• 2x pfSense /WAN/LAN/VLAN failover..

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ
    Yes, if you have CARP setup properly, if any one interface fails, the box will cut over to the secondary.
  • Alias IP Interface -HELLLLLLLLPPPPPPPPPPP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • CARP, 1:1 NAT, multiple WAN subnets

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    D
    Also, found a gotcha with Virtual IP sync that's worth noting.  The sync doesn't work properly – the virtual IP appears on the slave, but in the CARP Status page it lacks a carp interface.  It won't function until you edit the virtual IP assignment (on the slave) and click Save without making any changes -- after that it functions.
  • Multiple WAN IPs with CARP?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    You can do multiple CARP VIPs on the WAN with 1.2.3, there isn't a problem with that. Not sure what you might have been seeing that suggested you need 2.0, perhaps you were looking for IP aliases and not CARP VIPs. If you want multiple IPs on a failover cluster, you'd need CARP VIPs anyhow.
  • pfsense 2 rc1 3 boxes active active senario inbound

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    pfSense doesn't yet support active/active even in 2.0.
  • CARP VIP at single pfSense (1.2.3) fails to BACKUP constantly

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    T
    Whoa, I knew it's not problem of pfSense. My co-worker had done mistake in ESX advanced configuration - the 'Net.ReversePathFwdCheckPromisc' parameter must have the value of '1'.
  • 0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0 Votes
    2 Posts
    3k Views
    E
    This is mostly a routing way of doing. You can do through gateway failover or through ospf routing protocol. So each of you should see the others firewall as a provider/gateway
  • Routing two public IP subnets

    Locked
    3
    0 Votes
    3 Posts
    5k Views
    L
    Note: I believe this should be moved to Routing/MultiWan I wasn't able to make this work. I made a better diagram: [image: uctkd.png] Note the "Desired Configuration" on the image. I can see connections coming in from the internet on the 30.10.0.2 IP just fine. The Cisco still routes this connection because the IP is on its subnet and it is directly accessible. But replies will go out through the pfSense because that's the default gateway of the client. How can I make the pfSense route connections from 30.10.0.x/26 back to the Cisco? I tried using policy routing with a rule of Source 30.10.0.x/26 -> gateway IP: 192.168.100.1 (dedicated VLAN interface to Cisco) - but, initially, pfSense just dropped the packet and didn't even let it exit the firewall even with a 'pass all' rule. I had my head scratching for a few hours until I tried changing 'keep state' to 'none' on the rule, and I could now see it leave the DMZ interface, but it now gets stuck trying to exit the VLAN interface. The 'none' trick didn't work here, no matter what I tried (pass all, etc), the firewall didn't let the packet go out. Here's the packet getting stuck on its way out: [image: Iyjgw.png] My understanding is that the following needs to happen: [image: WfKx0.png] I looked through the pfSense book several times but couldn't find a similar scenario. Any ideas? Is this even possible or is there a better way? (I'm still not sure whether the Cisco will allow these packets to go out, they probably wouldn't have any state associated and they would come in on a different interface - the VLAN.)
  • Multiple IPs on WAN

    Locked
    4
    0 Votes
    4 Posts
    4k Views
    M
    I have the exact same problem as the thread starter. As a workaround it works like gullio said, but only for a few hours. The WAN interface is the via-rhine nic of my Via Epia-M. This nic is connected to a Cisco 1700 router from my ISP. Is it ARP related? Would it help to use another nic for WAN?
  • CARP XMLRPC updates wrong interface rules

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    jimpJ
    CARP systems must have an identical set of interfaces in the exact same order. That has always been the case.
  • [Solved] Clear All VIP in one clic/command

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    G
    Thank you jimp it work :)
  • 0 Votes
    2 Posts
    2k Views
    S
    Ah, I think I have a better understanding of what is really happening here. The only IP addresses that are showing up are ones that are for a Microsoft Load Balanced IP with two members.  I guessing what is getting blocked are the packets that are viewed as out of order by the non-active based on the fact that the primary firewall has already gotten past the part of the connection setup that a given packet type would be expected. So sorry for the false-alarm.  I just noticed when I went back through the logs that it was only happening on the LB IPs. The more I'm exposed to this implementation of load balancing the less I like it–unfortunately, we are committed to this at least for the near future.
  • Pls guide me (Solved)

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    V
    Thx Jimp for your reply. Your method solve my problem. Cheers!  :D
  • Should I ask for routed IP or forwarded IP from my provider?

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ
    In that case you'd use the whole /27 on a "DMZ" segment (And you can still do CARP there if you want if you need redundant routers) which doesn't get NAT, and then have a "LAN" segment with private IPs that does get NAT. You can filter between the interfaces that way. If you want to split the /27 on the inside into multiple interfaces you'd have to setup one interface with the /27 on it and then bridge the second internal interface to that one. I try to avoid bridging if at all possible, though.
  • Newbie - Packages and Multiple Sites Question

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • NAT1:1 Multiple external IPs pointing to same internal IP

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    R
    Hi Jim, Thanks for the clarification. Makes perfect sense. Melvin
  • Carp failover, multiple routers, how to setup gateways

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H
    If anyone cares, we setup OSPF and removed the GW's
  • Two CARP nodes. Split brains?

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    L
    Ordered.. thanks
  • MOVED: Carp VIP Failover

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.