@reberhar
Thanks all for your help...
Concerning the problem I am having with pfBlocker's CARP VIP not coming backup after doing pfBlocker an update and then pfb_dnsbl stopping. ..
So after a pfBlockerng update, the pfBlocker CARP VIP on the primary does not show MASTER or SECONDARY it is just blank and pfb_dnsbl stops. Then the secondary pfBlocker CARP VIIP takes over.
So if I make like I am editing the primary pfBlocker CARP VIP from the firewall menu and just save it the primary pfBlocker CARP VIP becomes MASTER and the secondary one becomes backup.
Then I can start pfb_dnsbl successfully.
Here is something from the general logs.
Jul 26 09:16:52 php 40257 [pfBlockerNG] DNSBL parser daemon started
Jul 26 09:16:52 lighttpd_pfb 39134 [pfBlockerNG] DNSBL Webserver started
Jul 26 09:16:52 lighttpd_pfb 36785 [pfBlockerNG] DNSBL Webserver stopped
Jul 26 09:16:41 kernel carp: 4@igb1: BACKUP -> MASTER (preempting a slower master)
Jul 26 09:16:40 check_reload_status 441 Reloading filter
Jul 26 09:16:40 kernel carp: 4@igb1: INIT -> BACKUP (initialization complete)
Jul 26 09:16:39 php-fpm 97364 /rc.filter_synchronize: XMLRPC reload data success with https://10.1.10.2:443/xmlrpc.php (pfsense.restore_config_section).
Jul 26 09:16:38 php-fpm 97364 /rc.filter_synchronize: Beginning XMLRPC sync data to https://10.1.10.2:443/xmlrpc.php.
Jul 26 09:16:38 php-fpm 97364 /rc.filter_synchronize: XMLRPC versioncheck: 23.3 -- 23.3
Jul 26 09:16:38 php-fpm 97364 /rc.filter_synchronize: XMLRPC reload data success with https://10.1.10.2:443/xmlrpc.php (pfsense.host_firmware_version).
Now I have 3 systems like this and one works correctly. There is an HA pair of two DELL Optiplex I-7 boxes on the pair that seems to be ok. The two pairs that are giving problems have the secondary pfsense running in a Virtualbox 7.0.2 guest machine using Paravirtualized Network adapters. Both have been recently updated to virtualbox 7.0 because a kernel update to Ubuntu 22.04 gave problems.
On reading the Virtualbox 7.0 ... forums, the developer mentioned that 7.0 . .. is really just in beta.
The CARP system seems to be fine otherwise. Once I have done the manual intervention things are fine until pfBlocker does its updates again.
I am wondering about trying a different network adapter than Paravirtualized, at least for the CARP VIP.
Observations? Suggestions? What am I missing?
Thanks
The other machines CARP pair
Jul 26 08:18:16 php-fpm 31382 /rc.carpmaster: HA cluster member "(10.33.10.1@em1): (GREENLAN)" has resumed CARP state "MASTER" for vhid 5
Jul 26 08:18:15 check_reload_status 457 Carp master event
Jul 26 08:18:15 kernel carp: 5@em1: BACKUP -> MASTER (preempting a slower master)
Jul 26 08:18:15 php-fpm 19625 /rc.carpbackup: HA cluster member "(10.33.10.1@em1): (GREENLAN)" has resumed CARP state "BACKUP" for vhid 5
Jul 26 08:18:15 php-fpm 19625 /rc.filter_synchronize: XMLRPC reload data success with https://172.16.1.3:443/xmlrpc.php (pfsense.restore_config_section).
Jul 26 08:18:14 check_reload_status 457 Reloading filter
Jul 26 08:18:14 kernel carp: 5@em1: INIT -> BACKUP (initialization complete)
Jul 26 08:18:14 check_reload_status 457 Carp backup event
Jul 26 08:18:12 php-fpm 19625 /rc.filter_synchronize: Beginning XMLRPC sync data to https://172.16.1.3:443/xmlrpc.php.
Jul 26 08:18:12 php-fpm 19625 /rc.filter_synchronize: XMLRPC versioncheck: 23.3 -- 23.3
Jul 26 08:18:12 php-fpm 19625 /rc.filter_sJul 26 08:18:16 php-fpm 31382 /rc.carpmaster: HA cluster member "(10.33.10.1@em1): (GREENLAN)" has resumed CARP state "MASTER" for vhid 5
Jul 26 08:18:15 check_reload_status 457 Carp master event
Jul 26 08:18:15 kernel carp: 5@em1: BACKUP -> MASTER (preempting a slower master)
Jul 26 08:18:15 php-fpm 19625 /rc.carpbackup: HA cluster member "(10.33.10.1@em1): (GREENLAN)" has resumed CARP state "BACKUP" for vhid 5
Jul 26 08:18:15 php-fpm 19625 /rc.filter_synchronize: XMLRPC reload data success with https://172.16.1.3:4443/xmlrpc.php (pfsense.restore_config_section).
Jul 26 08:18:14 check_reload_status 457 Reloading filter
Jul 26 08:18:14 kernel carp: 5@em1: INIT -> BACKUP (initialization complete)
Jul 26 08:18:14 check_reload_status 457 Carp backup event
Jul 26 08:18:12 php-fpm 19625 /rc.filter_synchronize: Beginning XMLRPC sync data to https://172.16.1.3:4443/xmlrpc.php.
Jul 26 08:18:12 php-fpm 19625 /rc.filter_synchronize: XMLRPC versioncheck: 23.3 -- 23.3
Jul 26 08:18:12 php-fpm 19625 /rc.filter_synchronize: XMLRPC reload data success with https://172.16.1.3:4443/xmlrpc.php (pfsense.host_firmware_version).
Jul 26 08:18:12 php-fpm 19625 /rc.filter_synchronize: Beginning XMLRPC sync data to https://172.16.1.3:4443/xmlrpc.php.
Jul 26 08:18:11 php-fpm 70712 /firewall_virtual_ip_edit.php: Beginning configuration backup to https://acb.netgate.com/save
ynchronize: XMLRPC reload data success with https://172.16.1.3:443/xmlrpc.php (pfsense.host_firmware_version).
Jul 26 08:18:12 php-fpm 19625 /rc.filter_synchronize: Beginning XMLRPC sync data to https://172.16.1.3:443/xmlrpc.php.
Jul 26 08:18:11 php-fpm 70712 /firewall_virtual_ip_edit.php: Beginning configuration backup to https://acb.netgate.com/save