• Upgrade to 2.6 redeploy ZFS layout CARP

    Moved
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ

    The maintenance mode switch is in the config and persists across reboots.

  • inconsistent icmp packets with VIP

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • After CARP failover packets go out the wrong WAN

    8
    0 Votes
    8 Posts
    3k Views
    C

    @chrullrich I replaced the pfSense 2.6 "local router/firewall"s in my test setup with OPNsense 22.1 (this is FreeBSD 13.0 instead of pfSense 2.6's 12.3) to get a second opinion. The behavior is the same: As soon as the CARP failover happens, everything sent towards the "Internet" goes out the default route with the NATed source address appropriate for the policy route.

    When I tried it the first time today I thought I saw ping (and only ping) work correctly, but now I cannot reproduce it. I probably just saw what I wanted to see.

  • CARP og IP Alias on additional IPs routed to us by the data center

    4
    0 Votes
    4 Posts
    2k Views
    P

    @derelict
    Yeah, same conclusion i had.

    @viragomann
    Yup.

  • No XMLRPC sync for rrd (Monitoring) settings, packages, Dashboard...

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Crestron NVX nor working with CARP interface

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • HA proxy issue to resolve local ip

    3
    0 Votes
    3 Posts
    2k Views
    O

    @viragomann

    Issue resolved with hostname override and haproxy listnening on LAN interface

    Thx

  • CARP IPv6 with routed network

    2
    0 Votes
    2 Posts
    2k Views
    S

    @skid9000 Perhaps some screenshots of the setup? Can you get it working without the VLANs and add those in after? I've not had occasion to set HA up with VLANs but have done so with aliases for other subnets on LAN.

  • Download-speed drops to 0 when pfSense statesync is enabled

    5
    0 Votes
    5 Posts
    2k Views
    U

    Just for your info. We've now seen the issue on multiple installations (even different hardware and pfsense versions) and could solve it on every single system by moving the sync-vlan to a dedicated physical interface.

  • Best way to access failover HA node from another subnet?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • ESX Physical NIC Failure Fails to Trigger Failover

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Issue with XMLRPC after adding a NAT rule

    7
    0 Votes
    7 Posts
    3k Views
    M

    @viragomann
    i think it's that
    https://forum.netgate.com/topic/150505/xmlrpc-restore_config_section-error

    because my rule to NAT with CARP ip make the backup node not able to reach the gateway
    so as it explain on that like you sent

    Filter reload sees the down gateway and resets states, terminating the connection currently used for XMLRPC.

    it make sense
    Thanks you very much, i think you resolve my issue :)

  • How Does "This Firewall (Self)" Apply in CARP Setups?

    17
    0 Votes
    17 Posts
    4k Views
    planedropP

    @kayavila OK this is great info, thank you! I read your entire write up you linked to as well but I'm still trying to wrap my brain around it. Think I've got it figured out but wanted to pose an example.

    This particular one will be between different VLAN/subnets rather than with WAN as I personally don't ever allow those connections via the WAN.

    So in theory if you had VLAN1 and VLAN2 setup, and there was an any-any rule below a block "This Firewall" rule on VLAN1, and some device on VLAN1 tried to contact the LAN interface of VLAN2, due to state syncing this would be let through? Since the first node would see the connection to the VLAN2 IP and see that it's not in it's block list but matches the any-any rule, and then the state would sync to the secondary which wouldn't assess it's rules?

    If that is the case, I would imagine not having a rule on the primary node that allows access to any would solve the issue, but since some people do use an any rule for internet access it could pose a problem (though best practice is of course to use an alias for RFC1918 and explicitly allow the inverse of that).

  • VIP & NAT

    3
    0 Votes
    3 Posts
    2k Views
    A

    @viragomann
    Thanks !
    Went with the port forward + outbound option, NAT is working finally.

  • HA Setup

    2
    0 Votes
    2 Posts
    2k Views
  • HA Interface OPT do not match on Secondary

    3
    0 Votes
    3 Posts
    2k Views
    V

    @mrfrenchfry
    You can export the interface config from the secondary node:
    Diagnostics > Backup & Restore > Backup & Restore
    At Backup area select "Interfaces".

    Download the file. Then load it into a text editor and order the interfaces accordingly to the primary.

    Save the file and re-import it into the secondary.

  • Question about switchs to be used between WAN CARP and ISP's

    17
    0 Votes
    17 Posts
    4k Views
    SipriusPTS

    More photos:

    20220201_181442.jpg
    20220131_180718.jpg
    20220201_181457.jpg
    20220119_165632.jpg
    20210929_162052.jpg 20201214_141056_HDR.jpg

  • Static DHCP lease Gateway/DNS problem

    2
    0 Votes
    2 Posts
    2k Views
    Urbaman75U

    Sorry, it probably was only a temporary problem while the network reconfigured to the static IP.
    It now seems to work properly.

  • DNS queries from HA backup?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Mac address of Carp/vip

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.