
Chapter 1 VRRP Overview Chapter 1 VRRP Overview
Chapter 2 Protocol Packets and State Machine Chapter 2 Protocol Packets and State Machine
Chapter 3 Special Topics Chapter 3 Special Topics
page 17
Huawei Symantec Technologies Co., Ltd.
VRRP Packet Format
Only one packet type ---- ADVERTISEMENT
Only the Master can send VRRP Advertisements
page 18
Huawei Symantec Technologies Co., Ltd.
IP Fields of VRRP Packets
The IP protocol number is 0x70 Protocol
Must be 255 TTL
IP multicast address 224.0.0.18 Destination
Address
Physical IP interface address of the
Master
Source Address
Value Field
page 19
Huawei Symantec Technologies Co., Ltd.
Virtual Router MAC Address
VRID 01 00 5E 00 00
The last one byte of a Virtual Router MAC
Address is the VRID of this Virtual Router
page 20
Huawei Symantec Technologies Co., Ltd.
Layer 2 fields of VRRP packets
0x0800 Type
The Virtual Router MAC Address Source MAC Address
Multicast MAC Address 01-00-5E-00-
00-12
Destination MAC
Address
Value Field
page 21
Huawei Symantec Technologies Co., Ltd.
Authentication
MD5 Password 2
Simple Text Password 1
No Authentication 0
Authentication Method Auth Type
page 22
Huawei Symantec Technologies Co., Ltd.
Protocol State Machine
Backup Master
Initialize
S
t
a
r
t
u
p
P
r
i
o
r
i
t
y

i
s

2
5
5
S
t
a
r
t
u
p
P
r
i
o
r
i
t
y

i
s

n
o
t

2
5
5
page 23
Huawei Symantec Technologies Co., Ltd.
Protocol State Machine
Backup Master
Initialize
S
h
u
t
d
o
w
n
Master_Down_Timer
page 24
Huawei Symantec Technologies Co., Ltd.
Protocol State Machine
Backup Master
Initialize
S
h
u
t
d
o
w
n
More prior Advertisement received
page 25
Huawei Symantec Technologies Co., Ltd.
Summary
VRRP Packet format
IP fields of VRRP Packets
Virtual Router MAC Address
Layer 2 fields of VRRP Packets
Authentication methods
Protocol State Machine
page 26
Huawei Symantec Technologies Co., Ltd.
Chapter 1 VRRP Overview Chapter 1 VRRP Overview
Chapter 2 Protocol Packets and State Machine Chapter 2 Protocol Packets and State Machine
Chapter 3 Special Topics Chapter 3 Special Topics
page 27
Huawei Symantec Technologies Co., Ltd.
Handling of ARP Requests
FCS DATA 0806 SMAC DMAC
10.1.1.1/24
10.1.1.254
RTA
10.1.1.254
00-00-5E-00-01-01
PCA
RTB
10.1.1.251/24
E0/0
E0/0
10.1.1.252/24
The Master
Broadcast
Requesting the MAC
Address for 10.1.1.254
FCS DATA 0806 SMAC DMAC
Unicast
1
2
Virtual MAC
Address
ARP Response
page 28
Huawei Symantec Technologies Co., Ltd.
VRRP and ICMP Redirect Message
10.1.1.1/24
10.1.1.254
RTA
10.1.1.254
00-00-5E-00-01-01
PCA
RTB
10.1.1.251/24
E0/0
E0/0
10.1.1.252/24
The Master
Loopback0
2.2.2.2/32
Loopback0
1.1.1.1/32
1
Send ICMP Echo Message
Dst IP = 1.1.1.1
Dst MAC = 00-00-5E-00-01-01
2 Send ICMP Redirect Message
Src IP = 10.1.1.254
Src MAC = RTB's Interface MAC
Address
page 29
Huawei Symantec Technologies Co., Ltd.
VRRP and ICMP Redirect Message
Using Virtual IP Address
as the source IP address
Using physical IP Address
as the source IP address
page 30
Huawei Symantec Technologies Co., Ltd.
VRRP and ICMP Redirect Message
There are two ARP
entries on PCA
page 31
Huawei Symantec Technologies Co., Ltd.
VRRP and ICMP Redirect Message
PCA adds a new route to destination
1.1.1.1/32, using 10.1.1.251 as the next hop
page 32
Huawei Symantec Technologies Co., Ltd.
Sending IP packets by the Master
Physical Interface MAC
Address
Physical IP Interface
Address
Sending IP Packets
originated by the Master
Physical Interface MAC
Address
Do not change Forwarding IP Packets
Physical Interface MAC
Address
Virtual IP Addresses
Physical Interface Address
ICMP Redirect Message
Virtual MAC Address of
the Virtual Router
Physical IP Interface
Address
VRRP Advertisement
Source MAC Address Source IP Address Type
page 33
Huawei Symantec Technologies Co., Ltd.
Summary
Handling of ARP Request
Sending Redirect Messages
Sending IP packets by the Master
Huawei Symantec Technologies Co., Ltd.

S-ar putea să vă placă și