• HA SYNC XMLRPC SYC virtual ips alias sync

    2
    0 Votes
    2 Posts
    1k Views
    M

    So from an old ticket:

    https://redmine.pfsense.org/issues/7010?tab=notes

    I'm confused why aliases on loopback interfaces would need a sync for HA cluster

  • How does XMLRPC config sync work across failover?

    5
    0 Votes
    5 Posts
    2k Views
    M

    I think there needs to be some work done e.a redesign of the whole xmlrpc process thing.
    I could easily see times that one firewall is broken and it takes weeks to perhaps months ( depending on supply of hardware vendor ) to get replaced and sycing can be moved back to original primary device.

    There should become an option to track changes on secondary device and have information tracking on primary device and as soon primary comes online there should become an option to sync the rules between devices.

    So basically what I am saying here is that a secondary node should have more involvement in this whole xmlrpc config process.

    Like there should also become an option when primary comes back online you can still keep the secondary running as the main firewall rule util you are sure the primary firewall is working correctly again.

    Just my 2 cents of thoughts.

  • 0 Votes
    1 Posts
    841 Views
    No one has replied
  • High Load during sync after update 2.6.0

    1
    0 Votes
    1 Posts
    961 Views
    No one has replied
  • HA setup however DNS clients use Primary servers DNS

    2
    0 Votes
    2 Posts
    1k Views
    V

    @spectre-988
    The clients use for DNS, what you tell them to use.
    Enter the CARP IP as DNS server, and the will send request to it.

    If they are configured by DHCP, tell the DHCP to send the CARP IP for DNS.
    In pfSense DHCP server you can enter it at "DNS servers".

  • Add HA to existing system

    2
    0 Votes
    2 Posts
    2k Views
    N

    Well, it can be done, with minimal changes.
    You need to change local ip's and make ha ones as vip
    Not a big thing

    But, do keep in mind that all interfaces have to be created in the same order in both ha instances.

    You will need some experience with the ha setup.
    Many things can go wrong if you don't know what you are doing. (as is usually the case too)

    I strongly suggest to setup a lab and experiment with ha setup. When you will feel confident, you can proceed with the real thing.
    Doing such chores on a live system without prior experience will probably cause significant downtime.

  • pfSense CARP + Cisco N5k vPC

    6
    0 Votes
    6 Posts
    3k Views
    P

    @dara said in pfSense CARP + Cisco N5k vPC:

    @philippe-richard Hi Philippe, Thanks a lot. This is more complete and interesting than our setup.

    I wonder how you configured the connection between the routers and switches?

    In my setup, each router has a single connection to a single switch configured as an Orphan port. For now it is working perfectly.

    I am not sure however how it will handle different link and device failure scenarios but I will test it sometime soon and post my findings here.

    Hello, have you made progress on your configuration?
    Have a good day

  • OpenVPN client cannot access second pfSense host

    4
    0 Votes
    4 Posts
    2k Views
    S

    Could someone post an example for the necessary NAT rule(s), please?
    EDIT: got it already, at least I think so 😊

  • Move all CARP IP's together

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD

    @neilewing When an interface with a CARP VIP loses carrier, all VIPs on that host are demoted. This makes the VIPs on the other node "better" and the rest of the VIPs on the first node swing to BACKUP status (because they see the "better" advertisements) and the ones on the backup node assume MASTER (because they see that they are the "best" VIP status).

  • Netgate 1537, OpenVPN & CARP High Availability

    3
    0 Votes
    3 Posts
    1k Views
    C

    @viragomann We indeed had very strange routing issues on the location the pfSense instances are deployed. It's really nothing wrong with them but we had a strange situation in combination with our WAN Switches and the LACP upstream to the provider.

    OpenVPN to the CARP Address is now running stable.

  • Azure Load Balancer Probe IP Routing

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • HAProxy - max_execution_time more than 30 sec

    1
    0 Votes
    1 Posts
    851 Views
    No one has replied
  • Ha proxy redirects to wrong ip

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Accessing the slave from remote networks

    6
    0 Votes
    6 Posts
    2k Views
    B

    @derelict
    IT WORKS!
    Thank you

  • CARP "Master" in All Nodes

    4
    0 Votes
    4 Posts
    2k Views
    DerelictD

    @brunoroza If that is really the case then your switch is likely not properly passing the CARP advertisements. They are multicast to 224.0.0.18.

    20:17:32.490656 IP 172.25.228.18 > 224.0.0.18: CARPv2-advertise 36: vhid=228 advbase=1 advskew=0 authlen=7 counter=2770184658337638700

    If those are not received by the secondary node, it will also become MASTER and begin advertising its CARP VIP.

  • HAproxy for NFS connection

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    3 Posts
    2k Views
    T

    Update: after turning the whole infrastructure from left to right we found the solution.
    It's the limiter bug that is already known. After removing the limiter from the firewall rule (it was a just one catch all rule for the whole NAT traffic), it works as before.
    Which also means: the same setting worked perfectly fine before the upgrade.

    I am some much hoping for a soon fix of the limiters in an official update or release!

  • HA randomly BACKUP goes to MASTER state

    21
    0 Votes
    21 Posts
    4k Views
    P

    @m4rek11 After applying the patches, I did not notice that the routers changed the roles of Master-> Backup, Backup-> Master.
    All the problems went with those when I made any changes to the rules, dns or DHCP.

    I found my configuration error early. For unknown reason, for 2 different networks I sent the same vhid for Virtual IP. But the problems were still there. After applying the patches, the problem was gone.

  • High Availability port forward to VIP -am i doing this right?

    13
    0 Votes
    13 Posts
    3k Views
    R

    @digger30 Perfect! Glad I could be of assistance.

  • LAN only HA + OpenVPN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.