• HAProxy default route when a rule doesnt match.

    6
    0 Votes
    6 Posts
    1k Views
    V
    @jaredadams An http frontend doesn't accept IP addresses for comprehensible reasons. This might only work in tcp mode.
  • Can / Should i use a CARP address as default GW (LAN)

    7
    0 Votes
    7 Posts
    1k Views
    P
    @viragomann Good, so this is the way it should work then, then i can stop suspecting this was related to the issues at hand, thx !
  • HAProxy Weiterleitung zum nextcloud-Server

    14
    0 Votes
    14 Posts
    2k Views
    V
    @alcamar said in HAProxy Weiterleitung zum nextcloud-Server: Kann das hier dokumentieren, falls es ähnliche unbedarfte wie mich in Zukunft gibt. Warum nicht? Nachdem der Threadtitel schon darauf hinweist, könnten Leute das finden. Allerdings ist deine Konstellation wohl eher eine Seltenheit. Wie gesagt, üblicherweise läuft ein Webserver heutzutage nicht in einem virtuellen Verzeichnis. Wenn HAproxy würde ich alle Anfragen einfach weiterleiten lassen und den Rest den Backendserver machen lassen. Dafür gibt es jede Menge Anleitungen. Ich kämpfe aber noch mit Zertikaten beim CALdav. Eigentlich müsste nur die pfsense Zertifikate jonglieren, oder? So wäre es wünschenswert. Funktioniert leider nicht immer. Ich weiß aber nicht, wie das bei Nextcloud ist. Meine betreibe ich nicht hinter einem Proxy. Aber bezüglich DAV und HAproxy habe ich schon Threads gesehen. Aber ich denke, hier würdest du mit den beiden Suchbegriffen im Netz rascher brauchbare Ergebnisse finden als hier. Die könnte man dann auf die Konfiguration in der pfSense GUI "übersetzen". Deinen Punkt hinsichtlich Sicherheit des Ports 443 habe ich mir für die nächsten Überlegungen vorgemerkt. Wenn du es geschafft hast, dass HAproxy die Anfragen in das virtuelle Verzeichnis von Nextcloud leitet und keine anderen zulässt, sollte es soweit eh sicher sein. Abgesehen natürlich, dass dir klar sein muss, dass die Nextcloud im Internet steht und damit ordentliche Zugangspasswörter braucht und aktuell gehalten werden muss.
  • What does this (backup) CARP status mean?

    6
    1
    0 Votes
    6 Posts
    1k Views
    DerelictD
    @mrpete Well, there you go. No CARP VIP no status. If you have MASTER/MASTER then you need to fix the layer 2 between that interface on both nodes.
  • DHCP failover in recover state

    2
    0 Votes
    2 Posts
    309 Views
    Urbaman75U
    And here's something from the log... DHCPDISCOVER from d0:94:66:4b:51:b6 via vtnet9: peer holds all free leases
  • One VLAN is master on both HA's??? Strange networking issue

    14
    0 Votes
    14 Posts
    2k Views
    MrPeteM
    Thanks all for the suggestions. Digging into it...
  • Help to config carp with HA configuration

    1
    2
    0 Votes
    1 Posts
    430 Views
    No one has replied
  • HaProxy not working on 22.05

    1
    0 Votes
    1 Posts
    702 Views
    No one has replied
  • Can't get to Internet from LAN VIP

    9
    0 Votes
    9 Posts
    2k Views
    S
    @viragomann said in Can't get to Internet from LAN VIP: the default gateway doesn't accept upstream traffic from this subnet Yeah, I asked the data center this question (again), and that was it. So apparently it was routing inbound but not allowing replies or outbound. Thanks for being a sounding board.
  • Does LAN Net include VIPs?

    3
    0 Votes
    3 Posts
    936 Views
    S
    @rcoleman-netgate OK thanks Ryan. That was my suspicion. Just trying to get all the rules set up before launch.
  • Moving from 5 static IP to only 1. : (

    8
    0 Votes
    8 Posts
    1k Views
    V
    @seeking-sense said in Moving from 5 static IP to only 1. : (: Are there any third party service that "tunnels" static / public IPv4 addresses? Likely it would be cost prohibitive if there is such an animal. What do you want to tunnel and how should this work? The thing is, there can only be a single service listen on the single port and IP. So you have to declare what do your need exactly. What does this mean: VM #1 Web, VM #2 Mail, VM #3 NAS, etc... I guess you can run all these services on different ports on pfSense WAN address, apart from "web" (HTTP/S, port 80 and 443). The latter you can treat with the HAproxy package. HAproxy can look into the HTTP host header and can redirect certain host names to different backend servers. This works pretty well.
  • 0 Votes
    2 Posts
    481 Views
    S
    @jasjitchopra It used to be the case to sync states, but not since 22.01, see https://docs.netgate.com/pfsense/en/latest/highavailability/pfsync.html#pfsync-and-physical-interfaces Edit: to clarify, the hardware doesn't have to be identical for HA, but the interfaces/interface order needed to be. If the routers have the same packages and usage then it would help if they are reasonably close in spec.
  • Installing an Apache2 Server cluster with a loading balance

    1
    1
    0 Votes
    1 Posts
    453 Views
    No one has replied
  • How to Create Second WAN Interface / HA

    3
    2
    0 Votes
    3 Posts
    1k Views
    O
    @rico Thank you! I configured the second WAN with SFP cable on IX0 interface
  • CARP switch Master/Backup every 15 minutes

    12
    0 Votes
    12 Posts
    2k Views
    M
    Ok everything is ok now. The sync problem was a bad rule on pfsync interface. Thanks again for your help and have a nice week end
  • CARP Sync problem on NSX-T (VMWare Cloud Director)

    2
    0 Votes
    2 Posts
    2k Views
    J
    You must allow for MAC Address changes, Promiscious MOde, and Forged Transmits on the port group to the VM for any interface that uses CARP. I created a single trunk portgroup that has these settings and only use it for my pfSense box.
  • HA - NO ENOUGH WAN IP Addresses

    14
    1
    0 Votes
    14 Posts
    2k Views
    R
    @amoschb said in HA - NO ENOUGH WAN IP Addresses: So the question is: if only 1 available WAN IP, can we build a HA pfsense? Yes but the backup won't be active until the primary fails. It is also not supported by TAC so if you have issues, purchase TAC support, and come to us and we see that config we won't touch anything related to a HA issue with it. Sometimes you can get your ISP to give you a single static and let you have two DHCP addresses (for the WAN on the two HAs) and go that route.
  • Connection states duplicated on failover/failback

    1
    0 Votes
    1 Posts
    607 Views
    No one has replied
  • pfSense Carp Interfaces via static routes VLT HSRP LAG LACP

    1
    0 Votes
    1 Posts
    510 Views
    No one has replied
  • HA between Pfsense Plus and Pfsense CE

    4
    0 Votes
    4 Posts
    1k Views
    Y
    Hi thanks to the help. I have made a HA between Pfsense plus firewall and Pfsense CE for backup . in production i have many problem like some network disconnection . My pfsense plus firewall has a lot of rules , nat inbound and outbound, 46 VLAN , 6 public VIP . My question is when deploying the HA , the backup firewall must be empty of rules befor activate HA to let the Xmlrpc sync rules automaticaly exept rules of sync interfaces ? because i have exported config xml then i changed what i want like ip interfaces to match the prerequisties oh HA, but rules are the same on both firewall . thank you
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.