Documente Academic
Documente Profesional
Documente Cultură
27
Contents
Information About HSRP and VRRP, page 27-2 How to Configure HSRP, page 27-3 Configuration Examples for HSRP, page 27-5 How to Configure VRRP, page 27-6 Configuration Examples for VRRP, page 27-8 Where to Go Next Additional References, page 27-9
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide OL-23826-09
27-1
Text Authentication
HSRP and VRRP ignore unauthenticated protocol messages. The default authentication type is text authentication. HSRP or VRRP authentication protects against false hello packets causing a denial-of-service attack. For example, Router A has a priority of 120 and is the active router. If a host sends spoof hello packets with a priority of 130, then Router A stops being the active router. If Router A has authentication configured such that the spoof hello packets are ignored, Router A will remain the active router. Packets will be rejected in any of the following cases:
The authentication schemes differ on the router and in the incoming packets. Text authentication strings differ on the router and in the incoming packets.
Preemption
Preemption occurs when a virtual router backup with a higher priority takes over a virtual router backup that was elected to become a virtual router master and a preemptive scheme is enabled automatically. When a newly reloaded router becomes active, despite an active router already existent on the network, it may appear that preemption is not functioning but it is not true. The new active router did not receive any hello packets from the current active router, and the preemption configuration never factored into the new routers decision making. In general, we recommend that all HSRP routers have the following configuration:
standby delay minimum 30 reload 60
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide
27-2
OL-23826-09
Chapter 27
Hot Standby Router Protocol and Virtual Router Redundancy Protocol How to Configure HSRP
The standby delay minimum reload interface configuration command delays HSRP groups from initializing for the specified time after the interface comes up. This command is different from the standby preempt delay interface configuration command, which enables HSRP preemption delay. You can disable the preemptive scheme by using the no vrrp preempt command. If preemption is disabled, the virtual router backup that is elected to become virtual router master remains the master until the original virtual router master recovers and becomes master again.
Configuring HSRP
Complete the following steps to configure HSRP:
Restrictions
HSRP is supported only on IPv4 devices and not on IPv6 devices. HSRP is supported only gigabyte etherchannel interfaces of the Layer 3 SVI. Bidirectional Forwarding Detection (BFD) protocol is not supported.
SUMMARY STEPS
1. 2. 3. 4. 5. 6. 7. 8. 9.
enable configure terminal interface type number standby [group-number] ip [ip-address mask [secondary]] standby [group-number] timers [msec] hellotime [msec] holdtime standby [group-number] preempt [delay {minimum delay | reload delay | sync delay}] standby [group-number] priority priority standby [group-number] authentication text string standby [group-number] track object-number [decrement priority-decrement]
10. end
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide OL-23826-09
27-3
DETAILED STEPS
Command or Action
Step 1
enable
Example:
Router> enable
Step 2
configure terminal
Example:
Router# configure terminal
Step 3
Example:
Router(config)# interface Ethernet0/1
Step 4
Example:
Router(config-if)# ip address 10.0.0.1 255.255.255.0
Step 5
Configures the interval at which packets are sent to refresh the MAC cache when HSRP is running.
Example:
Router(config-if)# standby 1 timers 14
Step 6
standby [group-number] preempt [delay {minimum delay | reload delay | sync delay}]
Example:
Router(config-if)# standby 1 preempt delay minimum 380
Step 7
Example:
Router(config-if)# standby 1 priority 110
Step 8
Example:
Router(config-if)# standby 1 authentication text authentication1
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide
27-4
OL-23826-09
Chapter 27
Hot Standby Router Protocol and Virtual Router Redundancy Protocol Configuration Examples for HSRP
Command or Action
Step 9
standby [group-number] track object-number [decrement priority-decrement]
Purpose Configures HSRP to track an object and change the Hot Standby priority on the basis of the state of the object.
Example:
Router(config-if)# standby 1 track 100 decrement 20
Step 10
end
Example:
Router(config-if)# end
Example: Configuring HSRP Active Router Example: Configuring HSRP Backup Router Example: HSRP Text Authentication
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide OL-23826-09
27-5
Router# configure terminal Router(config)# interface Vlan10 Router(config-if)# ip address 10.10.10.22 255.255.255.0 Router(config-if)# standby 1 ip 10.10.10.20 Router(config-if)# standby 1 timers 1 4 Router(config-if)# standby 1 priority 90 Router(config-if)# standby 1 preempt delay minimum 10 Router(config-if)# standby 1 authentication cisco6 Router(config-if)# standby 1 track 1 decrement 20 Router(config-if)# end
Configuring VRRP
Complete the following steps to configure VRRP:
Restrictions
VRRP is supported only on IPv4 devices and not IPv6 devices. VRRP is supported only on gigabyte etherchannel interfaces of the Layer 3 SVI. Bidirectional Forwarding Detection (BFD) protocol is not supported. MD5 authentication is not supported.
SUMMARY STEPS
1. 2. 3. 4. 5. 6.
enable configure terminal interface type number ip ip-address mask vrrp [group-number] timers advertise [msec] interval vrrp [group-number] preempt [delay minimum seconds]
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide
27-6
OL-23826-09
Chapter 27
Hot Standby Router Protocol and Virtual Router Redundancy Protocol How to Configure VRRP
7. 8. 9.
vrrp [group-number] priority level vrrp [group-number] authentication text string vrrp [group-number] track object-number [decrement priority-decrement]
10. end
DETAILED STEPS
Command or Action
Step 1
enable
Example:
Router> enable
Step 2
configure terminal
Example:
Router# configure terminal
Step 3
Example:
Router(config)# interface Vlan10
Step 4
Example:
Router(config-if)# ip address 10.10.10.25 255.255.255.0
Step 5
Configures the interval at which packets are sent to refresh the MAC cache when VRRP is running
Example:
Router(config-if)# vrrp 2 timers advertise 2
Step 6
Example:
Router(config-if)# vrrp 2 preempt delay minimum 10
Step 7
Example:
Router(config-if)# vrrp 2 priority 200
Step 8
Example:
Router(config-if)# vrrp 2 authentication text cisco7
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide OL-23826-09
27-7
Command or Action
Step 9
vrrp [group-number] track object-number [decrement priority-decrement]
Purpose Configures VRRP to track an object and change the Hot Standby priority on the basis of the state of the object.
Example:
Router(config-if)# vrrp 2 track 1 decrement 20
Step 10
end
Example:
Router(config-if)# end
Example: Configuring a VRRP Master Router Example: Configuring a VRRP Backup Router Example: VRRP Text Authentication
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide
27-8
OL-23826-09
Chapter 27
Hot Standby Router Protocol and Virtual Router Redundancy Protocol Where to Go Next
Router# configure terminal Router(config)# interface Vlan10 Router(config-if)# ip address 10.10.10.26 255.255.255.0 Router(config-if)# vrrp 2 ip 10.10.10.30 Router(config-if)# vrrp 2 timers advertise 2 Router(config-if)# vrrp 2 preempt delay minimum 10 Router(config-if)# vrrp 2 priority 90 Router(config-if)# vrrp 2 authentication text cisco7 Router(config-if)# vrrp 2 track 1 decrement 20 Router(config-if)# end
Where to Go Next
For additional information on configuring HSRP and VRRP, see the documentation listed in the Related Documents section on page 27-9.
Additional References
Related Documents
Related Topic Cisco IOS commands ASR 901 Command Reference Cisco IOS Interface and Hardware Component Commands Document Title Cisco IOS Master Commands List, All Releases Cisco ASR 901 Series Aggregation Services Router Command Reference Cisco IOS Interface and Hardware Component Command Reference
Standards
Standard None Title
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide OL-23826-09
27-9
MIBs
MIB None MIBs Link To locate and download MIBs for selected platforms, Cisco software releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs
RFCs
RFC No new or modified RFCs are supported by this feature, and support for existing RFCs has not been modified by this feature. Title
Technical Assistance
Description Link http://www.cisco.com/cisco/web/support/index.html The Cisco Support and Documentation website provides online resources to download documentation, software, and tools. Use these resources to install and configure the software and to troubleshoot and resolve technical issues with Cisco products and technologies. Access to most tools on the Cisco Support and Documentation website requires a Cisco.com user ID and password.
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide
27-10
OL-23826-09
Chapter 27
Hot Standby Router Protocol and Virtual Router Redundancy Protocol Feature Information for HSRP and VRRP
Note
Table 1 lists only the software release that introduced support for a given feature in a given software release train. Unless noted otherwise, subsequent releases of that software release train also support that feature.
Table 1
Releases 15.2(2)SNG
Feature Information The following sections provide information about this feature:
Overview of HSRP and VRRP Text Authentication Preemption Configuring HSRP Configuration Examples for HSRP Configuring VRRP Configuration Examples for VRRP
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide OL-23826-09
27-11
Cisco ASR 901 Series Aggregation Services Router Software Configuration Guide
27-12
OL-23826-09