• CARP crashes with two LAN sub networks on the same WAN network

    1
    2
    0 Votes
    1 Posts
    711 Views
    No one has replied
  • CARP gets corrupted when state sync is enabled

    5
    0 Votes
    5 Posts
    1k Views
    D
    @steveits Yes I need Snort on both interfaces, I like to know for example who from my family wants to download torrents. I have Zabbix and FreeRADIUS package install along with Snort.
  • Newbe HA question

    4
    0 Votes
    4 Posts
    1k Views
    kiokomanK
    @joezyz think about A Records later, first make the network work configure it step by step the gateway to the network will be the shared IP it's easy only after you understand it
  • Additional questions on CARP/HA behavior when using a single public IP

    1
    1 Votes
    1 Posts
    765 Views
    No one has replied
  • Multi-Wan High availability question

    6
    0 Votes
    6 Posts
    1k Views
    V
    @bp81 Exactly. You configure the secondary WANs as private network, so that they can talk together. Then you hook up the CARP VIP on this interface on the master and add the WAN gateway in System > Routing > Gateways to this interface. Internet access over the secondary WAN has only the router which has the master role. I.e. in case of failover to the secondary box it takes over the WAN2 CARP and gets access to the internet over WAN2. In normal state when the secondary box is backup it can access the internet over WAN1. So WAN1 GW has to be set as default gateway. There is also a workaround to get internet on the backup router over a single WAN connection and a single IP over the master, but that makes no sense in a Multi-WAN setup.
  • CARP/Pfsync Across Multiple Sites

    13
    0 Votes
    13 Posts
    4k Views
    H
    @binary_bandit I went with a solution roughly as explained by Mike here.. the advice came from elsewhere, but the comments were basically the same. Have two sites both routable always, each with its own carp cluster (no pfsync across sites, not necessary for me), but only one is routed to at a time. I allow my upstream provider to route for me, but could do this myself later by enabling/disabling an IP at either site and have them route to that instead. Each site is completely independent and although they advertise 3 public ranges they both have their own native/local range of public ips too. Really the concensus from everyone I've spoken to is to do this with switches and bgp not pfsense, which is a huge bottleneck - but it does work.
  • Firewall rules stopped syncing after NAT change

    1
    1
    0 Votes
    1 Posts
    808 Views
    No one has replied
  • HAProxy: HTTP frontend works, HTTPS frontend doesn't

    2
    0 Votes
    2 Posts
    1k Views
    johnpozJ
    @ronrn18 I have a domain with cloudflare, that points to my wan IP. And I use haproxy to do ssl offloading of this service because its just a docker and https is not really supported. I am not having any issues with this. I use a acme cert.. I can bounce off the proxy both internally, and externally my users are able to access it. I even share the outside 443 port being used with openvpn and have not problems.
  • Trying to config same subnet on two physical ports per firewall in HA

    1
    1
    0 Votes
    1 Posts
    616 Views
    No one has replied
  • VIP addresses stop working

    12
    0 Votes
    12 Posts
    3k Views
    DerelictD
    @magnus-maximus said in VIP addresses stop working: https://datatracker.ietf.org/doc/html/rfc3768#section-8.2 That seems to indicate what is included in the ARP IS AT response in the ARP protocol itself. It is silent about the source MAC address of the frame containing the ARP response. 8.2 pretty much describes what CARP does. The MAC address in the ARP response for a CARP VIP is always the virtual CARP MAC address. What, exactly, is the ISP doing that is breaking things? Why are they not issuing another ARP request when they have traffic for an IP address after the ARP cache has expired?
  • PFSENSE Cluster change password impact

    14
    0 Votes
    14 Posts
    3k Views
    P
    @viktor_g Thank you very much for your help and all details @viktor_g . I have successfully implemented the changes :) Regards
  • Adding VLANs in HA Config

    1
    0 Votes
    1 Posts
    881 Views
    No one has replied
  • pfSense HA LAN Interfaces Only

    Moved
    91
    0 Votes
    91 Posts
    29k Views
    V
    @iptvcld Interestingly. Didn't know that. Was assuming only the master is handing out DHCP leases and only the lease state is synced to the other node.
  • HA/CARP DHCP Lease Hand Out

    3
    0 Votes
    3 Posts
    1k Views
    S
    @iptvcld said in HA/CARP DHCP Lease Hand Out: showing the DHCP server IP of my backup node interface IP Normal: https://forum.netgate.com/topic/166542/pfsense-ha-lan-interfaces-only/27
  • 0 Votes
    2 Posts
    999 Views
    S
    @bp81 To sync states (for a transparent changeover) you need identical interfaces, see this. Otherwise the hardware shouldn't matter so much. Presumably the secondary would be using the same memory and packages as the primary.
  • Hard Code CARP MAC Address to something of my choosing

    1
    0 Votes
    1 Posts
    675 Views
    No one has replied
  • CARP VLAN and switch core routing doubts.

    1
    0 Votes
    1 Posts
    673 Views
    No one has replied
  • Need static IP?

    3
    0 Votes
    3 Posts
    1k Views
    perikoP
    @steveits them this is not for a mortal like me...thanks buddy.
  • HA config crashses

    3
    0 Votes
    3 Posts
    989 Views
    C
    @viragomann Thank you. Working perfectly now.
  • Cert Manager NOT syncing. How to diagnose?

    4
    0 Votes
    4 Posts
    1k Views
    MrPeteM
    Solved it. Diagnostic Method: Review ALL the basics... Interfaces are same, same order (easiest for me: check the Interfaces menu item links :) ) XMLRPC Sync setup is correct: correct IP, login, pw on Master. NONE of those on Backup. Sync setup is correct in other packages (depends on pkg) Fix any errors Now make a change in the area(s) that were not syncing In my case: Oops: I had an IP still in "Sync Config to IP" Then, make small changes as needed... changing one static DNS assign-> All transferred changing one HAproxy item -> All transferred changing one Cert item -> all sync'd incl old/bad certs gone etc.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.