H3C Comware VRRP Configuration and Verification - 夜莺博客

H3C Comware VRRP Configuration and Verification

VRRP on H3C Comware looks almost identical to Cisco's, with one important difference: the track object that lets a master demote itself when an uplink fails is a first-class configuration element you create and reference, and Comware also supports a standalone weight-based form. Teams migrating from Cisco routers to Comware switches routinely get the election and preemption behaviour wrong. This guide gives the configuration in the order it should be applied, together with the display commands that show precisely which router is master and why.

Priorities, Preemption and the Odd Rules

Priority ranges from 0 to 255, where a higher value wins. Values 1 to 254 are configurable, 0 is reserved, and 255 is reserved for the IP address owner - the router that actually owns the virtual address, which always runs at 255 and always becomes master while it is healthy. A backup in preempt mode does not take over the instant it sees a lower-priority advertisement; it waits for preemption delay plus skew time, which exists to stop flapping.

All routers in the same VRRP group must run the same VRRP version. Comware defaults to VRRPv3 for IPv4, while older peers may still be VRRPv2.

Basic Configuration on the Master

system-view
interface Vlan-interface 2
 ip address 10.1.1.1 255.255.255.0
 vrrp vrid 1 virtual-ip 10.1.1.111
 vrrp vrid 1 priority 110
 vrrp vrid 1 preempt-mode delay 5000
 quit

The delay is in centiseconds in this command form, so 5000 means 50 seconds. Longer delays are appropriate on links that bounce during convergence, shorter ones on stable LAN segments.

Configuration on the Backup

system-view
interface Vlan-interface 2
 ip address 10.1.1.2 255.255.255.0
 vrrp vrid 1 virtual-ip 10.1.1.111
 vrrp vrid 1 priority 100
 vrrp vrid 1 preempt-mode delay 5000
 quit

Interface Tracking: Demote When the Uplink Dies

Without tracking, a master whose uplink has failed keeps the virtual IP and black-holes traffic - the worst possible failure mode, because the network looks healthy from the clients' perspective. Create a track entry and reference it from the VRRP group.

system-view
track 1 interface Ten-GigabitEthernet 1/0/1
 quit

interface Vlan-interface 2
 vrrp vrid 1 track 1 priority reduced 50
 quit

When the tracked interface goes down, the master's running priority drops by the configured amount. Ensure the reduced value is below the backup's priority - a 20-point reduction on a router with priority 110 leaves it at 90, while a backup at 100 correctly takes over. Comware also supports the weight-based form, where the tracked object adds or subtracts a weight from the running priority.

Verification

display vrrp
display vrrp verbose
display vrrp interface Vlan-interface 2
display track all

The verbose output shows the running mode, VRID, advertisement timer, state, configured and running priority, preempt mode and delay, virtual IP and virtual MAC, the master's real IP, and any tracked objects with their state and reduction value. Read it in this order: state (Master or Backup), then running priority, then the track block. A master whose running priority has dropped but is still above every backup is a misconfigured reduction, not a broken tracking entry.

Load Sharing with Two Groups

Run two VRRP groups on the same interfaces with the priorities swapped so that each router is master for one group and backup for the other:

# DeviceA
interface Vlan-interface 2
 vrrp vrid 1 virtual-ip 10.0.0.1
 vrrp vrid 1 priority 120
interface Vlan-interface 3
 vrrp vrid 2 virtual-ip 11.0.0.1
# DeviceB
interface Vlan-interface 3
 vrrp vrid 2 virtual-ip 11.0.0.1
 vrrp vrid 2 priority 120

Split the client population across the two virtual addresses with DHCP scope options. For command translation between Comware and VRP see Comware vs Huawei VRP command mapping, and for Comware fundamentals H3C Comware CLI basics.

原文链接:https://www.h3c.com/en/d_202410/2284171_294551_0.htm