• Loadbalancing Webservers

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    A

    @Comradin:

    any hints on how to check if balanced sessions are sticky or not?

    Set it up and observe if your requests continue to hit a particular one of the backend servers.

  • HELP … An error code was received while attempting XMLRPC sync

    Locked
    10
    0 Votes
    10 Posts
    16k Views
    S

    Hopless… just no way to get MultiWAN working with CARP failover.

    I have this situation now...
    I figured out ISP2 gives me only 2 IPs, so im screwed... but im screwed because CARP sucks, not because of this ISP.

    U see.. there is no way to use Multiwan on MASTER and One WAN on BACKUP (so only one ISP would be CARP-ed)

    I ended up so that Backup is making random reboots now. It didnt survive Master crash at all.. and after Backup became Master.. and the real master woke up - it NEVER gave back the Master status to the right box. Basically after a crash.. the internet would never come back automatically.

    Seems im on "manual" hardware failover now.

  • Carp ICMP Filling up Firewall Log

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • CARP Sync failing ESX

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    N

    I re-installed 1.2 and the weird lockup issue went away.  CARP is working great, however SYNC'ing still doesn't work.  ???  The states table syncs but nothing else.

    SO my main issue has been corrected as I don't have a signal point of failure, however I would like the config's to sync so anytime I make a change I don't have to remember to make it to my "Backup"

    Not sure where else to look for the problem, would uploading a packet capture or config help someone troubleshoot this further?

    Thanks

  • Master becomes Slave and Slave becomes Master

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D

    I got the reason why it didn´t work:

    The LAN Interface of FW1 was a 10 mbit network card! Until I put in a 100 mbit network card it works fine!

  • Setting nic address and default gateway as the same ip

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Carp

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    B

    It sounds like you have it backwards. You want to enter the IP address of the backup on the carp page of the master. Putting an IP address in that field and checking the box essentially tells it to push the settings to that device.

  • CARP needed, limited IPs available

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    F

    Thanks dotdash, in my trolling I ultimately decided you had given the answer to me …I'm upping to /28 ideally ...it's a pain with my ISP ...I actually use a lot of port forwarding to get it down to the 5 ...i could get it to 3 maybe, but that's really pushing it ...but any way, thanks again ...and looking forward to CARPDEV someday.

  • Master-Master Config

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K

    I've your answer expected ;D but:
    In CARP-Documentation is written that's possible.

    Is it not supported because it's not tested? Or is not working and I'll get problems? Is it technical (e.g. unsupported) possible to sync in both directions (fw001 <–> fw002).

    I ask because I want share applications over two firewalls:

    fw001: vpn, internet access,...
    fw002: web hostings, dmz, ...

    If one firewall goes down then the other firewall run all.

    Is it planned in future to support master-master?

  • 3rd interface not failing back…

    Locked
    21
    0 Votes
    21 Posts
    32k Views
    S

    Iv seen this one before… sorry to say that im a noob and just figuring it out my own probs at:
    http://forum.pfsense.org/index.php/topic,10458.0.html

    At my configuration... it happened when the CARP suddenly "worked" after i sorted out some bugs... then again it didnt work. It was when the SYNC interfaces were on 10Mb/s old NICs. And the LAN VIP became master on Backup, WAN and WAN2 were left Master at the Master box. And then when i went to 100/10 NIC's the backup took all the VIP's as master... so it might be something different than your prob.

    One question... how would i bypass the "broadcast" thing if it really is the switch or NIC's bad appetite for not eating broadcast packets. ?

  • CARP Master/Backup failure

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    S

    Im fairly new to CARP stuff… u can read my try's at:
    http://forum.pfsense.org/index.php/topic,10458.0.html

    I can confirm this happening.

    I had 3 VIP's at master... LAN WAN WAN2
    I created LAN VIP on the backup and then got the CARP working...
    The same happened.. weirdly displayed and only icons showing at the CARP status screen.

    So i deleted all VIP's at backup, then saved CARP settings at Master and it synced VIP's to backup properly.
    I assume it has something to do with the VIP syncing over the one that already existed.

  • CARP w/Bridge, Switch Issue? [solved]

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    jimpJ

    And now I seem to have successfully trained the switch to properly prioritize the ports, I had to change not only the port priority, but the path cost.

    For the record, my DMZ port configuration on switch #2 look like this:

    interface FastEthernet0/1 description Firewall - Master - DMZ Port switchport access vlan 20 spanning-tree vlan 20 port-priority 64 no cdp enable interface FastEthernet0/2 description Firewall - Slave - DMZ Port switchport access vlan 20 spanning-tree vlan 20 cost 500 no cdp enable

    Sorry for the noise!

    Keep up the good work, everybody.

  • Ping WAN VIP from LAN

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    GruensFroeschliG

    Are you really really sure that you can ping these VIP's now?
    Because it's NOT possible to ping proxy type VIP's.

  • Added a VIP on LAN, can't ping it (same subnet)

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    GruensFroeschliG

    You cannot ping Proxy type VIP's.
    Only CARP type VIPs.
    http://forum.pfsense.org/index.php/topic,7001.0.html

  • CARP Settings Username and Password

    Locked
    10
    0 Votes
    10 Posts
    7k Views
    H

    and pay attention! the interfaces must have the same order, please take a look at the screenshot…..

    e.g. LAN, WAN, SYNC for the master and LAN,SYNC,WAN is not working......

    ScreenShot003.jpg
    ScreenShot003.jpg_thumb

  • CARP - DUAL WAN - WIFI

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    dotdashD

    @cyriles:

    I have 2 ADSL internet connexions (PPPOE) with dynamic IP addresses, I want them to work in Load Balancing mode, one connexion on the Master and one on the Slave.

    Here is your first issue. If you set it up this way, the failover will not be very clean and the slave connection will only be used when the master is down.
    Typically, you would use Two WAN ports on each computer, and connect both to both DSLs. In your case, two PPPoE WANs are not possible, and you would need a router between the second WAN and the DSL. Searching should provide detailed information on this.
    @cyriles:

    Now my second question :

    Do I have to plug one access point on each server and if yes, will they both be "online" or only one at the same time depending on the working server (Master or Slave) ?

    I would think the simple answer to this would be to setup your WIFI port like another LAN, connect the AP to a switch that is connected to the WIFI-OPT ports on both pfSense boxes and point the AP's gateway to the CARP address of the WIFI-OPT interface.

  • Inbound Loadbalancing - sticky connections- does not Round Robin

    Locked
    12
    0 Votes
    12 Posts
    7k Views
    G

    How do i configure Sticky Address? And what is the behavior with this option?
    Thanks
    G

  • LAN CARP as gateway

    Locked
    7
    0 Votes
    7 Posts
    7k Views
    N

    So I figured out that the problem is all about return-path. The real network servers had their own default routes and were basically returning traffic along that path instead of through pfsense.

    The equivalent of this is LVS-DR, for you linux virtual server types out there. Is there an equivalent of LVS-NAT, where web servers route traffic back to the pfsense load balancers that originally requested it?

  • Moving to a new Internet Line an keeping the old line activ

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    Ok that makes sense

    Thank you !!!

  • Internal load balance (virtual server)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    N

    Thanks GruiensForeschli. The NAT didn't work. I know that NAT is resolved prior to firewall rules.

    Does anyone know how "Virtual Servers" works? If it's a matter of configuration I can try to dig into the code to do this, or set up a bounty. Is it a combination of custom NAT with gateway routing, or what's the behind-the-scenes program that handles this?

    It's interesting to note, in the NAT, it says:

    If you want this rule to apply to another IP address than the address of the interface chosen above, select it here (you need to define Virtual IP addresses first). Note if you are redirecting connections on the LAN, select the "any" option.

    … why do LAN port forwards require the "any" option, but WAN does not? Is it a limitation of the program doing the NAT? If it's that kind of limitation, then I guess there is no solution.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.