• CARP + Dual WAN connection failover

    Locked
    6
    0 Votes
    6 Posts
    4k Views
    T

    I have found out the root causes.  It's not the problem with the switch.  It was b/c of the firewall rules.  When the FW outbound LAN rule got change to use the Failover pool, the default route is no long effective.  When master & slave send out the broadcast message of VRRP to 244.0.0.18, it used the Failover for it routing table and Failover pool is only routed to either WAN1 or WAN2 which doesn't know the route of the internal LAN subnet.  That's why stage MASTER/MASTER were on both machines.  Once I create the new rule for LAN subnet to allow traffic to 244.0.0.18 using the default gateway, then it fixed the problem.

    It's working great now.  Disable on master –> switch over to salve.  Enable back --> fallback to master.

  • CARP and Routed Real IP Subnet

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    Exactly

  • Kernel: carp3: incorrect hash

    Locked
    12
    0 Votes
    12 Posts
    7k Views
    U

    thanks for yours help

  • Sync problem when removing alias

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    S

    This was a bug.  Just fixed it.

  • Questions about Carp?

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    B

    Thank you

  • PPPoE Failover

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    M

    To answer the first of my two questions, I just came up with this:

    http://kerneltrap.org/node/1021

    Which basically means you can't bind scripts to it, just monitor link status from cron and act upon it (MASTER -> dial out)

    Which brings back the second question.

    What's the proper way of initiating PPPoE dialout from shell?

  • CARP and load balancing

    Locked
    5
    0 Votes
    5 Posts
    4k Views
    H

    @jmhoms:

    when you talk about adding firewall rules that utilize the pool as gateway, these rules must be added in the LAN interface, isnt it ?

    That is right, you have to make the rule on the interface the traffic comes in from.

    @jmhoms:

    and the gateway IPs in the load balacer configuration must be the WAN and WAN2 CARP addresses, isnt it ?

    No, you use their gateways (it's a gateway pool). If you use the latest snapshot you'll have these as pulldown options so there is no footshooting with this setting anymore.
    Don't forget to set your firewall>nat, outbound to advanced outbound nat to utilize your CARP VIPs.

    @jmhoms:

    If so, i'm trying to make this setup working in a wmare test environment, no luck for now, i'll keep trying.

    I have heard that CARP is not happy inside vmware. Haven't tried it myself though.

    @jmhoms:

    I supose it will work, so , do you think that if i have 2 offices with this configuration, will be possible to do IPSEC between the WANs CARP addresses ?

    Yes, just have a look at the failover tab at vpn>ipsec. I have a setup running in this configuration.

  • CARP / DMZ

    Locked
    3
    0 Votes
    3 Posts
    2k Views
    F

    whats the way around that ?

    would it just simply be

    if destination is in this range and from WAN forward out DMZ interface
    and back out again
    If destination is from DMZ servers range to the net forward out WAN interface ?

    That way you wouldnt need NAT or Bridging ?

  • Dual wan + carp feature clarification/request

    Locked
    5
    0 Votes
    5 Posts
    3k Views
    H

    http://faq.pfsense.com/index.php?action=artikel&cat=1&id=167&artlang=en&highlight=arp

  • Is this possible?

    Locked
    9
    0 Votes
    9 Posts
    6k Views
    J

    I'm trying the same that jpinder70, but with 2 adsl connections (and later will try to setup a redundant balaced ipsec meshed network).

    It seems obvious that each pfsense system must have a wan ip of each of the adsl/t1 connections in order to have a carp address for each connection. I only have 1 public static ip per adsl, and will belong to carp interface, because the traffic must go out with this ip, cos is the only routed to my connection by my isp. That way, as the wan adresses must be in the same subnet as the carp address, i will take 2+2 ip that not really belong to me, and i assume that my natted networks never will get to the real ips (anyway these probably doent have any public service that must be directly accessed by my users).

    Actually i only have 3 nic in each pfsense. So i'm trying some setups to see if they work without need of 4rt nic, hope to hear your feedback.

    I connected both adsl routers, and both wan of pfsenses to the same ethernet segment.
    My pfsense1 sync to pfsense2. I tried also to activate that pfsense2 sync to pfsense1. It seems to work, but there is some delay when apply changes, maybe there is some kind of cyclic action :? i don't know if it's ok that setup.
    Actually my  wan of pfsense1 have the adsl1 public ip, and wan of pfsense2 have the adsl2 public ip. I setup a carp address for adsl1 subnet in pfsense1, and a carp address for adsl2 suvnet in pfsense2. I was expecting for an error in sync, because pfsense1 doesnt know about adsl2 subnet, and pfsense2 neither of adsl1 net. Pfsense system have sync and now i have the carp adresses in both pfsenses. Maybe is not necessary that both pfsesne to be in both wan subnets ?¿¿ i think that yes it's mandatory, because don't seem to work (no error in frontend anyway).

    Assuming that both subnets are mandatory, i would like to know if it's possible to setup a wan interface with the two wan ips (1 per each adsl conn).  Maybe with proxy arp virtual ip ?? i don't see any aliasing option to assign multiple ip to an interface in the frontend (like in rc.conf _alias method in freebsd). I read somewhere that is not recommended, anyone have any hint with this ? maybe this will be an issue in the way the traffic wil go out ??¿ maybe the balacer will not work properly ?

    i keep monitoring this thread to see if the jpinder70 setup works.

    Thanks.

  • What is carp?

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    Demonstration of what it does:
    http://pfsense.com/mirror.php?section=tutorials/carp/carp_failoversim.htm

    How to set it up:
    http://pfsense.com/mirror.php?section=tutorials/carp/carp-cluster-new.htm
    http://doc.pfsense.org/index.php/Setting_up_CARP_with_pfSense

    Technical Info:
    http://www.openbsd.org/faq/pf/carp.html
    http://www.countersiege.com/doc/pfsync-carp/

  • Problem with failover, propably ARP problem

    Locked
    11
    0 Votes
    11 Posts
    6k Views
    K

    any help or comment?

    Thanks,
    Hans

  • FTP throuhg VIP

    Locked
    9
    0 Votes
    9 Posts
    5k Views
    X

    so I have to set wan /16 and vip /16 ?

  • Bug or how to add IP to CARP

    Locked
    2
    0 Votes
    2 Posts
    2k Views
    H

    Seems to be bad luck in that case. You'll have to wait for the next major version (most likely 2.0) which has support for another type of alias that should be able to handle this condition.

  • Okay may have found problem but how do i fix it

    Locked
    7
    0 Votes
    7 Posts
    3k Views
    M

    okay this is what i found if you have a address of *x.x.x.25 and you also have a address of x.x.x.2 you will ned up  with the same carp numbers. I have fixed it but still does not solve my problem of not being able to download files or email attachments. I have tried every suggestions mentioned on the forum. So i am open to new ideas

  • CARP/VIPS issue in downloading large file

    Locked
    17
    0 Votes
    17 Posts
    8k Views
    S

    http://faq.pfsense.com/index.php?action=artikel&cat=1&id=167&artlang=en&highlight=bad%20gateway

  • Carp interface

    Locked
    8
    0 Votes
    8 Posts
    4k Views
    H

    We enable preepmtion by default now, that's why the box is missing (the tutorial was not updated regarding this). I'll have a lokk at the doc if it can be made more clear or more easy to understand.

  • CARP setup document posted

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    S

    Oops, thats wrong :)  I'll get it updated.  Thanks

  • How should it run ?

    Locked
    23
    0 Votes
    23 Posts
    9k Views
    H

    See http://www.countersiege.com/doc/pfsync-carp/ for how it works.

  • VIP ip address not responding to ARP requests

    Locked
    3
    0 Votes
    3 Posts
    4k Views
    T

    Thanks for the quick response.  Flipped everything over to Proxy-ARP and it works.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.