• Stop specific service when CARP in Maintenance.

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • HAproxy issue with Transparent ClientIP

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Couple question: Force Master and Why CARP VIP on WAN?

    4
    0 Votes
    4 Posts
    2k Views
    S

    @skorpio The CARP alias skew is set in each alias: https://docs.netgate.com/pfsense/en/latest/recipes/high-availability.html#configuring-the-carp-virtual-ips

    "A primary node is typically set to 0 or 1, secondary nodes will be 100 or higher. This adjustment is handled automatically by XML-RPC synchronization."

  • Single WAN PPPOE Carp HA OpenVPN - remote LAN issue

    10
    0 Votes
    10 Posts
    3k Views
    MrPeteM

    @crl was this resolved? I'm having some issues myself.

    Hoping you found your solution. :)

  • Change interface MAC via commandline?

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • HA behind ISP modem/router

    9
    0 Votes
    9 Posts
    2k Views
    Urbaman75U

    @viragomann switching to CARP VIP in the OpenVPN config solved the issue, now I'm getting to the LAN. Thank you very much for pointing me on the right direction!

  • pfSense HA on Proxmox, DHCP strangeness

    2
    0 Votes
    2 Posts
    2k Views
    Urbaman75U

    Ok, found out the problem, maybe.

    there was a space in the Gateway IP in VAN50 dhcp settings also checked "Time from UTC to Local"

    With both changes, now DHCP works flawlessly.

    Thank you.

  • Rule problem in a cluster

    6
    0 Votes
    6 Posts
    2k Views
    C

    @steveits
    Hello,
    When I add the rule on the master, it is duplicated on the second pfsense. The master pfsense remains master in "status/CARP".
    The second pfsense is in "Backup".
    Yes the problem is not temporary, I have a total loss to the internet.
    The master's wan interfaces are up and communicating with their gateway. But unable to access the internet.
    The interfaces are in green on the dashboard.

    Regards.

  • PfSense HAProxy adds amp; on http check URL

    2
    0 Votes
    2 Posts
    2k Views
    A

    Is any one knows why the URL is getting changed by adding amp; every time while saving the configuration? this is kind of miss-behavior

  • 1 Votes
    4 Posts
    2k Views
    SipriusPTS

    @klaws Mail Report just let you know in time any issues that could occur.

    At least for me it helps a lot dealing with pfsense clusters.

    Examples:

    like when some CARP state changes states (master or backup),

    17:51:09 HA cluster member "(10.0.13.1@ixl3.13): (IXL3_VLAN13_IT_ADMINS)" has resumed CARP state "BACKUP" for vhid 12

    when WANs went offline or online in gateway groups:

    11:07:07 MONITOR: WAN_ROUTERA_WAN2_GW is available now, adding to routing group GW_GROUP x.x.x.225|172.16.2.2|WAN_ROUTERA_WAN2_GW|34.651ms|87.308ms|18%|online|loss

    when services stop working and watchdog service detect and handle the situation,

    9:26:00 Service Watchdog detected service openvpn stopped. Restarting openvpn (OpenVPN server: Internal Devices)

    when rules cannot load:

    15:42:40 There were error(s) loading the rules: /tmp/rules.debug:51: cannot load "/var/db/aliastables/pfB_NAmerica_v6.txt": Invalid argument - The line in question reads [51]: table <pfB_NAmerica_v6> persist file "/var/db/aliastables/pfB_NAmerica_v6.txt"

    when XMLRPC communication fails:

    17:29:59 A communications error occurred while attempting to call XMLRPC method restore_config_section: 16:43:28 Exception calling XMLRPC method restore_config_section # Impossible to encode value '' from type 'NULL'. No analogous type in XML_RPC.
  • Strange behaviour on CARP enabled devices

    6
    0 Votes
    6 Posts
    2k Views
    N

    @steveits It got solved. Rebooting the firewall did not help, resetting the states neither, but disabling the WAN interface and enabling it again DID help.
    And all is looking good again now

  • Configuring a /29 subnet

    3
    0 Votes
    3 Posts
    2k Views
    T

    049f21fe-c7d0-4640-8834-d5f7af093f0a-image.png

  • GW Group and/or CARP sync anomaly. Bug or ???

    5
    0 Votes
    5 Posts
    2k Views
    MrPeteM

    @viragomann

    The one thing I notice, examining config.xml: the internal ID for a gateway group is pretty unique.

    No idea how that is supposed to sync or not...

    I'm going to do more experiments tomorrow...

  • PPPoE is no longer always dynamic

    6
    0 Votes
    6 Posts
    2k Views
    MrPeteM

    @mrpete @viragomann
    I've got it working close to 100% now :)

  • 0 Votes
    10 Posts
    2k Views
    MrPeteM

    @mrpete @netblues @Cool_Corona

    I've updated the OP with results of my first set of experiments.

    When I have a chance, I'll redo a full install on secondary CARP and see how that goes.

  • [Solved] How should endpoints handle MAC changes during HA failover?

    4
    0 Votes
    4 Posts
    1k Views
    MrPeteM

    @netblues
    That page does not say that... But it does link to the a page hinting at this:
    https://docs.netgate.com/pfsense/en/latest/highavailability/index.html#switch-layer-2-concerns

    While "CARP VIPs each have their own unique MAC address derived from their VHID" "At minimum, the switch must... Allow the CARP VIP MAC address to move between ports."

    Thanks! I think I am beginning to understand this... 😏

  • 2.6 upgrade: XMLRPC fail. Missing file on secondary side?

    3
    0 Votes
    3 Posts
    1k Views
    MrPeteM

    @netblues duuuh. Thanks. That s embarrassing. I completely missed that pkg on my list to be manually installed.

    Thanks! 🤠

  • Primary neither master or backup on new CARP VIP

    2
    0 Votes
    2 Posts
    1k Views
    P

    Never mind, a reboot solved it.
    -nic

  • Multiple VLANs in HA config

    10
    0 Votes
    10 Posts
    2k Views
    N

    @viragomann said in Multiple VLANs in HA config:

    So ensure the VLAN is also properly configured on the switch.

    omg , so stupid :)

    Thx it all works now

  • HA Sync interfaces mismatch solved

    1
    0 Votes
    1 Posts
    672 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.