• Incorrect definition of CARP roles

    20
    2
    0 Votes
    20 Posts
    5k Views
    patient0P
    @Xando said in Incorrect definition of CARP roles: What is your version of pfsense? It does run on 2.7.2 CE, I really suspect Hyper-V - QEMU combination. Do you have the patients and/or time to setup the backup node on Hyper-V (export the config of the backup node, import on another Hyper-V machine)? Add: Or a package capture, although I haven't done that for CARP and don't know what to expect.
  • CARP and (HE.net) GIF tunnel

    4
    0 Votes
    4 Posts
    4k Views
    G
    @jason0 I am just facing the same issue! Any tricks to get GIF over CARP?
  • CARP sporadically flopping to BACKUP and then back to MASTER

    15
    0 Votes
    15 Posts
    9k Views
    M
    @awebster You must uncheck Synchronize Vitual IPs in the System -> High Avail. Sync, otherwise the MASTER will keep overwriting the ADVBASE value. This also means you must manually configure the VIP address on each box, initially check the Synchronize Vitual IPs when you do the setup, then uncheck it to go into production, and never check it again. In the year 2025 I found this comment which resolved my problem!
  • CARP alternative

    24
    0 Votes
    24 Posts
    11k Views
    jimpJ
    @michmoor said in CARP alternative: if the secondary firewall needs to install patches/packages, is that when you just flip it to Master (One WAN IP being shared). It needs to have packages and updates at all times, not just when it's master. Otherwise you'd have to fail over to it to do any sort of maintenance, which defeats the idea of HA to reduce disruptions.
  • Corrected sketch

    1
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • CARP VIP in DMZ with few public IP addresses

    1
    1
    0 Votes
    1 Posts
    335 Views
    No one has replied
  • Adding HA/CARP/SYNC to existing Infrastructure

    5
    0 Votes
    5 Posts
    828 Views
    T
    @bp81 I ended up performing the addition using the first method you mentioned, plus the firewall configuration, and then it worked like a charm. It even added all of the packages to the new node. Now, I'm dealing with an IPSec speed issue, but that is a whole separate issue and one I have already opened another thread on. Thank you for taking the time to reply; it is much appreciated, and now if someone else is looking for the same thing, they have some really good options! Have an excellent day! TSoF
  • Different CARP LAN - WAN unplug behavior

    3
    2
    0 Votes
    3 Posts
    657 Views
    B
    @Nyxtorm said in Different CARP LAN - WAN unplug behavior: I'm replying to myself in case anyone has the same case. On my WAN interfaces, I had a static IPv4 (on the local subnet of my Livebox (French ISP router)), and an IPv6 in DHCP6. Once I've also set the IPv6, and the gateway v6 to static, the behavior is fine when I disconnect the WAN: the WAN interface goes to INIT, the others to BACKUP on the primary, and the secondary recovers MASTER status on all interfaces. I believe that this behavior is what you would typically see if one of your WAN interfaces (your IPv6 gateway in this case) is set to DHCP instead of static addressing. CARP/HA doesn't tend to work that well with WANs using DHCP instead of static addressing.
  • 0 Votes
    2 Posts
    442 Views
    B
    We are also seeing this since we upgraded to 24.11 with all patches applied. "A communications error occurred while attempting XMLRPC sync." on primary node. Accessing the webgui on secondary node hangs the firewall after 5-10 seconds. If we access the CLI everything seems fine and no hangs unless we initiate a reboot, Then the secondary hangs and we need to pull the power to recover. This happens usually after 5-14 days of uptime of secondary node.
  • Need to switch to Policy Based States, cant find it in 2.7.2?

    1
    0 Votes
    1 Posts
    207 Views
    No one has replied
  • CARP Phishing

    4
    0 Votes
    4 Posts
    683 Views
    T
    It's helpful thanks for sharing.
  • User privileges ( admin group ) don't sync.

    2
    0 Votes
    2 Posts
    387 Views
    M
    I am seeing a similar problem on pfSense+ 24.11 (patches applied). The ADMIN group being REMOVED from user rights assignments on secondary/backup HA cluster members any time the password is changed on the primary member. I am having to logon to the secondary members and manually add the user(s) back to the ADMIN group. This is not desired behavior, and I confirmed it is not happening on CE 2.7.2 (patches applied).
  • Custom CARP failover script - Not working?

    1
    0 Votes
    1 Posts
    226 Views
    No one has replied
  • 0 Votes
    6 Posts
    1k Views
    M
    @mike_vc I used to have this issue too, so on every new firewall I setup, I always make sure to add the following values under System, Advanced, System Tunables: net.inet.carp.preempt 1 net.inet.carp.ifdown_demotion_factor 240 Also, make sure that the primary firewall's CARP skew is 0, and the backup firewall's CARP skew is 100.
  • SYNC interfaces keeps being overwritten

    2
    0 Votes
    2 Posts
    438 Views
    M
    @michmoor Ok i know the problem. OPT interfaces are mismatched. I don't know how to align the OPT interfaces so the master and backup are in sync.
  • HAProxy backend hostname issues

    1
    0 Votes
    1 Posts
    376 Views
    No one has replied
  • HA Proxy, same server multiple ports (Turnkey Linux)

    4
    1
    0 Votes
    4 Posts
    633 Views
    V
    @CreationGuy That's not a problem. However, you have to configure a separate backend for this. Then you can configure a frontend rule to forward certain traffic to it. Actually you have all three services within a single backend pool, all in active mode. Hence you cannot determine which per rule. HAproxy can only load balance between these backens this way.
  • HAproxy 503 error on secondary domain

    10
    0 Votes
    10 Posts
    1k Views
    A
    I got it working after creating a new server to replace the one serving butiktrip.2nd
  • strange connectivity errors in HA

    8
    0 Votes
    8 Posts
    945 Views
    P
    @viragomann Hi viragomann, thank you very much for your time and investigation. Your answer was very important bringing me back to the correct path for debugging. The reason, why clients can't reach the internet was an inconsistent configuration of pfBlockNG between the two HA members. I've ignored erros like this: /rc.filter_configure_sync: New alert found: Unresolvable source alias 'pfB_BinaryDefense_v4' for rule 'NAT Allow HTTPS_2_xxxxxxxx' Dec 14 16:17:17 svrfw02 php-fpm[32037]: /rc.filter_configure_sync: New alert found: Unresolvable source alias 'pfB_DNSBLIP_v4' for rule 'NAT Allow HTTP_2_xxxxxxxx' Dec 14 16:17:17 svrfw02 php-fpm[32037]: /rc.filter_configure_sync: New alert found: Unresolvable source alias 'pfB_DNSBLIP_v4' for rule 'NAT Allow HTTPS_2_xxxxxxxx' Dec 14 16:17:18 svrfw02 php-fpm[32037]: /rc.filter_configure_sync: New alert found: There were error(s) loading the rules: /tmp/rules.debug:299: syntax error - The line in question reads [299]: rdr on lagg1.808 inet proto tcp from ! to 83.x.x.54 port 443 -> $SERVER_xxxxxxxx After fixing this, switching between carps members works correctly. Again, thank you for your assistance !!!!!
  • 0 Votes
    1 Posts
    220 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.