• Want redundant LAN connection, whats the best way to do it

    Locked
    8
    0 Votes
    8 Posts
    7k Views
    jimpJ

    Since your CPE is already a SPOF, you might consider adding a cheap unmanaged switch behind each CPE, then you could have each CPE plugged into each switch directly, instead of having them plugged into only sw1 or sw2. That way if sw1 dies, you still have both ISP1 and ISP2 active.

    If a cheap unmanaged switch dies, you only lose either ISP1 or ISP2. Much more desirable scenario than losing both a managed switch and access to one ISP in the process.

  • Single VIP inappropriately failing over

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    That is correct; If one fails they all should fail.

    If the settings are right, the next thing to look at would be switches and cabling. It's possible that there is an issue there. I talked to someone last week who was getting odd master/slave flips and it turned out they were using the little switch on the back of their cable/dsl modem and it was not up to the task. Merely sticking a different switch in that role fixed all of the issues.

  • Exchange - email bounces back because seen as firewall by AOL/ATT/etc

    Locked
    4
    0 Votes
    4 Posts
    2k Views
    M

    Great; Thanks! JIMP  I love how this works so well and easy to setup! (With a little help ;) )

  • Simple question

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    J

    Yes so each PC on the network would point to the Gatway IP at the Virtual IP on the LAN port.

  • Failover cluster with two 3 LAN pfSense system

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ

    There are security issues with doing state sync on LAN, and it can consume a significant amount of bandwidth depending on the rate at which states are added/removed.

  • Packages on failover cluster

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ

    No, package settings are not synced between cluster nodes.

  • Bridge 3 OPT Interfaces to do this or is pfSense not capable? [SOLVED]

    Locked
    8
    0 Votes
    8 Posts
    8k Views
    J

    To follow up, Chris B was gracious enough to answer this for me on the mailing list.

    The solution was to just route the public IP's to the interfaces (as described in section 8.2 of the book).

  • CARP dropping packets to VIP

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    P

    Stupid me. I finally figured out that I was using a vhid already in use by our switches. Duh, right there in the troubleshooting carp doc…. All seems to be working great.

  • Execute script when failover happens?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    B

    Thank you, that seems to do the trick!

  • State table not synced?

    Locked
    15
    0 Votes
    15 Posts
    9k Views
    jimpJ

    Sounds good, hopefully that's the end of the issue :-)

  • On failover master still master, backup also master ESXi 4.0

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    B

    This has happened to me in the past when a vSwitch is bound to multiple NICs which are attached to a physical switch that isn't configured correctly for trunking.  What ends up happening is that the multicast CARP announce goes up one leg of the trunk, the physical switch sees the request, doesn't know that the other uplinks are trunk members, and shoots the same multicast packet right back up the other pipes back to the ESX server.  ESX passes the packet back into pfsense, and it thinks oh dear someone's responding already for that CARP IP and either marks it down or both members as master.

    Solution is to either remove any redundant uplinks in a vSwitch (whether active or not if they are physically in the config it'll screw it up) or properly configure the physical switch to handle trunking.

    ESX doesn't support LACP, so this gets a little tricky if you go for the latter.  Juniper gear needs a recent JunOS and ae interfaces configured with LACP mode set to none.  You can't use beaconing.  Ciscos should be set up properly with separate EtherChannel configs for the trunks.

  • VIP with specific address is not working

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • CARP with OpenVPN

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Multiple Public Subnets Routed

    Locked
    7
    0 Votes
    7 Posts
    5k Views
    B

    Thanks!  You have been a great help!

  • Slave doesn't want to be slave

    Locked
    12
    0 Votes
    12 Posts
    5k Views
    B

    @jimp:

    Packages do not sync to slaves, so that is expected. You can just manually configure the squid options on the secondary to match.

    But exactly that would be our problem. We want to allow access to the internet based on the clients IP address, so if we use squid, we have to put the list of allowed IPs in the squid config. Without the proxy, we would have to put that list in the firewall rules. So I guess we have to choose between using a proxy server (and duplicate configuration), or no proxy server (and auto synchronisation of the firewall rules)…

  • MultiIP over PPPoE

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Strange WRITE_DMA errors when switching on network port

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    E

    Hi Jimp,

    I tried that, it did reduce the errors but they were still there. As a last ditch attempt I stuck in a 160gb SATA disk i had laying around and that worked perfectly. So it must have been something strange with the converter.

    Strange thing is, I have the exact same setup on my primary firewall, with a 4GB CF card and converter, upgraded that to 1.2.3 and worked without any problems. So I am not sure why I had issues with the backup firewall, it would be a very strange coincidence if there was a hardware failure at the same time as upgrading the software.

    Either way things are back up and running, thanks for your help, much appreciated.

  • Load Balancing 3 webservers

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Slow failover recovery

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    L

    Actually, this problem may be related to another problem I posted at the same time:

    http://forum.pfsense.org/index.php/topic,25874.msg135322.html#msg135322

    I've been concentrating on the other problem because that one made pfSense unusable for my application.

    For now I'm forced to go with another solution.

    JBB

  • MUTLI SUBNET WAN VIRTUAL IP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.