Ha hrp
Huawei network device (USG firewall + S/CE switch) CLI skills pack for OpenClaw AI agent — also usable as a standalone cheatsheet.
npx -y skills add nanxiaoyao/network-huawei-skills --skill ha-hrpAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
This skill should be used when the user asks to configure or troubleshoot Huawei USG6000E firewall hot-standby (HRP/VGMP/VRRP) dual-system backup. Covers active/standby, load-balancing, layer-2 transparent, mirror-mode, and virtual-system HA scenarios. Applicable platforms USG6000E V600R007C20+ and USG6000/USG9500/NGFW Module V500R005C20+ (CLI syntax identical between versions).
SKILL.md
7.1 KB, ~2.5k tokens by cl100k_base, as published. Nobody here has run it
华为 USG 双机热备配置技能 (ha-hrp)
适用平台 USG6000E 系列 适用版本 V600R007C20+ 文档来源 HUAWEI USG6000E V600R007C20 产品文档 (案例编号 sec_case_ha_0001-0030)
USG 双机热备由 VGMP+HRP+VRRP 三者协同实现 VGMP 管理状态 HRP 备份配置和会话 VRRP 对外提供虚拟网关 任一台 FW 故障 业务秒级切换
触发场景
- 双机主备备份 active-standby 部署
- 双机负载分担 load-balancing 部署
- 防火墙二层透明接入主备
- 旁挂交换机 静态路由引流双机
- 镜像模式双机
- 虚拟系统双机
- 配置不同步 主备状态异常
- HRP 心跳通道异常 备份链路抖动
- 业务切换不丝滑 切换丢包多
三层组件协作模型
┌──────────────────────────────────────────────┐
│ VRRP 对外虚拟 IP 终端网关无感知切换 │
├──────────────────────────────────────────────┤
│ VGMP 组管理 决定整机主备 防止脑裂 │
├──────────────────────────────────────────────┤
│ HRP 配置/会话备份 心跳链路心跳 │
└──────────────────────────────────────────────┘
VGMP 是核心 VRRP 备份组加入 VGMP 管理 整机主备状态由 VGMP 决定 不再由单个 VRRP 自行选举
主流组网类型 选型表
| 组网 | 适用 | 上下行设备 | 关键技术 |
|---|---|---|---|
| 三层主备直连交换机 | 最经典 出口防火墙 | 交换机 | VRRP + VGMP |
| 三层主备连路由器 | ISP 给单 IP | 路由器 | VRRP + VGMP |
| 三层 OSPF 主备 | 上联路由器跑动态路由 | 路由器 | OSPF cost 调整 + VGMP |
| 二层透明主备 | 防火墙不当网关 | 上下交换机 | VLAN + VGMP |
| 三层负载分担 | 流量大 双活 | 交换机 | 双 VRRP 互为主备 |
| 旁挂静态路由 | 不改原有组网 | 交换机引流 | 静态路由 + VGMP |
| 虚拟系统 HA | 多租户隔离 | 同上 | vsys + 独立 VRRP |
| 镜像模式 | 抢救流量不丢 | 任意 | 镜像配置 + 会话同步 |
配置六步走 标准范式
1 接口 IP 与安全区域
两台 FW 业务接口规划相同 IP 不同 例如 GE0/0/1 主 10.2.0.1 备 10.2.0.2
2 配置 VRRP 备份组
上下行业务接口都要配 VRID 区分 主侧 active 备侧 standby
interface GigabitEthernet 0/0/1
vrrp vrid 1 virtual-ip 1.1.1.1 24 active # 主
vrrp vrid 1 virtual-ip 1.1.1.1 24 standby # 备
3 配置心跳口与 HRP
心跳口必须直连 不接安全区域 不配业务路由 走独立接口(如 GE0/0/7)
hrp interface GigabitEthernet 0/0/7 remote 10.10.0.2
hrp enable
启用后命令行出现 HRP_M / HRP_S 提示符
4 同步配置 在主上配 自动同步到备
启用 hrp enable 后 在主侧(HRP_M)配置安全策略 NAT 路由等 自动推到备
显式触发同步:hrp auto-sync config(默认开)
5 安全策略 NAT 等业务配置
注意 全部在主侧 HRP_M 配置 备侧 HRP_S 不要动 否则告警
6 验证与切换演练
拔主侧上行口 看备升主 业务丢包应 <3 秒
命令体系
VRRP
interface <if>
vrrp vrid <id> virtual-ip <ip> [<mask>] { active | standby }
vrrp vrid <id> priority <num> # 优先级
vrrp vrid <id> preempt-mode timer delay <s> # 抢占延时
VGMP 与 HRP 核心
hrp enable # 启用 HRP
hrp interface <if> [ remote <ip> ] # 心跳接口
hrp mirror session enable # 会话镜像 双活组网需开
hrp track interface <if> # 监控接口
hrp standby-device # 强制本机为备
hrp preempt [ delay <s> ] # 抢占
hrp adjust ospf-cost enable # 备机自动加 OSPF cost
查看
display vrrp # VRRP 状态
display hrp state [ verbose ] # VGMP 主备角色
display hrp interface # 心跳口
display hrp configuration # 已同步配置统计
display firewall session table # 看 Remote 标记 表示会话已备份
display hrp track # 监控接口状态
切换与维护
hrp standby-device # 强制降备 维护用
undo hrp enable # 解除 HRP 关系(谨慎)
hrp auto-sync config enable # 配置自动同步
hrp auto-sync connection-status enable # 会话自动同步
经典 CLI 范式 三层主备直连交换机
完整配置脚本(节选自 sec_case_ha_0002)
FW_A 主:
system-view
interface GigabitEthernet 0/0/1
ip address 10.2.0.1 24
vrrp vrid 1 virtual-ip 1.1.1.1 24 active
interface GigabitEthernet 0/0/3
ip address 10.3.0.1 24
vrrp vrid 2 virtual-ip 10.3.0.3 active
interface GigabitEthernet 0/0/7
ip address 10.10.0.1 24
firewall zone trust
add interface GigabitEthernet 0/0/3
firewall zone untrust
add interface GigabitEthernet 0/0/1
firewall zone dmz
add interface GigabitEthernet 0/0/7
ip route-static 0.0.0.0 0.0.0.0 1.1.1.10
hrp interface GigabitEthernet 0/0/7 remote 10.10.0.2
hrp enable
FW_B 备:仅 IP 不同(10.2.0.2 / 10.3.0.2 / 10.10.0.2)VRRP 状态改 standby HRP remote 改 10.10.0.1
随后在 HRP_M 提示符下配安全策略与 NAT 自动同步到备:
HRP_M[FW_A] security-policy
HRP_M[FW_A-policy-security] rule name trust_to_untrust
HRP_M[FW_A-policy-security-rule-trust_to_untrust] source-zone trust
HRP_M[FW_A-policy-security-rule-trust_to_untrust] destination-zone untrust
HRP_M[FW_A-policy-security-rule-trust_to_untrust] source-address 10.3.0.0 24
HRP_M[FW_A-policy-security-rule-trust_to_untrust] action permit
验证标志
display hrp state verbose 正常输出
Role: active, peer: standby
Running priority: 45000, peer: 45000
Backup channel usage: 30%
display firewall session table 在备侧能看到带 Remote 标记的会话 表示备份成功
常见陷阱
- 心跳口配错或没直连 → 双主脑裂 业务异常
- 备机被手工改了配置 → 出现 HRP_S 与 HRP_M 配置不一致告警 须
hrp auto-sync config enable并清差异 - VRRP 备份组 active/standby 写反 → 主备颠倒
- 没开
hrp mirror session enable→ 负载分担场景会话不双向同步 切换大量丢包 - 监控接口没用
hrp track interface→ 上行口断了 整机不切
相关文件
- references/ha-commands.md 完整命令速查
- references/ha-troubleshooting.md 故障定位流程