• VMWARE ESX 3.5 / vSwitch w/ 2 Physical NICs / CARP / PFSense 1.2.3

    Locked
    10
    0 Votes
    10 Posts
    9k Views
    Y

    In case people still experience this issue (I did very recently), I made a writeup of the solution:

    http://sysadminadventures.wordpress.com/2010/03/22/fixing-vm-based-pfsense-carp-announcement-echoes-when-using-teamed-network-adapters/

  • Any News on CARPDEV?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Internal Network

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    D

    After doing some more digging, it appears the answer lives here:

    http://doc.pfsense.org/index.php/Traffic_Shaping_Guide#Limiter

    Still a little confusing since this Pipe doesn't really act like a true interface.

  • Carp-failover problem (with multiwan)

    Locked
    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • PfSync sync peer IP

    Locked
    2
    0 Votes
    2 Posts
    4k Views
    jimpJ

    Yes, you're correct on both counts.

    That should be state table – I fixed that in HEAD.

    And you can leave it blank if you want, it will use multicast to update.

  • Additional WAN subnet working without VIPs?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    M

    I found the answer. It was caching. After the server was rebooted, NAT didn't work anymore and I had to recreate the Proxy Arp entry in the pfSense.

  • When are VIPs necessary for NAT, port fwrd?

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    N

    No, not yet, but I was planning on it:  I dug a little deeper in previous posts and found a similar problem which was fixed by rebooting a router.  After reading your reply, I'm confident that doing so (in conjunction with having the right type of VIPs) will take care of the problems I was having.  I can't try again for a few days because another project got elevated priority.  Thanks very much for your response.

  • How to make VIP to show in outbound connections in 1:1 NAT?

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Routing and Additional Networks

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    E

    Is your outbound nat set up to use this VIP?

  • CARP and Multi Subnet LAN

    Locked
    2
    0 Votes
    2 Posts
    3k Views
    E

    Are you trying to reach more redundancy by using two subnets or you really need to connect two subnets to LAN?

  • CARP + LoadBalancing failover mode

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    E

    You can explicitly disable multicast/broadcast and put these rules on the top.
    Or alternatively - do not allow ANY protocol to ANY address but allow only traffic you really need to allow.
    First approach is more efficient as multicast/broadcast packets are droped without going through all rules before being dropped by 'default deny all'.

  • CARP SYNC problem

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    E

    What does that mean please?
    @cpliu903:

    when R1 sync to R2, R2 change status to master,  not backup.

  • MOVED: Multiple IPs and outbound routing

    Locked
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Two ranges on WAN

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    I

    ok..thanx..that was my guess too.

  • Can't Get Static IP's Working

    Locked
    6
    0 Votes
    6 Posts
    3k Views
    jimpJ

    I believe some people have gotten this to work by adding 5 vlan interfaces and setting them all for DHCP. I'd do a forum/docs search going down that route and see if you can turn up better results. I seem to recall it coming up within the past two weeks.

  • PfSense kernel panic in load-balancing/failover config

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • CARPDEV support on 1.2 ?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    B

    I have not given all the details:

    I have configured squid to bind on the LAN if.

    I have a real IP on the WAN (ip of class 88.xx.xx.12/24)
    and several VIP (ips of  class 93.xx.xx.0/24)

    I need the squid users to come out with one of the  VIP, by adding
    directive tcp_outgoing_address 93.xx.xx.10  in squid conf.

    How can I do  to do that?
    (I think I need carpdev to have VIP on virtual interface CARP)

    kind regards

  • Is there a decent carp failover how-to/tutorial?

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    GruensFroeschliG

    You could put a dumb off-the-shelf router in NAT mode in front of the pfSense.
    Or if the modem supports that, reconfigure the modem.

    Basically put a static, private subnet in front of the pfSense.

  • Proxy ARP implementation

    Locked
    4
    0 Votes
    4 Posts
    5k Views
    M

    @GruensFroeschli:

    Are the additional IPs routed to your WAN?

    They are routed to my PPPoE address.  They are not configured on an adapter other than as virtual IP's.

    @GruensFroeschli:

    Are they all in use right now?

    The 8 IP Block is fully utilised via 1:1 NAT and are all working fine
    The 16 IP block is utilising 2 IP's at present.  1 is NAT, the other is configured as the live IP on the virtual linux system

    @GruensFroeschli:

    Do you have the public IP directly on the server?

    The only live IP configured is the PTP ip for my ADSL connection

    @GruensFroeschli:

    There are several ways to go at such a problem.

    Bridging VIPs –> The public IP on the pfSense, the internal servers have private IPs, traffic from the public IP forwarded to the private IP. routing
    You cannot use VIPs if you have the public IP directly on the server itself.

    Presently, VIP's and routing are accomplishing things for all the other IP's.
    The IP that is causing the issue is the virtual machine configured with the real world ip (no internal IP address allocated)

  • SNMP Graphing of Carp Virtual Interfaces

    Locked
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.