• CARP/HA working on WAN without any rules on interface

    2
    0 Votes
    2 Posts
    473 Views
    jimpJ
    Yes, the CARP traffic is allowed automatically. It is far too easy for user rules to break CARP unintentionally, and since it is multicast and thus only found in the local L2 segment, it is not a significant risk to allow the traffic. The automatic CARP rules also exempt CARP traffic from NAT.
  • TCP Problems like unsymetric routing with CARP

    1
    0 Votes
    1 Posts
    460 Views
    No one has replied
  • XMLRPC method errors

    2
    0 Votes
    2 Posts
    421 Views
    J
    Tjis issue is resolved
  • XMLRPC Sync and additional services

    2
    0 Votes
    2 Posts
    533 Views
    V
    You can select what to be synced in System > High Availability Sync. pfBlockerNG and Suricata have options to enable sync of all settings, other packages may also have sync options.
  • CARP with multi-wan [SOLVED]

    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    @chris4916: This computer (Anne) requests IP and get offers from the 2 DHCP servers, with different IP. I'm just wondering how this work  ;) Notice that some devices are receiving same IP from each DHCP server. That is normal. They will both offer since they are both active, but whichever lease the client accepts will be shared between the two systems. @chris4916: Problem was with FW rules for incoming flow on the WAN "group" interface. Having removed these rules and replaced with rules on each WAN1 & WAN2 interface fixed this issue with incoming flow. Great!
  • Failover VPN

    3
    0 Votes
    3 Posts
    819 Views
    C
    –keepalive directive?
  • CARP and transparent-mode

    1
    0 Votes
    1 Posts
    403 Views
    No one has replied
  • High Availability HA authentication failure

    10
    0 Votes
    10 Posts
    3k Views
    DerelictD
    Hmm. I have never done an HA pair with an LDAP-configured authentication backend for the webgui (which will also be xmlrpc sync.) Later versions (including 2.4.X) fixed the long-standing issue of being unable to specify the xmlrpc username and password. It might be worth creating a local user on the primary, which should sync to the secondary, that specifically includes the System - HA node sync permission then specifying that user on the primary in the XMLRPC settings. The secondary is the one that is controlling where things are authenticated. Are you certain the user being specified is present there? Does the XMLRPC sync user and password pass on the secondary in Diagnostics > Authentication? Is there any significant delay? Are the Authentication servers specified identical on the primary and the secondary? Do both nodes pass Diagnostics > Authentication? ![Screen Shot 2017-11-03 at 12.12.06 PM.png](/public/imported_attachments/1/Screen Shot 2017-11-03 at 12.12.06 PM.png) ![Screen Shot 2017-11-03 at 12.12.06 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-11-03 at 12.12.06 PM.png_thumb)
  • CARP on AWS

    3
    0 Votes
    3 Posts
    1k Views
    DerelictD
    You can't do that. Their AWS network will not allow the multicast between nodes, addresses are tied to specific instances, etc.
  • How common are IP Aliases on WAN interfaces?

    5
    0 Votes
    5 Posts
    1k Views
    jimpJ
    @coreybrett: If I ever run into this again and want to use the CARP option, would I need to fill in the Virtual IP Password, VHID Group or Advertising frequency when using a single firewall? Yes, you still need to fill that in even if it's a single unit since they are all required parameters to configure CARP.
  • Problems with HA and CARP

    1
    0 Votes
    1 Posts
    539 Views
    No one has replied
  • CARP + OpenVPN - slave not reachable over VPN

    3
    1 Votes
    3 Posts
    1k Views
    P
    Ahh, after re-read, re-read and re-read i found the solution! With 'The VPN tunnel network' they mean the subnet from the 'remote side' of the VPN tunnel. After change it works :)
  • CARP failover causes default route on master to go missing

    2
    0 Votes
    2 Posts
    1k Views
    P
    Go to Firewall > NAT > Outbound: Make sure you have 'Manual (or Hybrid) Outbound NAT' and create an extra rule: WAN - This Firewall - * - * - * - (WAN CARP IP) - * Also i think you need to reboot so the apinger is refreshed.
  • Virtual IP on Subnets

    3
    0 Votes
    3 Posts
    715 Views
    S
    THX for your help, and thx for the hint with udp, i think this is the problem, since the needed UDP traffic is not forwarded within these subnets. From Cisco i remember to configure ip helper addresses, f.e. UDP: 32410, 32412, 32413, 32414. ip helper-address 192.168.1.187 ip forward-protocol udp 32410 etc… is there something similar on pfsense?
  • Disable CARP

    5
    0 Votes
    5 Posts
    1k Views
    DerelictD
    Do you have any other suggestions? Yes. Upgrade.
  • Client peer-to-peer tunnels between CARP'd pfsenses

    3
    0 Votes
    3 Posts
    725 Views
    T
    Thanks for that! I double checked, and OpenVPN is not selected to sync.
  • CARP Entire Network

    1
    0 Votes
    1 Posts
    449 Views
    No one has replied
  • CARP Network Allocation Problem

    9
    0 Votes
    9 Posts
    1k Views
    T
    @Derelict: It is those who are making you do this who don't understand. Yep. I guess i am not the only one.
  • CARP setup on load balancing network

    1
    0 Votes
    1 Posts
    500 Views
    No one has replied
  • NAT Trouble with CARP

    4
    0 Votes
    4 Posts
    821 Views
    DerelictD
    Hard to say. But if the only difference is the CARP address being used for NAT that is where I would look. ISPs do crazy things. Also, you want to move that static port 500 NAT rule above the rule since, if left like that, it will never be matched. Unrelated to your speed issue. Just sayin'.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.