• Unplugging WAN only failover WAN and not LAN

    1
    0 Votes
    1 Posts
    652 Views
    No one has replied
  • 'Pinning' WAN interface to LAN carp

    3
    0 Votes
    3 Posts
    2k Views
    D
    I've put the scripts here https://github.com/deasmi/pf_interface_pin At some point I might try to make this into a package with a UI if anyone is interested. Please note you need to re-install after an upgrade.
  • Primary Pfsense Hangs/Freeze After 40-48 hours

    Locked
    15
    0 Votes
    15 Posts
    5k Views
    vallumV
    Mine is also running smoothly , no crash after upgrade . however Squidguard is not working now and makes the GUI slow . I have removed it for the time being . Steve Sir please mark this as solved . Thanks
  • Troubles getting CARP working with ESXi 5.5

    5
    0 Votes
    5 Posts
    2k Views
    C
    Yeah that should apply to all vswitches on the host. Is it all the CARP VIPs on one interface, or just one on that interface that has others that work fine?
  • 0 Votes
    2 Posts
    2k Views
    V
    Yes, this is normal if the firewall is the VPN server and you sync all settings from master to backup. This way the backup box has equal VPN setup and the same tunnel network exists on both, master and backup. So if the backup replies to a request from a VPN IP it sends the packet to its own VPN interface which is down though. To resolve this, you can use outbound NAT. Add an outbound NAT rule for the LAN interface, which translates IPs of packets coming from VPN tunnel network and have one of the LAN addresses of the boxes as destination (you may use an alias here or add a second rule for the other box) to its LAN address. So if you connect to the backup box over VPN, the packets get the LAN address of master and replies from backup box are sent back to the masters LAN IP and the master will route the packets to the VPN client.
  • Carp State takeover with cisco layer3 stacked switches

    1
    0 Votes
    1 Posts
    746 Views
    No one has replied
  • CARP using VPN IPsec

    9
    0 Votes
    9 Posts
    3k Views
    dotdashD
    I leave it enabled at defaults. It shouldn't need DPD to fail to the second node- the secondary should take over the existing IPSec connections.
  • Pfi_table_update: cannot set xx new ip addresses into table self: 22

    5
    0 Votes
    5 Posts
    1k Views
    C
    This issue was fixed in 2.2.3.
  • CARP + Stacked IP Aliases causing CARP conflicts on 2.2.2-RELEASE

    2
    0 Votes
    2 Posts
    742 Views
    V
    One more thing I've noticed - the behaviour seems to be the same when adding new CARP VIPs. When you click save to add a VIP, it is immediately synced and applied to the secondary node, and only gets applied on the primary after clicking 'apply'. It's not so much of a problem in that case of course, because it's a new VIP, and doesn't matter if it's MASTER on the secondary initially.
  • CARP Cluster - LACP - VLAN

    2
    0 Votes
    2 Posts
    1k Views
    I
    Ok,…Interface Order was different on the two nodes, so the Virtual IP Synchronization was incorrect, and so it didn't work at all,...same order on both nodes, everything fine.
  • Pfsync not syncing states to backup (2.2.2)

    17
    0 Votes
    17 Posts
    6k Views
    P
    Just Confirmation. I did the work around and the LAGG setup is working as intended.
  • 0 Votes
    3 Posts
    1k Views
    jimpJ
    There's already a patch for this in 2.2.3.
  • 2.2.2 Crash after enabling Syncronize States option

    5
    0 Votes
    5 Posts
    1k Views
    A
    I have had a similar issue, seemingly out of nowhere, with my master that was running 2.2 and my slave at 2.2.2 for a couple weeks (until Sunday afternoon).  Master affected with very slow performance, both throughput and it's own web interface.  I do not use any limiters, but I do use BGP.  I will also downgrade to 2.1.5.
  • PfSense 2.2.2 CARP-Backup becomes Master

    3
    0 Votes
    3 Posts
    2k Views
    M
    Figured out my issue. port security was enabled and set to restrict on the switchport that the LAN interfaces were connected to and I could see in the switch logs that it was getting tripped. Disabled port security now all is well.
  • High network latency between firewall and Dell clients

    2
    0 Votes
    2 Posts
    951 Views
    R
    Hello, Did you find something ? I have a similar configuration and have same troubles. It's quite temporary on my side but sometimes the ping between two systems in two different vlans can go from 0.200ms to 5/15 ms without any reason. Thank you
  • Using port other than 443 for webconfig

    2
    0 Votes
    2 Posts
    682 Views
    DerelictD
    Change the port on both primary and secondary.  That setting isn't synced.
  • What CARP interface name I must use for OpenBGP "Depend on" parameter? v2.2

    22
    0 Votes
    22 Posts
    5k Views
    G
    thank you jimp I already switch to new 2.2.2 with this patch I made a short test but when I switch back to master, bgp remains in ACTIVE for 2 sessions from a total of 4 I wil make more tests on this weekend P.S: attached my old 2.0.2 uptime  8) ![pfsense master.PNG](/public/imported_attachments/1/pfsense master.PNG) ![pfsense master.PNG_thumb](/public/imported_attachments/1/pfsense master.PNG_thumb)
  • Crash / BUG with CARP

    2
    0 Votes
    2 Posts
    868 Views
    jimpJ
    We've seen that before but not lately. What version of pfSense is on both units? And do you have Captive Portal + voucher sync enabled on that cluster?
  • Unable to delete VIP

    7
    0 Votes
    7 Posts
    2k Views
    S
    @jme: That is what i did too. @Jimp: i didn't verified, i'll check this next time and give you the log related to this action
  • Failover with 2 Pfsese boxex

    8
    0 Votes
    8 Posts
    2k Views
    KOMK
    Sorry, you've hit the limit of my knowledge on this subject.  Yes, I believe that the shared WAN IP is a Virtual IP.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.