• HAproxy for NFS connection

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    3 Posts
    2k Views
    T
    Update: after turning the whole infrastructure from left to right we found the solution. It's the limiter bug that is already known. After removing the limiter from the firewall rule (it was a just one catch all rule for the whole NAT traffic), it works as before. Which also means: the same setting worked perfectly fine before the upgrade. I am some much hoping for a soon fix of the limiters in an official update or release!
  • HA randomly BACKUP goes to MASTER state

    21
    0 Votes
    21 Posts
    4k Views
    P
    @m4rek11 After applying the patches, I did not notice that the routers changed the roles of Master-> Backup, Backup-> Master. All the problems went with those when I made any changes to the rules, dns or DHCP. I found my configuration error early. For unknown reason, for 2 different networks I sent the same vhid for Virtual IP. But the problems were still there. After applying the patches, the problem was gone.
  • High Availability port forward to VIP -am i doing this right?

    13
    0 Votes
    13 Posts
    3k Views
    R
    @digger30 Perfect! Glad I could be of assistance.
  • LAN only HA + OpenVPN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Upgrade to 2.6 redeploy ZFS layout CARP

    Moved
    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    The maintenance mode switch is in the config and persists across reboots.
  • inconsistent icmp packets with VIP

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • After CARP failover packets go out the wrong WAN

    8
    0 Votes
    8 Posts
    3k Views
    C
    @chrullrich I replaced the pfSense 2.6 "local router/firewall"s in my test setup with OPNsense 22.1 (this is FreeBSD 13.0 instead of pfSense 2.6's 12.3) to get a second opinion. The behavior is the same: As soon as the CARP failover happens, everything sent towards the "Internet" goes out the default route with the NATed source address appropriate for the policy route. When I tried it the first time today I thought I saw ping (and only ping) work correctly, but now I cannot reproduce it. I probably just saw what I wanted to see.
  • CARP og IP Alias on additional IPs routed to us by the data center

    4
    0 Votes
    4 Posts
    2k Views
    P
    @derelict Yeah, same conclusion i had. @viragomann Yup.
  • No XMLRPC sync for rrd (Monitoring) settings, packages, Dashboard...

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Crestron NVX nor working with CARP interface

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • HA proxy issue to resolve local ip

    3
    0 Votes
    3 Posts
    2k Views
    O
    @viragomann Issue resolved with hostname override and haproxy listnening on LAN interface Thx
  • CARP IPv6 with routed network

    2
    0 Votes
    2 Posts
    2k Views
    S
    @skid9000 Perhaps some screenshots of the setup? Can you get it working without the VLANs and add those in after? I've not had occasion to set HA up with VLANs but have done so with aliases for other subnets on LAN.
  • Download-speed drops to 0 when pfSense statesync is enabled

    5
    0 Votes
    5 Posts
    2k Views
    U
    Just for your info. We've now seen the issue on multiple installations (even different hardware and pfsense versions) and could solve it on every single system by moving the sync-vlan to a dedicated physical interface.
  • Best way to access failover HA node from another subnet?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • ESX Physical NIC Failure Fails to Trigger Failover

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Issue with XMLRPC after adding a NAT rule

    7
    0 Votes
    7 Posts
    4k Views
    M
    @viragomann i think it's that https://forum.netgate.com/topic/150505/xmlrpc-restore_config_section-error because my rule to NAT with CARP ip make the backup node not able to reach the gateway so as it explain on that like you sent Filter reload sees the down gateway and resets states, terminating the connection currently used for XMLRPC. it make sense Thanks you very much, i think you resolve my issue :)
  • How Does "This Firewall (Self)" Apply in CARP Setups?

    17
    0 Votes
    17 Posts
    4k Views
    planedropP
    @kayavila OK this is great info, thank you! I read your entire write up you linked to as well but I'm still trying to wrap my brain around it. Think I've got it figured out but wanted to pose an example. This particular one will be between different VLAN/subnets rather than with WAN as I personally don't ever allow those connections via the WAN. So in theory if you had VLAN1 and VLAN2 setup, and there was an any-any rule below a block "This Firewall" rule on VLAN1, and some device on VLAN1 tried to contact the LAN interface of VLAN2, due to state syncing this would be let through? Since the first node would see the connection to the VLAN2 IP and see that it's not in it's block list but matches the any-any rule, and then the state would sync to the secondary which wouldn't assess it's rules? If that is the case, I would imagine not having a rule on the primary node that allows access to any would solve the issue, but since some people do use an any rule for internet access it could pose a problem (though best practice is of course to use an alias for RFC1918 and explicitly allow the inverse of that).
  • VIP & NAT

    vip nat mail
    3
    0 Votes
    3 Posts
    2k Views
    A
    @viragomann Thanks ! Went with the port forward + outbound option, NAT is working finally.
  • HA Setup

    2
    0 Votes
    2 Posts
    2k Views
    DerelictD
    @starsandbars What questions do you have after reading this? https://docs.netgate.com/pfsense/en/latest/highavailability/index.html
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.