• CARP and WAN

    Locked
    11
    0 Votes
    11 Posts
    5k Views
    T

    Yeah, I got ya.

  • Unable to failover to backup pfsense

    Locked
    6
    0 Votes
    6 Posts
    5k Views
    E

    its me again. problem solved. i just made the host that used to be enslaved the master. exMaster is now the gimp. and gimp works fine. gimp is now encaged. and whenever master needs something from gimp, gimp may fulfill his duties. i think it was the builtin nic from some dellMachine.

    pfSense is a good product. i especially like the fact, that it is not a blackbox like some other enterPriseSolutions. well, whatever! good work it is.
    thanks a lot for this solution and think about it: if they say it is fiction, it is probably the truth.

  • Ping "carp" interface?

    Locked
    3
    0 Votes
    3 Posts
    8k Views
    I

    Sorted.  I disabled the default Anywhere->LAN rule at some point along the line.

    Thanks for the heads up hoba.

  • CARP and Web Filters

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    C

    You may be able to block IM if you so desire using Snort, not sure if it detects IM or not, that's the common way to block P2P traffic. IMSpector is available in packages to monitor IM. There isn't a good content filter yet, but there is a commercial one that will be available as a package before too long.

    Problem with routing branch office traffic back through your main office is it wouldn't go through Barracuda the way I showed it above. If you don't need to see the traffic before it gets NAT'ed, you could do this instead:

    LAN – pfsense -- switch -- Barracuda -- modem/router

    where modem/router is whatever device connects you to your ISP, whether a perimeter router, cable or DSL modem, etc.

  • Carp and static IPs

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    No, the CARP IPs and the real interface IPs have to be in the same subnet so you "lose" 1 IP per Member in the cluster per interface, at least it can't be used for failover with CARP. Portforwards for example will of course still work for those real interface IPs, they just won't failover in case one of the nodes dies.

  • CARP + QOS Setup solution

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Problem with CARP and inbound load balancing

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    S

    @dbuckle:

    CARP Status still shows a lot of (about 30-40) pfSync nodes which I'm worried about.

    This is normal.

    Also see http://wiki.pfsense.com/wikka.php?wakka=InBoundLoadBalancingTroubleShooting

  • VIP trouble I think.

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    K

    I am using an anonymous proxy to test from outside. I didn't reinstall, updated a while back to the new version (didn't cause a problem), and I don't believe I rebuilt the config. Everyone keeps telling my my config should work when I had this problem last time but I am not sure why it just started working back then. I switched NICs and had all my info in, no luck.

  • CARP spontaneous failover

    Locked
    11
    0 Votes
    11 Posts
    8k Views
    L

    It's possible that there is a soekris issue.  This pair are in production, but I have another 4801 at home running m0n0wall that I'll upgrade to pfSense 1.0.1 and test with iPerf to see if I can generate similar issues with polling and non.  Then I'll upgrade to the 1.2 snapshot and see if the upgrade of the base OS from 6.1 to 6.2 fixes any polling/performance issues.

    I'm running the latest bios that I know of, as these boxes were only purchased about 2 months ago.

    Thanks for your attention in this matter.  I'll report back if I can find anything useful.

  • Replaced my failover and…

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    I would go for a reinstall. Once the basic network is setup you can shoot over most of the settings with sync from the master.

    …oh, and thanks for loving pfSense  :D

  • Is this possible

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    Should work okay.  Start a bounty for the documentation request.

  • Something unbelievable

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    A

    some this  issue is only on your lan yes i have seen a similar issue a time ago now i just dont sync the lan with a vip i keep it out of the loop so agreed there must be a bug introduced somewhere. i think it only happened when the wan was multiwan though. can't be sure and dont have time to test ift for you.

    could you put the lan on a vlan and not use it and put the subnet in question on an opt and see if it goes away

    maybe try adding a ticket for it or wait a bit to see if someone can confirm it

  • Slightly Confused–> Outbound FTP via VIP

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    S

    I'm currently running 3-15-2007, but I will upgrade to the latest after I test a little bit.

    Thanks!
    Scott

  • CARP and Squid?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    Doesn't matter either way.  SQUID is a userland proxy and as soon as you fail over to the second host no matter what the application state is lost and any states will be lost.

    So basically even if it did use the correct WAN/CARP IP the situation would not change on fail over.

  • 1:1 NAT and Multiple Public IPs

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    M

    I had same problem, to map multiple WAN IP's to internal LAN/DMZ IPs. Example: 212.xx.xx.xx => 10.xx.xx.xx

    First I make Virtual IPs for every of my external IP (212.xx.xx.xx.) but it was not possible to use NAT 1:1 settings!
    You have to use "NAT Port Forward" insted. In the "External address" drop down you will see all your Virtual IPs and you can easy map them to your internal IPs and choose desired ports/ranges.

  • Problem with pfSync

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Virtual IP problem…

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    C

    Finally I did what I want… :)

    1 - I've created a vip (proxyarp).
    2 - I've added a 1:1 nat for my LAN ip for vip
    3 - I've added a port-forward for My LAN ip for ports 1-65500

    Now it work properly...

    But I couldn't solve high traffic on carp vips. ???

  • Carp sync issue with load balancing

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    R

    Looks like some people have read my post, but no response, also the ticket has not been touched….

    Here is the link to the ticket http://cvstrac.pfsense.com/tktview?tn=1262.  Will someone acknowledge this?

  • CARP - IPSEC - failover - listen (500) in racoon.conf

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    H

    Hello Scott,

    maybe later. It doesn't greatly matter.

    Greetings from Germany and special thanks for your help.

    Heiko

  • Setting up CARP cluster for LAN and WAN VIPs at the same time

    Locked
    15
    0 Votes
    15 Posts
    7k Views
    H

    danke, jetzt habe ich es
    gruß
    heiko

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.