Manual
Sample L2 Intrachassis HA Configuration
▀ WSG Configuration VM-1 (StarOS)
▄ SecGW Administration Guide, StarOS Release 17
76
exit
crypto template foo ikev2-dynamic
authentication local pre-shared-key encrypted key <encrypted_key>
authentication remote pre-shared-key encrypted key <encrypted_key>
ikev2-ikesa transform-set list ikesa-foo
payload foo-sa0 match childsa match ipv4
ip-address-alloc dynamic
ipsec transform-set list tselsa-foo
exit
identity local id-type ip-addr id 32.32.32.30
exit
interface clear
ip address 78.78.78.33 255.255.255.0
exit
interface ike
ip address 34.34.34.33 255.255.255.0
exit
interface loopback-clear loopback
ip address 78.78.78.50 255.255.255.255 srp-activate
exit
interface loopback-srpa loopback
ip address 34.34.34.101 255.255.255.255 srp-activate
exit
interface loopback-srvip loopback
ip address 32.32.32.30 255.255.255.255 srp-activate
exit
subscriber default
exit
aaa group default
exit
wsg-service abc
deployment-mode site-to-site
ip access-group one
bind address 32.32.32.30 crypto-template foo
exit
ip route 55.55.33.0 255.255.255.0 34.34.34.100 ike
ip route 66.66.66.0 255.255.255.0 78.78.78.100 clear
ip rri-route network-mode L2 78.78.78.50 next-hop 78.78.78.33 interface
clear
ip rri-remote-access next-hop 78.78.78.33 interface clear
exit
context srp
service-redundancy-protocol
chassis-mode primary
hello-interval 3
configuration interval 60
dead interval 15
checkpoint session duration non-ims-session 30
route-modifier threshold 10
priority 10