4 Engineering of firewall redundancy with
VRRP
The following configuration example uses the SCALANCE S615 firewall routers
instead of the SCALANCE XM408-8C routers. The configuration is identical to the
SCALANCE XM408-8C. The following example illustrates which additional firewall
settings on the master and backup need to be programmed.
Hardware setup
Figure 4-1
PC 2
IP address: 192.168.20.20
Subnet mask: 255.255.255.0
Gateway: 192.168.20.1
SCALANCE XC 206
IP address: 192.168.20.11
Subnet mask: 255.255.255.0
Gateway: 192.168.20.1
VLAN20/ subnet – B 192.168.20.0/24
SCALANCE S615 (Master)
Port 1.2: Interface VLAN 1
Function: Configuration
IP address: 192.168.1.2
Subnet mask: 255.255.255.0
Port 1.5: Interface VLAN 10
Function: Server room
IP address: 192.168.10.2
Subnet mask: 255.255.255.0
Port 1.4: Interface VLAN 20
Function: Cell
IP address: 192.168.20.2
Subnet mask: 255.255.255.0
SCALANCE S615 (Backup)
Port 1.2: Interface VLAN 1
Function: Configuration
IP address: 192.168.1.3
Subnet mask: 255.255.255.0
Port 1.5: Interface VLAN 10
Function: Server room
IP address: 192.168.10.3
Subnet mask: 255.255.255.0
Port 1.4: Interface VLAN 20
Function: Cell
IP address: 192.168.20.3
Subnet mask: 255.255.255.0
SCALANCE XC 206
IP address: 192.168.20.10
Subnet mask: 255.255.255.0
Gateway: 192.168.20.1
PC 1
IP address: 192.168.10.20
Subnet mask: 255.255.255.0
Gateway: 192.168.10.1
SCALANCE XC 206
IP address: 192.168.10.10
Subnet mask: 255.255.255.0
Gateway: 192.168.10.1
VLAN10/ subnet – B 192.168.10.0/24
VRRP Instance 10
IP: 192.168.10.1
VRRP Instance 20
IP: 192.168.20.1