• CARP/HA, SYNC and XMLRPC SYNC explained

    Pinned
    3
    1 Votes
    3 Posts
    14k Views
    M
    Thanks for the excellent reply. I've retested as you suggested by entering persistent maintenance and there is no packet loss that way (perst maint, reboot, leave persist maint). I am still having a small problem with freeradius xmlrpc sync between the two but I posted that in a separate topic (see https://forum.pfsense.org/index.php?topic=135864.0). Regards, Matt
  • HA sync overwrites certificates on backup router even if unchecked

    5
    1
    0 Votes
    5 Posts
    234 Views
    SteveITSS
    @Derelict I realized today that although the LE cert syncs to the secondary just fine, it doesn't restart nginx which continues using the expired cert. On the primary router the Post-Renew Actions is run to do that. That doesn't exist on the secondary because the cert doesn't exist on the secondary. Is there a proper solution other than restarting the secondary webGUI via cron or something?
  • Don't access GUI, SSH etc using CARP VIP?

    3
    0 Votes
    3 Posts
    72 Views
    luckman212L
    Guess I never really thought about the possibility of a failover event occurring in the middle of making configuration changes. But I guess that's as likely to happen as anything else. I'll now consider myself lucky that it never did. I've gone and updated all of my bookmarks and tooling to use the explicit primary and secondary IPs. Thanks again.
  • Possible bug + fix for HAproxy issue during upgrade to 2.8.1

    2
    1 Votes
    2 Posts
    136 Views
    D
    @ndemou I have what may be a related issue, but I'm hesitant try try this patch as I'm on pfSense plus 26.03.1. Although my certs are valid, when I try to setup a frontend in HAProxy,I don't get the cert dropdown, I just get an empty text box. I tried entering my cert name but then it throws a parsing error when I try to save it. [ALERT] (87716) : config : parsing [/var/etc/haproxy_test/haproxy.cfg:15] : 'bind 0.0.0.0:443' in section 'frontend': unknown keyword 'mynet.com'. [ALERT] (87716) : config : Error(s) found in configuration file : /var/etc/haproxy_test/haproxy.cfg [ALERT] (87716) : config : Fatal errors found in configuration. In the example above, unknown keyword mynet.com is my certificate name, which I entered into the textbox since there was no dropdown list.
  • OpenVPN interfering with CARP Failover

    26
    1 Votes
    26 Posts
    5k Views
    stephenw10S
    The redmine hasn't been addressed directly. As far as I know it has not been fixed but it's possible something has fixed it indirectly. If you have a good test case for it it would be good to know.
  • hardware needs to move to a cluster

    10
    0 Votes
    10 Posts
    264 Views
    SteveITSS
    @sgw You can run HA with pfSense CE.
  • HA with MULTIWAN Outbound NAT for CARP and VLANs

    3
    0 Votes
    3 Posts
    109 Views
    J
    @netblues Right. Thank you very much.
  • High Availability and TailScale

    1
    0 Votes
    1 Posts
    76 Views
    No one has replied
  • How to route to backup lan interface

    carp routing
    1
    0 Votes
    1 Posts
    95 Views
    No one has replied
  • 0 Votes
    6 Posts
    396 Views
    SteveITSS
    @Chebec Have a read through: https://docs.netgate.com/pfsense/en/latest/development/patches/custom.html and the rest of the topic. If you add a patch, it should detect whether it can be Applied and will or will not show the Apply button, as I recall. There is also a Debug button to test. Normally a patch can be reverted via that button, yes, unless the target file is later changed. (after updating pfSense you would not want to revert a patch and reintroduce a bug, just delete the custom patch) Note there's a later patch ID in that redmine: 8544b85f8c32d0f180c09a4d0986ac819919bd2b As long as patches are from Netgate developers I would have no issue installing them. For random patches in the forum I'd be a bit more cautious. In either case you can see the code being changed, in the patch details. Edit: Marcos M in the redmine is a Negate dev.
  • Virtual IP questio : traffic to a VIP doesnt seem to route

    4
    0 Votes
    4 Posts
    213 Views
    SteveITSS
    @boumacor I'm not a huge fan of floating rules if they can be set as regular rules, since the, er, rules change for floating. Just to maintain clarity. However if the rule triggers and a state is open you're through pf. Does the pfSense routing table show a route for the 192.168.1.0/24 subnet? I would still be suspicious of the switch ignoring traffic outside its own subnet unless you're sure it will allow it. You could set an IP on some other device and ping it, to check the connection through pfSense.
  • PFSense HA & OSPF Question

    4
    0 Votes
    4 Posts
    223 Views
    DerelictD
    @stowemotion59 It is an entirely new OSPF session requiring a complete reconvergence so it should be fine.
  • Nat issue with carp and 25.11.1

    1
    0 Votes
    1 Posts
    154 Views
    No one has replied
  • How to deal with VPN interfaces befor start XMLPRC Sync?

    1
    0 Votes
    1 Posts
    127 Views
    No one has replied
  • Virtual IP subnet IPs not expanding into NAT

    5
    0 Votes
    5 Posts
    356 Views
    patient0P
    @Barnzey90 do you have an account on https://redmine.pfsense.org/ to report the issue?
  • Query on HA and VIP

    4
    0 Votes
    4 Posts
    356 Views
    SteveITSS
    @netblues you can't really have carp failover without 3 ip's in the same subnet Depends, which is why I asked about it. We’ve set it up on Comcast/Xfinity using one shared static public IP and set the WAN IP on both routers in the default 10.1.10.x range. That works well. Docs cover only one IP but there’s no connectivity until failover: https://docs.netgate.com/pfsense/en/latest/highavailability/index.html#ip-address-requirements-for-carp If WAN2 is really only DHCP though then I don’t think there can be a shared IP.
  • Question about OpenVPN running on HA cluster on the CARP WAN on port 443

    2
    0 Votes
    2 Posts
    233 Views
    T
    @AlexMercer Move the webgui to 4443. Disable webConfigurator anti-lockout rule. Disable webConfigurator redirect rule. Add a specific rule for the internal interface (any LANish is good, preferrably the one which is your dedicated management LAN) to port 4443. This hardening and consistency ensures whatever goes wrong, any public WAN/443 combination won't ever reveal the webgui. Always remove excess rules- if you don't know why it is there, get rid of it.
  • Dynamic DNS + XMLRPC SYNC

    3
    0 Votes
    3 Posts
    324 Views
    luckman212L
    What is the recommended method of ensuring high availability of a service running on or behind an HA cluster then? Require running the DynDNS client on a separate system (not the firewall itself?)
  • No XMLRPC sync for rrd (Monitoring) settings, packages, Dashboard...

    2
    0 Votes
    2 Posts
    1k Views
    luckman212L
    Been about 4 years... anyone have any thoughts on this? Syncing packages seems like it should be table stakes at least.
  • On CARP switchover to secondary, *some* replicated states disappear

    1
    0 Votes
    1 Posts
    176 Views
    No one has replied
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.