Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    1. Home
    2. pfSense® Software
    3. HA/CARP/VIPs
    Log in to post
    • Newest to Oldest
    • Oldest to Newest
    • Most Posts
    • Most Votes
    • Most Views
    • J

      LAN only HA + OpenVPN
      • jasontaubman

      1
      0
      Votes
      1
      Posts
      929
      Views

      No one has replied

    • junicast

      Upgrade to 2.6 redeploy ZFS layout CARP
      • junicast

      4
      0
      Votes
      4
      Posts
      1714
      Views

      jimp

      The maintenance mode switch is in the config and persists across reboots.

    • P

      inconsistent icmp packets with VIP
      • parsecadmin

      1
      0
      Votes
      1
      Posts
      956
      Views

      No one has replied

    • C

      After CARP failover packets go out the wrong WAN
      • chrullrich

      8
      0
      Votes
      8
      Posts
      2155
      Views

      C

      @chrullrich I replaced the pfSense 2.6 "local router/firewall"s in my test setup with OPNsense 22.1 (this is FreeBSD 13.0 instead of pfSense 2.6's 12.3) to get a second opinion. The behavior is the same: As soon as the CARP failover happens, everything sent towards the "Internet" goes out the default route with the NATed source address appropriate for the policy route.

      When I tried it the first time today I thought I saw ping (and only ping) work correctly, but now I cannot reproduce it. I probably just saw what I wanted to see.

    • P

      CARP og IP Alias on additional IPs routed to us by the data center
      • professor

      4
      0
      Votes
      4
      Posts
      1361
      Views

      P

      @derelict
      Yeah, same conclusion i had.

      @viragomann
      Yup.

    • luckman212

      No XMLRPC sync for rrd (Monitoring) settings, packages, Dashboard...
      • luckman212

      1
      0
      Votes
      1
      Posts
      972
      Views

      No one has replied

    • B

      Crestron NVX nor working with CARP interface
      • bolvar

      1
      0
      Votes
      1
      Posts
      866
      Views

      No one has replied

    • O

      HA proxy issue to resolve local ip
      • overlaps

      3
      0
      Votes
      3
      Posts
      1383
      Views

      O

      @viragomann

      Issue resolved with hostname override and haproxy listnening on LAN interface

      Thx

    • S

      CARP IPv6 with routed network
      • skid9000

      2
      0
      Votes
      2
      Posts
      1687
      Views

      S

      @skid9000 Perhaps some screenshots of the setup? Can you get it working without the VLANs and add those in after? I've not had occasion to set HA up with VLANs but have done so with aliases for other subnets on LAN.

    • U

      Download-speed drops to 0 when pfSense statesync is enabled
      • unico-dm

      5
      0
      Votes
      5
      Posts
      1654
      Views

      U

      Just for your info. We've now seen the issue on multiple installations (even different hardware and pfsense versions) and could solve it on every single system by moving the sync-vlan to a dedicated physical interface.

    • P

      Best way to access failover HA node from another subnet?
      • planedrop

      1
      0
      Votes
      1
      Posts
      909
      Views

      No one has replied

    • C

      ESX Physical NIC Failure Fails to Trigger Failover
      • carlsond

      1
      0
      Votes
      1
      Posts
      888
      Views

      No one has replied

    • M

      Issue with XMLRPC after adding a NAT rule
      • mattiav

      7
      0
      Votes
      7
      Posts
      1859
      Views

      M

      @viragomann
      i think it's that
      https://forum.netgate.com/topic/150505/xmlrpc-restore_config_section-error

      because my rule to NAT with CARP ip make the backup node not able to reach the gateway
      so as it explain on that like you sent

      Filter reload sees the down gateway and resets states, terminating the connection currently used for XMLRPC.

      it make sense
      Thanks you very much, i think you resolve my issue :)

    • P

      How Does "This Firewall (Self)" Apply in CARP Setups?
      • planedrop

      17
      0
      Votes
      17
      Posts
      2031
      Views

      P

      @kayavila OK this is great info, thank you! I read your entire write up you linked to as well but I'm still trying to wrap my brain around it. Think I've got it figured out but wanted to pose an example.

      This particular one will be between different VLAN/subnets rather than with WAN as I personally don't ever allow those connections via the WAN.

      So in theory if you had VLAN1 and VLAN2 setup, and there was an any-any rule below a block "This Firewall" rule on VLAN1, and some device on VLAN1 tried to contact the LAN interface of VLAN2, due to state syncing this would be let through? Since the first node would see the connection to the VLAN2 IP and see that it's not in it's block list but matches the any-any rule, and then the state would sync to the secondary which wouldn't assess it's rules?

      If that is the case, I would imagine not having a rule on the primary node that allows access to any would solve the issue, but since some people do use an any rule for internet access it could pose a problem (though best practice is of course to use an alias for RFC1918 and explicitly allow the inverse of that).

    • A

      VIP & NAT
      vip nat mail • • Alek

      3
      0
      Votes
      3
      Posts
      1413
      Views

      A

      @viragomann
      Thanks !
      Went with the port forward + outbound option, NAT is working finally.

    • S

      HA Setup
      • StarsAndBars

      2
      0
      Votes
      2
      Posts
      1297
      Views

      Derelict

      @starsandbars What questions do you have after reading this?

      https://docs.netgate.com/pfsense/en/latest/highavailability/index.html

    • M

      HA Interface OPT do not match on Secondary
      • MrFrenchFry

      3
      0
      Votes
      3
      Posts
      1444
      Views

      V

      @mrfrenchfry
      You can export the interface config from the secondary node:
      Diagnostics > Backup & Restore > Backup & Restore
      At Backup area select "Interfaces".

      Download the file. Then load it into a text editor and order the interfaces accordingly to the primary.

      Save the file and re-import it into the secondary.

    • SipriusPT

      Question about switchs to be used between WAN CARP and ISP's
      • SipriusPT

      17
      0
      Votes
      17
      Posts
      2865
      Views

      SipriusPT

      More photos:

      20220201_181442.jpg
      20220131_180718.jpg
      20220201_181457.jpg
      20220119_165632.jpg
      20210929_162052.jpg 20201214_141056_HDR.jpg

    • U

      Static DHCP lease Gateway/DNS problem
      • Urbaman75

      2
      0
      Votes
      2
      Posts
      1280
      Views

      U

      Sorry, it probably was only a temporary problem while the network reconfigured to the static IP.
      It now seems to work properly.

    • P

      DNS queries from HA backup?
      • pyrodex

      1
      0
      Votes
      1
      Posts
      878
      Views

      No one has replied

    • P

      Mac address of Carp/vip
      • Pema

      1
      0
      Votes
      1
      Posts
      857
      Views

      No one has replied

    • I

      Stop specific service when CARP in Maintenance.
      • itNGO

      1
      0
      Votes
      1
      Posts
      845
      Views

      No one has replied

    • K

      HAproxy issue with Transparent ClientIP
      • killmasta93

      1
      0
      Votes
      1
      Posts
      840
      Views

      No one has replied

    • S

      Couple question: Force Master and Why CARP VIP on WAN?
      • skorpio

      4
      0
      Votes
      4
      Posts
      1173
      Views

      S

      @skorpio The CARP alias skew is set in each alias: https://docs.netgate.com/pfsense/en/latest/recipes/high-availability.html#configuring-the-carp-virtual-ips

      "A primary node is typically set to 0 or 1, secondary nodes will be 100 or higher. This adjustment is handled automatically by XML-RPC synchronization."

    • C

      Single WAN PPPOE Carp HA OpenVPN - remote LAN issue
      • crl

      10
      0
      Votes
      10
      Posts
      2078
      Views

      MrPete

      @crl was this resolved? I'm having some issues myself.

      Hoping you found your solution. :)

    • P

      Change interface MAC via commandline?
      • pyrodex

      1
      0
      Votes
      1
      Posts
      797
      Views

      No one has replied

    • U

      HA behind ISP modem/router
      • Urbaman75

      9
      0
      Votes
      9
      Posts
      1674
      Views

      U

      @viragomann switching to CARP VIP in the OpenVPN config solved the issue, now I'm getting to the LAN. Thank you very much for pointing me on the right direction!

    • U

      pfSense HA on Proxmox, DHCP strangeness
      • Urbaman75

      2
      0
      Votes
      2
      Posts
      1233
      Views

      U

      Ok, found out the problem, maybe.

      there was a space in the Gateway IP in VAN50 dhcp settings also checked "Time from UTC to Local"

      With both changes, now DHCP works flawlessly.

      Thank you.

    • C

      Rule problem in a cluster
      • cisco0613

      6
      0
      Votes
      6
      Posts
      1288
      Views

      C

      @steveits
      Hello,
      When I add the rule on the master, it is duplicated on the second pfsense. The master pfsense remains master in "status/CARP".
      The second pfsense is in "Backup".
      Yes the problem is not temporary, I have a total loss to the internet.
      The master's wan interfaces are up and communicating with their gateway. But unable to access the internet.
      The interfaces are in green on the dashboard.

      Regards.

    • A

      PfSense HAProxy adds amp; on http check URL
      • anandpeculiar

      2
      0
      Votes
      2
      Posts
      1298
      Views

      A

      Is any one knows why the URL is getting changed by adding amp; every time while saving the configuration? this is kind of miss-behavior

    • K

      XMLRPC Sync no longer performed after update to 2.5.2 (not even attempted) - but actually it broke earlier
      • Klaws

      4
      1
      Votes
      4
      Posts
      1403
      Views

      SipriusPT

      @klaws Mail Report just let you know in time any issues that could occur.

      At least for me it helps a lot dealing with pfsense clusters.

      Examples:

      like when some CARP state changes states (master or backup),

      17:51:09 HA cluster member "(10.0.13.1@ixl3.13): (IXL3_VLAN13_IT_ADMINS)" has resumed CARP state "BACKUP" for vhid 12

      when WANs went offline or online in gateway groups:

      11:07:07 MONITOR: WAN_ROUTERA_WAN2_GW is available now, adding to routing group GW_GROUP x.x.x.225|172.16.2.2|WAN_ROUTERA_WAN2_GW|34.651ms|87.308ms|18%|online|loss

      when services stop working and watchdog service detect and handle the situation,

      9:26:00 Service Watchdog detected service openvpn stopped. Restarting openvpn (OpenVPN server: Internal Devices)

      when rules cannot load:

      15:42:40 There were error(s) loading the rules: /tmp/rules.debug:51: cannot load "/var/db/aliastables/pfB_NAmerica_v6.txt": Invalid argument - The line in question reads [51]: table <pfB_NAmerica_v6> persist file "/var/db/aliastables/pfB_NAmerica_v6.txt"

      when XMLRPC communication fails:

      17:29:59 A communications error occurred while attempting to call XMLRPC method restore_config_section: 16:43:28 Exception calling XMLRPC method restore_config_section # Impossible to encode value '' from type 'NULL'. No analogous type in XML_RPC.
    • N

      Strange behaviour on CARP enabled devices
      • nick.loenders

      6
      0
      Votes
      6
      Posts
      1235
      Views

      N

      @steveits It got solved. Rebooting the firewall did not help, resetting the states neither, but disabling the WAN interface and enabling it again DID help.
      And all is looking good again now

    • T

      Configuring a /29 subnet
      • Turfrider

      3
      0
      Votes
      3
      Posts
      1231
      Views

      T

      049f21fe-c7d0-4640-8834-d5f7af093f0a-image.png

    • MrPete

      GW Group and/or CARP sync anomaly. Bug or ???
      • MrPete

      5
      0
      Votes
      5
      Posts
      1145
      Views

      MrPete

      @viragomann

      The one thing I notice, examining config.xml: the internal ID for a gateway group is pretty unique.

      No idea how that is supposed to sync or not...

      I'm going to do more experiments tomorrow...

    • MrPete

      PPPoE is no longer always dynamic
      • MrPete

      6
      0
      Votes
      6
      Posts
      1936
      Views

      MrPete

      @mrpete @viragomann
      I've got it working close to 100% now :)

    • MrPete

      Single WAN, Secondary CARP Internet access: How to automate this simple solution?
      • MrPete

      10
      0
      Votes
      10
      Posts
      991
      Views

      MrPete

      @mrpete @netblues @Cool_Corona

      I've updated the OP with results of my first set of experiments.

      When I have a chance, I'll redo a full install on secondary CARP and see how that goes.

    • MrPete

      [Solved] How should endpoints handle MAC changes during HA failover?
      • MrPete

      4
      0
      Votes
      4
      Posts
      705
      Views

      MrPete

      @netblues
      That page does not say that... But it does link to the a page hinting at this:
      https://docs.netgate.com/pfsense/en/latest/highavailability/index.html#switch-layer-2-concerns

      While "CARP VIPs each have their own unique MAC address derived from their VHID" "At minimum, the switch must... Allow the CARP VIP MAC address to move between ports."

      Thanks! I think I am beginning to understand this... 😏

    • MrPete

      2.6 upgrade: XMLRPC fail. Missing file on secondary side?
      • MrPete

      3
      0
      Votes
      3
      Posts
      698
      Views

      MrPete

      @netblues duuuh. Thanks. That s embarrassing. I completely missed that pkg on my list to be manually installed.

      Thanks! 🤠

    • P

      Primary neither master or backup on new CARP VIP
      • postilion

      2
      0
      Votes
      2
      Posts
      708
      Views

      P

      Never mind, a reboot solved it.
      -nic

    • N

      Multiple VLANs in HA config
      vlan high availabili • • nick.loenders

      10
      0
      Votes
      10
      Posts
      883
      Views

      N

      @viragomann said in Multiple VLANs in HA config:

      So ensure the VLAN is also properly configured on the switch.

      omg , so stupid :)

      Thx it all works now