• 1 Votes
    3 Posts
    681 Views
    R

    This seems to be identical to:

    https://forum.netgate.com/topic/161152/strange-problem-dhcp-failover-after-upgrade-to-2-5-0-xmlrpc-bug

    Solution:
    https://redmine.pfsense.org/issues/11519

  • 0 Votes
    1 Posts
    345 Views
    No one has replied
  • Cannot using LAN VIP to access control website

    7
    0 Votes
    7 Posts
    1k Views
    T

    @viragomann Thanks for your reply. Currently, I can't reach CARP IPs, I don't know where I'm wrong, CARP IPs of LAN is 172.16.100.4. I only can ping CARP IPs of WAN 10.84.100.4

    and if I create master 10.84.3.2, slave 10.84.3.3 with VLAN 3. After set up that you can add 10.84.3.1 as CARP VIP on the master. I cannot ping as well.

  • Distribute VIP's to specific LAN users

    2
    0 Votes
    2 Posts
    591 Views
    V

    @prk
    You can do that all with Firewall > NAT > Outbound. Switch it into hybrid mod, then you can add rules to override the default behaviour (masquerading).

    If you strict want to forward a public IP to a certain internal and have this internal IP use that public, you can use NAT 1:1 rules.

    However, before you have to assign each IP out of the additional /29 subnet in Firewall > virtual IPs as type "IP Alias" to your WAN.

  • Trouble Syncing DNS Resolver using XMLRPC over VPN...

    2
    0 Votes
    2 Posts
    666 Views
    T

    Still an issue with 2.5 by the way...

  • 0 Votes
    3 Posts
    1k Views
    cesarmsjC

    @jimp said in Can I find out the status of the CARP interface (BACKUP / MASTER) through a command?:

    ifconfig -a | grep 'carp:'

    This solution looks perfect, I only made one adjustment to get only the MASTER / BACKUP:

    UserParameter = pfsense.carp.state, ifconfig -a | grep 'carp:' | cut -d '' -f2 | sed -n 1p

    Sed is for taking only one CARP interface, it is very rare for one interface to be BACKUP while the others are MASTER, and vice versa.

    PS: I don't know if I should close this post as resolved or how to do it if I should.

  • HA on dual-ESXi: no LAN, no party

    3
    0 Votes
    3 Posts
    736 Views
    T

    @lucazio

    Hi,
    what you want is net.inet.carp.preempt.

    The preempt shold be enabled. That means if one interface is failing on a pfSense then ALL Interface do a failover not only one.

    Also bare in mind I have seen some complications with carp and multicast on the esxi and the security settings of the protgroup / swtich. (Multicat - promismode / ARP address Change)

  • Accessing VIP addresses from LAN

    2
    0 Votes
    2 Posts
    506 Views
    H

    Once I was able to properly google for things I already know I didn't know I found this.

    https://forum.netgate.com/topic/35849/accessing-wan-s-public-ip-from-the-lan-not-working-please-help/6

    Split DNS worked like a charm for me!

    Might need to enable reflection in the future but for now it the DNS method works fine.

  • Alert "XMLRPC method captive_portal_sync" in 2.5

    22
    0 Votes
    22 Posts
    2k Views
    jimpJ

    @free4 said in Alert "XMLRPC method captive_portal_sync" in 2.5:

    @jimp Oh ok

    But wait...What's the point to backport the fix into RELENG_2_5_0 then ?

    So it will be included in the next patch release, whenever that may be.

  • Routing using a single CARP WAN IP

    2
    0 Votes
    2 Posts
    529 Views
    V

    @mr_jinx
    You can configure a failover group with the WAN gateway and the others box LAN interface.
    So on the secondary you have to add the primarys LAN address as a gateway first. Then add a gateway failover group where you set the WAN GW as tier 1 and the pirmarys LAN IP as tier 2.
    So now if the WAN GW is not accessible (cause the primary owns the WAN CARP) it goes out over the primary.

    You can do the same on the primary with the secondarys LAN IP to retrieve updates when it's in CARP maintenance mode.

  • XMLRPC Sync to multiple secondary FWs

    3
    0 Votes
    3 Posts
    670 Views
    T

    @viragomann
    I already tried to build a chain, but dont like this aproach.
    If one is temporary not reachable the update gets lost for all others in the chain and you'll not notice it.

  • Help VIP to connect subnets

    2
    0 Votes
    2 Posts
    652 Views
    L

    @chrisnz
    Hello, being of two distinct networks which, I think, should not be able to communicate with each other, the solution is to add an interface to the pfSense router, in your case not physical.
    Since your switch is web managed the best thing you can do is to create a VLAN dedicated to the Guest network and use the switch for all your private connectivity. And only for those!
    You will find everything you need in the pfSense and Netgear documentation, in the respective sections that talk about VLANs.
    Googling I found this which looks a lot like the recommended solution:
    pfSense router-on-a-stick VLAN configuration with a Netgear GS108E
    I hope it will be useful to you.

  • HA/CARP, with DHCP error

    6
    0 Votes
    6 Posts
    1k Views
    lexxaiL

    @bimpe said in HA/CARP, with DHCP error:

    https://forum.netgate.com/topic/106394/dhcp-not-working-properly-solved

    The XMLRPC process will automatically add +100 to each skew when synchronizing the VIPs to the secondary node.

    skew on second server with DHCP is more than 20 by ifconfig | grep carp ?

  • Another XMLRPC communication error

    24
    0 Votes
    24 Posts
    4k Views
    JeGrJ

    @koby-peleg-hen said in Another XMLRPC communication error:

    ALL I want to achieve is 2 nodes on Heztner Cloud that can be sync between them for easy management

    Sync is always primary to standby, never "to each other" or "between them". So I'd be careful with that. If you just want the config to be synced but no HA why sync at all? Just to have the same Aliases? If you don't run HA you commonly have other NICs/Interfaces or additional Interfaces and rules, syncing that to another node with a whole different setup makes no real sense to me?

  • Suricata XMLRPC errors

    1
    0 Votes
    1 Posts
    415 Views
    No one has replied
  • VHIDs with two CARP HAs in the same LAN network?

    5
    0 Votes
    5 Posts
    979 Views
    N

    @derelict said in VHIDs with two CARP HAs in the same LAN network?:

    The CARP MAC address is derived from the VHID. This also applies to VRRP on the same segment.
    You must use unique VHIDs on the same broadcast domain or you will experience MAC address collisions.

    Hi, i will try it with unique VHIDs and let you know my results! Thanks for your fast help, regards Norbert!

  • VHIDs with two CARP HAs in the same LAN network?

    1
    0 Votes
    1 Posts
    273 Views
    No one has replied
  • Advskew and Gateway Status

    1
    0 Votes
    1 Posts
    837 Views
    No one has replied
  • CARP WAN 3 IPs - DHCP assigned

    10
    0 Votes
    10 Posts
    5k Views
    T

    Yes. consumer router between ISP modem and both pfsense. set the carp WAN IP as DMZ so you don't run into double nat scenario, and if you wish set the consumer router to hand out the same IP each time to each pfsense box. works like a charm. Yes, single point of failure in the consumer router, but with no rules or anything on it it's easy to swap out if you have a failure. perfect for home use or work.

  • GIF Tunnel Parent Interface IP Alias of CARP VIP Bug

    1
    0 Votes
    1 Posts
    297 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.