Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (J-Web)

  1. Enabling clusters

    See Step 1 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).

  2. Management interface

    See Step 2 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).

  3. Fabric interface

    See Step 3 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).

  4. Redundancy groups
    • Select Configure>System Properties>Chassis Cluster.
    • Enter the following, then click Apply:
      • Redundant ether-Interfaces Count: 2
      • Heartbeat Interval: 1000
      • Heartbeat Threshold: 3
      • Nodes: 0
      • Group Number: 0
      • Priorities: 254
    • Enter the following, then click Apply:
      • Nodes: 0
      • Group Number: 1
      • Priorities: 254
    • Enter the following, then click Apply:
      • Nodes: 1
      • Group Number: 0
      • Priorities: 1
    • Enter the following, then click Apply:
      • Nodes: 1
      • Group Number: 1
      • Priorities: 1
      • Preempt: Select the check box.
      • Interface Monitor—Interface: xe-5/0/0
      • Interface Monitor—Weight: 255
      • Interface Monitor—Interface: xe-5/1/0
      • Interface Monitor—Weight: 255
      • Interface Monitor—Interface: xe-17/0/0
      • Interface Monitor—Weight: 255
      • Interface Monitor—Interface: xe-17/1/0
      • Interface Monitor—Weight: 255
  5. Redundant Ethernet interfaces
    • Select Configure>System Properties>Chassis Cluster.
    • Select xe-5/1/0.
    • Enter the following:
      • Redundant Parent: reth1
    • Click Apply.
    • Select xe-17/1/0.
    • Enter the following:
      • Redundant Parent: reth1
    • Click Apply.
    • Select xe-5/0/0.
    • Enter the following:
      • Redundant Parent: reth0
    • Click Apply.
    • Select xe-17/0/0.
    • Enter the following:
      • Redundant Parent: reth0
    • Click Apply.
    • For last four configuration settings of Step 5, see Step 5 in Example: Configuring an Active/Passive Chassis Cluster Pair with an IPsec Tunnel (CLI).
  6. IPsec configuration
  7. Static routes
    • Select Configure>Routing>Static Routing.
    • Click Add.
    • Enter the following, then click Apply:
      • Static Route Address: 0.0.0.0/0
      • Next-Hop Addresses: 10.2.1.1
    • Enter the following, then click Apply:
      • Static Route Address: 10.3.0.0/16
      • Next-Hop Addresses: 10.10.1.2
  8. Security zones
  9. Security policies

Related Topics