• 0 Votes
    4 Posts
    971 Views
    V
    @Delegator5042 said in Setting up CARP Master and Backup on a per VLAN basis (Like VRRP): is it possible?: I've read that you can use a switch on the ISP Ethernet connection so it could be shared with multiple routers, but I haven't tried this. Yes, put a small switch into each line or even a VLAN capable switch and split it into two virtual switches. Consider that for CARP, you need an IP on each pfSense and a third as VIP. So you should have 3 IPs on each. If you haven't there is also a way to configure private IPs on the boxes, but this has some drawbacks. I would still like to know if I could force a vlan (or subnet) to use a specific gateway and only when that gateway is down to send the traffic over to designated backup connection. You can configure a gateway group and set this as default gateway. For routing traffic other than according the default gateway you can do policy routing by stating a gateway in the firewall pass rule. You your purposes you can configure an additional gateway group, say with inverted priorities, and use this in the policy routing rule.
  • is it possible to configure more than 2 pfsense for HA?

    5
    0 Votes
    5 Posts
    868 Views
    P
    @jimp Yea i know - but there is no other way when a single instance can not take the load, especially since it's a single CPU process only (see load below) - other ways to solve this ? please enlighten me :-) [image: 1692776780460-cce21a91-f3c8-4bdf-ab67-99f1a3fc7d85-image.png] I have handled this in the past by simply unlink CARP sync and manually set skew for VIP's to loadbalance load over two HA's Example: so some customers has fw1 as primary and some other customers has fw2 as primary - failover still works.
  • Is it possible to adjusting ARP table update or clear time?

    3
    0 Votes
    3 Posts
    779 Views
    E
    @johnpoz Thank you so much. I configured followed your comment.
  • Synchronize Configurations between Cluster Members via cli

    1
    0 Votes
    1 Posts
    341 Views
    No one has replied
  • ACL conditions

    7
    1
    0 Votes
    7 Posts
    1k Views
    E
    @viragomann said in ACL conditions: So are these IPs behind pfSense or are these IPs assigned to WAN? Ok, so we are using this in L4 mode, and it's working fine. To reply to you we have no need to hide those public IPs, for us those are on a DMZ assigned to our WAN, so it's ok. Thanks for your support Virago, sadly we are struggling a bit on this.
  • OpenVPN Clients issue in High Availability

    2
    0 Votes
    2 Posts
    504 Views
    V
    @nouman786 Which OpenVPN client are you talking about? Incoming connections to the firewall or outgoing from behind pfSense? If the issue is on incoming connections, do you connect to the WAN CARP VIP? Is your HA setup working properly, so that all interfaces are in master state on the primary and in backup on the secondary? Are all devices inside your network using the CARP VIP as their default gateway?
  • CARP issue (master on both nodes at the same time)

    6
    3
    0 Votes
    6 Posts
    3k Views
    I
    @jimp Sorry for my late reply. I performed several tests and CARP is working fine now :) Thanks for your help!
  • Pfsense and NordVPN

    4
    0 Votes
    4 Posts
    2k Views
    GertjanG
    @Astartes said in Pfsense and NordVPN: let the solution start here Not here. This is the Home > pfSense Software > HA/CARP/VIPs so no VPN talk here. Look here : Home > pfSense Software > OpenVPN and you'll find some recent NordVPN discussions.
  • VIPs and Firewall Rules

    1
    1
    0 Votes
    1 Posts
    257 Views
    No one has replied
  • CARP DUP! on External pings

    1
    2
    0 Votes
    1 Posts
    386 Views
    No one has replied
  • Hidden block quick rule dropping CARP advertisements

    1
    0 Votes
    1 Posts
    308 Views
    No one has replied
  • Adding configuration files for primary and secondary

    1
    0 Votes
    1 Posts
    245 Views
    No one has replied
  • Hidden block quick rule dropping CARP advertisements

    1
    0 Votes
    1 Posts
    416 Views
    No one has replied
  • HA Setup - gateway picking up wrong MAC in ARP Cache for CARP IP?

    7
    0 Votes
    7 Posts
    1k Views
    D
    FWIW, I found this older post from 2018 from @bw-linux who had the exact same issue as me. https://forum.netgate.com/topic/134297/cox-and-the-carp-mac Anyway, the short answer is that they weren't able to get it to work and it CARP/VRRP doesn't appear to be supported properly by the cable modems. I think the only way we could get it to work would be to get pfsense to always respond/send traffic for the CARP IP using the same MAC instead of the MAC address of whatever device is primary.
  • DNS Resolver on HA Pair

    1
    0 Votes
    1 Posts
    266 Views
    No one has replied
  • Request timed out due to default_socket_timeout php.ini

    1
    0 Votes
    1 Posts
    393 Views
    No one has replied
  • 0 Votes
    5 Posts
    1k Views
    shepradorS
    Thanks @viragomann
  • Do you need multiple public IP's for basic failover functionality?

    14
    0 Votes
    14 Posts
    3k Views
    V
    @Magoogle Check Status > Gateways. Is the tier2 the default now?
  • Configure an PPPoE on an CARP IF

    18
    0 Votes
    18 Posts
    15k Views
    JeGrJ
    @netblues said in Configure an PPPoE on an CARP IF: This never really worked. pppoe running on a carp interface isn't an option. It sure is. We have a few customers set up that way and working well - within boundaries. Of course in such a setup the secondary node of a CARP setup won't easily have internet which is/can be a problem and as such the setup isn't really recommended. But it IS working though. It's important to check though that both nodes on it's WAN "carrier" interface are connected to each other and the DSL modem correctly so both have access to dial-in if needed. If that's set up correctly it's a relatively simple setup: either node gets the physical interface for the PPPoE connection assigned with its own IP, say 10.12.34.251 and .252 check pinging from one to the other and back (allow ICMP on that interface first) then add a CARP VIP to it, e.g. .254 - that one should now be active on the primary node anad backup on the secondary node. If that is not the case you don't need to proceed with PPPoE stuff. That's basic CARP that should be working first! If that's running you can now add the PPPoE interface but as carrier you don't choose your physical interface BUT the NEW CARP VIP you created (yes, that .254 one from above!) This ensures the PPPoE connection switches from node 1 to 2 and back if needed. Then set up PPPoE as usual. When finished assign that interface (pppoe0) as your WAN_PPPoE or something else like it. THAT one is your actual WAN, the other physical interface and the VIP on it are only a sort-of transfer/carrier network. Cheers
  • High Availability with Multi-WAN and Multi-LAN

    13
    0 Votes
    13 Posts
    3k Views
    R
    @reberhar Yes of course. Why would you want to choose a gateway for every rule. I was just caught in the verbage.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.