• Multi-WAN HA PPPoE from different ISP

    2
    0 Votes
    2 Posts
    375 Views
    S
    CARP is designed for a router failing or router interface going down, so the IP addresses will switch to the backup router. The CARP IP on WAN isn't going to work on both ISPs without some sort of SD-WAN arrangement.
  • HAProxy forwarding to NGINX Seafile

    5
    0 Votes
    5 Posts
    1k Views
    L
    @PiBa said in HAProxy forwarding to NGINX Seafile: How to do it, basically still follow the instructions and don't do what do you don't need.? If you don't want to offload, leave the ssl checkbox on the frontend 'off' and choose for mode 'ssl/https'.. As your then not using offloading, also leave the 'Encrypt-SSL' checkbox on the backend server 'off', (but do check the SSL-Checks checkbox..). Should be pretty easy.. give it a try, and if it doesn't work show the config as you have made, and tell what the stats page looks like, is the server green and if not what does lastchk column say?. I'm not inclined to write a step-by-step guide tailored to a specific user. As that would be more work for me, and less of a learning experience for you.. Really.. if it doesn't work first time you can try again for no additional fee Thank you with your help I got it done. Unfortunately I don't understand most of it because it is completely new territory for me. here it is difficult to say what you need and what you don't. the side can be reached from the outside and everything should go :) THANKS again
  • Execute script on failover

    1
    1 Votes
    1 Posts
    222 Views
    No one has replied
  • CARP failover caused by large transfer

    2
    0 Votes
    2 Posts
    341 Views
    jimpJ
    It might be your switch doing it and not the firewall, check for and disable things like multicast storm control to rule that out. Also you could set advbase higher on the VIPs so that it takes longer to trigger a failover. If you increase advbase to 1 that would take 1 second + skew to switch. Or use QoS to limit the initial burst to a lower speed.
  • 2 ISP, 2 pfSense and 2 Core Switch

    9
    0 Votes
    9 Posts
    1k Views
    D
    Nobody?!?
  • Only VIP no Interface IP

    2
    0 Votes
    2 Posts
    476 Views
    V
    @cmcologne said in Only VIP no Interface IP: Why is it not possible to only assign a CARP-IP to a Interface? Cause the interfaces which are sharing a CARP VIP must be able to communicate over Layer 3. So they need to have a unique IP each within a common subnet. It's possible to assign IPs out of a private subnet to the interfaces with some drawbacks. You may find threads discussing that topic here in this forum when you search for "CARP with only one public IP".
  • XMLRPC restore_config_section Error

    5
    0 Votes
    5 Posts
    1k Views
    S
    @jimp Brilliant. Thank you for clarifying that.
  • Sync error with packages since today

    3
    0 Votes
    3 Posts
    474 Views
    JeGrJ
    @jimp said in Sync error with packages since today: That's just one possibility, but something to consider. Absolutely, thanks. As this was some elevated by my boss because of the constant nagging ;) I can report, that Paighton from Support has found it out. To my surprise our old FreeRadius configuration (since the FR2 package times) contained a manual sync setting instead of using the systems sync (which would be the right way but I can remember it sometimes being bugged in the beginning). So as we switched UI Port a few weeks ago we never had any problem until there was a request for a new customer VPN server and Radius User. Didn't see that coming and perhaps would have found it in the end after debugging hours, but happy to say that support got it faster :) So always check your packages that allow syncing to the cluster peer and make sure the sync is using the right ip/port/credentials or is using the system ones in the first place :) Should have found that myself, but sometimes especially in your own setup environments you get stuck in a rut... In a customer setup I'm fairly certain we would've found that ;)
  • VIP persisting after removal

    7
    0 Votes
    7 Posts
    886 Views
    P
    I created a new vm, assigned the offending IP to that VM, let it hang out for a day, deleted the VM and the DNS records in Infoblox. Finally, after the weekend the record has cleared in Infoblox and presumably the switch. Switch weirdness in the end, I suppose. Thanks to Derelict for the suggestions in trying to track this down.
  • CARP Address showing Master on both FWs

    2
    0 Votes
    2 Posts
    380 Views
    jimpJ
    That's called out in the documentation in several places https://docs.netgate.com/pfsense/en/latest/book/highavailability/high-availability-troubleshooting.html#issues-inside-of-virtual-machines-esx https://docs.netgate.com/pfsense/en/latest/highavailability/configuring-high-availability.html#vmware-esx-users https://docs.netgate.com/pfsense/en/latest/highavailability/troubleshooting-high-availability-clusters.html#hypervisor-users-especially-vmware-esx-esxi [...]
  • CARP/NAT issue on cable modem

    1
    0 Votes
    1 Posts
    349 Views
    No one has replied
  • Maximum distance between HA devices / sync

    2
    0 Votes
    2 Posts
    388 Views
    jimpJ
    As long as the L1/L2 between them is clean and fast that should be OK. You can adjust advbase if it isn't. With a higher advbase it won't fail over as fast, but it is more tolerate of latency between the nodes. Having them in different places in the same building is not unheard of, or even separate buildings on the same campus. It's not ideal but it can work. I think we even had someone try to use CARP for HA to a node in a DC as some attempt at DR, but I can't remember if that ended up working in the end. When working with skew and base values for CARP VIPs, Skew values are 1/256th of a second, and base values add whole seconds. So if you set advbase to 1, then it would wait 1 second + skew, rather than only the skew time.
  • CARP not failing over all interfaces

    1
    0 Votes
    1 Posts
    352 Views
    No one has replied
  • Unplug WAN cable on primary and lose internet access

    lan failover routing wan sg-1100
    1
    0 Votes
    1 Posts
    732 Views
    No one has replied
  • Using CARP primary AND backup for DNS?

    5
    0 Votes
    5 Posts
    549 Views
    jimpJ
    In other words: Using the CARP VIP you get guaranteed failover and consistent behavior across all client platforms. Using both you are completely reliant upon the client to behave in specific ways, which only gets worse on networks with many different types of clients.
  • 0 Votes
    3 Posts
    533 Views
    J
    @Derelict Thanks for the confirmation that the behaviour is as expected. Very much appreciated.
  • VRRP Cluster on lan behind pfsense - how much arp is too much?

    1
    0 Votes
    1 Posts
    293 Views
    No one has replied
  • CARP IPv6 /127 not working

    2
    0 Votes
    2 Posts
    622 Views
    T
    I think I'm at least partially encountering this bug, which I updated with what I'm seeing: https://redmine.pfsense.org/issues/6579
  • Override xmlrpc version check

    3
    0 Votes
    3 Posts
    464 Views
    C
    Thanks for the reply
  • HA setup, client hostname request not added to DNS

    3
    0 Votes
    3 Posts
    502 Views
    S
    Thanks for contacting me. We did mostly static reservations but then it got too much overhead with devices coming online. And yes, when the backup dhcp answers it registers with unbound on the backup DNS where I can see the entry. but the backup DNS does not sync back to the master, and when there is an update from the master the entry in the backup gets wiped (i think, didn't verify). I thought I had a solution by blocking dhcp from 0.0.0.0 to lan-address:67 which gets propagated to the backup. and dhcp traffic is only received via the carp address. That seemed to work but then I found a client with which it did not work haven't found why. The proper way is to turn DDNS and have a separate DNS server to take the registration from either dhcp server. This will also solve one deficiency of pfsense where it can not resolve/access DNS servers on the other side of an ipsec tunnel (if you have branch offices) We had to resort to having a second caching DNS server for that purpose to forward inquiries too.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.