• Panic every time set up carp vip

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    C

    @dbuckle:

    I was having a similar problem on a wrap board where whenever the CRAP interface was changed

    Hey now, don't call it names.  ;D

  • 2 NODE WRAP : How to upgrade?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    C

    Yeah, the config file can be restored. You'll have to reflash to get to 1.2b1, but once you're on that version you can use the firmware update page to upgrade going forward.

  • Transparent Bridge + CARP, possible ?

    Locked
    7
    0 Votes
    7 Posts
    5k Views
    M

    Hi,

    Thanks for the kind link. I was searching the forum, but in some strange way I got 0 results for some time.

    I have read about the spanning tree option, this migt be a good idea, but this solution is also what I really like, thanks a lot !!

  • Multi WAN IP issues

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    K

    I got it.

    My ISP had not removed the filter on their side, even though they had assigned the ip to me.  Once they made the change, everything started working.

    Cheers!
    Ken

  • Best VHID practice for multiple CARP VIP ?

    Locked
    3
    0 Votes
    3 Posts
    7k Views
    M

    There's really not much to the VHID numbering other than making them unique.  This is not something that you'll ever need to change or inspect once it's set up.

    -Martin

  • LAN -> Lan Load Balancing?

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    J

    turn on nat reflection

  • Backup Always Assumes Role of Master

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    A

    Thanks a lot for your help!  The passwords were correct.  What I ended up doing is deleting that CARP interface and recreating it.  Then I rebooted the backup machine.  When it came back up, it became backup for all the interfaces, including the one I had a problem with.  I made the master fail so that the IPs were handed over to the backup, and when the master came back up, the backup gave all the IPs back to the master without issue.  I hope this just stays this way and wasn't a one time thing…

  • FW crashes when removing a VIP?

    Locked
    8
    0 Votes
    8 Posts
    3k Views
    S

    Please test a recent snapshot.  I have added a patch that may resolve this issue.

  • Carp + DUAL WAN does this make sense

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    B

    Not to make life more complicated, but how would I add BGP into the mix to provide failover to another site?

    Eric

  • Could be useful…....or not ;-)

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • VLAN Setup of pfSense.

    Locked
    4
    0 Votes
    4 Posts
    10k Views
    D

    @Perry:

    You setup vlans like any other nic
    http://pfsense.hotserv.dk/hmm.htm

    VERY, VERY helpful … thanks bunches!!  I have it up and running now with little difficulty thanks to this great presentation.

  • LAN -> VIP (Carp) -> internet not working

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Failover conditional

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • CARP and VIP's NOT working

    Locked
    7
    0 Votes
    7 Posts
    4k Views
    dotdashD

    @rexsrexs:

    I can't make the CARP type VIP with subnet xxx.xxx.xxx.44/32 the pfbox will also complaint, it said

    Sorry, we could not locate an interface with a matching subnet for 202.133.1.44/32. Please add an ip in this subnet on a real interface.

    If you are using a CARP VIP, the subnet mask of the VIP should match the subnet mask of the Interface (/29 in your case). The 1-1 NAT should still be a /32 to match one internal and one external address.

  • CARP and WAN

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    T

    Yeah, I got ya.

  • Unable to failover to backup pfsense

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    E

    its me again. problem solved. i just made the host that used to be enslaved the master. exMaster is now the gimp. and gimp works fine. gimp is now encaged. and whenever master needs something from gimp, gimp may fulfill his duties. i think it was the builtin nic from some dellMachine.

    pfSense is a good product. i especially like the fact, that it is not a blackbox like some other enterPriseSolutions. well, whatever! good work it is.
    thanks a lot for this solution and think about it: if they say it is fiction, it is probably the truth.

  • Ping "carp" interface?

    Locked
    3
    0 Votes
    3 Posts
    8k Views
    I

    Sorted.  I disabled the default Anywhere->LAN rule at some point along the line.

    Thanks for the heads up hoba.

  • CARP and Web Filters

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    C

    You may be able to block IM if you so desire using Snort, not sure if it detects IM or not, that's the common way to block P2P traffic. IMSpector is available in packages to monitor IM. There isn't a good content filter yet, but there is a commercial one that will be available as a package before too long.

    Problem with routing branch office traffic back through your main office is it wouldn't go through Barracuda the way I showed it above. If you don't need to see the traffic before it gets NAT'ed, you could do this instead:

    LAN – pfsense -- switch -- Barracuda -- modem/router

    where modem/router is whatever device connects you to your ISP, whether a perimeter router, cable or DSL modem, etc.

  • Carp and static IPs

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    No, the CARP IPs and the real interface IPs have to be in the same subnet so you "lose" 1 IP per Member in the cluster per interface, at least it can't be used for failover with CARP. Portforwards for example will of course still work for those real interface IPs, they just won't failover in case one of the nodes dies.

  • CARP + QOS Setup solution

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.