• Simple question

    Locked
    5
    0 Votes
    5 Posts
    2k Views
    J
    Yes so each PC on the network would point to the Gatway IP at the Virtual IP on the LAN port.
  • Failover cluster with two 3 LAN pfSense system

    Locked
    4
    0 Votes
    4 Posts
    3k Views
    jimpJ
    There are security issues with doing state sync on LAN, and it can consume a significant amount of bandwidth depending on the rate at which states are added/removed.
  • Packages on failover cluster

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    jimpJ
    No, package settings are not synced between cluster nodes.
  • Bridge 3 OPT Interfaces to do this or is pfSense not capable? [SOLVED]

    Locked
    8
    0 Votes
    8 Posts
    8k Views
    J
    To follow up, Chris B was gracious enough to answer this for me on the mailing list. The solution was to just route the public IP's to the interfaces (as described in section 8.2 of the book).
  • CARP dropping packets to VIP

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    P
    Stupid me. I finally figured out that I was using a vhid already in use by our switches. Duh, right there in the troubleshooting carp doc…. All seems to be working great.
  • Execute script when failover happens?

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    B
    Thank you, that seems to do the trick!
  • State table not synced?

    Locked
    15
    0 Votes
    15 Posts
    10k Views
    jimpJ
    Sounds good, hopefully that's the end of the issue :-)
  • On failover master still master, backup also master ESXi 4.0

    Locked
    8
    0 Votes
    8 Posts
    5k Views
    B
    This has happened to me in the past when a vSwitch is bound to multiple NICs which are attached to a physical switch that isn't configured correctly for trunking.  What ends up happening is that the multicast CARP announce goes up one leg of the trunk, the physical switch sees the request, doesn't know that the other uplinks are trunk members, and shoots the same multicast packet right back up the other pipes back to the ESX server.  ESX passes the packet back into pfsense, and it thinks oh dear someone's responding already for that CARP IP and either marks it down or both members as master. Solution is to either remove any redundant uplinks in a vSwitch (whether active or not if they are physically in the config it'll screw it up) or properly configure the physical switch to handle trunking. ESX doesn't support LACP, so this gets a little tricky if you go for the latter.  Juniper gear needs a recent JunOS and ae interfaces configured with LACP mode set to none.  You can't use beaconing.  Ciscos should be set up properly with separate EtherChannel configs for the trunks.
  • VIP with specific address is not working

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • CARP with OpenVPN

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Multiple Public Subnets Routed

    Locked
    7
    0 Votes
    7 Posts
    5k Views
    B
    Thanks!  You have been a great help!
  • Slave doesn't want to be slave

    Locked
    12
    0 Votes
    12 Posts
    5k Views
    B
    @jimp: Packages do not sync to slaves, so that is expected. You can just manually configure the squid options on the secondary to match. But exactly that would be our problem. We want to allow access to the internet based on the clients IP address, so if we use squid, we have to put the list of allowed IPs in the squid config. Without the proxy, we would have to put that list in the firewall rules. So I guess we have to choose between using a proxy server (and duplicate configuration), or no proxy server (and auto synchronisation of the firewall rules)…
  • MultiIP over PPPoE

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Strange WRITE_DMA errors when switching on network port

    Locked
    5
    0 Votes
    5 Posts
    5k Views
    E
    Hi Jimp, I tried that, it did reduce the errors but they were still there. As a last ditch attempt I stuck in a 160gb SATA disk i had laying around and that worked perfectly. So it must have been something strange with the converter. Strange thing is, I have the exact same setup on my primary firewall, with a 4GB CF card and converter, upgraded that to 1.2.3 and worked without any problems. So I am not sure why I had issues with the backup firewall, it would be a very strange coincidence if there was a hardware failure at the same time as upgrading the software. Either way things are back up and running, thanks for your help, much appreciated.
  • Load Balancing 3 webservers

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Slow failover recovery

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    L
    Actually, this problem may be related to another problem I posted at the same time: http://forum.pfsense.org/index.php/topic,25874.msg135322.html#msg135322 I've been concentrating on the other problem because that one made pfSense unusable for my application. For now I'm forced to go with another solution. JBB
  • MUTLI SUBNET WAN VIRTUAL IP

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • FYI - CARP with Disable Firewall option checked

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • PfSense, VmWare ESXi and Virtual IPs

    Locked
    4
    0 Votes
    4 Posts
    7k Views
    O
    I'm not sure that what SuperMule is suggesting makes sense in this situation. This is where I'd suggest you start. In the VMWare VIC (virtual infrastructure client): On the HOST: Configuration - Networking Get 'properties' on the switch associated with these IP addresses.  Then, clicn on the vSwitch, and click "Edit" Under "Securty" - set all three (Promiscuous Mode, MAC Address Changes, Forged Transmits) to "Accept" PLEASE NOTE that this has security implications!  You may want to be more specific in how you configure this, etc.
  • Multimaster?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    B
    What is the recommended procedure for recovery? Let's say FW-A fails, FW-B becomes master… if FW-A returns to service before any changes are required, GREAT - but what it you have to make changes? Are you better to re-connect FW-A as a slave to FW-B? Or backup and restore selective parts of the FW-B config to FW-A? Thanks!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.