• Hidden block quick rule dropping CARP advertisements

    1
    0 Votes
    1 Posts
    382 Views
    No one has replied
  • HA Setup - gateway picking up wrong MAC in ARP Cache for CARP IP?

    7
    0 Votes
    7 Posts
    1k Views
    D
    FWIW, I found this older post from 2018 from @bw-linux who had the exact same issue as me. https://forum.netgate.com/topic/134297/cox-and-the-carp-mac Anyway, the short answer is that they weren't able to get it to work and it CARP/VRRP doesn't appear to be supported properly by the cable modems. I think the only way we could get it to work would be to get pfsense to always respond/send traffic for the CARP IP using the same MAC instead of the MAC address of whatever device is primary.
  • DNS Resolver on HA Pair

    1
    0 Votes
    1 Posts
    236 Views
    No one has replied
  • Request timed out due to default_socket_timeout php.ini

    1
    0 Votes
    1 Posts
    377 Views
    No one has replied
  • 0 Votes
    5 Posts
    1k Views
    shepradorS
    Thanks @viragomann
  • Do you need multiple public IP's for basic failover functionality?

    14
    0 Votes
    14 Posts
    3k Views
    V
    @Magoogle Check Status > Gateways. Is the tier2 the default now?
  • Configure an PPPoE on an CARP IF

    18
    0 Votes
    18 Posts
    15k Views
    JeGrJ
    @netblues said in Configure an PPPoE on an CARP IF: This never really worked. pppoe running on a carp interface isn't an option. It sure is. We have a few customers set up that way and working well - within boundaries. Of course in such a setup the secondary node of a CARP setup won't easily have internet which is/can be a problem and as such the setup isn't really recommended. But it IS working though. It's important to check though that both nodes on it's WAN "carrier" interface are connected to each other and the DSL modem correctly so both have access to dial-in if needed. If that's set up correctly it's a relatively simple setup: either node gets the physical interface for the PPPoE connection assigned with its own IP, say 10.12.34.251 and .252 check pinging from one to the other and back (allow ICMP on that interface first) then add a CARP VIP to it, e.g. .254 - that one should now be active on the primary node anad backup on the secondary node. If that is not the case you don't need to proceed with PPPoE stuff. That's basic CARP that should be working first! If that's running you can now add the PPPoE interface but as carrier you don't choose your physical interface BUT the NEW CARP VIP you created (yes, that .254 one from above!) This ensures the PPPoE connection switches from node 1 to 2 and back if needed. Then set up PPPoE as usual. When finished assign that interface (pppoe0) as your WAN_PPPoE or something else like it. THAT one is your actual WAN, the other physical interface and the VIP on it are only a sort-of transfer/carrier network. Cheers
  • High Availability with Multi-WAN and Multi-LAN

    13
    0 Votes
    13 Posts
    3k Views
    R
    @reberhar Yes of course. Why would you want to choose a gateway for every rule. I was just caught in the verbage.
  • HA-proxy using multipe port numbers !??

    1
    0 Votes
    1 Posts
    234 Views
    No one has replied
  • How to debug state sync issues?

    7
    0 Votes
    7 Posts
    1k Views
    A
    This seems to be the same issue as https://redmine.pfsense.org/issues/13569 -- I'd love to debug this further but I am not sure what else to look into.
  • SG-1100 : HAproxy fails after upgrade to 23.01

    13
    0 Votes
    13 Posts
    2k Views
    S
    contacted support, reinstalled from scratch, same errors again. provided diagnosis data, support reproduced issue, now we have this issue in redmine: bug
  • HAProxy help

    3
    0 Votes
    3 Posts
    574 Views
    kiokomanK
    it happened to me several times, don't change the port, delete the backend and redo it
  • Dynamic PPPOE WAN on carp

    1
    0 Votes
    1 Posts
    384 Views
    No one has replied
  • CARP-related messages do not sent in syslog

    3
    0 Votes
    3 Posts
    549 Views
    E
    @jimp These two pfSenses are in the middle of network, the issue didn't affect interfaces faced to syslog server, syslog source set as local pfSense interface, not as CARP VIP. We see in syslog other messages like FW rules actions during the issue period, but not CARP-related ones.
  • Many questions about HA

    4
    0 Votes
    4 Posts
    686 Views
    S
    @damianhl If it has ZFS there is a Disks widget that can expand to show details: [image: 1685732278018-e80dceed-465d-4da2-9b03-30e91c0a4dcd-image.png] Not sure about hardware RAID, have never used it. Unless FreeBSD/pfSense includes a driver the pfSense OS will probably only be able to see what the BIOS shows it.
  • 504 Gateway Time-out status_dhcp_leases.php page

    3
    0 Votes
    3 Posts
    679 Views
    J
    DHCPD LOG.txt
  • CARP VIPs with different states on secondary firewall

    9
    0 Votes
    9 Posts
    2k Views
    DerelictD
    @decibel83 A problem at Layer 2 is the most common cause.
  • Pfsense HA CARP with mode only routing (firewall disabled)

    5
    0 Votes
    5 Posts
    842 Views
    jimpJ
    FYI- You can disable NAT and route without also disabling the firewall. Firewall > NAT, Outbound tab, set it to Disable Outbound NAT and save/apply.
  • Warm spare capabilitiy (similar to Meraki)?

    1
    0 Votes
    1 Posts
    405 Views
    No one has replied
  • High-Availability Issues

    2
    0 Votes
    2 Posts
    529 Views
    S
    @james92 Yes a dumb switch is fine.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.