• Debug CARP backup promoting itself?

    4
    0 Votes
    4 Posts
    856 Views
    S
    @jimp said in Debug CARP backup promoting itself?: That can pretty much only be a layer 2 issue. Investigate your switch. Especially if it has any "smart" multicast or broadcast features like storm control. Thanks I found some debugging steps for my switches (Extreme networks) and ended up turning off IGMP snooping and it started to work. IGMP snooping was enabled on all VLANS but only one was having problems. Go figure, but at least we're back in business. Thanks!
  • What subnet should CARP VIP used ? /32 or the subnet of the gateway?

    3
    0 Votes
    3 Posts
    504 Views
    D
    Thanks for this confirmation. Indeed even /32 it will still works(confusing that with the VIP). But anyway i will keep it as the subnet mask of the gateway.
  • HA CARP setup, WAN not working

    3
    0 Votes
    3 Posts
    872 Views
    awebsterA
    As @Derelict suggests, consult the docs, and to that I would add that it is important to remember that at the base of Ethernet communication, it is between two mac addresses, layer 3 comes after, consequently, you need to make sure that the layer 2, mac address visibility is as you expect it to be on the devices facing the CARP cluster, both upstream and downstream, and as well as on pfSense boxes. Packet captures (detail level full) are a great way to check this, and pay particular attention to the ethernet addresses.
  • HA more secure firewall rules

    6
    0 Votes
    6 Posts
    755 Views
    JeGrJ
    @pmisch said in HA more secure firewall rules: Obviously no one is actually concerned with nonrestrictive rules for local interfaces. Of course we are. But that depends of the scope of the setup. Also it has something to do with filtering. As we do inbound filtering, the packet - for a direct connection to be exploited with a "pass any rule" - has to come from the other firewall's sync interface. Actually we set the IF up with "from: sync_net" to "sync_addr" but you'd also have to setup HA with unicast so no multicast address is used. Of course you also need the right port for https if you modified the WebUI port and need pfsync protocol like @Derelict explains.
  • [SOLVED] STP blocks CARP?

    3
    0 Votes
    3 Posts
    841 Views
    FrankyeF
    For posterity, the problem was initially solved by changing the switch between the two CARP members. Apparently the Aruba-flavoured HP switches call home ( to activate.arubanetworks.com ), and while I'm not sure why this wrecks things for a multi-WAN CARP setup, once the feature was disabled on the switch it ceased causing STP problems. We only found out because we had to replace the (replaced) CARP switch in a hurry (next planned setup will have redundant switches too). The guy who arrived first grabbed the first unattended switch he could find (it was the HP), without knowing the problem it initially caused, and was just happy to have it already configured with the correct VLAN groups. Asking around, it turned out the only change in configuration was the mentioned call home feature being disabled. Hope this helps someone. It had me banging my head against the rack for way too long.
  • HA setup on different hardware

    2
    0 Votes
    2 Posts
    394 Views
    DerelictD
    Works best if you do. In general, if it is worth HA it is worth doing right. Especially if you are responsible for moving multi-gigabits of traffic around.
  • HA Sync not working

    2
    0 Votes
    2 Posts
    364 Views
    T
    Okay seemd 18.9 ist the 2.4.4._p2 and 19.1 ist 2.4.4_p3. Both system have installed the p3 release according to /conf/upgrade_log [16/16] Upgrading pfSense from 2.4.4_2 to 2.4.4_3... [16/16] Extracting pfSense-2.4.4_3: ..... done @Mode: Please move to install / Update category
  • HA XMLRPC error

    44
    0 Votes
    44 Posts
    10k Views
    B
    Problem "solved". I have monitoring on my wan gw and both on my core router. I have disabled the monitoring on my wan gw and the error gone. So if you only have 1 public ip the gw monitoring should be off. Not the best solution but this workes only.
  • Outbound NAT using CARP IP

    2
    0 Votes
    2 Posts
    456 Views
    DerelictD
    Sounds like your ISP is not compatible with CARP. Some aren't. https://forum.netgate.com/topic/134297/cox-and-the-carp-mac/ https://forum.netgate.com/topic/146254/carp-outgoing-traffic-black-hole/
  • Downstream CARP upstream BGP

    3
    0 Votes
    3 Posts
    626 Views
    junicastJ
    Thank you for your response. We are going to use CARP. We will also build LAGGs for upstream and downstream links so the probability for failure should be pretty low. We thought about using BGP because our upstream devices can handle that and because it would mean less cabling / ports.
  • CARP outgoing traffic black hole

    8
    0 Votes
    8 Posts
    1k Views
    M
    Just FYI I got an answer to this, just not the one I wanted. See my response in https://forum.netgate.com/topic/134297/cox-and-the-carp-mac/17
  • COX and the CARP mac

    18
    0 Votes
    18 Posts
    3k Views
    DerelictD
    Yeah that's too bad. Thanks for pursuing it further and reporting back.
  • CARP/HA VMWARE ESXi 6.0.0 - Breaking HA after latest ESX patching ....

    2
    0 Votes
    2 Posts
    471 Views
    A
    @zimmy6996 said in CARP/HA VMWARE ESXi 6.0.0 - Breaking HA after latest ESX patching ....: Net.ReverseProsCheck Hey there Zimmy, i am setting up a similar setup within my vmware environment for HA, i have a couple questions for you. 1. where can i find the Net.ReverseProsCheck setting on my host? 2. on your secondary (slave) pfsense vm node did you configure all of the interfaces with an ip or only config the lan and carp interfaces. for example my primary pfsense has about 8 different networks: lan/wifi/wan/sonos/etc do i need to recreate all of these interfaces and set them with a static ip on the secondary box? Thank you in advanced any bit of guidance you can provide would be greatly appreciated.
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    26 Views
  • Tricking a WAN Only Router

    1
    0 Votes
    1 Posts
    272 Views
    No one has replied
  • 0 Votes
    3 Posts
    511 Views
    T
    Thanks for the insight. The other traffic on that physical interface will be negletible (only management data), so we will go for redundancy with VLAN.
  • VIPs not responding to clients

    4
    0 Votes
    4 Posts
    551 Views
    G
    OK, so I didn’t manage to work out what was specifically causing the problem. I was using a relatively old version of pfsense (2.3.3). I downloaded the latest version and redid the setup from scratch, and it just worked!
  • PfSense Vsphere redundancy LAN problem?

    1
    0 Votes
    1 Posts
    254 Views
    No one has replied
  • Additionnal Subnet /29 over a PPPOE Connection

    2
    0 Votes
    2 Posts
    407 Views
    Y
    @Yathus said in Additionnal Subnet /29 over a PPPOE Connection: I tried with /32 one by one, not working too. Finally i re-add all IP from my block, one by one, /32 over Locahost interface and now i can ping ! Over WAN interface it's not working...
  • VIP on Azure

    1
    0 Votes
    1 Posts
    357 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.