• CARP Config with Outbound Address Pools

    12
    0 Votes
    12 Posts
    4k Views
    D
    Silly question.  Glad no one answered.  Removed that NAT and it's working great! Thanks again for your help! Dino
  • What type of VIP should I use?

    2
    0 Votes
    2 Posts
    829 Views
    V
    IP Alias
  • CARP : MASTER -> BACKUP (more frequent advertisement received)

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Intermittent interface blips leading to brief CARP failovers

    16
    0 Votes
    16 Posts
    3k Views
    DerelictD
    This can be added to the growing list of "Realtek sucks" threads. I have had zero problems with a pair of APUs, however.
  • CARP backup shows master

    2
    0 Votes
    2 Posts
    1k Views
    S
    Answering my own question, the "moved permanently" error was caused by protocol mismatches.  I had HTTP enabled on my primary and HTTPS on the backup. From: https://doc.pfsense.org/index.php/Configuring_pfSense_Hardware_Redundancy_%28CARP%29 Before proceeding, set the same admin user password and webConfigurator protocol (e.g. HTTPS) on each cluster node. This protocol is set at:  System/Advanced/Admin Access/Protocol
  • CARP issues after 2.2.6 upgrade

    4
    0 Votes
    4 Posts
    1k Views
    C
    Not sure if it will help much, but I feel like I had a similar issue that with one of our VIPs and CARP. I was able to resolve the issue by rebooting the backup firewall followed by rebooting the master after the backup is back online. Something with failing over all of the VIPs to both firewalls during the reboots fixed the issue.
  • Carp crash of the backup

    9
    0 Votes
    9 Posts
    3k Views
    G
    I am in a similar situation.  I have a number of firewalls that I have upgraded and need the limiters working.  I really don't want to revert back to 2.1.5
  • XMLRPC Sync failing after password change

    3
    0 Votes
    3 Posts
    2k Views
    T
    Ok so I got to the datacenter and restarted the webconfigurator on the slave which seemed to sort things out for a short period of time. However this morning, the web UI on the slave has failed again and I am getting sync errors again. I will go and do a full restart of the slave today but failing that, what else can I look at or do without having to do a full rebuild?
  • IP interface doesn't respond after switched CARP

    2
    0 Votes
    2 Posts
    871 Views
    DerelictD
    Why would you do that and why do you consider it a problem?
  • 4 LAN Interface Question

    5
    0 Votes
    5 Posts
    1k Views
    DerelictD
    It and will not allow you to detect when one member of the LAGG goes down Well you could look for traps from the switch/stack doing the LACP for LACP issues but it really seems like overkill but it depends on the application. Everything always comes down to the endpoints. Unless you are going to LACP to two NICs in every endpoint to two different switches (You can LACP a group across stack members or sometimes with multi-chassis trunking), when the switch that the endpoints are connected to has a problem, those endpoints lose connectivity. On all of your LANs: X.X.X.1 CARP X.X.X.2 Master interface X.X.X.3 Backup interface All clients pointed to .1 for routing, DNS, etc.
  • CARP for VLANs? Gateway issue.

    3
    0 Votes
    3 Posts
    1k Views
    R
    Yup… [image: j6E1C1b.png]
  • DHCP server handing out DNS of Slave CARP gateway to clients

    2
    0 Votes
    2 Posts
    923 Views
    C
    Manually input DNS as you did, and upgrade to 2.2.6. There were CARP issues with captive portal in 2.2.2 fixed in newer versions.
  • [Hyper-V] Both Nodes in MASTER-State

    3
    0 Votes
    3 Posts
    2k Views
    R
    I know this is an old topic but it has just taken me 4 hours but I had this same problem and have resolved it so if it helps someone else i thought it would be worth it! You have to enable Mac spoofing on the advanced settings of the NICs in Hyper-V & also set a static MAC address on the adapters. simple as that but frustrating if you didn't know & I spent hours searching!
  • Adding 2,000 External IPs to device

    5
    0 Votes
    5 Posts
    2k Views
    luckman212L
    @KenBeanNet: I added the virtual IPs under WAN I'm curious what VIP type you chose for this- are you using "Other" or Proxy ARP?
  • Multi-WAN CARP (1 Static IP) With Gateway Groups Bonded/Failover

    5
    0 Votes
    5 Posts
    2k Views
    dotdashD
    @Atlantisman: Nevermind, i think i figured it out. I just setup an outbound NAT rule that applies to the firewall (self) and NATs it to each of the CARP VIPs (1 rule for each WAN interface) Mind sharing the details of your OB NAT rule? I've tried this in the past with something like WAN, This firewall, ,,,CARP VIP,,NO And my gateway still shows as down… EDIT- Nevermind... It does work, you just have to start and stop apinger after adding the NAT rule.
  • CARP applying VIP MASTER in firewall Backup.

    1
    0 Votes
    1 Posts
    837 Views
    No one has replied
  • TCPDump - Strange VRRP Packets?

    3
    0 Votes
    3 Posts
    3k Views
    awebsterA
    Actually Wireshark undersands CARP just fine, the problem stems from the fact that both VRRP and CARP use IP Protocol number 112. That means you have to TELL Wireshark, tcpdump, etc, that you want to decode IP Protocol as CARP, not VRRP. In wireshark, select the packet, right click and select Decode As…  Then choose CARP in the list. If you are using tcpdump from command line pfSense, add -T carp flag.
  • Carp: often master crash!

    8
    0 Votes
    8 Posts
    2k Views
    C
    Not CARP, pfsync. Disable pfsync under System>HA Sync on both systems and you'll be fine. CARP can still work fine, just won't have states synced.
  • CARP changes from master to backup without reason

    2
    0 Votes
    2 Posts
    884 Views
    awebsterA
    See this thread: https://forum.pfsense.org/index.php?topic=102740.0
  • CARP triggered on the BACKUP only without obvious reason

    13
    0 Votes
    13 Posts
    4k Views
    B
    Great! (& tnx!) I would have done it otherwise, but credits go to you…
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.