• CARP/HA, SYNC and XMLRPC SYNC explained

    Pinned
    3
    1 Votes
    3 Posts
    13k Views
    M

    Thanks for the excellent reply. I've retested as you suggested by entering persistent maintenance and there is no packet loss that way (perst maint, reboot, leave persist maint). I am still having a small problem with freeradius xmlrpc sync between the two but I posted that in a separate topic (see https://forum.pfsense.org/index.php?topic=135864.0).

    Regards,
    Matt

  • Dynamic dns don't work with carp ip

    4
    0 Votes
    4 Posts
    158 Views
    I

    Hello! Same thing here using Dyndns. 2.8 and 2.7.2 side by side, and it doesn't work in 2.8, it's getting the interface address, it doesn't seem to obey the Virtual IP instruction. The virtual IP field selects which (virtual) IP should be used when this group applies to a local Dynamic DNS, IPsec or OpenVPN endpoint.

  • Hyper-V Failover Clustering

    2
    0 Votes
    2 Posts
    71 Views
    S

    @bimmerdriver You need one IP that can move between the routers. Technically both WANs can be private IPs…Comcast business allows for this even if their modem is bridged, then the shared IP is a public. Maybe that helps.

  • multiple ISP/WAN interfaces

    6
    0 Votes
    6 Posts
    133 Views
    N

    @georgelza said in multiple ISP/WAN interfaces:

    I want to make it as simple as possible, without me becoming their IT department....

    Well, you ARE their it department.

    Leave it as it is, if it works why fix it?

  • Switches getting wrong MAC for CARP interface

    8
    0 Votes
    8 Posts
    127 Views
    S

    Just for reference: https://docs.netgate.com/pfsense/en/latest/highavailability/index.html#switch-layer-2-concerns

    "switch must...Allow traffic to be sent and received using multiple MAC addresses"

  • CARP Protocol Requests Blocked on pfSense 2.8.0 HA Setup

    1
    0 Votes
    1 Posts
    35 Views
    No one has replied
  • ISP CPE reboot causing problems

    1
    0 Votes
    1 Posts
    48 Views
    No one has replied
  • CARP Error

    1
    0 Votes
    1 Posts
    73 Views
    No one has replied
  • Can I duplicate VHID group in CARP VirtualIP ?

    5
    0 Votes
    5 Posts
    132 Views
    BenGonGonB

    @patient0 Thank you very much for yours knowledges.

  • Slow Ipsec when CARP is enabled and behind primary

    1
    0 Votes
    1 Posts
    67 Views
    No one has replied
  • HA CARP VIPs for 1:1 NAT?

    3
    0 Votes
    3 Posts
    364 Views
    R

    @SteveITS Thanks for the link. I had not considered the VIP stacking idea. I'm not sure how much of an issue my setup will have with VIP multicast traffic on my WAN link but good to know this technique is available to reduce some of that. Again, thanks for the link.

  • How to make HA on 2 pfSense on bare metal WITH 4 x UPLINKS WANs ?

    40
    0 Votes
    40 Posts
    6k Views
    Sergei_ShablovskyS

    @stephenw10 said in How to make HA on 2 pfSense on bare metal WITH 4 x UPLINKS WANs ?:

    Well it would remove load from the firewall. So if you were under a DDoS attack and needed to still route between internal subnets that could be useful. But it wouldn't help with the attack itself much.

    Agree! Anyway for middle/big DDoS better to deal on local ISPs + CloudFlare level. Here no room for edge FW… :)

    Let me to note, if thinking in “Zero thrust” direction, also FW on end local node/service as “fine tuning firewalling” would be great, because each end node better know what particular (and how) need to be secured.

    So at the end we build 3-layered (as minimum) defense:

    ACLs on edge ASIC-based switches; pfSense as edge FW; PF/IPF/IPFW FW (sertificates, tokens, etc…) on end node/service;

    What do You think about this 3-layered scheme, @stephenw10 ?

  • HA Setup with Multi-WAN and DHCP Guide

    7
    1 Votes
    7 Posts
    3k Views
    F

    Happy to report that I was able to upgrade both of my servers to CE 2.8 with no issues. Everything still works as expected. 👍

  • HA CARP with FRR OSPF on PFSense LAN Interface

    2
    0 Votes
    2 Posts
    263 Views
    R

    So thought about this a bit and realize I'd need to have the CARP VIP on the LAN to if nothing more facilitate the failover state on the WAN in the case of a LAN failure. CARP on here fails together so would still want the CARP VIP IP on the LAN even if I don't technically need it for routing traffic.

    Still could use some help on getting the next hop for the default route learned by my switches to be the VIP address and not the LAN interface IP.

  • HA not switching for all interfaces at the same time to other node

    7
    0 Votes
    7 Posts
    903 Views
    S

    I thought there was a doc page on this but can't find it. Maybe it was a forum post. All I can say is, it's supposed to move both.

    https://docs.netgate.com/pfsense/en/latest/highavailability/test.html#test-carp-failover
    notably, "Unplug the WAN or LAN cable" (my bold)

    I tried a quick search and found some really old stuff like https://www.reddit.com/r/PFSENSE/comments/4yebk5/comment/d6s45xk/ but note Jim-P I'm pretty confident is https://www.netgate.com/blog/author/jim-pingle.

  • 0 Votes
    7 Posts
    1k Views
    w0wW

    @Yathus said in [SOLVED]CARP Cluster, what will happen if i bring back my backup online after configuration change ?:

    OK we started this night and backup node tried to take "Primary" on the two CARP IP, backup node won't came up as backup status so...

    I think this is expected behaviour, untill it synced, if it possible to sync at all.

    I'm glad everything worked out for you.

    I'd like to slightly correct your terminology, which is also referenced in the documentation. Refer to the firewalls as Primary and Secondary—these are their permanent roles. Only their status changes, which can be either Master or Backup.

    And for the future, if everything is set up correctly, there's no need to power off the Secondary firewall at all. It should properly synchronize what it needs to. If synchronization of certain settings isn't possible, use Maintenance Mode or Disable CARP, provided it doesn't cause conflicts in the network.

  • 0 Votes
    2 Posts
    360 Views
    R

    @bp81

    https://forum.netgate.com/topic/185693/ha-setup-with-multi-wan-and-dhcp-guide this is an excellent way to actualy get failover to occur with single ip dhcp WAN side.

    if you already have the spare hardware, this would be the optimal solution. full failover, (CARP only on LAN side)

  • CARP with DHCP - Non Zero Demotion Status

    3
    0 Votes
    3 Posts
    433 Views
    R

    @t04s

    not sure, but i suggest you look at this one:

    https://forum.netgate.com/topic/185693/ha-setup-with-multi-wan-and-dhcp-guide

    you can get the devd system to only run on specific vhid events.

  • HAProxy, error 503

    1
    0 Votes
    1 Posts
    195 Views
    No one has replied
  • No Failover Peer IP visible in DHCP server web interface

    3
    0 Votes
    3 Posts
    911 Views
    C

    I recently followed the same guide and stumbled over that thread because I have the same issue.
    Is it support now?
    thanks,

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.