• HA LAN interface into Layer 3 switch - InterVLAN Routing

    1
    0 Votes
    1 Posts
    314 Views
    No one has replied
  • CARP with single PPOE - Make internet working from the slave node

    3
    0 Votes
    3 Posts
    524 Views
    G
    It survived also the CARP Maintenance and the upgrade of both units, without the Port Forward NAT. The only issue is that in this way OpenVPN Client (to a VPN Service) binded to WAN interface will start on both nodes because both will have connectivity. Solution is to bind to a real CARP VIP like LAN and it correctly starts only on the node where LAN is MASTER.
  • openvpn client failover ... fails

    1
    3
    0 Votes
    1 Posts
    327 Views
    No one has replied
  • 0 Votes
    1 Posts
    232 Views
    No one has replied
  • HA Setup with 1 WAN IP and port forward to FTP Server [SOLVED]

    10
    0 Votes
    10 Posts
    1k Views
    B
    admin please close this thread. minimum 3 IP's for CARB. Thanks everyone for support.
  • Packet loss when pinging Carp vip

    3
    0 Votes
    3 Posts
    675 Views
    O
    I have just realized that I had the mtu set to 9000 everywhere except on the routers. Setting it to 9000 on the routers solved the problem...
  • pfSense Setup with 250+ CARP VIPs

    9
    0 Votes
    9 Posts
    1k Views
    DerelictD
    I'd get an ISP that is willing to do things right. Just sayin'. I'd pcap and see exactly what's happening. Maybe they have something silly like an inability to ARP for more than X IP addresses per MAC address or something. It is almost certainly NOT the pfSense software.
  • DHCP Server wrong IP CARP

    4
    2
    0 Votes
    4 Posts
    676 Views
    T
    @jimp said in DHCP Server wrong IP CARP: On the primary, add the secondary interface address in each active DHCP server tab. Yup, did that! Thanks both of you - I didn't realize it was supposed to be that way, and although I've read the HA docs a number of times I guess I missed the part where DHCP server address would show as the actual IP of the box, not the VIP. Thank you! Cheers Tiwing
  • Impossible to encode value '' from type 'NULL'

    2
    0 Votes
    2 Posts
    421 Views
    T
    OK forget it. I was messing around and disabled, then re-enabled guest interface on both primary and secondary and problem is now gone. I can't explain why, but ..... woohooo! mods, you can close or outright delete this thread! cheers
  • Help with script for single DHCP WAN IP in HA pair

    1
    0 Votes
    1 Posts
    367 Views
    No one has replied
  • CARP/HA with keepalived in the network!

    5
    0 Votes
    5 Posts
    1k Views
    P
    We are having L3 switches and I can't find anything about that... I'm thinking more and more that our pfSense appliance is having a hard time with the traffic!
  • Interface LAN stay master

    15
    0 Votes
    15 Posts
    2k Views
    Y
    Thank you, I'm going to look at all this documentation and I'll come back to tell you the solution to the problem or more specific questions for more specific help.
  • Multi-WAN HA PPPoE from different ISP

    2
    0 Votes
    2 Posts
    409 Views
    S
    CARP is designed for a router failing or router interface going down, so the IP addresses will switch to the backup router. The CARP IP on WAN isn't going to work on both ISPs without some sort of SD-WAN arrangement.
  • HAProxy forwarding to NGINX Seafile

    5
    0 Votes
    5 Posts
    1k Views
    L
    @PiBa said in HAProxy forwarding to NGINX Seafile: How to do it, basically still follow the instructions and don't do what do you don't need.? If you don't want to offload, leave the ssl checkbox on the frontend 'off' and choose for mode 'ssl/https'.. As your then not using offloading, also leave the 'Encrypt-SSL' checkbox on the backend server 'off', (but do check the SSL-Checks checkbox..). Should be pretty easy.. give it a try, and if it doesn't work show the config as you have made, and tell what the stats page looks like, is the server green and if not what does lastchk column say?. I'm not inclined to write a step-by-step guide tailored to a specific user. As that would be more work for me, and less of a learning experience for you.. Really.. if it doesn't work first time you can try again for no additional fee Thank you with your help I got it done. Unfortunately I don't understand most of it because it is completely new territory for me. here it is difficult to say what you need and what you don't. the side can be reached from the outside and everything should go :) THANKS again
  • Execute script on failover

    1
    1 Votes
    1 Posts
    227 Views
    No one has replied
  • CARP failover caused by large transfer

    2
    0 Votes
    2 Posts
    374 Views
    jimpJ
    It might be your switch doing it and not the firewall, check for and disable things like multicast storm control to rule that out. Also you could set advbase higher on the VIPs so that it takes longer to trigger a failover. If you increase advbase to 1 that would take 1 second + skew to switch. Or use QoS to limit the initial burst to a lower speed.
  • 2 ISP, 2 pfSense and 2 Core Switch

    9
    0 Votes
    9 Posts
    1k Views
    D
    Nobody?!?
  • Only VIP no Interface IP

    2
    0 Votes
    2 Posts
    518 Views
    V
    @cmcologne said in Only VIP no Interface IP: Why is it not possible to only assign a CARP-IP to a Interface? Cause the interfaces which are sharing a CARP VIP must be able to communicate over Layer 3. So they need to have a unique IP each within a common subnet. It's possible to assign IPs out of a private subnet to the interfaces with some drawbacks. You may find threads discussing that topic here in this forum when you search for "CARP with only one public IP".
  • XMLRPC restore_config_section Error

    5
    0 Votes
    5 Posts
    1k Views
    S
    @jimp Brilliant. Thank you for clarifying that.
  • Sync error with packages since today

    3
    0 Votes
    3 Posts
    524 Views
    JeGrJ
    @jimp said in Sync error with packages since today: That's just one possibility, but something to consider. Absolutely, thanks. As this was some elevated by my boss because of the constant nagging ;) I can report, that Paighton from Support has found it out. To my surprise our old FreeRadius configuration (since the FR2 package times) contained a manual sync setting instead of using the systems sync (which would be the right way but I can remember it sometimes being bugged in the beginning). So as we switched UI Port a few weeks ago we never had any problem until there was a request for a new customer VPN server and Radius User. Didn't see that coming and perhaps would have found it in the end after debugging hours, but happy to say that support got it faster :) So always check your packages that allow syncing to the cluster peer and make sure the sync is using the right ip/port/credentials or is using the system ones in the first place :) Should have found that myself, but sometimes especially in your own setup environments you get stuck in a rut... In a customer setup I'm fairly certain we would've found that ;)
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.