<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[HA&#x2F;CARP&#x2F;VIPs]]></title><description><![CDATA[Discussions about High Availability, CARP, and utilizing additional IP addresses]]></description><link>https://forum.netgate.com/category/32</link><generator>RSS for Node</generator><lastBuildDate>Tue, 16 Jun 2026 03:32:10 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/category/32.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 01 Jun 2026 02:58:00 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Don&#x27;t access GUI, SSH etc using CARP VIP?]]></title><description><![CDATA[Guess I never really thought about the possibility of a failover event occurring in the middle of making configuration changes. But I guess that's as likely to happen as anything else. I'll now consider myself lucky that it never did.
I've gone and updated all of my bookmarks and tooling to use the explicit primary and secondary IPs. Thanks again.
]]></description><link>https://forum.netgate.com/topic/200754/don-t-access-gui-ssh-etc-using-carp-vip</link><guid isPermaLink="true">https://forum.netgate.com/topic/200754/don-t-access-gui-ssh-etc-using-carp-vip</guid><dc:creator><![CDATA[luckman212]]></dc:creator><pubDate>Mon, 01 Jun 2026 02:58:00 GMT</pubDate></item><item><title><![CDATA[hardware needs to move to a cluster]]></title><description><![CDATA[@SteveITS great, thanks (sorry for the late reply)
Currently the project waits for some dependencies and decisions.
As soon as I get the go I might start preparing the config.
Obviously I have a working pfSense config in place, I will start to think about how to migrate that to a cluster config.
I might start with 2 VMs and follow something like this recipe  (?)
]]></description><link>https://forum.netgate.com/topic/200677/hardware-needs-to-move-to-a-cluster</link><guid isPermaLink="true">https://forum.netgate.com/topic/200677/hardware-needs-to-move-to-a-cluster</guid><dc:creator><![CDATA[sgw]]></dc:creator><pubDate>Wed, 13 May 2026 12:16:40 GMT</pubDate></item><item><title><![CDATA[HA with MULTIWAN Outbound NAT for CARP and VLANs]]></title><description><![CDATA[@netblues Right. Thank you very much.
]]></description><link>https://forum.netgate.com/topic/200654/ha-with-multiwan-outbound-nat-for-carp-and-vlans</link><guid isPermaLink="true">https://forum.netgate.com/topic/200654/ha-with-multiwan-outbound-nat-for-carp-and-vlans</guid><dc:creator><![CDATA[Jdwind]]></dc:creator><pubDate>Fri, 08 May 2026 07:04:49 GMT</pubDate></item><item><title><![CDATA[High Availability and TailScale]]></title><description><![CDATA[<p dir="auto">Hi All,</p>
<p dir="auto">I  use OpenVPN effectively, but I need to move the head system to a place where there a fixed IP is unavailable and DDNS is ineffective because of ISP ip changes, sometimes several within a very should period of time.</p>
<p dir="auto">So I am looking at TailScale.</p>
<p dir="auto">In 4 of my 5 locations I am using HA / CARP. With openVPN on pfSense there is provision for handling openVPN shutdown and restart when the backup server has to start and shudown.</p>
<p dir="auto">I don't see any configuration for this in TailScale. Is there one that I am missing? If not will it be added?</p>
<p dir="auto">Thanks,</p>
<p dir="auto">Roy Eberhardt</p>
]]></description><link>https://forum.netgate.com/topic/200628/high-availability-and-tailscale</link><guid isPermaLink="true">https://forum.netgate.com/topic/200628/high-availability-and-tailscale</guid><dc:creator><![CDATA[reberhar]]></dc:creator><pubDate>Mon, 04 May 2026 16:12:01 GMT</pubDate></item><item><title><![CDATA[Possible bug + fix for HAproxy issue during upgrade to 2.8.1]]></title><description><![CDATA[@ndemou  I have what may be a related issue, but I'm hesitant try try this patch as I'm on pfSense plus 26.03.1. Although my certs are valid, when I try to setup a frontend in HAProxy,I don't get the cert dropdown, I just get an empty text box. I tried entering my cert name but then it throws a parsing error when I try to save it.
[ALERT] (87716) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:15] : 'bind 0.0.0.0:443' in section 'frontend': unknown keyword 'mynet.com'. [ALERT] (87716) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg [ALERT] (87716) : config : Fatal errors found in configuration.
In the example above, unknown keyword mynet.com is my certificate name, which I entered into the textbox since there was no dropdown list.
]]></description><link>https://forum.netgate.com/topic/200566/possible-bug-fix-for-haproxy-issue-during-upgrade-to-2.8.1</link><guid isPermaLink="true">https://forum.netgate.com/topic/200566/possible-bug-fix-for-haproxy-issue-during-upgrade-to-2.8.1</guid><dc:creator><![CDATA[dstacey147]]></dc:creator><pubDate>Mon, 20 Apr 2026 16:04:37 GMT</pubDate></item><item><title><![CDATA[How to route to backup lan interface]]></title><description><![CDATA[<p dir="auto">We have 3 offices with VPN connections between every pair.  We use OSPF to configure routing.  We are adding backup routers with a CARP configuration in each office.  Each backup router has OSPF triggering on the CARP IP so it is not active.  The VPN connections are also not active until the backup becomes primary.</p>
<p dir="auto">My question is how can I route from one office to another office's backup firewall's LAN interface?</p>
<p dir="auto">One thought has been to add a static route to the full internal IP address range (10.0.0.0/8) to the LAN CARP IP - and then perhaps have an OSPF filter to prevent that route from propagating - but I'm a little unsure of how to configure that.</p>
<p dir="auto">Any other suggestions?<br />
FWIW - I'm not syncing state because the firewalls are not identical hardware (at least at the moment)</p>
]]></description><link>https://forum.netgate.com/topic/200549/how-to-route-to-backup-lan-interface</link><guid isPermaLink="true">https://forum.netgate.com/topic/200549/how-to-route-to-backup-lan-interface</guid><dc:creator><![CDATA[opoplawski]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:23:25 GMT</pubDate></item><item><title><![CDATA[Virtual IP questio : traffic to a VIP doesnt seem to route]]></title><description><![CDATA[@boumacor I'm not a huge fan of floating rules if they can be set as regular rules, since the, er, rules change for floating. Just to maintain clarity.  However if the rule triggers and a state is open you're through pf.
Does the pfSense routing table show a route for the 192.168.1.0/24 subnet?
I would still be suspicious of the switch ignoring traffic outside its own subnet unless you're sure it will allow it.  You could set an IP on some other device and ping it, to check the connection through pfSense.
]]></description><link>https://forum.netgate.com/topic/200330/virtual-ip-questio-traffic-to-a-vip-doesnt-seem-to-route</link><guid isPermaLink="true">https://forum.netgate.com/topic/200330/virtual-ip-questio-traffic-to-a-vip-doesnt-seem-to-route</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Wed, 11 Mar 2026 09:23:56 GMT</pubDate></item><item><title><![CDATA[HA sync overwrites certificates on backup router even if unchecked]]></title><description><![CDATA[I was reminded using an IP address may bypass HSTS/the invalid cert...will need to wait another couple months to try it though.
Also one could disable HSTS on the secondary router, ahead of time. (I suspect that setting is not synced...)
]]></description><link>https://forum.netgate.com/topic/200255/ha-sync-overwrites-certificates-on-backup-router-even-if-unchecked</link><guid isPermaLink="true">https://forum.netgate.com/topic/200255/ha-sync-overwrites-certificates-on-backup-router-even-if-unchecked</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Fri, 27 Feb 2026 17:36:44 GMT</pubDate></item><item><title><![CDATA[DDNS updates wrong IP after CARP failover (system traffic uses node WAN IP instead of CARP VIP)]]></title><description><![CDATA[@Chebec Have a read through:
https://docs.netgate.com/pfsense/en/latest/development/patches/custom.html
and the rest of the topic.
If you add a patch, it should detect whether it can be Applied and will or will not show the Apply button, as I recall.  There is also a Debug button to test.  Normally a patch can be reverted via that button, yes, unless the target file is later changed.  (after updating pfSense you would not want to revert a patch and reintroduce a bug, just delete the custom patch)
Note there's a later patch ID in that redmine: 8544b85f8c32d0f180c09a4d0986ac819919bd2b
As long as patches are from Netgate developers I would have no issue installing them.  For random patches in the forum I'd be a bit more cautious.  In either case you can see the code being changed, in the patch details.
Edit: Marcos M in the redmine is a Negate dev.
]]></description><link>https://forum.netgate.com/topic/200238/ddns-updates-wrong-ip-after-carp-failover-system-traffic-uses-node-wan-ip-instead-of-carp-vip</link><guid isPermaLink="true">https://forum.netgate.com/topic/200238/ddns-updates-wrong-ip-after-carp-failover-system-traffic-uses-node-wan-ip-instead-of-carp-vip</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Wed, 25 Feb 2026 14:24:47 GMT</pubDate></item><item><title><![CDATA[PFSense HA &amp; OSPF Question]]></title><description><![CDATA[@stowemotion59 It is an entirely new OSPF session requiring a complete reconvergence so it should be fine.
]]></description><link>https://forum.netgate.com/topic/200237/pfsense-ha-ospf-question</link><guid isPermaLink="true">https://forum.netgate.com/topic/200237/pfsense-ha-ospf-question</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Wed, 25 Feb 2026 12:38:43 GMT</pubDate></item><item><title><![CDATA[Nat issue with carp and 25.11.1]]></title><description><![CDATA[<p dir="auto">I believe I hit a bug with nat port forward.</p>
<p dir="auto">Setup<br />
2 pf nodes sharing a /29 public subnet. with carp.<br />
Carp works as expected.<br />
An internal host running a web server on port 80 exists on the lan interface.<br />
Firewall rules are correctly adjusted to allow incoming traffic to port 80.<br />
(to the internal ip)<br />
No related firewall rules are used on nat.<br />
If an ip is configured as carp, then port forwading 80 on this ip to internal port 80, doesn't work.<br />
Making this an alias to the same wan interface works.</p>
<p dir="auto">Downgrading to 25.07 makes carp nat work too.</p>
]]></description><link>https://forum.netgate.com/topic/200197/nat-issue-with-carp-and-25.11.1</link><guid isPermaLink="true">https://forum.netgate.com/topic/200197/nat-issue-with-carp-and-25.11.1</guid><dc:creator><![CDATA[netblues]]></dc:creator><pubDate>Thu, 19 Feb 2026 14:57:57 GMT</pubDate></item><item><title><![CDATA[How to deal with VPN interfaces befor start XMLPRC Sync?]]></title><description><![CDATA[<p dir="auto">Hello all,</p>
<p dir="auto">I have a firewall (FW1) with the following interfaces:</p>
<ul>
<li>WAN</li>
<li>LAN0</li>
<li>LAN1</li>
<li>LAN2</li>
<li>OpenVPN1</li>
<li>LAN3</li>
<li>OpenVPN2</li>
<li>pfSync</li>
</ul>
<p dir="auto">No I want to enable HA Features for a new firewall (FW2)</p>
<p dir="auto">For firewall FW2 I can prepare all "real" interfaces beeing in the same order, but how to deal with virtual OpenVPN1 &amp; 2 interfaces before activate XMLPRC Sync? I guess they will generated on FW2 after start XMLPRC Sync, isn't it?</p>
<p dir="auto">How can I ensure that the interface orders are the same when I want do enable HA features years after starting with FW1</p>
<p dir="auto">Kind regards</p>
]]></description><link>https://forum.netgate.com/topic/200120/how-to-deal-with-vpn-interfaces-befor-start-xmlprc-sync</link><guid isPermaLink="true">https://forum.netgate.com/topic/200120/how-to-deal-with-vpn-interfaces-befor-start-xmlprc-sync</guid><dc:creator><![CDATA[benausgz]]></dc:creator><pubDate>Mon, 09 Feb 2026 16:31:45 GMT</pubDate></item><item><title><![CDATA[Virtual IP subnet IPs not expanding into NAT]]></title><description><![CDATA[@Barnzey90 do you have an account on https://redmine.pfsense.org/ to report the issue?
]]></description><link>https://forum.netgate.com/topic/200082/virtual-ip-subnet-ips-not-expanding-into-nat</link><guid isPermaLink="true">https://forum.netgate.com/topic/200082/virtual-ip-subnet-ips-not-expanding-into-nat</guid><dc:creator><![CDATA[patient0]]></dc:creator><pubDate>Thu, 05 Feb 2026 10:57:25 GMT</pubDate></item><item><title><![CDATA[Dynamic DNS + XMLRPC SYNC]]></title><description><![CDATA[What is the recommended method of ensuring high availability of a service running on or behind an HA cluster then? Require running the DynDNS client on a separate system (not the firewall itself?)
]]></description><link>https://forum.netgate.com/topic/199963/dynamic-dns-xmlrpc-sync</link><guid isPermaLink="true">https://forum.netgate.com/topic/199963/dynamic-dns-xmlrpc-sync</guid><dc:creator><![CDATA[luckman212]]></dc:creator><pubDate>Thu, 22 Jan 2026 13:36:56 GMT</pubDate></item><item><title><![CDATA[Query on HA and VIP]]></title><description><![CDATA[@netblues

you can't really have carp failover without 3 ip's in the same subnet

Depends, which is why I asked about it. We’ve set it up on Comcast/Xfinity using one shared static public IP and set the WAN IP on both routers in the default 10.1.10.x range. That works well.
Docs cover only one IP but there’s no connectivity until failover:
https://docs.netgate.com/pfsense/en/latest/highavailability/index.html#ip-address-requirements-for-carp
If WAN2 is really only DHCP though then I don’t think there can be a shared IP.
]]></description><link>https://forum.netgate.com/topic/199962/query-on-ha-and-vip</link><guid isPermaLink="true">https://forum.netgate.com/topic/199962/query-on-ha-and-vip</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Thu, 22 Jan 2026 12:12:40 GMT</pubDate></item><item><title><![CDATA[On CARP switchover to secondary, *some* replicated states disappear]]></title><description><![CDATA[<p dir="auto">First, this is pfSense CE 2.8.1, two VMs on KVM and conventional Linux bridge devices.   vNICs are all virtio.   Best I know, none of the latter (platform) has any bearing on this.  Plenty of RAM on both VMs, avg. usage no more than about 60% and avg. around 1k entries in the state tables.</p>
<p dir="auto">TL;DR: state and XMLRPC replication works great... then some, but not all - states disappear when the secondary takes over.  When the primary takes over again, if not rebooted, the missing states are re-replicated and any hung connections resume.   No apparent suspicious entries in the system log.</p>
<p dir="auto">What works: in normal CARP pair operation, states are replicated - by inspection of the state table - about same number of by watching pfinfo.  Spot checks also match, the VM configs are identical, including the interface names and enumeration order.   When I do either a manual carp maintenance mode, or e.g. reboot the primary, the VIPs all migrate virtually instantly and as they should.   If I'm 1/sec pinging a host routed through the firewall, it doesn't miss a ping on the takeover/giveback - good.   There are no obvious errors in the system log during this process.</p>
<p dir="auto">What doesn't work: even though the states are apparently replicated, just as the secondary takes over, it quietly drops 30-50% of its states by count.   Not all, just some.   If I'm logged in via TCP to that same host I'm pinging via firewall routing (requiring a state), that connection hangs until the primary takes over again.   Manually inspecting the state tables for that host's IP on the backup/temp primary, all states for the host are among those that disappeared - so no surprise the connection hung.  When I re-enable CARP and primary takes over again, state for that connection is re-replicated and data flows again.   BTW this behavior occurs whether the VMs are on the same host or different hosts (latter the usual case for HW HA), so it's not a switch problem per se - seemingly already ruled that out.   The loss of states appears to be occurring inside the secondary, because replication itself via the layers below, is otherwise working.</p>
<p dir="auto">I've dug deep on the net for any clues, including running through the full CARP troubleshooting guide, including using unicast for state replication instead of the default directed multicast.  (Both behave the same.)   Still, something is causing loss of not all, but a portion of the states that were replicated and appeared in the secondary's state table.   I don't see any clear pattern except that new(er) states seem to be the ones most likely lost.</p>
<p dir="auto">I do use some policy routing on a couple internal interfaces, and tried disabling that with no behavior change.  The topology here is pretty simple for the HA pair: a single WAN-facing interface towards my cable modem with outbound NAT enabled plus a handful of inbound port forwards, and several internal interfaces e.g. LAN, DMZ.    One interface is dedicated to SYNC, has a wide-open firewall rule, and nothing about the interface seems to be a problem. All interfaces except SYNC host a CARP VIP.  I am not using trunking inside pfSense but have brX devices on the host, one per VLAN defined via netplan.  Once upon a time this worked seamlessly.  I'm not aware of any config changes that would cause this.</p>
]]></description><link>https://forum.netgate.com/topic/199941/on-carp-switchover-to-secondary-some-replicated-states-disappear</link><guid isPermaLink="true">https://forum.netgate.com/topic/199941/on-carp-switchover-to-secondary-some-replicated-states-disappear</guid><dc:creator><![CDATA[syncword]]></dc:creator><pubDate>Mon, 19 Jan 2026 21:49:37 GMT</pubDate></item><item><title><![CDATA[interface number mismatch]]></title><description><![CDATA[@beloc The short answer is yes you can edit the config file and upload.
This can happen if interfaces are added out of order or inconsistently.  Note the visible name label (MGMT below) is not necessarily the same as the internal name in the config file (opt4 below).
&lt;opt4&gt;
&lt;descr&gt;MGMT&lt;/descr&gt;
&lt;if&gt;igc3&lt;/if&gt;
&lt;enable/&gt;
&lt;spoofmac/&gt;
&lt;ipaddr&gt;x.x.x.x&lt;/ipaddr&gt;
&lt;subnet&gt;24&lt;/subnet&gt;
&lt;/opt4&gt;

Rules use the "opt4" name. States use the "igc3" name if "Interface Bound States" are used.
If you find &amp; replace just be careful to not replace strings in other places such as certificates.
]]></description><link>https://forum.netgate.com/topic/199866/interface-number-mismatch</link><guid isPermaLink="true">https://forum.netgate.com/topic/199866/interface-number-mismatch</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Thu, 15 Jan 2026 16:15:13 GMT</pubDate></item><item><title><![CDATA[Question about OpenVPN running on HA cluster on the CARP WAN on port 443]]></title><description><![CDATA[@AlexMercer Move the webgui to 4443. Disable webConfigurator anti-lockout rule. Disable webConfigurator redirect rule. Add a specific rule for the internal interface (any LANish is good, preferrably the one which is your dedicated management LAN) to port 4443.
This hardening and consistency ensures whatever goes wrong, any public WAN/443 combination won't ever reveal the webgui.
Always remove excess rules- if you don't know why it is there, get rid of it.
]]></description><link>https://forum.netgate.com/topic/199819/question-about-openvpn-running-on-ha-cluster-on-the-carp-wan-on-port-443</link><guid isPermaLink="true">https://forum.netgate.com/topic/199819/question-about-openvpn-running-on-ha-cluster-on-the-carp-wan-on-port-443</guid><dc:creator><![CDATA[tsmalmbe]]></dc:creator><pubDate>Wed, 14 Jan 2026 15:33:46 GMT</pubDate></item><item><title><![CDATA[Two locations, two ISP (WAN) and HA setup]]></title><description><![CDATA[@Jdwind I just meant, maybe duplicate their routing in the example.
]]></description><link>https://forum.netgate.com/topic/199638/two-locations-two-isp-wan-and-ha-setup</link><guid isPermaLink="true">https://forum.netgate.com/topic/199638/two-locations-two-isp-wan-and-ha-setup</guid><dc:creator><![CDATA[SteveITS]]></dc:creator><pubDate>Sun, 21 Dec 2025 01:44:06 GMT</pubDate></item><item><title><![CDATA[Hetzner vSwitch subnet: second subnet receives no traffic]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I am running pfSense as a virtual machine connected to a <strong>Hetzner vSwitch</strong> (VLAN ID 4000).</p>
<p dir="auto">I have two IPv4 subnets attached to the same Hetzner vSwitch (Layer-2 network):</p>
<ul>
<li>Existing subnet (working): <code>192.0.2.48/28</code></li>
<li>Additional subnet (not working): <code>198.51.100.192/27</code></li>
</ul>
<p dir="auto">The pfSense VM has a single interface connected to this VLAN.</p>
<p dir="auto">Current situation:</p>
<ul>
<li>pfSense is configured with an IP address from 192.0.2.48/28 on the interface</li>
<li>This subnet works correctly (ICMP traffic is received, confirmed via packet capture)</li>
<li>The additional /27 is shown in Hetzner as attached to the same vSwitch (not routed to the server’s public interface)</li>
</ul>
<p dir="auto">For testing purposes, I configured the IP <code>198.51.100.194</code> on the same pfSense interface using:</p>
<ul>
<li><strong>Virtual IP (IP Alias)</strong></li>
<li><strong>Virtual IP (Proxy ARP)</strong></li>
</ul>
<p dir="auto">In both cases, pfSense does not receive any traffic for the <code>198.51.100.192/27</code> subnet.<br />
A packet capture on the VLAN interface shows no ARP or <strong>ICMP traffic</strong> for addresses in the <code>/27</code> subnet, while traffic for the <code>/28</code> subnet is visible.</p>
<p dir="auto">No NAT is involved; I only want pfSense to respond to ICMP for now.<br />
Firewall rules allow ICMP to the interface and to the Virtual IP.</p>
<p dir="auto">My question is:<br />
<strong>What is the correct way in pfSense to handle multiple public subnets on the same VLAN/interface when they are delivered via a Hetzner vSwitch (Layer-2)?</strong></p>
<p dir="auto">Is IP Alias or Proxy ARP the correct approach in this scenario, or is some additional configuration required when multiple public subnets share the same interface?</p>
<p dir="auto">Any guidance or similar experiences would be appreciated.</p>
<p dir="auto">Thanks in advance.</p>
]]></description><link>https://forum.netgate.com/topic/199579/hetzner-vswitch-subnet-second-subnet-receives-no-traffic</link><guid isPermaLink="true">https://forum.netgate.com/topic/199579/hetzner-vswitch-subnet-second-subnet-receives-no-traffic</guid><dc:creator><![CDATA[decibel83]]></dc:creator><pubDate>Mon, 15 Dec 2025 17:51:24 GMT</pubDate></item><item><title><![CDATA[HA-proxy How to use Custom ACL&#x27;s]]></title><description><![CDATA[@louis2
When you click on the three points on the upper right side, there should be an option to start a chat.
]]></description><link>https://forum.netgate.com/topic/199461/ha-proxy-how-to-use-custom-acl-s</link><guid isPermaLink="true">https://forum.netgate.com/topic/199461/ha-proxy-how-to-use-custom-acl-s</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Sun, 30 Nov 2025 15:14:54 GMT</pubDate></item><item><title><![CDATA[How to use HA proxy to route HTTP traffic? It does not work as I expected :(]]></title><description><![CDATA[@louis2
[image: 1764426797353-cc6d5848-ab46-499c-bd4e-4021f820d63f-image.png]
How about custom?
and then an action.
Yes it is not intuitive or easy, and no, I don't have that much experience on that, but the options exist.
]]></description><link>https://forum.netgate.com/topic/199452/how-to-use-ha-proxy-to-route-http-traffic-it-does-not-work-as-i-expected</link><guid isPermaLink="true">https://forum.netgate.com/topic/199452/how-to-use-ha-proxy-to-route-http-traffic-it-does-not-work-as-i-expected</guid><dc:creator><![CDATA[netblues]]></dc:creator><pubDate>Fri, 28 Nov 2025 18:22:43 GMT</pubDate></item><item><title><![CDATA[HA setup is flapping between primary and backup devices]]></title><description><![CDATA[So I disconnected the backup device and my network is back to normal (even though I haven't removed the CARP and HA settings yet). Just for the sake of testing, I configured two identical Steelheads CX770s with Opnsense and got the same results as with pfSense.  I get the same results with two sets of completely different hardware! How can this be possible?!
I thought it was the connection to the switch (since both firewalls connect to the same stack) but as soon as I remove the backup unit from the HA setup, all network connectivity is restored.
Has anyone here encountered this problem before?
Martin M. Mune
US Army Combat Veteran
Operation Iraqi Freedom
Volunteer Soldier
International Legion for the Defense of Ukraine
Слава Україні!
Героям Слава!
]]></description><link>https://forum.netgate.com/topic/199391/ha-setup-is-flapping-between-primary-and-backup-devices</link><guid isPermaLink="true">https://forum.netgate.com/topic/199391/ha-setup-is-flapping-between-primary-and-backup-devices</guid><dc:creator><![CDATA[martimun]]></dc:creator><pubDate>Fri, 21 Nov 2025 17:41:30 GMT</pubDate></item><item><title><![CDATA[Wireguard HA Sync to second PFS?]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have a PfSense HA Setup using Wireguard Point-to-point with FRR/BGP to connect to 3 different Systems. The tunnels are setup on the CARP IP of the HA setup. Now I run into the problem, that I found no way to export/import or sync the Wireguard setup to Pfsense2.</p>
<p dir="auto">Is there anything I oversee?</p>
<p dir="auto">I need the same Keys and peers on the second Pfsense in case of the CARP switches to it. Otherwise I would have to create 3 extra Tunnels on Pfsense2?</p>
<p dir="auto">Thank you for any hint.</p>
]]></description><link>https://forum.netgate.com/topic/199243/wireguard-ha-sync-to-second-pfs</link><guid isPermaLink="true">https://forum.netgate.com/topic/199243/wireguard-ha-sync-to-second-pfs</guid><dc:creator><![CDATA[vsatmydynipnet]]></dc:creator><pubDate>Thu, 06 Nov 2025 10:10:39 GMT</pubDate></item><item><title><![CDATA[HA WAN Configuration - The first router to boot occupies all available IP&#x27;s on the WAN interface]]></title><description><![CDATA[@AaronH said in HA WAN Configuration - The first router to boot occupies all available IP's on the WAN interface:

When connecting the HA cluster, the first router to boot claims all of the available IP's on the subnet

So did you assign all available IPs to the router?

If we connect two laptops with the same IP addresses to the Comcast network, both can function as expected with no issues.

Both with the same IP??
]]></description><link>https://forum.netgate.com/topic/199177/ha-wan-configuration-the-first-router-to-boot-occupies-all-available-ip-s-on-the-wan-interface</link><guid isPermaLink="true">https://forum.netgate.com/topic/199177/ha-wan-configuration-the-first-router-to-boot-occupies-all-available-ip-s-on-the-wan-interface</guid><dc:creator><![CDATA[viragomann]]></dc:creator><pubDate>Fri, 31 Oct 2025 17:12:55 GMT</pubDate></item></channel></rss>