The termcontrollerin this section refers to a stand-alonecontrolleror amanaged device运行阿鲁巴斯version 8.x.x.x.

The Virtual Router Redundancy Protocol (VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.) is used to create various redundancy solutions, such as pairs ofcontrollers通过使用虚拟IP地址以Active-Backup模式或以主机模式作用。当主人时controller变得不可用,备份controllersteps in as the master and takes ownership of the virtual IP address. All network elements (APs and othercontrollers) can be configured to access the virtual IP address, thereby providing a transparent redundant solution to your network.

VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.通过提供选举机制来消除单点失败VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握controller。如果VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.preemption is disabled (the default setting) and allcontrollersshare the same priority, the firstcontrollerthat comes up becomes theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握。However, ifVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.preemption is enabled and allcontrollersshare the same priority, thecontrollerwith the highest IP address becomes theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握。

When you need to change the master-ip on themanaged devicefrom interface IP of the activeMobility Master到vrrp-ipMobility Master,changes need to be performed in themanaged device。需要在managed device是因为当主IP在managed device,managed device不知道新的Master-IP是否是现有的VRRP-IPMobility Master或新的IPMobility Master

Therefore, when you change the master-ip, the setup dialog should be executed on themanaged devicewith write erase followed by deleting the device entry on theMobility Masterfor thismanaged deviceto start setup-dialogue. This is to avoid issues in the network that will be caused by old setup dialogue which will be maintained in themanaged device,如果我们不做写擦掉and brought upmanaged devicecleanly.

阿鲁巴斯supportsVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.-基于LMS本地管理开关。在多控制器网络中,每个控制器充当LMS,并终止从APS,处理的用户流量,并将流量转发到有线网络。redundancy in a deployment with active-backup redundancy. In the topology illustrated inFigure 1,当AP连接到主controller(M1), the AP receives a standby IP. The standby IP is used by the AP to establish a standby connection to the backup master (M2). If the active master becomes unreachable or reboots, the backup master changes itsVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握并接受主动AP连接的角色。

When M1 comes back up, it initially acts as a backup master, and APs associated to M2 establish a standby connection to M1. When thecontrollerschange roles and M1 becomes the active master once again, M2 forces the APs to use M1 as their active master. If an AP has not established a connection to M1 before it disassociates from M2, the AP rebootstraps before it reconnects back to M1.

Figure 1Redundancy with an Active-Backup MasterController一对

当一个VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例是在controllerVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。,不会有任何改变VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.state if the failover scenario was tested by shutting down the port or bringing down theVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。。Thecontrollerremains in the Master state and sendsVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.广告,没有到达同行controller。当端口下降时,controllerbecomes the Master. However, when the port on the previous master is enabled, it takes over the Master state. The peercontrollermoves out of the master state when the original master sends a higher priority advertisement, even when preemption is not enabled. The peercontroller如果主人不会被抢占controllercrashes or reboots.

Before you Begin

Before you begin configuringVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.冗余,获取以下网络信息:

Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。ID为两个controllerson the same Layer-2 network.

用于用于该的虚拟IP地址VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例。

Configuring a Primary and Backup Master for Failover Redundancy

以下过程配置VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.在主要和备份大师controllers:

1.为一个stand-alonecontroller, 在下面Mobility Controller, select your device and then navigate to theConfiguration > Redundancy > L2 redundancy标签。

2.为一个managed device, navigate toConfiguration > Redundancy > L2 redundancyin the托管网络节点层次结构。

3.扩展Virtual Router Tableaccordion.

4.点击+to add a new virtual router. The新的虚拟路由器字段出现。

5.Select the IP version from theIP Version下拉列表。

6。Select theVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。on which you want to configureVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.来自Vlan下拉列表。

7。SetAdmin StatetoUP

8。Specify the priority value in thePriority场地。用于备份controller, use the default priority value of 100. For the primarycontroller, use a priority value higher than the default, such as 110.

9。Configure otherVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.parameters as described inTable 1


11.点击Pending Changes

12.In thePending Changeswindow, select the check box and clickDeploy changes

13.Repeat steps 1-11 to configureVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.on the othercontroller在主要和备份冗余对中。

每当您修改主机时,请确保重新加载设备VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.主冗余下的配置以避免任何配置错误。

Table 1:VRRP Configuration Parameters




ID独特地识别了这一点VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例。For ease in administration, you should configure this with the same value as theVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。ID。


这是一个可选的文本描述VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例。

IP version

从下拉列表框中选择IPv4 \ ipv6。

Authentication Password

这是一个可选的密码,最多可以验证八个字符VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.peers in their advertisements. If this is not configured, there is no authentication password.


Reconfirm the password, if configured.

IP address

根据IP版本字段中的选择,将显示任何IP地址\ IPv6地址。This is the virtual IP address that will be owned by the electedVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握。Ensure that the same IP address andVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.IDis used on each member of the redundant pair.

笔记:IP地址必须是唯一的,不能瞧opback address of the device. A maximum of only two virtual IPv6 addresses can be configured on eachVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例。Only IPv6 address format is supported for the v6 instance.

IPv6 address

Configure the virtual IPv6 address that will be owned by the electedVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握。Use the same IPv6 address on each member of the redundant pair.

This IPv6 address will be redundant - it will be active on theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.主人,并将活跃在VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.备份时VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.主失败。

笔记:The IPv6 address must be unique and cannot be the loopback address of the device. A maximum of only two virtual IPv6 addresses can be configured on eachVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例。从...开始阿鲁巴斯8。2.1.0, you can configure a unique local address as theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.IPv6地址Mobility Masterand themanaged devices


Priority level of theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.设备的实例。该值用于主人的选举机制。配置时VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.在备用设备上,使用默认优先级值为100。对于主设备,使用更高的优先级值,例如110。

Advertisement interval (secs)

This is the interval, in seconds, between successiveVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.advertisements sent by the current master. The default interval time is recommended.

Default: 1 second

Enable router Pre-emption

Selecting this option means that a device can take over the role of master if it detects a lower priority device currently acting as master.

Pre-emption delay (secs)

指定值启用延迟计时器。当计时器被触发时VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.state moves out of backup or init state to become a master. This is applicable only if you enable router pre-emption.

When the timer is triggered, it forcesVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.to wait for a specified period of time, so that all the applications are ready before coming up. This prevents the APs from connecting to themanaged deviceor the stand-alonecontroller在接收他们之前。同时,如果有另一个广告VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.,VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.停止计时器,不会过渡到主机。


Administrative state of theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例。To start theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.实例,将管理状态更改为UPin the WebUI.


Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。在哪个VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.protocol runs.


(可选)执行VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.优先跟踪基于设备已成为主的时间。此功能旨在确保只允许主人接受并保持对VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.if it has been up for a certain amount of minutes (0-1440). This prevents an issue where a device that is periodically going up and down assumes the role of primary master.


(Optional) The additional priority given to the master once it has been up for the time interval defined by theTracking Master Up-time范围。

Tracking VRRP master state ID

(可选)执行tracking based on the UP or DOWN state of anotherVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.通过指定VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.IDof the master to be tracked.

Tracking VRRP master state priority

(Optional) The priority taken away from aVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握if it is in a DOWN state. The priority levels are returned to their previous state when theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握comes back up.


(可选)执行VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.priority tracking based on the UP or DOWN state of aVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。。点击+以下跟踪Vlantable and specify the following values:

Vlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。Id: ID of theVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。被跟踪。

Subtract: Priority level to be subtracted from the device'sVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.priority if the trackedVlan虚拟局域网。在计算机网络中,可以对单层2网络进行分区,以创建多个不同的广播域,它们是相互隔离的,因此数据包只能通过一个或多个路由器之间传递它们。这样的域称为虚拟局域网,虚拟LAN或VLAN。goes down.

Tracking interface

(可选)执行VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.priority tracking based on the UP or DOWN state of a specific interface. Click+以下跟踪接口table and specify the following values:

Interface: Interface Port to be tracked.

Subtract: Priority level to be subtracted from the device'sVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.priority if the tracked interface goes down.




(host) [mynode] (config-submode)#vlan

(host) [mynode] (config-submode)#priority <0-255>

Execute the following commands to configure a new virtual router on amanaged device:

(host) [md] (config) #vrrp

(host) [md] (config-submode)#ip address

(host) [md] (config-submode)#vlan

(host) [md] (config-submode)#priority <0-255>

Configuring APs to use the VRRP IP

Configure the APs associated with the mastercontrollerto terminate their tunnels on theVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.virtual-IP address . To specify thecontrollerto which an AP or AP group tunnels client traffic, you configure theLMS本地管理开关。在多控制器网络中,每个控制器充当LMS,并终止从APS,处理的用户流量,并将流量转发到有线网络。Master上的AP系统配置文件中的IPcontroller

This configuration must be executed on the mastercontroller; the APs obtain their configuration from the mastercontroller

以下过程配置VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.在AP系统配置文件上:

1.为一个stand-alonecontroller, 在下面Mobility Controller, select your device and then navigate toConfiguration > System > Profiles标签。

2.为一个managed device, navigate toConfiguration > System > Profilesin the托管网络节点层次结构。

3.UnderAll Profiles > AP, expandAP系统

4.Select the AP system profile for which you want to configureVRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.

5.扩展LMS设置accordion and enter the virtual IP address into theLMS IP场地。


7。点击Pending Changes

8。In thePending Changeswindow, select the check box and clickDeploy changes

后续过程配置VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.for an AP group:

1.为一个stand-alonecontroller, 在下面Mobility Controller, select your device and then navigate to配置> AP组

2.Select theLMS从选定的AP组表中进行选项卡。

3.输入virtual IP address into theIP address场地。For IPv6 address, enter the value in theIPv6 address场地。


5.点击Pending Changes

6。In thePending Changeswindow, select the check box and clickDeploy changes

The followingCLI命令行接口。带有命令行壳的控制台接口,允许用户执行文本输入为命令,并将这些命令转换为适当的函数。命令配置VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.on an AP system profile and applies it to an AP profile and an AP group:


(host) [mynode] (config) #ap system-profile

(主机)[myNode](AP系统配置文件“ ”)#lms-ip

(主机)[myNode](AP系统配置文件“ ”)#ap-name

(host) [mynode] (AP name "") #ap-system-profile

(主机)[myNode](ap名称“ ”)#exit

(host) [mynode] (config) #ap-group

(host) [mynode] (AP group "") #ap-system-profile

managed device:

(主机)[MD](config)#ap System-Profile

(主机)[MD](AP系统配置文件“ ”)#lms-ip

(host) [md] (AP system profile "") #ap-name

(主机)[MD](AP名称“ ”)#AP-System-Profile

(host) [md] (AP name "") #exit


(host) [md] (AP group "") #ap-system-profile

如果DNS域名系统。DNS服务器可作为Intranet和Internet用户的电话簿。它将人类可读的计算机主机名称转换为IP地址和IP地址为主机名称。它存储了域名的几个记录,例如地址“ A​​”记录,名称服务器(NS)和Mail Exchanger(MX)记录。地址“ A​​”记录是存储在DNS服务器中的最重要记录,因为它为网络外围或元素提供了所需的IP地址。resolution is the chosen mechanism for the APs to discover their mastercontroller,确保名称aruba-masterresolves to the same virtual IP address configured as a part of the master redundancy.

Configuring Master Redundancy and Database Synchronization

在冗余大师中controller方案,您可以配置冗余对,以同步其WMS和本地用户数据库。您可以手动或自动同步数据库。当手动同步数据库时VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.掌握synchronizes its database with the standby. The command takes effect immediately. When configuring automatic synchronization, you set how often the twocontrollerssynchronize their databases. To ensure successful synchronization of database events, you should set periodic synchronization to a minimum period of 20 minutes.

冗余之间的主机配置和数据库同步controllersis not applicable tocontrollersconfigured asmanaged devices。However, it is applicable to stand-alonecontrollersrunning阿鲁巴斯8。x.x.x.


1.For standalonecontroller, 在下面Mobility Controller, select your device and then navigate to theConfiguration > Redundancy > L2 redundancy标签。

2.In the Mobility master node hierarchy, navigate totheConfiguration > Redundancy > L2 redundancy标签。

3.UnderMaster Redundancy, do the following:

4.输入VRRPVirtual Router Redundancy Protocol. VRRP is an election protocol that dynamically assigns responsibility for a virtual router to one of the VRRP routers on a LAN.IDto be associated to the master-redundancy pair in theMaster VRRP场地。


6。Select the authentication method from theAuthenticationdrop-box.

a.如果IPSec keyis selected as an authentication method, enter the同伴的ipsec键andRe-type the key

b.如果证书is selected as an authentication method and工厂is selected as the证书type,enter the同行的MAC地址

c.如果证书is selected as an authentication method andCustomis selected as the certificate type, enter thePeer的Mac地址,CA证书,服务器证书并选择一个Suite B algorithm来自下拉列表。


8。点击Pending Changes

9。In thePending Changeswindow, select the check box and clickDeploy changes

The followCLI命令行接口。带有命令行壳的控制台接口,允许用户执行文本输入为命令,并将这些命令转换为适当的函数。命令配置a master redundancy pair. This configuration is applicable on both active and the standbycontrollers:

(host) [mynode] (config) #master-redundancy

(host) [mynode] (config-submode)#master-vrrp

(host) [mynode] (config-submode)#peer-ip-address

(host) [mynode] (config-submode)#write memory

The followCLI命令行接口。带有命令行壳的控制台接口,允许用户执行文本输入为命令,并将这些命令转换为适当的函数。命令配置synchronization:


To view the database synchronization settings on thecontroller, use the following command:

(主机)[myNode] #show数据库同步
