• CARP/HA, SYNC and XMLRPC SYNC explained

    Pinned
    3
    1 Votes
    3 Posts
    16k Views
    M
    Thanks for the excellent reply. I've retested as you suggested by entering persistent maintenance and there is no packet loss that way (perst maint, reboot, leave persist maint). I am still having a small problem with freeradius xmlrpc sync between the two but I posted that in a separate topic (see https://forum.pfsense.org/index.php?topic=135864.0). Regards, Matt
  • 0 Votes
    1 Posts
    71 Views
    No one has replied
  • I tried, I can't get it to work

    22
    0 Votes
    22 Posts
    714 Views
    M
    @johnpoz Too bad you’re not here. Like I said, I can’t get it to work. You must have knowledge about these things I do not possess currently. Maybe someday if I live long enough. Thanks, Jack
  • Feature request: Set a gateway for each VIP

    1
    0 Votes
    1 Posts
    53 Views
    No one has replied
  • LAN only HA + OpenVPN

    3
    0 Votes
    3 Posts
    1k Views
    patient0P
    @reberhar said in LAN only HA + OpenVPN: You still need to do a vip for the wan Answer 4 years later to a user who has posted only once.
  • HA sync overwrites certificates on backup router even if unchecked

    9
    1
    0 Votes
    9 Posts
    4k Views
    SteveITSS
    I was reminded using an IP address may bypass HSTS/the invalid cert...will need to wait another couple months to try it though. Also one could disable HSTS on the secondary router, ahead of time. (I suspect that setting is not synced...)
  • Different CARP LAN - WAN unplug behavior

    5
    2
    0 Votes
    5 Posts
    3k Views
    N
    @karmacop Hello, never dug further into it ; switching from DHCP to static for IPv6 fixed it for me and I haven't had any issues since then, so I didn't feel the need to investigate more. ;)
  • hardware needs to move to a cluster

    11
    0 Votes
    11 Posts
    4k Views
    S
    @SteveITS great, thanks (sorry for the late reply) Currently the project waits for some dependencies and decisions. As soon as I get the go I might start preparing the config. Obviously I have a working pfSense config in place, I will start to think about how to migrate that to a cluster config. I might start with 2 VMs and follow something like this recipe (?)
  • Don't access GUI, SSH etc using CARP VIP?

    3
    0 Votes
    3 Posts
    2k Views
    luckman212L
    Guess I never really thought about the possibility of a failover event occurring in the middle of making configuration changes. But I guess that's as likely to happen as anything else. I'll now consider myself lucky that it never did. I've gone and updated all of my bookmarks and tooling to use the explicit primary and secondary IPs. Thanks again.
  • Possible bug + fix for HAproxy issue during upgrade to 2.8.1

    2
    1 Votes
    2 Posts
    1k Views
    D
    @ndemou I have what may be a related issue, but I'm hesitant try try this patch as I'm on pfSense plus 26.03.1. Although my certs are valid, when I try to setup a frontend in HAProxy,I don't get the cert dropdown, I just get an empty text box. I tried entering my cert name but then it throws a parsing error when I try to save it. [ALERT] (87716) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:15] : 'bind 0.0.0.0:443' in section 'frontend': unknown keyword 'mynet.com'. [ALERT] (87716) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg [ALERT] (87716) : config : Fatal errors found in configuration. In the example above, unknown keyword mynet.com is my certificate name, which I entered into the textbox since there was no dropdown list.
  • OpenVPN interfering with CARP Failover

    26
    1 Votes
    26 Posts
    14k Views
    stephenw10S
    The redmine hasn't been addressed directly. As far as I know it has not been fixed but it's possible something has fixed it indirectly. If you have a good test case for it it would be good to know.
  • HA with MULTIWAN Outbound NAT for CARP and VLANs

    3
    0 Votes
    3 Posts
    2k Views
    J
    @netblues Right. Thank you very much.
  • High Availability and TailScale

    1
    0 Votes
    1 Posts
    741 Views
    No one has replied
  • How to route to backup lan interface

    carp routing
    1
    0 Votes
    1 Posts
    715 Views
    No one has replied
  • 0 Votes
    6 Posts
    3k Views
    SteveITSS
    @Chebec Have a read through: https://docs.netgate.com/pfsense/en/latest/development/patches/custom.html and the rest of the topic. If you add a patch, it should detect whether it can be Applied and will or will not show the Apply button, as I recall. There is also a Debug button to test. Normally a patch can be reverted via that button, yes, unless the target file is later changed. (after updating pfSense you would not want to revert a patch and reintroduce a bug, just delete the custom patch) Note there's a later patch ID in that redmine: 8544b85f8c32d0f180c09a4d0986ac819919bd2b As long as patches are from Netgate developers I would have no issue installing them. For random patches in the forum I'd be a bit more cautious. In either case you can see the code being changed, in the patch details. Edit: Marcos M in the redmine is a Negate dev.
  • Virtual IP questio : traffic to a VIP doesnt seem to route

    4
    0 Votes
    4 Posts
    2k Views
    SteveITSS
    @boumacor I'm not a huge fan of floating rules if they can be set as regular rules, since the, er, rules change for floating. Just to maintain clarity. However if the rule triggers and a state is open you're through pf. Does the pfSense routing table show a route for the 192.168.1.0/24 subnet? I would still be suspicious of the switch ignoring traffic outside its own subnet unless you're sure it will allow it. You could set an IP on some other device and ping it, to check the connection through pfSense.
  • PFSense HA & OSPF Question

    4
    0 Votes
    4 Posts
    2k Views
    DerelictD
    @stowemotion59 It is an entirely new OSPF session requiring a complete reconvergence so it should be fine.
  • Nat issue with carp and 25.11.1

    1
    0 Votes
    1 Posts
    827 Views
    No one has replied
  • How to deal with VPN interfaces befor start XMLPRC Sync?

    1
    0 Votes
    1 Posts
    760 Views
    No one has replied
  • Virtual IP subnet IPs not expanding into NAT

    5
    0 Votes
    5 Posts
    3k Views
    patient0P
    @Barnzey90 do you have an account on https://redmine.pfsense.org/ to report the issue?
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
Privacy Policy · Cookie Policy