HP 6125G HP 6125G & 6125G/XG Blade Switches High Availability Command - Page 108

vrrp un-check ttl, vrrp vrid authentication-mode

Page 108 highlights

Examples # Map the virtual IP address of a VRRP group to the real MAC address of the interface. system-view [Sysname] vrrp method real-mac vrrp un-check ttl Syntax vrrp un-check ttl View undo vrrp un-check ttl Interface view Default level 2: System level Parameters None Description Use vrrp un-check ttl to disable TTL check on VRRP packets. Use undo vrrp un-check ttl to enable TTL check on VRRP packets. By default, TTL check on VRRP packets is enabled. The master of a VRRP group periodically sends VRRP advertisements to indicate its existence. The VRRP advertisements are multicast onto the local network segment and not forwarded by a router, and therefore the packet TTL value will not be changed. When the master of a VRRP group advertises VRRP packets, it sets the packet TTL to 255. After you configure to check the VRRP packet TTL, when the backups of the VRRP group receive VRRP packets, they check the packet TTL and drop the VRRP packets whose TTL is smaller than 255 to prevent attacks from other network segments. Because devices of different vendors might implement VRRP in a different way, when the device is interoperating with devices of other vendors, VRRP packet TTL check might result in dropping packets that should not be dropped. In this case, use the vrrp un-check ttl command to disable TTL check on VRRP packets. Examples # Disable TTL check on VRRP packets. system-view [Sysname] interface vlan-interface 2 [Sysname-Vlan-interface2] vrrp un-check ttl vrrp vrid authentication-mode Syntax vrrp vrid virtual-router-id authentication-mode { md5 | simple } [ cipher ] key undo vrrp vrid virtual-router-id authentication-mode 103

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159

103
Examples
# Map the virtual IP address of a VRRP group to the real MAC address of the interface.
<Sysname> system-view
[Sysname] vrrp method real-mac
vrrp un-check ttl
Syntax
vrrp un-check ttl
undo vrrp un-check ttl
View
Interface view
Default level
2: System level
Parameters
None
Description
Use
vrrp un-check ttl
to disable TTL check on VRRP packets.
Use
undo vrrp un-check ttl
to enable TTL check on VRRP packets.
By default, TTL check on VRRP packets is enabled.
The master of a VRRP group periodically sends VRRP advertisements to indicate its existence. The VRRP
advertisements are multicast onto the local network segment and not forwarded by a router, and
therefore the packet TTL value will not be changed. When the master of a VRRP group advertises VRRP
packets, it sets the packet TTL to 255. After you configure to check the VRRP packet TTL, when the backups
of the VRRP group receive VRRP packets, they check the packet TTL and drop the VRRP packets whose TTL
is smaller than 255 to prevent attacks from other network segments.
Because devices of different vendors might implement VRRP in a different way, when the device is
interoperating with devices of other vendors, VRRP packet TTL check might result in dropping packets that
should not be dropped. In this case, use the
vrrp un-check ttl
command to disable TTL check on VRRP
packets.
Examples
# Disable TTL check on VRRP packets.
<Sysname> system-view
[Sysname] interface vlan-interface 2
[Sysname-Vlan-interface2] vrrp un-check ttl
vrrp vrid authentication-mode
Syntax
vrrp vrid
virtual-router-id
authentication-mode
{
md5
|
simple
} [
cipher
]
key
undo vrrp vrid
virtual-router-id
authentication-mode