• Load balancer with failover, not quite right.

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Annoyed at Carp. How many different ways can you say no?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    C

    I did finally get sync working.  Discovered that one of the network cards was bad.  The thing that annoyed me initially is that once I told it to sync, I could never get it to stop making the attempt short of resetting to factory.

  • Newb Dual IP/Failover question

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jahonixJ

    AFAIK this depends on how you setup your ISPs.
    pfSense currently only supports PPPoE client on WAN interface. If the second ISP can be handled by an external router you should be fine.

  • Unable to Sync Rules without XMLRPC Code 2 error

    Locked
    23
    0 Votes
    23 Posts
    13k Views
    S

    i tried http/https, various ports and passwords, various carp-configurations (what to sync) and so on.
    the link to the wiki was already posted above and i considered it carefully but to no success.

    a note to special characters: the default generated rules already contain '-' in their description, also the aliases get comments added with timestamps in them containing ':'. so i guess those characters are ok (but i have non other than [[:alnum:]] in my own rules and descriptions, not even blanks).

  • CARP and bridge on same system .. working .. kinda :-)

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • ProxyArp question

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    H

    @hexa:

    I could go with filtered bridge, but won't this break other functionality i want in this set up?

    If I enable bridge WAN <> OPT2, then DNAT (WAN<>OPT1) rules stop working.
    So bridge isn't a solution.

  • Pfsense in active-active setup?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    C

    At least a year I would guess, it's impossible to say.

  • CARP Failover with several LAN:s

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    GruensFroeschliG

    yes this should be possible.

  • Multiple Public IP's

    Locked
    9
    0 Votes
    9 Posts
    8k Views
    D

    @MrPK:

    Use CARP! Even if you wont use the CARP capabilities, this works fine for me. You must enter some VIP Password (any you like, you won't need it anyway). Every Virtual IP must have different VHID Group. Leave Advertising Frequency on 0. When you're done go to NAT, use "Port forwarding", map your external IP (VIP's) to your internal IP. Done!

    Thank you, MrPK. This solutoin solved my problems.
    Just want to know what the difference is between CARP and Other in NAT 1:1 setting.
    Please advise me.

    Thank you in advance.

  • Master not sharing states

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    M

    I think the soekris boards should be ok.

    even if they were too weak it shouldn't stop it being setup right it just might not work properly.

    Check and resave the carp config on the master.
    Check the masters interface assignments especially the CARP sync link.
    Check the subnet masks on both nodes for the CARP sync link

    If it still won't go post a screen shot of the carp setup for both boxes and the sync interfaces

  • Unable to failover

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M

    A diagram of your network would help.

    You need 3 IPs per wan connection 1 for each real box and 1 for them to share as the CARP address

  • Larger state table on backup compared to master

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    M

    I had something like this because I had not ticked the "Synchronize Enabled" on the slave but it was not as many states

  • VIP / CARP Question

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    A

    Ok I've figured out all of my confusion and it is working seamlessly.

    Thanks for the help!

  • Firewall not responding to virtual IPs - resolved… sort of

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    dotdashD

    The box I have with all the VIPs is running 1.2 beta2, but I haven't heard of any recent issues with VIPs. I forget if beta 2 had the additional save button with the carp reboot warning…

  • Carp with double WAN

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    D

    Thanks for your help, Hoba

    if i have 3 real IPs : 212.172.11.27, 213.172.11.27, 214.172.11.28.

    Although i have read the tutorial many time but seem i not be able to understand well  so that you can base on 3 ip real ips and give me some major setting on pfsense.

    To ngoc ( may be you are VietNamese)  ::)

    Can you give me your email i want some questions about the pfsense want to ask you. Thanks Ngoc so much

  • CARP on PPPoE

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    C

    Hoba, thanks for confirming what I suspected.  At the moment I am using a Netopia router to map IP addresses from public to internal.  While a Netopia tech assured me that this is not simply a straight pass-thru tunnel, from what I can determine it is and that leaves my servers exposed.  That's why I was attempting to use pfSense and get a solid, configurable firewall I know won't leave my servers unprotected.

    How do I make FTP work using proxy ARP for VIPs?  Since I don't maintain all the domains I host FTP is necessary.

    Tony

  • Problem with carp vip's on wan

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    J

    Anybody???

  • Carp documentation

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    J

    Thanks, and although I've only been using pfsense for a short time I have to say it's very impressive

  • Should CARP VIP + LB VIP match?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Using IEEE1394 has the CARP interface

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    R

    It is actually working fine for a month now on 1.0.1.  Download 1.2-BETA-2 today, having fw support built-in but not fwip.

    I would also like to have it in 1.2

    Martin

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.